{"id":34778,"date":"2026-08-26T10:34:28","date_gmt":"2026-08-26T14:34:28","guid":{"rendered":"https:\/\/www.oxebridge.com\/emma\/?p=34778"},"modified":"2026-08-26T13:57:22","modified_gmt":"2026-08-26T17:57:22","slug":"how-the-cmmc-scheme-can-fix-its-iso-17020-problem","status":"publish","type":"post","link":"https:\/\/www.oxebridge.com\/emma\/how-the-cmmc-scheme-can-fix-its-iso-17020-problem\/","title":{"rendered":"How the CMMC Scheme Can Fix Its ISO 17020 Problem"},"content":{"rendered":"<p>My <a href=\"https:\/\/www.oxebridge.com\/emma\/cyber-ab-may-have-committed-wholesale-fraud-on-cmmc-c3paos\/\">post the other day<\/a> about how the Cyber AB may have committed wholesale fraud on its C3PAO client base caught a lot of flak from CMMC shills who insist there&#8217;s nothing wrong. This piece breaks down just what is wrong and how the AB and Dept. of War can fix it.<\/p>\n<p>All of this assumes, however, that we still live in a world where rules matter and companies face consequences for breaking them, which is a fantasy. The timeline we live in not only allows fraud and deception, but <em><strong>rewards<\/strong> <\/em>those who engage in it. So the unfortunate truth is that, as soon as I write this, it will already be considered quaint and naive. But I tilt at windmills anyway.<\/p>\n<p>My <a href=\"https:\/\/www.oxebridge.com\/emma\/cyber-ab-may-have-committed-wholesale-fraud-on-cmmc-c3paos\/\">prior piece<\/a> showed how ISO 17020 prohibits CMMC C3PAOs from also providing CMMC consulting. This creates problems because the Cyber AB must obtain its own accreditation (to another standard, ISO 17011) as a body that will accredit inspection bodies under ISO 17020. It cannot accredit any C3PAO that also performs consulting since the C3PAO would not be complying with ISO 17020, making the entire scheme a bit pointless.<\/p>\n<p><strong><span style=\"font-size: 18pt;\">Inspection Body Types<\/span><\/strong><\/p>\n<p>ISO 17020 defines three types of inspection bodies: Type A, B, and C. (The latest edition, released just this year, breaks it down into two types &#8212; &#8220;<em>Type A<\/em>&#8221; and &#8220;<em>Non-Type A<\/em>&#8221; &#8212; but that standard is not yet mandatory, and the DoD&#8217;s FAR rule requires compliance with the 2012 version.)<\/p>\n<p>Per ISO 17020:2012:<\/p>\n<ul>\n<li><strong>Type A inspection bodies<\/strong> perform third-party assessments for client companies and have the most restrictive rules for ensuring impartiality and objectivity. The C3PAOs would fall under this category, as they certify third-party companies (called &#8220;<em>Organizations Seeking Certification<\/em>,&#8221; or OSCs, in CMMC parlance).<\/li>\n<li><strong>Type B inspection bodies<\/strong> only perform assessments on themselves, so that does not apply at all to CMMC.<\/li>\n<li><strong>Type C inspection bodies<\/strong> are a hybrid of A and B: they provide assessments on their own products, but then offer third-party assessments to outside clients.<\/li>\n<\/ul>\n<p>Additional rules are then defined in ILAC document P15, which I cited in my last article, and which I am sure neither the CyberAB nor any of the C3PAOs have ever even heard of. But regardless, it is <em><strong>required<\/strong> <\/em>for accreditation if the CyberAB intends to follow the rules under 17011.<\/p>\n<p>Obviously, the CMMC C3PAOs are Type A bodies. The entire CMMC scheme was cooked up to allow for trusted third-party certification because, the CMMC shills insist, years of self-attestation to cybersecurity controls had not worked. The idea of third-party certification is baked into the very DNA of the CMMC scheme.<\/p>\n<p>To get around the ISO 17020 prohibitions for Type A bodies, the CyberAB once just made shit up. They claimed that the C3PAOs might <em><strong>also<\/strong><\/em> act as Type C bodies, which have <em><strong>fewer<\/strong> <\/em>rules governing objectivity. They then added a\u00a0<span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">risk-mitigation rule\u2014again, entirely made up and\u00a0<em><strong>not<\/strong><\/em><em>\u00a0<\/em>supported by the 17020 standard\u2014that says a C3PAO may consult for its<\/span>\u00a0own certification clients if a three-year cooling-off period has been observed.<\/p>\n<p>Now, neither of these self-interested interpretations is legal under 17020 nor ILAC P15, and I will explain why.<\/p>\n<p>First, a Type C body is clearly meant to refer to a company that builds a certain product and then inspects its own product; because it has the capability of inspection, it can also offer that inspection service to any third-party customer who might want it. It&#8217;s a high-risk arrangement, but it&#8217;s clearly defined as suitable only if a company is already building the thing it is inspecting. Examples include overhead crane manufacturers who inspect their cranes against safety standards, or a wind turbine manufacturer that inspects its products against relevant structural codes.<\/p>\n<p>Under no possible interpretation could a C3PAO be considered a Type C body, no matter how much wish fulfillment the CyberAB wants to engage in. While you could argue that, as consultants, they &#8220;<em>build<\/em>&#8221; CMMC systems, they do not then inspect their own systems. Under the CMMC rules, each C3PAO must have its in-house cybersecurity controls audited against CMMC by <em><strong>DIBCAC<\/strong><\/em>. Self-certification by the C3PAO is strictly prohibited.<\/p>\n<p>Next, even if by some magical rewiring of the rules of reality the world agreed that C3PAOs <em><strong>were<\/strong> <\/em>Type C bodies, a mere three-year cooling-off period would not be sufficient. Instead, ISO 17020 (both the old and new versions) requires significant risk-mitigation activities that the overwhelming bulk of C3PAOs clearly do not\u2014and cannot\u2014comply with. These typically include:<\/p>\n<ol>\n<li>Entirely separate leadership (top management) between the consulting and certification sides. Tiny one-person shops like Amira Armond&#8217;s Kieri Solutions or most of the other C3PAOs do not have sufficient staff <em><strong>to<\/strong><\/em> separate their leadership, making this impossible. They can never comply with ISO 17020, period.<\/li>\n<li>Independent impartiality reviews led by an independent Impartiality Committee. This committee would hold considerable authority over the company&#8217;s operations to ensure independence and objectivity. Even medium-sized C3PAOs, like Redspin, would struggle with this. The giants, like Cherry Beckaert, Booz Allen, and Coalfire, could pull it off.<\/li>\n<li>Separate technical manager: a dedicated person overseeing the CMMC certification activities who is wholly unrelated to the consulting side.<\/li>\n<li>Active, updated risk register: the C3PAO would have to create and update a risk register defining the risks to their impartiality and the mitigations for those risks.<\/li>\n<\/ol>\n<p>Now, many will argue that they can do all of these things or that the standards are not explicit enough to literally require them; or they may ignore P15 entirely since the CyberAB never mentions it. But it&#8217;s all moot since the first rule applies, and <em><strong>C3PAOs cannot be Type C since they don&#8217;t inspect their own CMMC products or services&#8230; DIBCAC does.<\/strong><\/em> (And, let&#8217;s face it, their consulting services are not inspected at all by <em><strong>anyone<\/strong><\/em>.)<\/p>\n<p><span style=\"font-size: 18pt;\"><strong>The Risks<\/strong><\/span><\/p>\n<p>The conflict of interest risks presented by the CyberAB&#8217;s plan are insurmountable:<\/p>\n<ul>\n<li><strong>Scenario A:<\/strong> C3PAO Number 1 can assess a client whose controls were built by their competitor, C2PAO Number 2. There is a financial incentive for C3PAO Number 1 to trash-talk any competitor&#8217;s systems or work if only to sneakily market their own consulting. When it works, the client can fire C3PAO Number 2 and hire C3PAO Number 1 to take over as their consultant. The AB&#8217;s rules don&#8217;t cover this. In this scenario, the certifier moves from assessor to consultant, and the AB only limits the opposite. Since there&#8217;s more money to be made by consulting, C3PAO Number 1 would not care if they lost the CMMC certification assessment contract.<\/li>\n<li><strong>Scenario B:<\/strong> C3PAO Number 1 assesses a client who used work done by C3PAO Number 2. During that assessment, they note C3PAO Number 2&#8217;s approaches and implementation methods, and then secretly come back and roll that into their <em><strong>own<\/strong> <\/em>consulting work. They essentially steal their competitor&#8217;s intellectual property and methods.<\/li>\n<li><strong>Scenario C:<\/strong> Everyone works honestly, but since the conflicts of interest are embedded into the CMMC scheme itself, no one really has any confidence in CMMC certifications and the defense primes begin requiring other controls anyway, like ISO 27001 or even customer-driven audits. So the honest people suffer, too.<\/li>\n<\/ul>\n<p><strong><span style=\"font-size: 18pt;\">How Accreditation Works<\/span><\/strong><\/p>\n<p>So, why is the CyberAB in a bind? To answer this, we have to understand how accreditation works under the IAF scheme (now rebranded as &#8220;Global ACI,&#8221; but I will keep using the name IAF for simplicity). And remember, the DoD decided to require the IAF oversight for CMMC, not me or ISO or anyone else. <em><strong>They<\/strong> <\/em>baked this into the contract between itself and the AB.<\/p>\n<p>The accreditation is pyramid-shaped, with each entity assessed by the body above it against a given standard.<\/p>\n<ul>\n<li>At the bottom is the OSC, which is assessed by the C3PAO against the CMMC standard.<\/li>\n<li>Next, the C3PAO is assessed by the CyberAB against ISO 17020.<\/li>\n<li>Next, the CyberAB is assessed by the IAF &#8212; through its Americas regional body, IAAC (in Mexico!) &#8212; against ISO 17011.<\/li>\n<\/ul>\n<p>To obtain its ISO 17011 accreditation, the CyberAB must prove it is assessing the C3PAOs properly and fully against an <em><strong>unmodified<\/strong> <\/em>version of ISO 17020. But the AB made up those rules about a three-year cooling-off period and allowing C3PAOs to be considered either Type A or Type C bodies. Since those last two interpretations violated ISO 17020,\u00a0<span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">the CyberAB will actually be accrediting the C3PAOs against a\u00a0<em><strong>modified<\/strong><\/em> version of ISO 17020<\/span>\u00a0of its own making.<\/p>\n<p>So, the IAF (through its regional body IAAC) can <em><strong>never<\/strong> <\/em>issue ISO 17011 to the CyberAB, since it is not actually assessing C3PAOs to ISO 17020. They are assessing them against some weird frankenstandard they made up themselves.<\/p>\n<p>So no 17011 for the AB, and thus no ISO 17020 for any C3PAO.<\/p>\n<p>(An aside: to date, the AB has only issued 178020 accreditation to one C3PAO, which is run by the DoD&#8217;s own Stacy Bostjanick, called Cybersec Investments. That company does not perform consulting at all, so it would be treated as a Type A. Because the AB does not have its accreditation yet, it is using an already-accredited body, ANAB, to perform assessments on its behalf. That breaks some other rules, but &#8212; again &#8212; no one seems to care. <a href=\"https:\/\/www.oxebridge.com\/emma\/cyberab-is-outsourcing-assessments-to-anab-and-didnt-tell-anyone\/\">See here<\/a> for more on that.)<\/p>\n<p><span style=\"font-size: 18pt;\"><strong>The Fix<\/strong><\/span><\/p>\n<p>There <em><strong>is<\/strong> <\/em>a fix to be had here, but the CyberAB are likely to just keep cheating and hope no one notices. It would require both time and effort, but it is entirely workable. This would require, however, a modification to the FAR, which is not easy to achieve.<\/p>\n<p>First, the Dept. of War would have to modify the FAR clause (<a href=\"https:\/\/www.ecfr.gov\/current\/title-32\/subtitle-A\/chapter-I\/subchapter-G\/part-170\/subpart-C\/section-170.9\">here<\/a>) to allow the CyberAB to accredit C3PAOs to rules &#8220;<em>based on<\/em>&#8221; ISO 17020. The current language is pretty explicit that the SACT standard (down to the exact 2012 version) is to be used, and that&#8217;s problematic. But the FAR <em><strong>can<\/strong> <\/em>be modified. Since the new 2026 version of ISO 17020 is out now, the FAR has to be updated anyway.<\/p>\n<p>Next,\u00a0<span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">CyberAB would have to approach the IAF regional body, IAAC and ask it to develop an\u00a0<em><strong>alternate<\/strong><\/em><em>\u00a0<\/em>accreditation scheme specifically for CMMC, based on\u2014but not exactly in line with\u2014<\/span>ISO 17020. That would then add language allowing for the three-year cooling-off period, etc. This also ensures compliance with 17020, which allows some deviations when a &#8220;<em>regulatory requirement<\/em>&#8221; allows it. (As it&#8217;s written now, the FAR does <em><strong>not<\/strong> <\/em>allow for deviations from 17020.)<\/p>\n<p>The IAAC would have to create internal procedures on its own and get them blessed by its mothership, the IAF (now &#8220;Global ACI &#8220;). That&#8217;s easy.<\/p>\n<p>The CyberAB would then have to update its accreditation procedures and contracts with the C3PAOs to match the new program. That is also somewhat easy, but time-consuming.<\/p>\n<p>At which point, the CyberAB would pursue accreditation by IAAC to this new, mutated scheme, but with full international approval and oversight. Then, it would issue accreditation certificates to C3PAOs not to ISO 17020, but under the name of the mutated scheme, perhaps &#8220;<em>CMMC Accredited Inspection Body Scheme<\/em>.&#8221;<\/p>\n<p>Now, everything is neat, legal, and fully compliant.<\/p>\n<p>But, as you can see, it requires coordinated effort between the Dept. of War, the CyberAB and the IAF regional body, IAAC. That&#8217;s a lot of moving pieces.<\/p>\n<p>Had the DoD and AB paid attention to actual accreditation experts at the start of this thing, none of this would be necessary. But the DoD allowed the AB to cook up its own rules, and the AB&#8217;s Board, including Jeff DAlton, made up definitions and interpretations, with the focus being on how to generate as much money as possible for the AB (and its individual Board members), rather than to ensure any trust and confidence in the resulting CMMC certifications.<\/p>\n<p>Greed won the day, but it <em><strong>can<\/strong> <\/em>be fixed.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>","protected":false},"excerpt":{"rendered":"<p>ISO 17020 prohibits C3PAOs from providing consulting, but there is a (complicated) workaround.<\/p>","protected":false},"author":2,"featured_media":34785,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","mc4wp_mailchimp_campaign":[],"footnotes":""},"categories":[7774,5],"tags":[7679,8081,7683,7699,8907,8846,614,83,181,106],"class_list":["post-34778","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cmmc","category-opinion","tag-cmmc","tag-cyberab","tag-cybersecurity-maturity-model-certification","tag-dept-of-defense","tag-dept-of-war","tag-global-aci","tag-iaac","tag-iaf","tag-iso-17011","tag-iso-17020","et-has-post-format-content","et_post_format-et-post-format-standard"],"_links":{"self":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts\/34778","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/comments?post=34778"}],"version-history":[{"count":5,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts\/34778\/revisions"}],"predecessor-version":[{"id":34792,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts\/34778\/revisions\/34792"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/media\/34785"}],"wp:attachment":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/media?parent=34778"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/categories?post=34778"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/tags?post=34778"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}