Skip to main content
Category: CMMC & DIB Assessment

Accreditation Body

Also known as:
Simply put

An accreditation body is an independent, third-party organization that formally assesses and authorizes other entities, such as certification bodies, testing laboratories, or verification bodies, to confirm they are competent to perform their work. In effect, it does not certify products or systems directly, but rather vouches for the competence of the organizations that do. This creates a chain of trust: the accreditation body accredits the certifiers, and the certifiers assess the products, systems, or processes.

Formal definition

An accreditation body (AB) is an independent third-party entity recognized to formally assess and authorize other conformity assessment bodies, such as certification bodies, testing laboratories, and validation/verification bodies, against defined competence, systems, or process requirements. Accreditation issued by such a body constitutes a formal statement that specified conformity-related requirements have been met, and functions as an authoritative attestation of a conformity assessment body's competence rather than a direct certification of an end product or system. Some accreditation bodies participate in international arrangements, such as membership in the International Accreditation Forum (IAF), which administers programs for accrediting validation/verification and other bodies. The evidence provided describes the concept generically and does not establish which specific accreditation body applies within any particular defense or public sector compliance program; readers should verify the governing authority and any program-specific recognition requirements against current authoritative sources.

Why it matters

Accreditation bodies underpin the credibility of any conformity assessment regime by establishing a chain of trust: rather than certifying products or systems directly, an accreditation body attests to the competence of the certification bodies, testing laboratories, and verification bodies that perform those assessments. Without this layer of independent oversight, the value of a certificate would rest entirely on the self-declared competence of the entity issuing it. For compliance officers and authorizing officials, understanding where an accreditation body sits in this hierarchy matters because it determines how much weight a given certification can bear and whether the assessing organization was itself judged competent by a recognized authority.

This distinction is a frequent source of confusion. Practitioners sometimes assume that a certificate is trustworthy simply because it was issued, without asking whether the issuing certification body was accredited by a recognized accreditation body. An accreditation body accredits the certifiers; the certifiers then assess products, systems, or processes. Conflating these two roles, or assuming that an accreditation body directly certifies an end product or system, undermines the assurance the model is designed to provide.

The specific accreditation body that applies within any given defense or public sector compliance program is not established by the general concept alone. Recognition arrangements, program-specific requirements, and the governing authority vary, and some accreditation bodies participate in international arrangements such as membership in the International Accreditation Forum (IAF). Readers should not assume that accreditation under one program or arrangement automatically satisfies the requirements of another; the governing authority and any program-specific recognition requirements must be verified against current authoritative sources.

Who it's relevant to

Compliance Officers and ISSMs
Those responsible for demonstrating conformity need to confirm that any certification or test result relied upon was issued by a body that was itself accredited by a recognized accreditation body. Verifying this chain of trust, accreditation body to certifier to assessed product or system, helps ensure that a certificate carries the assurance it appears to convey rather than resting on unverified self-declared competence.
Authorizing Officials
Officials who rely on third-party assessments as inputs to authorization decisions should understand that an accreditation body attests to the competence of the assessing organization, not to the security or acceptability of the end system itself. Assessment and accreditation of a conformity assessment body are distinct from authorization of a system, and the two should not be conflated.
Government Contractors
Contractors seeking or relying on certifications should identify which accreditation body underlies the certification body they engage and confirm that its recognition satisfies the specific program's requirements. Accreditation or recognition under one arrangement does not automatically satisfy the requirements of another program, so program-specific recognition requirements must be verified.
Auditors and Assessors
Auditors evaluating a compliance posture should trace whether certifiers and laboratories cited as evidence were accredited by a recognized accreditation body, and note where accreditation scope is program-specific or where the governing authority is unclear. Documenting the source of accreditation and any international arrangement membership, such as IAF, supports a defensible assessment record.

Inside AB

Accreditation Body (AB) Role
An organization designated to oversee and administer the ecosystem of assessors and assessment organizations for a given program, rather than to issue security control sets or authorizations itself. In the CMMC context, the CMMC Accreditation Body (established under agreement with the DoD) has historically served this function for the third-party assessment ecosystem. Readers should verify the current organization name, scope, and agreement terms against official DoD and program sources, as governance arrangements have evolved through CMMC's phased rollout.
Authorization and Accreditation of Assessors
A core function generally involves authorizing, training, and credentialing the assessors and assessment organizations (such as Certified Third-Party Assessment Organizations) that conduct assessments. This is distinct from the government's authorization decision to operate a system and from the technical control baselines maintained by bodies such as NIST.
Quality and Ethics Oversight
Responsibilities commonly include establishing standards of conduct, quality assurance processes, and dispute or complaint mechanisms for the assessor community. The specific procedures and their binding effect depend on the governing agreements and program documentation, which the reader should confirm.
Relationship to the Governing Authority
An accreditation body typically operates under an agreement with a governing authority (for example, the DoD CIO or program office for CMMC) that retains ultimate policy control. The AB administers the assessment ecosystem but does not set the underlying regulatory requirements, which derive from sources such as DFARS clauses and NIST publications.

Common questions

Answers to the questions practitioners most commonly ask about AB.

Is the Accreditation Body the same organization that issues a company's CMMC certification?
No. The Accreditation Body does not directly issue certifications to defense contractors. Its role is generally to accredit and oversee the third-party assessment ecosystem, such as the organizations that conduct assessments and the individuals who perform them. The certification determination itself flows from an assessment conducted by an accredited assessor organization, not from the Accreditation Body performing the assessment directly. Readers should verify the current division of responsibilities against the authoritative CMMC program documentation, as the structure and terminology have evolved across CMMC's phased rollout and revisions.
Does an Accreditation Body set the underlying security requirements that contractors must meet?
Generally no. The Accreditation Body should not be confused with the authority that defines the technical control requirements. In the CMMC context, the underlying safeguarding requirements trace to NIST-authored guidance and to DoD-issued program rules, not to the Accreditation Body. The Accreditation Body's function centers on accrediting and maintaining the quality of the assessment infrastructure rather than authoring control sets or contractual clauses. Confirm the specific allocation of authority against current official DoD and NIST sources, which may change across revisions.
How does an organization confirm that an assessor or assessment organization is properly accredited?
In most implementations, the Accreditation Body maintains or supports a listing of accredited assessment organizations and authorized assessors. A prospective client should verify an assessor's current standing against that authoritative listing rather than relying on a self-reported claim, because accreditation status can change over time. Because the program has evolved through phased rollout and revisions, readers should confirm the current verification mechanism and any status categories against the applicable official program resources at the time of engagement.
What should a contractor do if an accredited assessor's status changes during or after an engagement?
Because accreditation is not permanent and is subject to ongoing oversight, a change in an assessor's or assessment organization's status can affect the validity or continuity of an engagement. As a practical matter, a contractor should monitor the assessor's standing on the authoritative listing and confirm how status changes are handled under the current program rules. This entry does not cover the contractual, legal, or remediation specifics of such situations, which the reader must confirm against current official guidance and applicable contract terms.
Does accreditation of an assessor by the Accreditation Body guarantee a favorable assessment outcome?
No. Accreditation addresses the qualification and oversight of the assessment provider, not the result of any particular assessment. An accredited assessor evaluates an organization's implementation against the applicable requirements, and the outcome depends on that implementation. Compliance-focused readers should treat accreditation as a marker of assessor legitimacy rather than a predictor or substitute for meeting the underlying security requirements.
Where should an organization go for the definitive scope of the Accreditation Body's authority and responsibilities?
Because the role, terminology, and division of responsibilities have changed across CMMC's phased rollout and revisions, an organization should anchor its understanding to the current authoritative program documentation issued through the relevant DoD channels rather than to prior descriptions. This entry describes the concept at a general level and does not substitute for the current official text, which the reader should verify for the applicable revision, scope boundaries, and any agency-specific interpretations.

Common misconceptions

The Accreditation Body creates the cybersecurity requirements or control sets that organizations must meet.
The accreditation body generally administers the assessor ecosystem; it does not author the underlying control baselines or regulatory requirements. Those requirements trace to authorities such as NIST (for control sets like SP 800-171) and DoD contractual clauses (such as DFARS 252.204-7012), which are maintained by different bodies. Verify the current division of responsibilities against official sources.
Accreditation by the body is the same as an Authority to Operate (ATO) or authorization for a system.
Accreditation of an assessor or assessment organization is distinct from an authorization decision (such as an ATO) made by a government authorizing official. Assessment is not authorization, and credentialing an assessor is a separate concept from authorizing a system to operate. These should not be conflated.
The Accreditation Body's structure and authority are fixed and permanent.
Governance arrangements in this space, particularly for CMMC, have evolved through phased rollout and program revisions. The organization's name, scope, and governing agreements may change over time, so the reader should confirm current arrangements against authoritative DoD and program sources rather than assume continuity.

Best practices

Confirm the current name, scope, and governing agreement of the applicable accreditation body against official DoD or program sources before relying on it, given that governance in this area has evolved through phased rollout and revisions.
Distinguish clearly in your own documentation between accreditation of assessors, assessment activities, and government authorization decisions such as an ATO, and avoid treating them as interchangeable.
Trace cybersecurity requirements back to their actual governing authorities (such as NIST publications and applicable DFARS clauses) rather than attributing them to the accreditation body.
Verify that any assessor or assessment organization you engage holds current credentials from the recognized accreditation body, and confirm the status against official program listings.
Treat program guidance and accreditation-related terminology as subject to change, and periodically recheck for revisions rather than relying on prior versions.
Consult authoritative official texts, and where necessary legal or contracting counsel, for implementation, contractual, and eligibility specifics that fall outside the scope of a general reference definition.