Public discussion of CMMC assessment capacity often begins with the number of credentialed assessors listed in the Marketplace.
Current figures show approximately 1,060 Certified CMMC Assessors, including 618 Lead Certified CMMC Assessors. Those numbers demonstrate meaningful progress, but they do not by themselves show how much assessment capacity is available for immediate deployment.
An assessor or auditor should look beyond the headline.
The 618 Lead CCAs are included within the total of 1,060. They are not an additional population. That leaves fewer than 450 non-lead CCAs before accounting for whether individuals are:
- Employed by an authorized C3PAO
- Supporting a C3PAO as independent contractors
- Available for additional assessment work
- Tier 3 screened
- Qualified and available for QA
- Already committed to active assessments
- Actually using their credentials
The more useful question is not:
How many people possess a CCA or Lead CCA credential?
It is:
How many qualified, experienced, screened, affiliated, available, and appropriately assigned professionals can participate in defensible assessments today?
Those are materially different measurements.
Marketplace Listings Do Not Equal Deployable Capacity
The Marketplace confirms that an individual possesses a credential. It does not establish that the person is available to an authorized C3PAO or ready for immediate assignment.
There is no reliable public method to determine:
- How many CCAs are W-2 employees of authorized C3PAOs
- How many support C3PAOs as 1099 contractors
- How many work elsewhere in the ecosystem
- How many are actively looking for assessment work
- How many have completed Tier 3 screening
- How many are awaiting screening
- How many are eligible and available to serve as QA
- How many credentials are technically active but operationally unused
Without those details, Marketplace totals should not be treated as verified assessment capacity.
A Limited Recruiting Review Illustrates the Data Problem
Resilient IT conducted a limited recruiting review when the Marketplace contained approximately 750–800 CCAs.
We initially focused on approximately 115 profiles using personal email addresses. We did not target individuals listing corporate or business addresses because those addresses could indicate an existing employer, business affiliation, or established role.
Of those contacted:
- Approximately 10 expressed interest only in 1099 opportunities.
- Approximately 12 expressed interest in W-2 employment with the specific C3PAO conducting the outreach.
- The remaining individuals did not express interest, did not respond, or could not be confirmed as available.
This was a recruiting exercise, not a statistically representative labor-market survey. It should not be used to calculate a market-wide employment or availability rate.
It does, however, support a limited but important conclusion:
A credentialed individual appearing in the Marketplace cannot automatically be counted as deployable assessment capacity.
An individual may already work for another C3PAO, an OSC, a consultant, an MSP, or another organization. The person may seek only W-2 employment, only contract work, or neither. The individual may be waiting for Tier 3 screening, unavailable geographically, fully committed, or uninterested in a particular opportunity.
Better workforce data is needed before implementation schedules are based on credential counts.
The Lead CCA Number Also Requires a Competency Lens
The presence of 618 Lead CCAs may look especially reassuring because Lead CCAs are authorized to direct assessments and make final determinations.
However, a lead designation does not necessarily mean that every holder has equivalent practical assessment experience or judgment.
During our recruiting review and related candidate discussions, we encountered some Lead CCA holders who appeared to have little meaningful assessment experience and who could not clearly describe appropriate methods for evaluating common security controls or assessment objectives.
That observation should not be generalized to the entire Lead CCA population. Many Lead CCAs are highly experienced and capable professionals.
It does raise a legitimate governance question:
Does the process for issuing and maintaining the Lead CCA designation sufficiently validate applied assessment competence?
The distinction matters because leading an assessment requires more than memorizing model language or passing a knowledge-based examination. A Lead CCA must be able to:
- Translate requirements into defensible assessment procedures
- Select appropriate examine, interview, and test methods
- Recognize weak, incomplete, or misleading evidence
- Determine appropriate sampling
- Resolve conflicting evidence
- Evaluate inheritance and shared responsibilities
- Distinguish policy language from operational implementation
- Document conclusions that can withstand QA, appeals, and government scrutiny
- Direct and calibrate the assessment team
ISACA now administers the CCA and Lead CCA credentialing programs, and its published materials describe the Lead CCA designation as validating the ability to lead teams, interpret complex requirements, and make final determinations. That transition may improve rigor, consistency, and credential governance for future candidates.
However, a strengthened future process does not automatically correct older designations that may have been issued under a less mature screening model.
Lead CCA Competency Should Be Demonstrated, Not Assumed
The lead-designation process should include evidence of practical assessment competence.
Recommended enhancements include:
1. Require a practical assessment examination
Candidates should complete a scenario-based or simulated assessment in which they must:
- Interpret representative requirements
- Identify appropriate evidence
- Apply examine, interview, and test methods
- Evaluate contradictory artifacts
- Determine whether objectives are satisfied
- Document defensible conclusions
- Identify when additional testing is required
A written multiple-choice examination may test knowledge, but it cannot fully test professional judgment.
2. Require documented assessment experience
Before receiving lead authority, a candidate should demonstrate supervised experience participating in actual or approved simulated assessments.
That experience could include:
- Serving as a supporting CCA
- Completing defined assessment tasks
- Producing workpapers
- Participating in evidence evaluation
- Receiving documented performance feedback
- Demonstrating competence across multiple control families
3. Use a supervised lead pathway
Newly designated Lead CCAs could be required to lead an initial assessment under observation or enhanced QA before exercising fully independent lead authority.
4. Revalidate competence periodically
Maintenance should include more than continuing professional education.
Periodic revalidation could involve:
- Scenario testing
- Workpaper review
- QA findings
- Appeals outcomes
- Calibration exercises
- Evidence of continued assessment activity
5. Review legacy designations proportionately
Existing Lead CCAs should not automatically lose their status merely because the credentialing administrator changed.
However, legacy designation holders who cannot demonstrate recent assessment experience, practical competence, or satisfactory QA outcomes should be required to complete:
- A competency assessment
- Refresher training
- Supervised practice
- A remediation plan
Removal should be reserved for individuals who cannot demonstrate the required capability after a fair opportunity to remediate.
This balances due process with the need to protect assessment quality.
Lead CCA Counts Do Not Equal Assessment-Team Counts
Even a highly qualified Lead CCA cannot perform the entire certification process alone.
Each assessment also requires:
- Supporting assessors
- Independent QA
- Administrative coordination
- C3PAO quality-management infrastructure
- Scheduling capacity
- Tier 3-cleared personnel
- Customers prepared for assessment
Lead CCA availability may be further constrained by:
- Existing employment obligations
- Concurrent assessments
- Management responsibilities
- QA responsibilities
- Travel limitations
- Customer readiness
- Assessment complexity
- C3PAO affiliation
Counting lead credentials without measuring the supporting workforce and competence of each role risks overstating throughput.
A High-Output Case Study Still Reveals a Constraint
Consider an intentionally aggressive scenario.
Assume that each of approximately 106 authorized C3PAOs completes 100 assessments per year, roughly matching the output attributed to the most productive C3PAO over a recent 12-month period.
That produces approximately:
106 C3PAOs × 100 assessments = 10,600 assessments per year
This should not be viewed as a realistic present-day capacity estimate.
C3PAOs vary materially in:
- Number of employed and contracted assessors
- Lead CCA experience and availability
- Supporting CCA capacity
- QA availability
- Tier 3 completion
- Customer size and architecture
- Assessment duration
- Travel requirements
- Quality-management maturity
- OSC readiness
Many authorized C3PAOs could not currently sustain 100 assessments annually.
The scenario is still useful because even an aggressive theoretical output may not support later implementation phases and accumulating three-year reassessment cohorts.
Phase 2 may be more manageable because the number of affected awards is comparatively limited. Phase 3, Phase 4, and recertification demand present a different scale.
The rollout schedule should therefore be based on verified throughput, competency, and deployable workforce data, not Marketplace totals alone.
Tier 3 Screening May Be the Largest Onboarding Bottleneck
Every current assessment-team member, including QA personnel, is required to complete Tier 3 screening.
The process commonly takes approximately 9–12 months.
That delay creates substantial operational problems:
- Qualified candidates may remain unusable for nearly a year
- C3PAOs cannot reliably forecast workforce availability
- Candidates may accept other work while waiting
- Small C3PAOs carry recruiting and training costs without revenue
- The market cannot respond quickly to increased demand
- Additional candidates may be stuck in the pipeline
A workforce strategy cannot scale efficiently when a critical onboarding step takes up to a year.
Tier 3 Requirements Should Reflect Actual Role Risk
The case for Tier 3 screening is strongest for Lead CCAs because they direct the assessment, interact extensively with the OSC, review sensitive evidence, and make consequential decisions.
The same risk profile may not apply equally to every supporting CCA or QA reviewer.
QA personnel primarily review the record, verify support for findings, confirm process conformity, and complete quality and submission activities. The role requires competence, independence, and accountability, but it differs from directing evidence collection and making primary determinations.
DoW should evaluate screening requirements by role, access, and actual risk.
Recommended Workforce Reforms
Retain Tier 3 for Lead CCAs
Lead CCAs should continue to meet Tier 3 requirements because of their authority and access.
Remove the automatic Tier 3 requirement for supporting CCAs
Supporting CCAs should remain subject to suitability, identity, confidentiality, and security requirements. Tier 3 should apply only where their access and assignment justify it.
Permit qualified CCPs to serve as QA reviewers
Properly trained and independent CCPs should be permitted to perform QA when they:
- Did not participate in evidence collection
- Complete a formal QA qualification program
- Demonstrate knowledge of the assessment methodology
- Operate independently from the team’s conclusions
- Work within the C3PAO quality system
- Document and escalate discrepancies
Complete Tier 3 screening within 90 days
The government should establish a measurable 90-day service-level objective, except where documented complications justify additional time.
Strengthen Lead CCA competency validation
Lead designation should require practical evaluation, relevant experience, supervised performance, and periodic revalidation.
Publish meaningful capacity data
DoW and The Cyber AB should publish anonymized aggregate data showing:
- Active CCAs and Lead CCAs
- C3PAO affiliation
- Employee and contractor populations
- Tier 3 completed and pending
- QA-qualified personnel
- Active versus inactive credentials
- Assessment utilization
- Actual annual throughput
- Practical experience levels where measurable
Accreditation Administration Is Also a Capacity Constraint
The workforce pipeline is not the only point of concentration.
The Cyber AB currently holds the exclusive ecosystem-administration and accreditation role. Centralization can improve consistency, but exclusivity also creates a single point of failure and limits competitive pressure on fees, processing times, service quality, and market access.
Participants pay fees associated with multiple credentials, designations, applications, authorizations, and maintenance requirements.
Not every designation provides equal operational value. Paying for a designation does not by itself demonstrate implementation quality or market competence.
C3PAOs must fund application and authorization fees, recurring maintenance, personnel, Tier 3 screening, insurance, accreditation, quality-management systems, and operations—often before predictable assessment volume exists.
The concern is not that a nonprofit should operate without revenue or that personnel should not be paid appropriately.
The concern is whether exclusive authority, mandatory fees, and limited transparency support the rapid growth DoW says it needs.
Recommended Accreditation Reforms
Allow other qualified organizations to participate
DoW should evaluate whether multiple qualified bodies can perform defined portions of:
- C3PAO accreditation
- Authorization processing
- Credential administration
- Training approval
- Quality oversight
- Workforce development
Any additional body should meet uniform standards and operate under government oversight and conflict-of-interest controls.
Alternatively, require transparent fee governance
If exclusive administration continues, DoW should require:
- Published fee ranges
- Independent reasonableness review
- Transparent pricing methodology
- Audited financial reporting
- Disclosure of fee use
- Notice before material increases
- Service-level commitments
- Processing-time reporting
This is basic oversight where ecosystem participants do not have a competing administrator.
Extending the Rollout Is Not Weakening CMMC
Recognizing capacity and competency constraints does not require eliminating independent assessment.
The stronger approach is to:
- Preserve third-party verification
- Improve lead competency
- Remove unnecessary screening barriers
- Expand QA capacity
- Reduce Tier 3 processing time
- Publish real workforce data
- Increase accreditation capacity
- Align later phases with demonstrated throughput
- Account for reassessment cohorts
An unrealistic schedule creates rushed assessments, inflated labor rates, inconsistent quality, customer backlogs, assessor burnout, and pressure to reduce rigor simply to meet volume.
A measured extension tied to objective milestones would strengthen the program.
Conclusion
CMMC capacity should not be measured simply by counting names in a directory.
Real capacity consists of professionals who are:
- Properly credentialed
- Practically competent
- Appropriately screened
- Affiliated with an authorized C3PAO
- Available for assignment
- Qualified for their designated role
- Supported by adequate QA capacity
- Operating within a functioning accreditation system
The current figures demonstrate progress. They do not establish that the ecosystem can meet later rollout phases and recurring reassessment demand under the current schedule.
The goal should not merely be to issue more credentials.
It should be to produce enough qualified, experienced, screened, affiliated, and available assessment teams to perform accurate, consistent, and defensible assessments.


