CMMC Assessment Checklist
If you think you are ready for a CMMC assessment, use this resource to test where you actually are before contacting a professional.
The CMMC ecosystem rests on the concepts of trust, security, and confidentiality. Companies undergoing CMMC third-party assessments need to know their results will stand up before any Department of War project requirement or Prime Contractor supply chain demand. It is not just money at stake. The information defense contractors must protect Controlled Unclassified Information (CUI) that can endanger our Armed Forces if it finds its way into the wrong hands.
All CMMC Third-Party Assessor Organizations need to pass through several steps in order to earn authorization from the CyberAB. One of these steps is passing an assessment by DIBCAC (Defense Industrial Base Cybersecurity Assessment Center), which ascertains whether the C3PAO can proceed with assessments. While earning authorized status is a large undertaking both in terms of finance and time, it is not a differentiating factor because all C3PAOs must overcome these hurdles. This can make it difficult to know how far you can trust the C3PAO you select. How do you know they are right for your organization?
Smithers is unique in the ecosystem because it is an ANAB-accredited certification body. ANAB (ANSI National Accreditation Board) is the largest accreditation body in the United States and offers accreditation both domestically and internationally. The ANAB accreditation is an international standard for quality. In the words of ANAB itself, “Most important, accreditation assures industry and government decision-makers that accredited organizations are competent and their results can be relied on.”
Smithers has maintained its status as an ANAB-accredited certification body for over 30 years. Smithers undergoes an annual assessment by ANAB against the ISO 17021-1 standard for certification bodies, which means our processes are documented, repeatable, consistent, and validated. When we tell our clients they can trust the results we provide via assessments, we are backed by a third party ourselves.
If you are an organization seeking CMMC certification, choosing an ANAB-accredited certification body as your C3PAO ensures there will be no conflicts of interest and also ensures the C3PAO will provide efficient, accurate, and dependable assessments. We bring our ANAB-approved processes to our work as a C3PAO, so contractors who work with Smithers know that their assessors have been through many processes like this and that the industry respects them. CMMC assessments are too important to gamble on. Selecting a C3PAO that has earned accreditation from a powerful organization is a good bet.
Because of its status as an accredited certification body, Smithers can also assist you with assessments in addition to CMMC. Smithers is accredited against many standards, including ISO 9001, ISO 27001, IATF 16949, and AS9100. If your organization wants to achieve multiple certifications, Smithers can assist in that endeavor to help save money and time.
If you are interested in talking to Smithers about your CMMC assessment, even if you are not ready for that assessment today, please reach out and schedule a conversation with us.