Answers 2025/2026
RPO - ANSWERSRegistered Practitioner Organizations
C3PAO - ANSWERSCMMC Third Party Assessment Organization
LPP - ANSWERSLicensed Partner Publishers
LTP - ANSWERSLicensed Training Providers
CCI - ANSWERSCertified CMMC Instructor
What does DFARS 252.204-7019 Require? - ANSWERSDFARS 252.204-7019 requires the
implementation of NIST SP 800-171 standards with an assessment no older than 3 years.
SPRS Score
What does DFARS 252.204-7020 Require? - ANSWERSDFARS 252.204-7020 requires a
contractor/sub contractor to provide the government with access to its facilities.
What does DFARS 252.204-7021 Require? - ANSWERSDFARS 252.204-7021 requires the CMMC
Certification
, What does DFARS 252.204-7012 Require? - ANSWERSDFARS 252.204-7012 requires reporting of
cyber incidents within 72 hours, the submission of malicious software, and damage
assessments.
What organization is in charge of CMMC Assessors and Instructors? - ANSWERSCAICO (CMMC
Assessors and Instructors Certification Organization)
What organization ensures that stakeholders operate in accordance with ethical and
professional guidelines, and that assessments are fair, consistent, and meet with the CMMC
requirements? - ANSWERSCMMC Accreditation Body (CYBER AB)
What entities fall under the C3PAO/Assessment Category? - ANSWERSCCA
CCP
PA
What entities fall under the RPO/ Peparation category? - ANSWERSRP
What entities fall under the Training/LTP category? - ANSWERSCCI
PI
What entities fall under the education category? - ANSWERSLPP
True or False:
Self assessments must be done every year, and C3PAO assessments must be done every three
years for CMMC Level 2. - ANSWERSTrue
How long can an OSC maintain a Level 2 (third party assessment) status? - ANSWERSThree Years