# Certified CMMC Assessor (CCA) | Secureframe

> Learn what a Certified CMMC Assessor (CCA) does, CCA training and certification requirements, the CCA’s role on a C3PAO assessment team, and how CCAs conduct CMMC assessments.

canonical: https://secureframe.com/glossary/cca

A Certified CMMC Assessor (CCA) is an individual credentialed to lead and conduct official CMMC Level 2 assessments on behalf of a CMMC Third-Party Assessment Organization (C3PAO).

## What is a Certified CMMC Assessor (CCA)?

A Certified CMMC Assessor (CCA) is an individual credentialed to lead and conduct official CMMC Level 2 assessments on behalf of a [CMMC Third-Party Assessment Organization (C3PAO)](https://secureframe.com/glossary/c3pao). In addition to meeting the requirements of a CCP and achieving CCP certification, CCAs must:

- Complete a CMMC Certified Assessor class offered by an [Approved Training Provider (ATP)](https://secureframe.com/glossary/approved-training-provider-atp)
- Pass the CMMC Certification Assessor exam
- Have at least three years of cybersecurity experience and one year of assessment or audit experience
- Hold at least one baseline certification aligned to the Intermediate and/or Advanced Proficiency Level for the Career Pathway Certified Assessor 612 from the [DoD Manual 8140.3 Cyberspace Workforce Qualification & Management Program](https://public.cyber.mil/dcwf-work-role/security-control-assessor/).
- CCAs are responsible for evaluating an organization’s implementation of CMMC practices and controls against the appropriate level of certification.

Once a CCA has met all these requirements, they are qualified to work on and make final determinations on CMMC Level 2 assessments as part of a C3PAO assessment team.
