Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA

CMMC Certified Assessor

The CMMC Certified Assessor (CCA) certification equips experienced cybersecurity and compliance professionals with the advanced skills needed to conduct formal CMMC Level 2 certification assessments. As the credential required to evaluate organizations for the US Department of War's CMMC ecosystem, CCA holders verify security controls, review evidence, and determine whether organizations handling Controlled Unclassified Information (CUI) meet CMMC Level 2 requirements. This certification is essential for those performing official assessments and advancing in the defense industrial base.

Exam formatComputer-based
DeliveryPSI
Free questions117

Content last reviewed 30 July 2026 · Up to date

The certification

What CMMC Certified Assessor proves, and what it asks of you

What this certification covers, who it is written for, and what the exam itself looks like on the day.

4domains
6objectives
36concepts
US $575.00exam fee
What it is

What this certification is

What it validates, who it is written for, and the experience it assumes.

About this certification

The CMMC Certified Assessor (CCA) certification is the credential required to perform formal CMMC Level 2 certification assessments within the US Department of War's (DoW) cybersecurity ecosystem. It validates that experienced cybersecurity professionals can evaluate evidence, validate security controls, conduct interviews, and determine whether organizations handling Controlled Unclassified Information (CUI) meet CMMC Level 2 certification requirements.

CCA holders are equipped with the advanced, job-ready skills needed to conduct official CMMC Level 2 assessments. The certification covers evaluating organizations seeking certification against CMMC Level 2, assessment scoping, the CMMC Assessment Process (CAP), and assessing CMMC Level 2 practices. As ISACA serves as the official CMMC Assessor & Instructor Certification Organization (CAICO), this credential is globally recognized and required for many organizations and government agencies.

Who it’s for

The CCA certification is designed for experienced cybersecurity and compliance professionals who are ready to conduct formal CMMC Level 2 assessments. It is ideal for IT and security practitioners transitioning into compliance, government contractors and defense industry personnel, risk, audit, and compliance professionals, and aspiring Lead CCAs. Candidates should have a strong background in cybersecurity and be comfortable evaluating security practices, reviewing evidence, and making compliance determinations. The certification is particularly relevant for those working within the defense industrial base and supporting organizations pursuing CMMC certification.

Recommended experience

ISACA recommends that candidates have experience in cybersecurity and compliance, particularly in evaluating security controls and conducting assessments. While not mandatory, this experience helps candidates succeed on the exam and in the role. Experience in cybersecurity, compliance, or risk assessment; Familiarity with CMMC requirements and assessment processes; Understanding of Controlled Unclassified Information (CUI) handling; Ability to evaluate evidence and validate security controls

The syllabus

What you’ll learn

Every domain and objective ISACA measures, with the weight they carry on the exam.

The official ISACA exam outline · checked 30 July 2026 · See the source

Domain 1: Evaluating Organizations Seeking Certification (OSC) Against CMMC Level 2 (15%)
  • Assess the various environmental considerations of Organizations Seeking Certification (OSCs) against CMMC Level 2 practices
1 objectives · 28 free questions · 6 pages
Domain 2: CMMC Level 2 Assessment Scoping (20%)
  • Analyze the CMMC assessment scope of Controlled Unclassified Information (CUI) assets using the five categories of CUI assets as defined in the CMMC Level 2 Assessment Scoping Guide
  • Given a scenario, analyze the CMMC assessment scope based on the redetermined CUI categories within the CMMC Level 2 Assessment Scoping Guide
  • Evaluate the CMMC assessment scope considerations based on the CMMC Level 2 Assessment Scoping Guide
3 objectives · 35 free questions · 7 pages
Domain 3: CMMC Assessment Process (CAP) (25%)
  • Given a scenario, apply the appropriate phases and steps to plan, prepare, conduct, and report on a CMMC Level 2 Assessment
1 objectives · 26 free questions · 6 pages
Domain 4: Assessing CMMC Level 2 Practices (40%)
  • Identify evidence verification/validation methods and objects for practices based on the CMMC Level 2 Assessment Guide and CMMC Assessment Process (CAP) documentation
1 objectives · 28 free questions · 6 pages
On the day

The exam itself

Everything ISACA publishes about sitting it, and nothing we inferred.

Prerequisites

Complete the mandatory CAICO-approved CCA course

CertificationCMMC Certified Assessor
Exam formatComputer-based
DeliveryPSI
LanguagesEnglish
PricingUS $575.00
After you pass

Where this credential goes next

The path ISACA lays out, how the credential is kept, and where to book.

Step-by-step path to CMMC Certified Assessor

PrerequisiteComplete the mandatory CAICO-approved CCA course
CMMC Certified Assessor badgeCredential earnedCMMC Certified Assessor Certification
Renewal and maintenance

ISACA certifications require renewal through earning CPE credits. The CCA certification must be maintained by adhering to the Continuing Professional Education Policy. Stay current with the latest technologies and maintain your certification.

Learn more about renewal requirements
Lifecycle status

This certification is currently active and available. ISACA maintains this certification to validate current skills and industry relevance.

Exam status: ActiveMaintained by ISACA

Exam registration

Register for the exam through PSI, ISACA’s authorized testing partner.

Schedule your exam

Visit the official ISACA certification page for exam policies and requirements.

View the official page
Your coach

And when you are serious, your coach Pip takes over

Your coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.

See how the coach works
Before you book

Questions people ask

How does the CCA exam relate to the CCP certification?

The CCA exam requires candidates to hold an active CCP certification. CCP is the foundational certification for the CMMC ecosystem, and CCA builds on that foundation to prepare professionals for conducting formal CMMC Level 2 assessments.

Is the CCA certification required to perform CMMC Level 2 assessments?

Yes, the CCA certification is required to perform formal CMMC Level 2 certification assessments within the US Department of War's cybersecurity ecosystem.

Can I take the CCA exam without completing Tier 3 training?

Yes, CCA candidates do not need to complete Tier 3 before taking CCA training and exam.

How long is my exam eligibility period after registration?

Upon registration, CCA exam candidates have a six-month eligibility period to take their exam. This means that from the date you register, you have six months to take your CCA exam.

What is the retake policy for the CCA exam?

ISACA has a zero-tolerance policy for fraudulent test-taking activities. Specific retake policies are not detailed on the official page, but candidates should refer to the Terms of Use for exams.

Are there any special accommodations for candidates with disabilities?

ISACA provides special accommodations for candidates with disabilities. Candidates should refer to the Special Accommodations guide available on the ISACA website.

How soon will I receive my exam results?

The official page does not specify the exact timing for score reports. Candidates should refer to the Exam Candidate Guide for details.

What job roles does the CCA credential map to?

The CCA credential is designed for IT and security practitioners transitioning into compliance, government contractors and defense industry personnel, risk, audit, and compliance professionals, and aspiring Lead CCAs.

Can I recertify by passing a different ISACA exam?

ISACA certifications require renewal through earning CPE credits. Passing a different exam may contribute to CPE requirements, but specific recertification policies are not detailed on the official page.

Is the CCA exam available globally?

Yes, ISACA's CCA certification exams are computer-based and administered at authorized PSI testing centers globally or as remotely proctored exams.

Information freshness · Content last reviewed on 2026-07-30 Up to date
Practice free questions 117 questions, free, no account needed.