sha3:0528dad004c75aa3d461847c862cd0e73f1d8a07bda13d72e202e43e7e5e79efIntact8e0aa73ab67b19f26dfc0f7d9cc14460fd27892840746c3e657f665c40f49f0eprev:7320efc35e8cRegisterGlossary
What is C3PAO?
A C3PAO is an organization authorized by the Cyber AB to conduct official CMMC Level 2 certification assessments.
2fe880aa69298f6a1b9f0586dd7433ed2ef798dcfa6c7333e67564c695223dcaprev:8e0aa73ab67bC3PAO stands for CMMC Third-Party Assessment Organization.
A CMMC Third-Party Assessment Organization (C3PAO) is the entity that performs your formal Level 2 assessment and issues certification. C3PAOs are authorized and listed on the Cyber AB Marketplace.
C3PAOs continue to conduct authorized Level 2 assessments, but the Department suspended the Phase II transition and future implementation milestones on July 13, 2026. Contractors should schedule against actual contract and prime requirements rather than the former November deadline.
A C3PAO cannot both consult for and assess the same client within a defined window, which is why readiness partners (RPOs) and assessors work as separate roles in the ecosystem.
0528dad004c75aa3d461847c862cd0e73f1d8a07bda13d72e202e43e7e5e79efprev:2fe880aa6929Related records
Guides and articles describe the work. The evidence that work produces is described in three proof pages and one architecture page.
- proof.state
- Proof of State. What the environment was, as of a date someone else picks: point-in-time records, content hashed and chained.
- proof.change
- Proof of Change. Who or what altered the environment, under what authority, with before and after state hashes.
- proof.agency
- Proof of Agency. What a machine was permitted to do before it acted, what it did, and what would have stopped it.
- architecture
- Architecture. How the chain is built and where it lives: inside your tenant, with no egress of evidence.
Related terms and reading
Know the term. Then see the record behind it.
- Sealed
- Last amended