CMMC Assessor Jobs:
The New Cleared Role, What It Pays, and How to Qualify
CCP, CCA, Lead Assessor – a job category that did not exist three years ago and cannot be filled. What each pays.
July 22, 2026
Cybersecurity
On 13 July 2026 the Department of War suspended the CMMC Phase II requirements due to take effect on 10 November 2026. Phase II would have made a third-party certification assessment a condition of contract award, and it was the entire commercial case for the CMMC Certified Assessor. Nothing in that announcement revokes a certification, closes an assessment firm, or repeals the regulation.
Key takeaways
- CMMC Phase II was suspended on 13 July 2026. Phase I self-assessment requirements remain in force.
- This is not a cleared job. The rule states the Tier 3 background investigation “will not result in a security clearance” (32 CFR 170.11(b)(3), 2024).
- We looked for a published salary survey covering CCP or CCA roles and found none. DoD’s model rate of $260.28 per hour (2023 dollars) is a bill rate, overhead and profit included, not a wage.
- The Cyber AB self-reports over 1,000 assessors and 110 authorized C3PAOs as of 15 July 2026.
- The reform RFI closes at noon EDT on 14 August 2026, not end of day. The 60-day review ordered on 13 July runs out around 11 September 2026, our count rather than a published deadline.
What did the Department of War actually suspend?
Short answer. Phase II, the stage that would have made a C3PAO-led Level 2 certification a condition of award. Program managers may no longer designate Level 2 (C3PAO) or Level 3 (DIBCAC) assessments. No rule was repealed, no certification cancelled.
DoW Chief Information Officer Kirsten A. Davies announced it alongside “a 60-day study of the future of this program,” aimed at reducing compliance barriers for small and medium sized businesses. The same release characterises SBA reporting as confirming that CMMC compliance is pushing companies out of the industrial base; that is the Department’s characterisation, and we did not obtain the underlying SBA analysis.
The implementing memorandum, signed the same day by Michael P. Duffey, Under Secretary of War for Acquisition and Sustainment, tells requiring activities they “may not designate CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) assessments during this period.” Active solicitations must be amended, existing contracts modified before the next option period, and no waivers granted during the review.
Now the half that matters if you hold a certification. The Federal Register shows no CMMC rulemaking between 1 October 2025 and 21 July 2026, so 32 CFR part 170 stands as written and DFARS 252.204-7021 still carries its NOV 2025 date. The CIO reform memo sets the interim posture: NIST SP 800-171 Rev 2 continues through self-assessments and select government-led assessments, and DFARS 252.204-7012 is untouched. The third-party layer lost its mandate; compliance work did not vanish.
Is a CMMC assessor job a cleared job?
Short answer. No, and the regulation says so in words. The Tier 3 investigation an assessor must pass yields national security eligibility for a non-critical sensitive, Moderate Risk position, and the rule states it “will not result in a security clearance.”
It is the most expensive misunderstanding attached to the role, setting pay expectations wrong before the first interview. Section 170.11(b)(3) of the final rule at 89 FR 83092 reads: “This Tier 3 background investigation will not result in a security clearance and is not being executed for the purpose of government employment.”
The vetting burden starts at the entry rank too: a CMMC Certified Professional faces the identical requirement under 170.13(b)(3). Where a candidate is not eligible for a Tier 3, DoD may determine an equivalent, for the CMMC Program only. The paperwork looks like clearance paperwork; the credential does not carry into classified work. If you have been pricing a CCA role against what a security clearance is actually worth, subtract that premium. The machinery is familiar, as our explainer on what DCSA does describes.
What does a CMMC assessor actually get paid?
Short answer. Nobody publishes a defensible number. We searched for a salary survey covering CMMC Certified Assessors or Certified Professionals and found none. What exists is a government cost model whose rate is what a client pays a firm.
DoD’s Regulatory Impact Analysis prices C3PAO assessor labour at $260.28 per hour in 2023 dollars. Footnote 45 calls it “The ESP/C3PAO rate” and says it “includes the labor rate, overhead expense, G&A expense, and profit.” An assessor’s wage is the remainder after the firm takes those out, and the split is never published, so it cannot honestly be converted into a salary, as our explainer on wrap rate sets out.
It is softer still. Footnote 64 assumes an external service provider is an “Information Assurance Specialist Level 7” with an hourly rate of $260, one assumed category covering service providers and assessors alike. DoD disclaims the exercise, writing that “market forces of supply and demand will determine C3PAO pricing.”
The engagement shapes below are cost-model assumptions, not legal minimums; both come to 40 assessor-hours per person, our arithmetic. The rule’s floor is a Lead CCA plus one other CCA (170.9(b)(12)) and a separate CCA doing quality assurance who cannot be on that team (170.9(b)(13)), so three distinct CCAs touch any Level 2 assessment, which is our inference.
| Figure | What it measures | Basis and caveat | Vintage |
|---|---|---|---|
| $260.28/hr | C3PAO assessor labour, DoD cost model | Bill rate, not a wage: includes overhead, G&A and profit (fn 45). An assumed “Information Assurance Specialist Level 7” rate (fn 64). | 2023 dollars |
| $52,056 / $31,234 | Modelled C3PAO revenue per assessment | Firm revenue over a 5-person, 200-hour or 3-person, 120-hour engagement. Team sizes are model assumptions, not the regulatory minimum. | 2023 dollars |
| $124,910 | BLS median wage, information security analysts (SOC 15-1212) | A real wage, loose proxy: all such analysts nationwide, every industry; cannot separate assessors from those they assess. | May 2024 |
| Under $69,660 to over $186,420 | BLS 10th and 90th percentiles, same occupation | Same page and release as the median, so they are one distribution, not a splice of survey years. | May 2024 |
| CCA / CCP salary survey | None we could find | A “CMMC assessor salary” on a jobs aggregator is self-reported crowd data, undisclosed sample. | n/a |
Every BLS figure here came from one Internet Archive capture, because bls.gov returns 403 to automated clients: the Occupational Outlook Handbook page captured 5 July 2026, the most recent that exists. Median and percentiles share that page, so they share a basis.
The surrounding market is the fairest thing on offer: BLS put the median for information security analysts at $124,910 in May 2024, with 29% projected growth to 2034. It bundles CMMC assessors with corporate SOC analysts and hospital security staff. Weather, not forecast.
How do you qualify as a CCP, a CCA or a Lead CCA?
Short answer. Through the CAICO, and only the CAICO. The CCP is the mandatory first step. A CCA needs the CCP plus three years of cybersecurity work, one year of assessment or audit work, and an Intermediate qualification under DoDM 8140.03. Lead CCA is not a parallel route; its years stack on top.
| Role | Experience gate | DCWF 612 proficiency | Vetting | Validity |
|---|---|---|---|---|
| CCP | CAICO training and certification. Advises clients; may sit on a Level 2 team only under CCA oversight. | Not required by the provisions cited here | Tier 3 (170.13(b)(3)) | 3 years if maintained: annual renewal, $250 |
| CCA | Be a CCP, plus 3 years cybersecurity and 1 year assessment or audit experience | Intermediate | Tier 3 (170.11(b)(3)) | 3 years if maintained: annual renewal, $500 |
| Lead CCA | Everything in the CCA row, then 5 years cybersecurity, 5 years management, 3 years assessment or audit. Cumulative, not an alternative route. | Advanced | Tier 3 | 3 years if maintained: CCA renewal plus a Lead renewal |
Read those rows as a stack, not a menu. Lead CCA requirements sit at 170.11(b)(10), inside the list 170.11(a) says CCAs “must meet all of,” and DoD told a commenter that “the experience requirements referenced for the Lead CCA are cumulative.” A Lead is a CCP first, then a CCA.
The proficiency levels come from DoD Manual 8140.03, dated 15 February 2023. Intermediate means extensive knowledge of basic concepts applied with periodic high-level guidance; Advanced means in-depth command of advanced concepts with little to no guidance. The manual permits any one of three foundational options: education, training or certification.
For assessors the CAICO closes that latitude. The Cyber AB’s published CCA requirements demand at least one baseline certification aligned to Intermediate or Advanced for work role 612. Its qualifying table, captioned as of September 2025, includes Security+, CASP+, Cloud+, PenTest+, CGRC/CAP and GSEC at Intermediate; CISSP, CISA, CISM, CySA+, CCISO, GSLC and GSNA at Advanced. Budget for one of those exams: a degree or DoD training satisfies the manual and still stops you at the CCA application, because 170.10(a) makes the CAICO the only body that may certify anyone. DoD’s own 612 page sits behind a login; check the Cyber AB list before booking.
One recency trap sits inside the manual: a degree or approved training used for the foundational portion must generally fall within five years unless continuous work in the discipline is shown, no more than three consecutive years’ lapse. Our guides to 8140 certification requirements and the IAT Level II path cover verification.
Was the assessor market actually short of people?
Short answer. The government says yes: the CIO memo names “severe shortages in third-party assessment capacity” as a reason for the pause. We tested that against DoD’s own projections: the arithmetic does not contradict the memo, though one figure inside it cuts the other way.
Take DoD’s pre-suspension forecast: C3PAO-led assessments ramping from 135 in year one to 673, then 2,252, then 4,452 in year four, against a population the rule puts at 8,350 medium and large entities needing Level 2 certification. Those carry the model’s other-than-small shape of 200 team-hours, so year four is 890,400 hours of C3PAO labour, about 890 hours a year across the “over 1,000” assessors the Cyber AB reports. The division is ours, and here is the benchmark that cuts against us: 890 hours is roughly 45% of a 2,000-hour year, which on its own reads as slack, not shortage. Two things stop it settling the question.
The first is the column beside it: DoD models small entities separately and in larger numbers, its year-two calculation booking 673 other-than-small assessments and, on a separate line, 1,926 small-entity ones. None of it falls inside the 4,452, and the year-four small-entity count sits in a Federal Register table published as an image, so we will not extrapolate. So 890 hours is a floor: medium and large entities alone, before travel, the quality-assurance pass the rule demands from a CCA outside the team, and a small-business population several times larger. Reporting is not on that list; the modelled 200 hours already cover planning, assessment and reporting. The second is time: year four of a ramp that began 10 November 2025 lands around 2029, while the headcount we divided by is a July 2026 count that nothing here projects forward. We looked for a number contradicting the shortage claim and found none.
Headcount was probably the wrong place to look. An assessor cannot sell an assessment; only an authorised firm can, and there were 110 authorized C3PAOs, each required to pass its own DIBCAC-conducted Level 2 assessment and clear an SF-328 foreign ownership review, a narrow gate our piece on FOCI and the SF-328 explains. Authorisation, scheduling and geography ration this work before headcount does. That fits the memo and the arithmetic, and we cannot prove it.
Handle the supply figures carefully. Every Cyber AB count here is self-reported, published two days after the suspension inside a statement arguing the programme should survive. Not an independent audit.
What should a defense employer hire for right now?
Short answer. Internal self-assessment capability against NIST SP 800-171 Rev 2, because Level 1 (Self) and Level 2 (Self) are the only designations a program manager may now require. Third-party assessor headcount has no mandate behind it.
The implementing procedures restrict designations to the two self-assessment levels, while the CIO memo keeps NIST SP 800-171 Rev 2 in force and leaves DFARS 252.204-7012 untouched. A contractor still has to know its score, affirm it and report incidents; what it no longer has to do is buy a third-party certificate. Our companion piece on the staff CMMC Level 2 forces you to hire covers that team shape, and reading a DoD contract award shows where demand surfaces.
The Cyber AB’s chief executive argues that a Level 2 certification “remains a compelling calling card for subcontracting viability to primes.” He may be right, and he runs the organisation whose survival depends on it. The Department’s July 2026 FAQ still points companies at the Cyber AB marketplace, a signal the other way.
Frequently Asked Questions
Does a CMMC assessor need a security clearance?
No. The rule requires a Tier 3 background investigation resulting in a determination of national security eligibility, and states expressly that it “will not result in a security clearance.” The position is non-critical sensitive at a Moderate Risk level. It is initiated on the SF-86, which is why the two get confused.
Are existing CCP and CCA certifications still valid after the July 2026 suspension?
Nothing published on 13 July 2026 revokes one, and the accreditation body says training, exams and C3PAO assessments continue. Read the rule’s wording, though: 170.11(b)(1) and 170.13(b)(1) say “obtain and maintain certification from the CAICO,” then give the three-year term. Maintaining means good standing plus an annual renewal fee, $250 for a CCP and $500 for a CCA on the Cyber AB’s schedule. Skip a renewal because the programme looks paused and the certification lapses well inside the three years.
What is the average salary for a CMMC assessor?
There is no defensible answer. We found no published statistical survey of CCP or CCA pay, and aggregator numbers are self-reported with undisclosed sample sizes. The nearest official figure, $260.28 per hour from DoD’s 2023-dollar cost model, is a bill rate containing overhead, G&A and profit.
Can I work as a CMMC assessor independently?
Not in the usual freelance shape. Assessors work Level 2 certification assessments in support of a C3PAO, and the rule forbids using any IT other than that issued by the engaged C3PAO, including personal devices and cloud services, to handle assessment information. The firm supplies the tooling and holds the authorisation.
What to watch between now and September 2026
Two dates decide whether this category recovers or gets redesigned. The reform Request for Information closes at 12:00 noon EDT on 14 August 2026, asking respondents to name the five most prohibitive cost drivers and propose regulatory changes. The SAM.gov notice carries that cutoff; the SBA Office of Advocacy write-up covers the substance but prints only the date, so do not file on the afternoon of the 14th. The 60-day clock that started on 13 July then runs out around 11 September 2026, our count rather than a commitment: the Department promised guidance “at the conclusion of the CIO’s 60-day review,” with no date attached.
Read the task force’s charter: it is directed to recommend a framework that “replaces prohibitive, third-party compliance models with scalable, realistic security measures.” Our reading, inference rather than anything the memos state, is that a credential requiring a Tier 3 investigation, an annual renewal and a firm-issued laptop does not survive a mandate written around speed and small-business entry without being rewritten. The recommendations would confirm or falsify that. Until they land, treat the CCP as the lighter commitment that keeps you eligible, and any plan assuming 2027 assessment volume as a bet on a document nobody has read.