Job Description
The Certified CMMC Assessor (CCA) is responsible for conducting official CMMC assessments of organizations seeking certification under the Department of Defense (DoD) Cybersecurity Maturity Model Certification (CMMC) program. CCAs evaluate the implementation and effectiveness of CMMC practices and processes, validate evidence, conduct interviews, and contribute to assessment findings under the governance and ethical standards established by Cyber AB.
This role operates as part of a CMMC Third-Party Assessment Organization (C3PAO) and may work independently or under the direction of a Lead CCA.
Key Responsibilities
CMMC Assessment Execution
- Conduct CMMC assessments in accordance with the CMMC Assessment Process (CAP).
- Evaluate implementation of CMMC practices and processes against:
- NIST SP 800-171
- NIST SP 800-172 (as applicable)
- Perform evidence review, interviews, and technical walkthroughs.
- Validate the adequacy, completeness, and consistency of assessment artifacts.
Evidence Documentation Review
- Review and assess:
- System Security Plans (SSPs)
- Policies and procedures
- Plans of Action Milestones (POAMs)
- Document assessment results, observations, and rationale clearly and accurately.
Reporting Assessment Support
- Contribute to official assessment reporting and supporting documentation.
- Communicate findings to Lead CCA and assessment leadership.
- Support quality assurance and internal review processes.
Professional Conduct Security
- Maintain strict assessor independence and avoid conflicts of interest.
- Protect Controlled Unclassified Information (CUI) and sensitive assessment data.
- Adhere to Cyber AB Code of Professional Conduct and ethics requirements.
, Required Skills
Certifications
- Active Certified CMMC Assessor (CCA) certification issued by Cyber AB
- Good standing with Cyber AB and applicable C3PAO
Experience
- Prior experience in cybersecurity assessments, audits, or compliance programs
- Demonstrated familiarity with DoD cybersecurity requirements
- Experience working with regulated environments preferred
Skills
- Strong analytical and documentation skills
- Ability to interpret technical and regulatory requirements
- Professional communication with technical and non-technical stakeholders
- Attention to detail and assessment rigor
, Additional Details
- CCAs may not independently issue final certification decisions unless designated as Lead Assessor
- CCAs operate under C3PAO authority and assessment governance
, About The Enterprise Security Consultants, LLC
TES Consultants is an SBA 8(a) certified Woman-Owned Small Business (WOSB) specializing in advanced cybersecurity and IT solutions. We leverage extensive industry experience and technical expertise to deliver automated, innovative, and impactful strategies for our DoD, Federal Civilian and Private sector clients.