Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence Community
    • DHS
    • Federal Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence Community
    • DHS
    • Federal Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Cybersecurity

DOD OIG Flags Deficiencies in C3PAO Authorization Process

by Jerry Petersen
January 15, 2025
in Cybersecurity, Department of War, News
DOD OIG Flags Deficiencies in C3PAO Authorization Process

The Department of Defense has failed to effectively implement the process by which third-party organizations are authorized to carry out Level 2 assessments under Cybersecurity Maturity Model Certification 2.0.

Table of Contents

    • You might also like
    • DHS S&T Opens AI Prize Challenge to Detect Biological Threats
    • GSA, OpenAI Reach OneGov Deal for Discounted ChatGPT Access
    • Department of War Seeks AI Tools to Track Space & Missile Threats
  • Lack of Signed Code of Professional Conduct
  • Professional Certification Not Verified
  • Possible Lack of Quality Control Leads on Staff
  • Quality Assurance Process

You might also like

DHS S&T Opens AI Prize Challenge to Detect Biological Threats

GSA, OpenAI Reach OneGov Deal for Discounted ChatGPT Access

Department of War Seeks AI Tools to Track Space & Missile Threats

This is the conclusion that the DOD Office of Inspector General said it had reached on Tuesday, following an audit where it reviewed the application packages of 11 of the 48 CMMC third-party assessment organizations, or C3PAOs, authorized as of Sept. 21, 2023.

Lack of Signed Code of Professional Conduct

According to the audit report, the process implementation failure was demonstrated by three findings. First, of the 11 C3PAOs reviewed, two were given authorization even though they did not have a signed C3PAO Agreement and Code of Professional Conduct. This document details the terms, conditions and expectations of C3PAOs, including their adherence to the principles of professionalism, objectivity, confidentiality, proper use of methods and information integrity.

Professional Certification Not Verified

Second, authorizing officials did not verify whether the quality control leads, or QCLs, of four of the 11 C3PAOs possessed the requisite certification. An individual must undergo trainings and examinations to become a CMMC certified professional and then a CMMC certified assessor, or CCA, before the person can be designated as QCL. These trainings work to ensure that a QCL possesses the ability to perform a CMMC Level 2 assessment and evaluate the members of an assessment team.

Possible Lack of Quality Control Leads on Staff

Third, all 11 C3PAOs received authorization even if it was not adequately verified that they had CCAs and QCLs on staff or under contract.

Quality Assurance Process

DOD OIG attributed the issues to a lack of a quality assurance process that would verify C3PAO compliance with the requirements for authorization. The agency consequently offered 10 recommendations, including the development and implementation of a quality assurance process for C3PAO authorization.

Stay connected via Google News
Follow us for the latest travel updates and guides.
Add as preferred source on Google
Share5Tweet19
Previous Post

Elizabeth John Named CHIPS’ Chief Portfolio Admin Officer

Next Post

CISA Guidebook Enables Cybersecurity Collaboration in AI Community

Recommended For You

White House Calls for Inclusion of Unmanned Vessels in 355-Ship Goal

by Jane Edwards
December 26, 2019
White House Calls for Inclusion of Unmanned Vessels in 355-Ship Goal

The White House has asked the U.S. Navy to propose the inclusion of unmanned surface vessels and unmanned underwater vehicles in its planned 355-ship Battle Force fleet, the...

Read moreDetails

Verizon Federal Lands Contract for Navy Office Voice and Data Services; Maggie Hallbach Quoted

by Charles Lyons-Burt
August 22, 2022
Verizon Federal Lands Contract for Navy Office Voice and Data Services; Maggie Hallbach Quoted

The federal arm of Verizon has won a five-year, $28.3 million contract award from Naval Computer and Telecommunications Area Master Station Atlantic for voice and data assistance. The network...

Read moreDetails

Northcom, NORAD to Host Five-Day AI System Demo

by Matthew Nelson
March 18, 2021
Northcom, NORAD to Host Five-Day AI System Demo

The U.S. Northern Command (USNORTHCOM) and the North American Aerospace Defense Command (NORAD) will hold a five-day demonstration to test artificial intelligence technologies that will be incorporated into...

Read moreDetails

CACI Among 5 Companies Chosen to Participate in DON, USSOCOM Joint Threat Warning System Project

by Ireland Degges
June 23, 2023
Electromagnetic warfare

Applied Signals Intelligence, CACI, DRS Advanced ISR, Resonant Sciences and Roke USA have been selected by the Department of the Navy and U.S. Special Operations Command for the Joint Threat Warning System Directional...

Read moreDetails

DARPA to Sponsor Proposers Day for Speed and Runway-Independent X-Plane Project

by Jamie Bennet
June 17, 2024
DARPA to Sponsor Proposers Day for Speed and Runway-Independent X-Plane Project

The Defense Advanced Research Projects Agency Tactical Technology Office will host a Proposers Day to inform potential proposers on its Speed and Runway Independent Technologies X-Plane Demonstrator initiative...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Australia
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • C5ISR
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • Department of War
  • DHS
  • Digital Assets
  • Digital Modernization
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Cloud
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence Community
  • Legislation
  • M&A Activity
  • Middle East
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Technology
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence Community
    • DHS
    • Federal Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!