Cyber AB
The Cyber AB is the organization designated as the accreditation body for the Cybersecurity Maturity Model Certification (CMMC) program, which the Department of Defense uses to verify that contractors meet cybersecurity requirements. It authorizes the companies that perform CMMC assessments and certifies the individuals who conduct them, rather than issuing the CMMC program requirements itself. It is a Maryland-based nonprofit organization and was formerly known as the CMMC Accreditation Body.
The Cyber AB, formerly the CMMC Accreditation Body, is described in the available evidence as the accreditation body for the CMMC Ecosystem, functioning as a Maryland-based 501(c)(3) nonprofit organization. In this role it is generally responsible for accrediting CMMC Third-Party Assessment Organizations (C3PAOs), certifying individual assessors, and maintaining the Cyber AB Marketplace, as well as establishing, managing, controlling, and administering aspects of the CMMC assessment and certification ecosystem. Practitioners should distinguish the Cyber AB from the DoD (which owns and defines the CMMC program itself, per the DoD CIO), and should not treat the Cyber AB's accreditation activities as equivalent to the underlying CMMC or DFARS requirements. Because CMMC is subject to phased rollout and revision, the Cyber AB's specific roles, authorities, and relationships with other bodies may change, and readers should verify the current authoritative structure against official DoD and Cyber AB sources.
Why it matters
The Cyber AB occupies a distinct and often misunderstood position in the CMMC ecosystem. The Department of Defense, through the DoD CIO, owns and defines the CMMC program itself, but the assessment infrastructure that determines whether a contractor's certification is credible depends on the Cyber AB. As the accreditation body, it authorizes the Third-Party Assessment Organizations (C3PAOs) that conduct assessments and certifies the individuals who perform them. For contractors seeking certification, this means the quality and legitimacy of an assessment ultimately trace back to the accreditation activities the Cyber AB administers, even though the underlying requirements do not originate with it.
A common and consequential mistake is to treat the Cyber AB's accreditation activities as if they were equivalent to the CMMC or DFARS requirements themselves. They are not. The Cyber AB accredits assessors and manages the ecosystem; it does not issue the substantive cybersecurity requirements a contractor must meet, nor does its accreditation of a C3PAO substitute for actually satisfying the applicable CMMC controls. Compliance officers and contractors should keep this separation clear when evaluating vendors, engaging assessors, or interpreting who is authoritative for a given question, program requirements come from the DoD, while the credentials of the parties performing assessments come through the Cyber AB.
Because CMMC is subject to phased rollout and revision, the Cyber AB's specific roles, authorities, and relationships with other bodies may evolve over time. Organizations relying on its accreditation should verify the current structure and status of any C3PAO or assessor against official DoD and Cyber AB sources rather than assuming a fixed arrangement, and should treat descriptions of its authority as accurate as of the applicable point in the program's development.
Who it's relevant to
Inside Cyber AB
Common questions
Answers to the questions practitioners most commonly ask about Cyber AB.