The CMMC accreditation body “CyberAB” has been outsourcing its work related to ISO 17020 assessment for C3PAOs, but has not revealed this information to the CMMC ecosystem. Because the CyberAB has been unable to obtain ISO 17011 accreditation of its own — a requirement for it to perform the required ISO 17020 assessments — the body has instead outsourced the work to ANAB, an existing US accreditation body.
Oxebridge discovered the arrangement when investigating the work done by former DoD CMMC Program Management Office head Stacy Bostjanick. Bostjanick retired from the Dept. of War and immediately took up a position with the CMMC services company Cybersec Investments. Oxebridge has filed a felony criminal complaint against Bostjanick with the DOD Inspector General’s office.
Cybersec had been found to be claiming full “accreditation” to ISO 17020, which should not be possible since only the CyberAB may accredit C3PAOs and that body does not yet have ISO 17011. During its research, Oxebridge found this statement on the Cybersec website, revealing the outsourcing to ANAB:
An ANAB blog post, published by its parent company ANSI, did mention the arrangement in 2020:

While that post was dated 2020, an Oxebridge source reported that the contract between ANAB and the CyberAB may have actually been signed in 2024, and the date on the blog post is not correct.
The original contract between the Dept. of Defense and the CyberAB (then called the “CMMC AB“) required the CyberAB to perform ISO 17020 accreditation assessments and did not allow for outsourcing. The CyberAB was specifically created by Katie Arrington to perform these assessments, and ANAB was denied the role.
Oxebridge has argued it was illegal for Arrington to create a private company to compete with existing companies that were already fully accredited to offer the exact service. Arrington’s prior boss and campaign donor, Ty Schieber, later took over the AB as its first Board chair.
It is believed the DoD contract was updated twice — once to allow for “authorization” of C3PAOs prior to full accreditation, and a second time after the CyberAB changed its name — but Stacy Bostjanick blocked FOIA requests to release the contract, saying it was not “a benefit” to the American people. Under federal law, such contracts are required to be made public.
Oxebridge argues that Bostjanick’s new employer, Cybersec, now benefits from her blockage of that contract, since we cannot know if CyberAB’s accreditation of Cybersec, using ANAB as its outsourced service provider, was allowed under the contract modification. By blocking the contract, Bostjanick has effectively made it impossible to know if Cybersec’s accreditation is valid.
Oxebridge did confirm with ANAB that it is performing ISO 17020 assessments for the CyberAB:

The arrangement creates more problems for CyberAB, since ISO 17011 requires that when outsourcing of assessments is performed, the AB must have a “documented process” on how it manages outsourcing. From that standard:
When asked to provide the document, the CyberAB instead answered with a cryptic reply that only admitted to the arrangement, but then did not provide the document.

The CyberAB publishes its procedures on its website, but no procedure for outsourcing appears on that site.
As a result, it does not appear that the CyberAB has the required procedure, and thus is in violation of ISO 17011.
Oxebridge has since learned that the only fully ISO 17020 accredited C3PAO is Bostjanick’s Cybersec Investments, according to a search on the CyberAB’s “CMMC Marketplace” site. On that site, accredited C3PAOs are granted the “ACC C3PAO” icon.

The ISO 17020 accreditation certificate appearing on the CyberAB website then indicates the assessment was performed in July of 2026:

Bostjanick retired from the Dept. of War in April, just three months before the accreditation of Cybersec. Four days later, she was announced as having been hired by Cybersec. The assessment by the CyberAB and ANAB would thus have been performed while Bostjanick was working at Cybersec.
It raises suspicions that the only ISO 17020 accredited C3PAO is the same one that Bostjanick — who heavily promoted the CyberAB for years while working at the DoD — works for. No other C3PAO has been granted ISO 17020 by the AB to date.
Because the CyberAB has not yet obtained its own ISO 17011 accreditation, there remains no clear way to escalate the problem to the body tasked with oversight of the AB. That is the IAAC, a Mexican organization that the DoD assigned to grant ISO 17011 to the AB. For now, however, the AB is only an “Associate Member,” and complaints cannot be filed against such members until they achieve “Full” member status.
Given the nature of the suspected violations, however, it would be unlikely the CyberAB could obtain ISO 17011 accreditation if the IAAC were to take up the matter.
It is also not clear how any decision by Mexico would be received by the Dept. of War, which unwittingly handed final oversight of the CMMC to that country while the PMO was led by Arrington and Bostjanick.
Oxebridge alleges that Bostjanick engaged in inside deals to benefit herself and Cybersec, using her role while at the DoD to do so. If the DODIG finds merit in the complaint, the cases could be handed over to the Dept. of Justice for criminal prosecution, and Bostjanick could face years in jail if convicted.







