CMMC Certified Professional (CCP)
CMMC Certified Professional (CCP)
CMMC Certified Professional (CCP)
The CMMC Certified Professional (CCP) certification validates foundational knowledge of the CMMC framework, its governance structure, assessment process, scoping requirements, and cybersecurity practice evaluation. The certification is designed to help learners understand how CMMC applies to organizations within the Defense Industrial Base and how professionals can support organizations in becoming assessment-ready.
Knowledge Gained
- Learn how to interpret CMMC source documents, understand the distinction between Federal Contract Information (FCI) and Controlled Unclassified Information (CUI), evaluate cybersecurity practices, review evidence, understand assessment activities, and determine appropriate assessment scope.
- The CCP credential is particularly useful for professionals entering the CMMC ecosystem, organizations preparing for CMMC compliance, and individuals looking to build a pathway toward becoming a CMMC Certified Assessor.
Who Should Take the CCP Course?
The CCP certification can be valuable for:
Defense Industry Professionals
- Professionals working for organizations that need to prepare for CMMC requirements.
IT and Security Managers
- Technology leaders responsible for implementing and maintaining cybersecurity practices.
GRC and Compliance Professionals
- Professionals managing governance, risk and compliance programs.
Cybersecurity Professionals
- Security professionals who want to specialize in CMMC and Defense Industrial Base compliance.
IT Auditors
- Auditors seeking to expand their knowledge of cybersecurity assessments and CMMC requirements.
Aspiring CMMC Assessors
- Professionals planning to progress toward the CMMC Certified Assessor (CCA) credential.
Early-Career Cybersecurity Professionals
- Professionals looking to enter the CMMC and defense cybersecurity compliance space.
Skills Required
Candidates should ideally have a basic understanding of:
- Cybersecurity concepts
- Information technology
- Security controls
- Risk and compliance
- IT governance
- Assessment and audit concepts
- Security documentation
- Evidence collection
- Federal cybersecurity requirements
The certification does not require candidates to already be CMMC assessors. However, the certification application requires candidates to meet specified education or experience requirements.
CCP Course Outline
The current CCP examination is organized into six job-practice domains.
- Module 1: CMMC Ecosystem (5%)
- Module 2: CMMC Code of Professional Conduct and Ethics (5%)
- Module 3: CMMC Governance and Source Documents (15%)
- Module 4: CMMC Model Construct and Implementation Evaluation (35%)
- Module 5: CMMC Assessment Process (CAP) (25%)
- Module 6: CMMC Scoping (15%)
