How to Choose a C3PAO, and When to Book One
A C3PAO is not a consultant with a better logo, and 32 CFR 170.9 guarantees more about one than most buyers realize. An authorized CMMC Third-Party Assessor Organization must "achieve and maintain compliance with ISO/IEC 17020:2012(E)" within 27 months of authorization, clear a Foreign Ownership, Control or Influence review by submitting an SF 328 and receiving a non-disqualifying eligibility determination from the CMMC Program Management Office, put every person participating in a Level 2 certification assessment through a Tier 3 background investigation, field an assessment team of at least a Lead Certified CMMC Assessor plus one more assessor, and undergo a Level 2 certification assessment of itself, which the rule notes pointedly "will not result in a CMMC Status of Level 2 (C3PAO)". Those are entry conditions, not differentiators. And as of August 2026, with Phases 2 through 4 suspended, most contractors reading this should not be booking one at all.
This article separates what the rule already guarantees from what actually varies, covers the conflict rule that decides who you are allowed to hire, and gives the booking decision honestly.
Key takeaways
- 32 CFR 170.9 already fixes foreign-ownership screening, personnel vetting, and minimum team composition, so vetting questions about those are wasted breath.
- Only an authorized or accredited C3PAO can perform a Level 2 certification assessment, per 32 CFR 170.17(c)(1). Those are two different states: ISO/IEC 17020 accreditation is due within 27 months of authorization, so ask which one your candidate holds today.
- The rule delegates conflict-of-interest detail to the Accreditation Body's policies, and the practical effect is that the organization that builds your program does not certify it.
- What genuinely differs between assessors is sector familiarity, team continuity, scheduling behaviour, and how they handle a disputed finding.
- With Phases 2 through 4 suspended since July 13, 2026, booking an assessment your contracts do not require is a spending decision, not a hedge.
What the rule already guarantees, so you can stop asking
Buyers arrive with a vendor-vetting checklist built for consultancies, and most of it is answered by the regulation before the call starts.
Accreditation, with a caveat worth the question
170.9(b)(2) requires a C3PAO to achieve and maintain compliance with ISO/IEC 17020:2012(E), the international standard for bodies performing inspection, within 27 months of authorization. Read the window: an organization inside its first 27 months can be authorized without having completed accreditation yet, and 170.9(b)(1) treats authorization and accreditation as two things a C3PAO obtains. 170.17(c)(1) permits either an "authorized or accredited" C3PAO to run your assessment. So the useful version of this question is not "do you have a quality system" but "are you accredited to ISO/IEC 17020 today, or still inside the 27-month window", and the answer is checkable on the Cyber AB Marketplace.
Foreign ownership
170.9(b)(5) requires compliance with Foreign Ownership, Control or Influence provisions through submission of an SF 328 and a non-disqualifying eligibility determination from the CMMC Program Management Office. This is screened centrally rather than by you.
Personnel vetting
170.9(b)(3) requires that all C3PAO company personnel participating in the Level 2 certification assessment process complete a Tier 3 background investigation. Every person who will see your environment has been through it.
Team composition
170.9(b)(12) requires an assessment team of at least two people: a Lead Certified CMMC Assessor and at least one other Certified CMMC Assessor. A solo assessor is not a cheaper option; it is not an option.
The assessor's own posture
170.9(b)(6) requires the C3PAO to undergo a Level 2 certification assessment itself, and states that the assessment "will not result in a CMMC Status of Level 2 (C3PAO)". Worth knowing because it means an assessor advertising its own CMMC status is describing something the rule explicitly does not create.
The consequence: questions about screening and staffing tell you nothing, because every authorized C3PAO answers them identically. Current ISO/IEC 17020 accreditation status is the one item on the standard checklist that can still differ between candidates, so ask that one and spend the rest of the call on the things that vary.
What actually differs between assessors
Four things, in roughly descending order of how much they affect your experience.
Sector familiarity
An assessor who has worked through a dozen small manufacturing environments understands operational technology, test equipment, and shop-floor realities, and will not spend two days learning why a machine controller cannot run an endpoint agent. An assessor whose experience is entirely software companies will get to the same answer more slowly. This is the largest real difference and it is the least advertised.
Team continuity
Ask who will actually be on the team, and whether the lead you speak with in the first call is the lead who runs the assessment. Assessment teams are at least two people by rule, and the identity of those two matters more than the logo above them.
How they handle a disputed finding
Ask for the process directly: what happens when your team believes a requirement is met and the assessor's initial read says otherwise, who adjudicates, and at what point in the assessment that conversation occurs. An assessor who has a clear answer has been through it. One who has never had a disputed finding has either had a very short career or does not surface disagreements, and neither is reassuring.
Scheduling behaviour under uncertainty
Given the current suspension, ask what happens to a deposit and a slot if the program's requirements change. The answer is a contract term, and it should be in writing.
Two things worth asking about that are not differentiators but are still useful signals: how they scope the assessment from your system security plan, and what they expect from you before arriving. An assessor who wants your SSP and scoping documentation early is planning the work; one who wants nothing until the week before is improvising it.
The conflict rule that decides who you can hire
This one narrows your list before your preferences do.
32 CFR 170.9(b)(2) requires C3PAOs to comply with "the Accreditation Body policies for Conflict of Interest, Code of Professional Conduct, and Ethics set forth in 170.8(b)(17)". Read that structure carefully, because it matters for how you verify it: the regulation delegates the specific rules to the Accreditation Body rather than writing the prohibition into the CFR text itself. The operative documents are therefore the Accreditation Body's conflict-of-interest and ethics policies, and the ISO/IEC 17020 independence requirements sitting underneath the accreditation.
The practical effect the market runs on is straightforward: the organization that builds your program is not the organization that certifies it. If a firm has written your system security plan, remediated your gaps, or run your readiness engagement, expect that firm to be unable to assess you. Verify it against the assessor's own conflict-of-interest statement rather than against this paragraph, and do it before you contract for readiness rather than after, because discovering the constraint late means either changing assessors or changing advisors at the worst point in the calendar.
Both structures are legitimate. Buying readiness and assessment from one logo is what creates the problem, and it is a problem you can avoid for free by asking one question early.
Reading the marketplace, with a date on it
Counts in this ecosystem move and are reported inconsistently, so take any figure with its date attached.
Secureframe's analysis of the March 2026 Cyber AB town hall (a compliance platform vendor, so read their numbers accordingly) reports roughly 103 authorized C3PAOs and 759 Certified CMMC Assessors, drawn from marketplace data and the town hall. Even within that one page the assessor count moves, since its Marketplace snapshot lists 764 where its town hall series says 759, so treat the number as an order of magnitude rather than a census and check the Cyber AB Marketplace directly when the question is live for you.
What the count is genuinely useful for is calibration. A few hundred assessors is a small professional community, which means reference checks work: contractors in your sector will have opinions about specific teams, and those opinions travel. It also means an assessor's reputation is a real asset they are protecting, which is a better guarantee of behaviour than any contract term.
Why most readers should not book one right now
Here is the part that costs the industry money, and us none, which is exactly why it should be stated plainly rather than buried.
The Department of War CIO suspended CMMC Phases 2 through 4 on July 13, 2026, pausing the trigger that would have introduced third-party certification requirements into solicitations, while a reform task force reviews the program with recommendations due in roughly 60 days. We cover the full scope of what paused and what did not in what the Phase 2 suspension did and did not change.
So the booking decision splits cleanly.
If a current award or a live solicitation names a Level 2 certification assessment, you owe it, and you should be selecting an assessor now. The suspension does not release a requirement already written into a contract.
If you were going to book against the November 2026 trigger and nothing in your contracts requires it yet, re-price that decision. Paying now for a certification whose governing model is under active review is a real risk rather than a hedge, and it is not obviously offset by queue anxiety, because a task force could plausibly change which contracts need a third-party assessment at all.
If you handle only Federal Contract Information, this decision is not yours. Level 1 has always been self-assessed, and there is no C3PAO in that path.
What we would not do is stop the readiness work. The 110 requirements are owed under DFARS 252.204-7012 today, they are the same requirements under any plausible reform, and the pause is the cheapest window available to fix a Supplier Performance Risk System score that is no longer true.
Where Top Floor fits
Our CMMC practice does the readiness half: scoping the boundary, working the requirements at the assessment-objective level, and getting the system security plan into a state an assessor can follow. Because of the conflict structure above, that is a deliberate choice about which side of the line to stand on, and it means we cannot assess a client we have prepared.
For organizations that also carry commercial attestation and certification obligations, our audit and assurance work covers the evidence and readiness discipline that all of them share, which is usually cheaper run once than three times.
When the time comes to select an assessor, we will help you evaluate one and then get out of the way. If your contracts do not require an assessment yet, we will tell you that too, and that conversation has never cost anyone anything.
How to decide this week
Read your contracts and open solicitations for a named CMMC level and assessment type. That document, not a prime's letter and not a vendor's email, is what determines whether the booking decision exists at all.
If it does, shortlist on sector familiarity and ask each candidate the disputed-finding question. The answers separate them faster than any capability matrix.
Ask every readiness advisor you are considering, in writing, whether engaging them precludes any assessor you might want. Do this before signing readiness work, not after.
And if your contracts name nothing yet, put the assessment decision down and pick up the plan of action instead. The requirements are already owed, and the requirement to close them is not suspended. The rules for what can be deferred are in CMMC POA&M rules, and the calendar arithmetic is in how long CMMC Level 2 takes.
Frequently asked questions
What is a C3PAO?
A CMMC Third-Party Assessor Organization is the only kind of entity that may perform a CMMC Level 2 certification assessment: 32 CFR 170.17(c)(1) states that "an authorized or accredited C3PAO must perform a Level 2 certification assessment". Under 32 CFR 170.9 such an organization must achieve and maintain compliance with ISO/IEC 17020:2012(E) within 27 months of authorization, clear a Foreign Ownership, Control or Influence review via an SF 328, put every person involved in a Level 2 assessment through a Tier 3 background investigation, and field a team of at least a Lead Certified CMMC Assessor plus one additional assessor.
Can the firm that helped us prepare also assess us?
Expect not, and confirm it early. 32 CFR 170.9(b)(2) requires C3PAOs to comply with the Accreditation Body's policies for conflict of interest, professional conduct, and ethics, with the detail delegated to those policies and to the ISO/IEC 17020 independence requirements underneath the accreditation rather than written into the CFR text. The practical market effect is that the organization building your program does not certify it. Ask any prospective readiness advisor, in writing, whether engaging them rules out assessors you may want, and ask before you sign the readiness work rather than after.
How many C3PAOs are there?
Roughly 103 authorized C3PAOs and 759 Certified CMMC Assessors as of March 2026, per Secureframe's analysis of the Cyber AB town hall and marketplace data; they sell compliance software, so read the figures accordingly. Counts in this ecosystem are reported inconsistently, and the discrepancy is visible on that one page: its Cyber AB Marketplace snapshot lists 764 certified assessors where its town hall series says 759. Treat any single number as an order of magnitude and check the Cyber AB Marketplace directly when the answer matters to a decision.
Do we need a C3PAO during the Phase 2 suspension?
Only if a contract says so. CMMC Phases 2 through 4 were suspended on July 13, 2026, which paused the mechanism that would have put third-party certification requirements into new solicitations, but it did not release a requirement already named in an award or a live solicitation. If your contract documents name a Level 2 certification assessment, you still owe it. If you were booking in anticipation of the original November 2026 trigger, that is now a spending decision to re-price rather than a hedge, because the reform task force could change which contracts require third-party assessment at all.
Related Services
Need help with your compliance program?
Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.
Schedule a Free ConsultationGet insights like this in your inbox
Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.
Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.