
The United States Department of Defense (“DoD“) has been diligently shepherding a series of groundbreaking requirements through the regulatory process to help implement the Cybersecurity Maturity Model Certification (“CMMC“) program. Under the CMMC program, companies that directly or indirectly supply goods and services to DoD (i.e., those in the “Defense Supply Chain“) must put in place certain information security requirements. If a company in the Defense Supply Chain is expected to handle information that a law, regulation, or government-wide policy says is sensitive, the CMMC program will also require that company to obtain from an independent third-party (a CMMC 3rd Party Assessment Organization, or “C3PAO“) a certification that the requirements have been properly implemented.
DoD expects that at least ~75,000 companies will need CMMC certifications. Those certifications are performed by CMMC Certified Assessors (“CCAs“). To become a CCA, a person must first become a CMMC Certified Professional (“CCP“).
The CUI Institute estimates that the CMMC Ecosystem needs at least 1,800-2,000 CCAs and Lead CCAs to meet industry demand for assessments once a variety of factors are taken into account. We also estimate that the CMMC Ecosystem needs at least 4,000-4,500 CCPs to meet industry demand. As of September 2, 2025 there are approximately 500 CCAs and 1100 CCPs. This means there is likely to be significant demand for new CCPs and CCAs for at least the next 12-18 months. When the proposed Federal Acquisition Regulation (“FAR“) regulation governing Controlled Unclassified Information (“CUI“) is finalized, we anticipate that the numbers noted above will at least double, and could triple.
To become a CCP, a candidate must demonstrate basic knowledge of information security by having a relevant college degree or equivalent work experience. The CCP candidate must then take a course and pass the corresponding exam. This helps industry feel confident that the CCP candidate has a reasonable understanding of the CMMC program and the associated information security requirements. The exam covers a range of topics and studying for it can be a challenge.
As part of our mission to help educate the CMMC Ecosystem, the CUI Institute is excited to announce the availability of a CMMC Program v. 2.0 Core Knowledge Test for our members. This test includes a pool of 150 questions that help CCP candidates and others test their knowledge of the CMMC program.
If you are studying for the CCP exam, be sure to join the CUI Institute today and take advantage of the test!
