Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Cybersecurity

DOD OIG Flags Deficiencies in C3PAO Authorization Process

by Jerry Petersen
January 15, 2025
in Cybersecurity, DoD, News
DOD OIG Flags Deficiencies in C3PAO Authorization Process

The Department of Defense has failed to effectively implement the process by which third-party organizations are authorized to carry out Level 2 assessments under Cybersecurity Maturity Model Certification 2.0.

Table of Contents

    • You might also like
    • Jay Clayton Nominated as Director of National Intelligence
    • Navy Discloses Topics for SBIR-STTR FY26 Release 3 Solicitation
    • DHS S&T Highlights New SPARTA Resources for Defending Spacecraft Against Cyberattacks
  • Lack of Signed Code of Professional Conduct
  • Professional Certification Not Verified
  • Possible Lack of Quality Control Leads on Staff
  • Quality Assurance Process

You might also like

Jay Clayton Nominated as Director of National Intelligence

Navy Discloses Topics for SBIR-STTR FY26 Release 3 Solicitation

DHS S&T Highlights New SPARTA Resources for Defending Spacecraft Against Cyberattacks

This is the conclusion that the DOD Office of Inspector General said it had reached on Tuesday, following an audit where it reviewed the application packages of 11 of the 48 CMMC third-party assessment organizations, or C3PAOs, authorized as of Sept. 21, 2023.

Lack of Signed Code of Professional Conduct

According to the audit report, the process implementation failure was demonstrated by three findings. First, of the 11 C3PAOs reviewed, two were given authorization even though they did not have a signed C3PAO Agreement and Code of Professional Conduct. This document details the terms, conditions and expectations of C3PAOs, including their adherence to the principles of professionalism, objectivity, confidentiality, proper use of methods and information integrity.

Professional Certification Not Verified

Second, authorizing officials did not verify whether the quality control leads, or QCLs, of four of the 11 C3PAOs possessed the requisite certification. An individual must undergo trainings and examinations to become a CMMC certified professional and then a CMMC certified assessor, or CCA, before the person can be designated as QCL. These trainings work to ensure that a QCL possesses the ability to perform a CMMC Level 2 assessment and evaluate the members of an assessment team.

Possible Lack of Quality Control Leads on Staff

Third, all 11 C3PAOs received authorization even if it was not adequately verified that they had CCAs and QCLs on staff or under contract.

Quality Assurance Process

DOD OIG attributed the issues to a lack of a quality assurance process that would verify C3PAO compliance with the requirements for authorization. The agency consequently offered 10 recommendations, including the development and implementation of a quality assurance process for C3PAO authorization.

Share5Tweet19

Recommended For You

Jay Clayton Nominated as Director of National Intelligence

by Jane Edwards
June 12, 2026
Jay Clayton. The U.S. attorney for the Southern District of New York has been nominated to serve as DNI.

Trump has nominated Jay Clayton to serve as director of national intelligenceClayton currently serves as U.S. attorney for the Southern District of New YorkThe 2026 Intel Summit will...

Read moreDetails

Navy Discloses Topics for SBIR-STTR FY26 Release 3 Solicitation

by Jane Edwards
June 12, 2026
Department of the Navy seal. The Navy has announced the topics for its SBIR and STTR Release 3 for fiscal year 2026.

The Department of the Navy has started the pre-release period for FY26 Release 3 SBIR/STTR topicsThe solicitation targets quantum, artificial intelligence and contested logistics technologiesThe 2026 Navy Summit...

Read moreDetails

DHS S&T Highlights New SPARTA Resources for Defending Spacecraft Against Cyberattacks

by Kristen Smith
June 12, 2026
DHS S&T logo. The directorate is supporting space cybersecurity research via SPARTA.

DHS S&T is backing research to defend space systems from cyberattacksThe work has produced two additions to The Aerospace Corporation's SPARTA frameworkDHS pointed to a 2022 attack on...

Read moreDetails

NASA Opens Applications for M-STAR Funding Opportunity

by Miles Jamison
June 12, 2026
Artemis logo. NASA has begun accepting applications for the M-STAR program.

NASA has opened M-STAR applications to support university-led space technology researchThe M-STAR program will help eligible institutions build stronger aerospace research capabilitiesThe initiative intends to fund projects supporting...

Read moreDetails

HHS to Sunset All NITAAC GWACs in October, Shift IT Buying to GSA

by Kristen Smith
June 12, 2026
HHS logo. HHS will sunset all NITAAC GWACs on Oct. 29.

HHS is sunsetting all NITAAC governmentwide acquisition contractsThe decision covers CIO-SP3, its small business counterpart and CIO-CSThe shutdown follows the cancellation of CIO-SP4The Department of Health and Human...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • DHS
  • Digital Modernization
  • DoD
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • General News
  • GovCon Expert
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Legislation
  • M&A Activity
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved.

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved.

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!