
CMMC Assessor
The ISACA CMMC Certified Assessor (CCA) course teaches experienced cybersecurity professionals how to evaluate organizations seeking certification, scope CMMC Level 2 assessments, conduct the assessment process, and verify Level 2 practices, ensuring compliance and readiness.
Who Should Take This
It is intended for Certified Cybersecurity Professionals (CCP) who serve as assessment team members and need formal authorization to perform CMMC Level 2 assessments. These learners typically have several years of information‑security experience, familiarity with NIST 800‑171, and seek to deepen their expertise in CMMC scoping, process execution, and practice validation.
Course Outline
1Domain 1: Evaluating Organizations Seeking Certification 2 topics
Organizational readiness evaluation
- Evaluate organizational readiness for CMMC Level 2 assessment by reviewing system security plans, network diagrams, and CUI data flow documentation.
- Analyze organizational security posture to identify potential gaps between current control implementations and CMMC Level 2 requirements.
- Apply pre-assessment evaluation techniques to verify that the organization has adequate documentation, personnel availability, and system access for assessment execution.
- Apply the CMMC scoping guidance to determine OSC (organization seeking certification) boundary, including FCI/CUI flow analysis.
- Apply the CMMC scoping guidance to determine OSC (organization seeking certification) boundary, including FCI/CUI flow analysis.
System security plan assessment
- Evaluate system security plan completeness by verifying that all 110 security requirements are addressed with specific implementation descriptions.
- Apply assessment techniques to verify that SSP descriptions accurately reflect actual system configurations, policies, and operational procedures.
- Analyze POA&M entries to evaluate remediation timelines, resource allocations, and milestones for conditional certification eligibility determination.
- Examine an OSC's System Security Plan (SSP) and POA&M for completeness against NIST SP 800-171 controls.
- Examine an OSC's System Security Plan (SSP) and POA&M for completeness against NIST SP 800-171 controls.
2Domain 2: CMMC Level 2 Assessment Scoping 1 topic
Advanced scoping techniques
- Apply advanced scoping techniques for complex CUI environments including multi-enclave architectures, cloud-hosted enclaves, and geographically distributed systems.
- Evaluate asset categorization decisions to verify correct classification of CUI Assets, Security Protection Assets, and Contractor Risk Managed Assets.
- Analyze external service provider relationships to determine assessment boundary inclusions and inheritance of security requirements.
- Design assessment scope validation procedures to confirm that all CUI data flows, processing locations, and storage repositories are captured within assessment boundaries.
- Identify the asset categories within CMMC scope (CUI assets, security protection assets, contractor risk-managed assets, specialized assets, out-of-scope assets).
- Construct a scoping recommendation for an OSC with mixed cloud and on-premises infrastructure.
- Examine CUI flow diagrams and recommend boundary refinements that minimize assessment scope without compromising compliance.
- Identify the asset categories within CMMC scope (CUI assets, security protection assets, contractor risk-managed assets, specialized assets, out-of-scope assets).
- Construct a scoping recommendation for an OSC with mixed cloud and on-premises infrastructure.
- Examine CUI flow diagrams and recommend boundary refinements that minimize assessment scope without compromising compliance.
3Domain 3: CMMC Assessment Process 2 topics
Assessment planning and execution
- Apply assessment planning procedures to develop detailed assessment schedules, evidence request lists, and interview plans for CMMC Level 2 assessments.
- Apply assessment interview techniques to elicit relevant information from organizational personnel about security control implementation and operational procedures.
- Evaluate evidence sufficiency by determining whether collected documentation, interview responses, and technical observations adequately support scoring decisions.
- Apply the CAP (CMMC Assessment Process) phases (planning, conducting, reporting) to an upcoming Level 2 assessment.
- Apply the CAP (CMMC Assessment Process) phases (planning, conducting, reporting) to an upcoming Level 2 assessment.
Scoring and reporting
- Apply CMMC scoring methodology consistently across all practices to determine Met, Not Met, and Not Applicable results with documented justification.
- Analyze scoring results to determine overall assessment outcome including certification recommendation, conditional certification, or certification denial.
- Design comprehensive assessment reports that clearly document findings, scoring rationale, deficiency descriptions, and recommendations for remediation.
- Examine common assessment scenarios (test, examine, interview methods) and recommend the appropriate evidence-collection method per practice.
- Examine common assessment scenarios (test, examine, interview methods) and recommend the appropriate evidence-collection method per practice.
4Domain 4: Assessing CMMC Level 2 Practices 5 topics
Access control and identification assessment
- Evaluate access control practice implementations including account management, access enforcement, remote access, and wireless access controls against CMMC Level 2 requirements.
- Apply assessment techniques for identification and authentication practices including MFA implementation, authenticator management, and replay-resistant authentication.
- Analyze personnel security and awareness training implementations to assess hiring practices, access agreements, and role-based security training adequacy.
- Identify the 14 NIST SP 800-171 control families and the 110 practices CMMC Level 2 inherits.
- Identify the 14 NIST SP 800-171 control families and the 110 practices CMMC Level 2 inherits.
System protection and communications assessment
- Evaluate system and communications protection practices including boundary protection, CUI encryption in transit and at rest, and session management controls.
- Apply assessment techniques for system and information integrity practices including flaw remediation, malicious code protection, and security alert monitoring.
- Evaluate configuration management and maintenance practices including baseline configurations, change control, system maintenance controls, and maintenance personnel oversight.
- Apply MET, NOT MET, and NOT APPLICABLE scoring to a sampled control during assessment.
- Apply MET, NOT MET, and NOT APPLICABLE scoring to a sampled control during assessment.
Audit, incident response, and risk assessment
- Evaluate audit and accountability practice implementations including audit event generation, analysis, storage protection, and correlation across system components.
- Apply assessment techniques for incident response practices including incident handling, reporting, response testing, and incident monitoring capabilities.
- Evaluate risk assessment and security assessment practices including vulnerability scanning, risk management, and security assessment planning and execution.
- Design integrated practice assessment strategies that efficiently evaluate interdependent security requirements across multiple NIST SP 800-171 families.
- Construct an assessment finding (Met/Not Met) with supporting rationale and references to specific evidence.
- Construct an assessment finding (Met/Not Met) with supporting rationale and references to specific evidence.
Media and physical protection assessment
- Evaluate media protection practices including CUI media marking, storage, transport, sanitization, and disposal controls for physical and digital media.
- Apply assessment techniques for physical protection practices including physical access controls, visitor management, and environmental protection measures.
- Evaluate recovery and contingency planning practices including system backup, information system recovery, and alternate processing capabilities for CUI environments.
Practice-Specific Methodology
- Identify the highest-frequency assessment objectives across the 110 practices and the typical evidence types each requires.
- Recommend an assessment plan that batches practices by control family for efficient evidence collection.
5Domain 5: Reporting and Findings 1 topic
Documentation and Quality
- Identify the components of a CMMC Final Findings Report (FFR) and their content requirements.
- Apply quality-assurance review to assessment artifacts before submission to The Cyber AB.
- Construct a sample FFR that demonstrates traceability between practices, evidence, and findings.
6Domain 6: Professional Conduct 1 topic
Ethics in Practice
- Identify the ethics requirements for Certified Assessors (independence, confidentiality, conflict-of-interest disclosure).
- Examine ethical dilemmas an assessor may face and recommend principle-based responses.
Exam Structure
Question Types
- Multiple Choice
Scoring Method
Scaled score 500-800 required to pass (out of 200-800 range)
Delivery Method
PSI online proctored or test center
What's Included in AccelaStudy® AI
Scope
Included Topics
- All domains and objectives in the CMMC Certified Assessor (CCA) exam: Domain 1 Evaluating Organizations Seeking Certification against CMMC Level 2 (15%), Domain 2 CMMC Level 2 Assessment Scoping (20%), Domain 3 CMMC Assessment Process (25%), and Domain 4 Assessing CMMC Level 2 Practices (40%).
- Professional-level CMMC assessment knowledge including assessment team operations, advanced evidence evaluation, interview techniques, practice-by-practice assessment, and certification determination.
- Advanced assessment scoping: complex CUI environments, multi-enclave architectures, cloud and hybrid scoping, external service provider assessment boundaries, and interconnection scoping.
- Assessment process mastery: assessment planning, assessment team coordination, evidence sufficiency determination, scoring consistency, deficiency documentation, and assessment report compilation.
- Practice-level assessment: deep evaluation of all 110 NIST SP 800-171 security requirements including evidence sufficiency, implementation effectiveness, and documentation completeness.
- Organizational evaluation: system security plan analysis, POA&M review, risk assessment evaluation, and continuous monitoring capability assessment for CMMC Level 2 certification.
Not Covered
- CMMC assessment team leadership and oversight responsibilities (covered by LCCA).
- CMMC training development and curriculum delivery (covered by CCI).
- Basic CMMC ecosystem knowledge and foundational model understanding (covered by CCP).
- General cybersecurity operations beyond CMMC assessment context.
- Vendor-specific compliance automation platform administration.
Official Exam Page
Learn more at ISACA