Skip to main content
Category: CMMC & DIB Assessment

Cyber AB

Also known as: The Cyber AB, CMMC Accreditation Body, CMMC-AB
Simply put

The Cyber AB is the organization designated as the accreditation body for the Cybersecurity Maturity Model Certification (CMMC) program, which the Department of Defense uses to verify that contractors meet cybersecurity requirements. It authorizes the companies that perform CMMC assessments and certifies the individuals who conduct them, rather than issuing the CMMC program requirements itself. It is a Maryland-based nonprofit organization and was formerly known as the CMMC Accreditation Body.

Formal definition

The Cyber AB, formerly the CMMC Accreditation Body, is described in the available evidence as the accreditation body for the CMMC Ecosystem, functioning as a Maryland-based 501(c)(3) nonprofit organization. In this role it is generally responsible for accrediting CMMC Third-Party Assessment Organizations (C3PAOs), certifying individual assessors, and maintaining the Cyber AB Marketplace, as well as establishing, managing, controlling, and administering aspects of the CMMC assessment and certification ecosystem. Practitioners should distinguish the Cyber AB from the DoD (which owns and defines the CMMC program itself, per the DoD CIO), and should not treat the Cyber AB's accreditation activities as equivalent to the underlying CMMC or DFARS requirements. Because CMMC is subject to phased rollout and revision, the Cyber AB's specific roles, authorities, and relationships with other bodies may change, and readers should verify the current authoritative structure against official DoD and Cyber AB sources.

Why it matters

The Cyber AB occupies a distinct and often misunderstood position in the CMMC ecosystem. The Department of Defense, through the DoD CIO, owns and defines the CMMC program itself, but the assessment infrastructure that determines whether a contractor's certification is credible depends on the Cyber AB. As the accreditation body, it authorizes the Third-Party Assessment Organizations (C3PAOs) that conduct assessments and certifies the individuals who perform them. For contractors seeking certification, this means the quality and legitimacy of an assessment ultimately trace back to the accreditation activities the Cyber AB administers, even though the underlying requirements do not originate with it.

A common and consequential mistake is to treat the Cyber AB's accreditation activities as if they were equivalent to the CMMC or DFARS requirements themselves. They are not. The Cyber AB accredits assessors and manages the ecosystem; it does not issue the substantive cybersecurity requirements a contractor must meet, nor does its accreditation of a C3PAO substitute for actually satisfying the applicable CMMC controls. Compliance officers and contractors should keep this separation clear when evaluating vendors, engaging assessors, or interpreting who is authoritative for a given question, program requirements come from the DoD, while the credentials of the parties performing assessments come through the Cyber AB.

Because CMMC is subject to phased rollout and revision, the Cyber AB's specific roles, authorities, and relationships with other bodies may evolve over time. Organizations relying on its accreditation should verify the current structure and status of any C3PAO or assessor against official DoD and Cyber AB sources rather than assuming a fixed arrangement, and should treat descriptions of its authority as accurate as of the applicable point in the program's development.

Who it's relevant to

Defense Contractors Pursuing CMMC Certification
Contractors that must demonstrate CMMC compliance rely on assessors and C3PAOs whose credentials trace back to the Cyber AB's accreditation and certification activities. When selecting an assessment provider, contractors should verify that the organization is currently accredited and that assessors are certified, using the Cyber AB Marketplace and official sources, while remembering that accreditation of an assessor does not substitute for actually meeting the applicable CMMC requirements.
C3PAOs and Individual Assessors
Organizations seeking to perform CMMC assessments must be accredited as C3PAOs, and the individuals conducting assessments must be certified, both functions administered by the Cyber AB. These parties depend on the Cyber AB for their standing in the ecosystem and should monitor its evolving requirements and processes, which may change as the CMMC program is phased in and revised.
Compliance Officers and Acquisition Personnel
Those responsible for interpreting CMMC obligations or evaluating whether a vendor's certification is legitimate need to distinguish the Cyber AB's accreditation role from the DoD's ownership of the program requirements. This distinction matters when determining the authoritative source for a given question and when assessing the credibility of a certification presented during procurement.
Small, Medium, and Non-Traditional Businesses
Firms new to the defense industrial base should understand where accreditation authority sits so they can identify legitimate assessors and avoid conflating a provider's Cyber AB standing with the substantive cybersecurity work still required to meet CMMC. Given the program's phased rollout, these organizations should verify the current ecosystem structure against official DoD and Cyber AB sources.

Inside Cyber AB

Cyber AB (The Cyber Accreditation Body)
The organization designated to serve as the accreditation body for the Cybersecurity Maturity Model Certification (CMMC) ecosystem, formerly known as the CMMC Accreditation Body (CMMC-AB). It operates under an agreement with the DoD but is a distinct, non-governmental entity rather than a part of the Department of Defense itself.
Accreditation function
The Cyber AB is generally responsible for accrediting the third-party assessment ecosystem rather than issuing certifications directly to defense contractors. Readers should verify the current division of responsibilities against official Cyber AB and DoD sources, as roles have evolved across the program's development.
Assessment ecosystem oversight
The body is associated with authorizing and overseeing the participants who conduct or support CMMC assessments, such as assessment organizations and individual assessors. The specific titles, credentials, and authorization pathways are defined by program documentation that should be confirmed against current authoritative text.
Relationship to DoD CIO and CMMC
The Cyber AB supports the CMMC program, which the DoD established to verify contractor implementation of safeguards for Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). The DoD CIO's office maintains policy authority over CMMC, while the Cyber AB fills an accreditation role distinct from that policy authority.

Common questions

Answers to the questions practitioners most commonly ask about Cyber AB.

Is the Cyber AB the government body that issues CMMC requirements?
No. The Cyber AB (Cyber Accreditation Body) is not a government agency and does not issue CMMC requirements. CMMC as a program is established by the Department of Defense (DoD CIO), and the underlying security requirements generally derive from sources such as NIST SP 800-171. The Cyber AB operates as the accreditation body responsible for the assessment ecosystem rather than for setting the security controls themselves. Readers should confirm the current division of responsibilities against official DoD and Cyber AB sources, as the program has evolved through multiple phases and revisions.
Does being accredited or trained through the Cyber AB ecosystem mean my organization is CMMC certified?
No. Accreditation and training within the Cyber AB ecosystem apply to the assessors and assessment organizations, not to the defense contractors seeking certification. An organization seeking a CMMC certification is assessed by an authorized assessment organization; the assessment and any resulting certification are distinct from the accreditation of the parties who perform that work. Assessment is not the same as authorization or certification, and readers should verify current certification pathways against official program guidance.
What role does the Cyber AB play in the CMMC assessment ecosystem?
The Cyber AB is generally described as the accreditation body that oversees the ecosystem of assessment organizations and individual assessors under CMMC. Its function centers on accrediting and authorizing the parties that perform assessments rather than on performing the assessments of contractors directly or issuing the DoD's requirements. Because the program has been rolled out in phases and revised over time, the reader should confirm the Cyber AB's current specific responsibilities against the latest official DoD and Cyber AB publications.
How does an organization find an assessor or assessment organization associated with the Cyber AB?
Organizations typically identify authorized assessment organizations and assessors through the ecosystem maintained under the Cyber AB's accreditation processes. Because the roster of authorized parties and the mechanisms for locating them can change as the program matures, this entry does not provide a specific list or count. The reader should consult the current official Cyber AB and DoD CMMC resources to confirm which organizations and individuals are presently authorized.
Does Cyber AB involvement replace an organization's obligations under DFARS clause 252.204-7012?
No. The Cyber AB's role in the assessment ecosystem does not by itself substitute for a contractor's distinct contractual obligations, which may include requirements under DFARS clauses and the safeguarding of Controlled Unclassified Information (CUI). CMMC and existing DFARS safeguarding obligations are related but distinct, and the reader should confirm how they interact for a given contract against current DoD guidance and the specific contract terms rather than assuming one satisfies the other.
How should compliance officers stay current with changes affecting the Cyber AB's role?
Because CMMC has been implemented through a phased rollout and successive revisions, the Cyber AB's specific responsibilities, terminology, and processes may change. Compliance officers should track official DoD CMMC program publications and current Cyber AB communications rather than relying on prior descriptions. This entry does not cover implementation, contractual, or legal specifics, which the reader must verify against the applicable current authoritative sources.

Common misconceptions

The Cyber AB is a part of the Department of Defense or a federal agency.
The Cyber AB is a separate, non-governmental accreditation body operating under an agreement with the DoD. It is not itself a federal agency, and DoD policy authority over CMMC generally rests with the DoD CIO rather than the Cyber AB.
The Cyber AB directly certifies defense contractors as CMMC compliant.
In most implementations the Cyber AB's role centers on accrediting and overseeing the assessment ecosystem rather than personally certifying individual contractors. Contractors generally obtain assessments through authorized third parties, and the specifics should be verified against current program documentation.
The Cyber AB and CMMC are the same thing and can be used interchangeably.
CMMC is the DoD certification program and model, while the Cyber AB is the accreditation body that supports parts of that program. Conflating the two obscures who issues policy (DoD), who accredits the assessment ecosystem (Cyber AB), and who conducts assessments (authorized assessment organizations).

Best practices

Confirm the Cyber AB's current name, scope, and responsibilities against official Cyber AB and DoD sources before relying on them, since the organization and the CMMC program have evolved through multiple phases and revisions.
Distinguish clearly in your documentation between DoD policy authority over CMMC, the Cyber AB's accreditation role, and the assessment activities performed by authorized third parties.
Do not assume the Cyber AB issues contractor certifications directly; verify the correct pathway for obtaining a CMMC assessment against current program requirements.
Verify assessor and assessment organization authorization status through the appropriate official channels rather than assuming any provider is Cyber AB accredited.
Track program updates, as CMMC requirements, phased rollout timelines, and the accreditation body's responsibilities are subject to change and should be reconfirmed against the applicable current text.
Remember that engaging an accredited assessment party addresses assessment and certification steps but does not by itself equate to comprehensive security; maintain ongoing safeguards for FCI and CUI independent of the certification milestone.