The Cyber AB may have engaged in massive, industry-wide fraud by misleading the entire pool of C3PAO organizations regarding their capability to achieve ISO 17020 accreditation. C3PAOs would be within their rights to sue en masse.

Per its contract with the Dept. of War, the CyberAB is supposed to accredit C3PAOs before they can provide CMMC certifications. Because the AB itself has failed to obtain its own ISO 17011 accreditation, it was forced to offer a provisional step, “authorizing” C3PAOs before it can accredit them. Then, per the CyberAB’s rules, an “authorized” C3PAO must obtain full ISO 17020 accreditation — from the CyberAB — within 27 months.

Because it can’t get its own ISO 17011 accreditation, the CyberAB has had to outsource ISO 17020 audits to ANAB, thus making this workable in the short term.

But all of this may be moot for most of the C3PAOs out there. I’ve now uncovered a far greater problem: the overwhelming bulk of C3POAs cannot ever obtain their required ISO 17020 accreditation, no matter what, because the CyberAB’s own directives to them have been fraudulently incorrect. I say “fraudulently” because I personally told them about this years ago, and they pushed ahead anyway, meaning their actions were intentional. This cannot say the did not know.

Per the DoD and AB’s own scheme, C3PAOs are considered “Type A inspection bodies” under the definition within ISO 17020. Under that standard, the provision of managed services, consulting, documentation, etc. for CMMC is prohibited outright. From the 2012 edition of that standard, which the CyberAB is still using:

An inspection body shall not be a part of a legal entity that is engaged in design, manufacture, supply, installation, purchase, ownership, use or maintenance of the items inspected.

And, from the recently updated 2026 version which actually expanded the restriction (rather than diluting it):

The inspection body shall not be a part of a legal entity that is engaged in the design, manufacture, supply, installation, purchase, ownership, use or maintenance of the item inspected or similar competitive items.

That’s it. No quarter, no allowances, no caveats. Providing anything that could be used to create or maintain a CMMC system is fully prohibited. A C3PAO may not sell it at all. Period.

Meanwhile, what’s happening in the real world? The bulk of the C3PAOs are selling certification alongside their consulting and implementation services. They had to, because they had to earn money waiting years for the CyberAB to get its act together and begin authorizing and accrediting C3PAOs. Worse, some of them are “co-marketing,” conflating them all into one combined service. Here is Redspin:

And here is Amira Armond’s Kieri Solutions:

And one more, from Kratos:

I found a lot more:

All of these are “authorized” C3PAOs, blessed by the CyberAB. All are awaiting an ISO 17020 accreditation they can never achieve.

If ISO 17020 prohibits this, how does the CyberAB explain this?

The CyberAB has published two procedures on its website: the first is the rules for C3PAOs to obtain provisional authorization, and the second defines what they must do to later achieve full ISO 17020 accreditation. Here is what the latter says about the apparent conflict of interest:

The C3PAO shall not conduct CMMC Level 2 certification assessments of an OSC within three years of providing consulting, implementation or product sales/services to the OSC under assessment.

The CyberAB added a three-year cooling-off period between the provision of consulting and implementation work and then CMMC certification. It sounds fine, except — as I quoted above — it’s not allowed at all by ISO 17020. Per that standard (I know I am repeating myself, but the CyberAB guys are slow learners), Type A inspection bodies cannot sell these services, period.

Where did the 3-year rule come from? It comes from an entirely different standard, ISO 17021-1 (“ISO 17021” for short). That standard provides for a two-year cooling-off period when certification bodies offer internal auditing, consulting, etc. One of the clauses reads as follows:

Where a client has received management systems consultancy from a body that has a relationship with a certification body, this is a significant threat to impartiality. A recognized mitigation of this threat is that the certification body shall not certify the management system for a minimum of two years following the end of the consultancy.

The problem is that ISO 17021 is for management system certification bodies, such as those issuing ISO 9001 or ISO 27001 certificates, and not inspection bodies. I argued with Kevin Fahey and Katie Arrington that ISO 17020 was never appropriate for CMMC, and that ISO 17021-1 would have been better, but they disagreed and imposed 17020. Later, CyberAB brought in Jeff Dalton to provide ISO 17011 consulting, and he bungled it while refusing my advice. One of the mistakes made at the time, presumably by Dalton, was to invoke the cooling-off period rules from ISO 17021, while never actually checking to see if it was allowed under ISO 1702o.

And it’s not.

(I’m not sure where the AB got the “three” years from at all, as it appears in no standards anywhere.)

So the AB has misled every single C3PAO into thinking they could legally sell consulting and MSP services while ramping up their CMMC assessment operations and preparing for their ultimate — mandatory! — accreditation to ISO 17020.

To date, we only have one C3PAO that has obtained ISO 17020 accreditation, and that is Stacy Bostjanick’s new employer, Cybersec Investments. How did they do it? Well, to their credit, Cybersec does not offer any consulting or MSP services at all. They only do CMMC assessments. (At least that’s all they market on their website.) So there was no conflict of interest; that’s why ANAB found no issues, and CyberAB was allowed to issue them an ISO 17020 accreditation certificate.

When ANAB goes to audit Redspin or Kratops or Kieri or any of the others, they are all in for a rude shock.

There are only two ways this ends, and one of those requires more fraud, not less. First, the CyberAB just rubber-stamps the C3PAOs without adhering to any rules at all. Given ANAB’s long history of fraud, they might even be able to pull this off while outsourcing their audits to them. If questioned, ANAB can just claim they were only performing the audits, not making the final accreditation decisions, so they have no legal liability. (Not sure that would be true, but we can pretend.)

Alternatively, the CyberAB would have to go back to the DoD again and get a new contract. This time, they would have to admit that they can’t use ISO 17020 at all, and would instead have to pursue their ISO 17011 accreditation for a self-created scheme. They could call it the CyberAB CMMC Accreditation scheme, or something, but could not say it conformed to ISO 17020. They’d have to get that approved by the IAAC, which is scheduled to issue the AB its ISO 17011 someday. That would take about two years to accomplish, by my estimation, if everyone started now. (Both the AB and IAAC would have to create new or modified procedures.)

The more likely outcome is that the CyberAB does nothing and keeps on scamming its own customers, the C3PAOs. It’s not like Matt Travis or Jon Hanny care what happens to them at this point.

But to be clear: this has been intentional fraud and — for once — the C3PAOs are the victims here. They should be livid and on the phone with their attorneys right now.

If the bodies follow the rules, then there is no way that any of these C3PAOs can obtain ISO 17020 without fully unloading all CMMC consulting and service provision activities.

 

Advertisements

ISO 45001 Implementation