As promised, Oxebridge has helped develop a gentle off-ramp for CMMC assessors affected by the Dept. of War’s rugpull on third-party CMMC certification requirements.

If you recall, the DoW announced a temporary pause on the third-party certification aspects of CMMC, even though overall compliance with CMMC is still required. (For now, we are back to self-attestation.) All signs point to the new DoW scuttling the third-party angle entirely, as they seem hell-bent against it. (An official memo issued a few days ago instructs Federal contracting officers to remove all requirements for CMMC certification from their contracts ASAP.)

This led to a far more dramatic fallout than the DoW had probably expected. Hundreds of people fell into the trap of false promises made by Katie Arrington, Ellen Lord, Kevin Fahey and Stacy Bostjanick, who pushed “credentials” issued by the Cyber AB as the way forward. Those folks spent many thousands of dollars pursuing various credentials for CMMC auditors, consultants, and more, only to — now — learn that they might have spent that time for nothing.

The response was so devastating that Oxebridge launched a suicide prevention campaign for those who might be facing bankruptcy, divorce, or other personal traumas. This was no joke.

We weren’t about to stop there, though. As usual, I like to provide real-world, actionable solutions, so I reached out to see if there was a way these folks — with their various CyberAB credentials now useless in their pockets — could transition to the more stable world of ISO 27001 certification. That scheme has the advantage of, you know, actually existing and being in desperate need of new auditors. More and more contracts require ISO 27001 for defense contractors, especially those in the IT world.

I spoke with Eric LaChapelle, the CEO of PECB, one of the largest auditor certification and training bodies on the planet. Unlike its competitors in the ISO field, PECB is also the only one actually accredited as a credentialing authority. (Yes, most ISO credentialers don’t get ISO accredited themselves.)

I proposed that he develop a specific program that would take the current Cyber AB credentials into account and provide a training course to transition current CMMC assessors to make them qualified to pursue ISO 27001 career status. I also suggested he offer it for free, given the crisis that we are facing.

Amazingly, LaChapelle agreed. It took about a month, but now they have announced the program, which you can read about here.

Under the program, current certified persons holding CyberAB CMMC Certified Professional (CCP) credentials can transition to ISO 27001 Lead Implementer. For those holding CMMC Certified Assessor (CCA) or Lead Certified Lead Assessor (Lead CCA), they can transition to ISO 27001 Lead Auditor.

For those wanting to work for third-party ISO 27001 Certification Bodies, they will need the latter (Lead Auditor) credential.

And, yes, PECB is doing it entirely for free.

Deadline for signup is December 31, 2026, so I urge you to hurry and sign up soon.

PECB has two downloadable PDF guides to help, which you can download here, depending on which path you want to pursue.

I want to say this again: I urge you to consider this free lifeline. A lot of you were sold a bill of goods with CMMC, and this may be a way to salvage the time and effort you spent in chasing that unicorn. Nobody in this industry gives anything away for free, so PECB deserves some credit for agreeing to do this.

 

Advertisements

Aerospace Exports Inc