
CMMC Certified Professional
The CMMC Certified Professional (CCP) certification is the foundational credential for professionals entering the US Department of War's Cybersecurity Maturity Model Certification (CMMC) ecosystem. It validates your ability to help organizations achieve assessment-ready cybersecurity programs and to participate on official CMMC assessment teams. Earning the CCP is the required first step toward the CMMC Certified Assessor (CCA) credential, creating a clear pathway into assessment and higher-level consulting roles.
322 practice questions · Updated 2026-07-30
CCP Curriculum
Every domain, objective, and concept the CCP exam measures.
- CMMC Ecosystem Authorities
- Role Comparison
- Requirements Analysis
- Identify CoPC guiding principles
- Apply CoPC practices
- Understand ISO/IEC requirements
- Understand DOW requirements
- Integrate CoPC, ISO/IEC, and DOW
- Definition of FCI
- Definition of CUI
- CUI Categories and Markings
- FCI and CUI in Nonfederal Systems
- Differences Between FCI and CUI
- Regulatory Basis for FCI and CUI
- Roles and Responsibilities for FCI/CUI Protection
- Roles and Responsibilities for FCI
- Roles and Responsibilities for CUI
- Authority for FCI and CUI
- Identify CMMC source documents
- Identify CMMC supplementary documents
- Understand the purpose and hierarchy of CMMC documents
- Understand the role of source documents in defining CMMC requirements
- Understand the role of supplementary documents in CMMC implementation
- Recognize updates and revisions to CMMC documents
- Identify CMMC source documents
- Map practices to source requirements
- Evaluate practice implementation
- Determine Level 1 compliance
- CMMC Assessment Criteria
- CMMC Assessment Methodology
- Mapping Practices to Assessment Criteria
- Evaluating Practice Implementation
- Scoring and Determining Compliance
- Handling Assessment Findings
- Evidence Location Adequacy
- Evidence Collection Sufficiency
- Evidence Quality Evaluation
- Evidence Usage Appropriateness
- CCP Role in Phase 1
- Phase 1 Objectives
- Pre-Assessment Activities
- Role Boundaries
- Coordination with Lead Assessor
- Preparation Deliverables
- Role of CCP as Assessment Team Member
- Phase 2 Assessment Activities
- Evidence Collection Methods
- Assessment Procedures and Standards
- Documenting Assessment Findings
- Handling Nonconformities
- Communication and Coordination
- Maintaining Objectivity and Independence
- Role of CCP in Phase 3
- Assessment Results Documentation
- Report Submission Procedures
- Handling Non-Conformities
- Post-Assessment Communication
- Purpose of Phase 4
- Role of the CCP in Phase 4
- POA&M Item Evaluation Process
- Evidence Review and Verification
- Documentation of Findings
- Communication with Assessment Team
- Handling Unresolved POA&M Items
- Phase 1: Pre-Assessment Preparation
- Phase 2: On-Site Assessment Execution
- Phase 3: Post-Assessment Reporting
- Phase 4: Assessment Close-Out
- Phase Sequencing and Dependencies
- CMMC Scoping Overview
- Scoping Steps in Assessment Process
- Asset Categorization
- CUI Identification
- Scoping Considerations
- Scoping Documentation
- Identify FCI in a scenario
- Apply scoping criteria to FCI assets
- Classify assets by FCI handling role
- Determine scope boundaries for FCI
- Document FCI asset scope
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for CCP, so none is invented.