# Organization Seeking Certification (OSC) | Secureframe

> OSC vs OSA, what you commit to during a CMMC Level 2 assessment, how to prepare, and how to select a C3PAO before you're fully ready.

canonical: https://secureframe.com/glossary/organization-seeking-certification

An Organization Seeking Certification is a defense contractor pursuing CMMC Level 2 or Level 3 certification via a formal third-party (C3PAO) or government (DIBCAC) assessment. The term distinguishes these contractors from OSAs (Organizations Seeking Assessment), which is the broader category that also includes Level 1 self-assessments. When a C3PAO engagement kicks off, you are an OSC from that point until certification is issued or denied.

### OSC vs OSA

OSA (Organization Seeking Assessment) is the umbrella term for any entity undergoing a CMMC assessment at any level. OSC specifically refers to Level 2 or Level 3 candidates undergoing third-party or DIBCAC assessment. The distinction matters for official Cyber AB documentation and assessment tracking; in everyday conversation the terms get used interchangeably.

### What an OSC Commits To

- **Define t**he CMMC Assessment Boundary and document it in the SSP.
- **Provide the C3PAO wi**th the SSP, POA&M, network diagrams, and other evidence as requested.
- **Make personnel a**vailable for interviews during the assessment.
- **Maintain evidence organized by** NIST SP 800-171 requirement number.
- **Respond to assessor findin**gs in real time during the assessment.

### Preparing as an OSC

Start with a gap assessment against all 110 NIST 800-171 practices. An RPO can run this. Fix the easy gaps first (MFA configuration, password policies, audit log retention). Plan the harder gaps (network segmentation, DLP, SIEM tuning) with realistic timelines. Write the SSP as you go, not at the end. If the SSP is an afterthought, the assessment will reflect that.

### Selecting a C3PAO Before You're Ready

You can start talking to C3PAOs early, even before remediation is done. Good C3PAOs will advise on timing, scope, and readiness without crossing into consulting (which they can't do). A C3PAO that has performed assessments at similar-sized organizations in your industry segment is the right fit. Check the Cyber AB Marketplace and ask for references.
