What is covered on the Certified CMMC Professional (CCP) exam?
The Certified CMMC Professional™ (CCP™) is the foundational certification for the Department of Defense’s Cybersecurity Maturity Model Certification (CMMC) program, validating expertise in assessment-ready cybersecurity. It is required for professionals supporting defense contractors with 2.0 compliance. The CCP exam consists of 170 questions covering 6 job practice domains.
Job practice areas tested for and validated by a CCP certification
5% DOMAIN 1 – CMMC Ecosystem
A—Identify and compare roles/responsibilities/requirements of authorities across the CMMC ecosystem.
5% DOMAIN 2 – CMMC-AB Code of Professional Conduct (Ethics)
A—Identify and apply knowledge of the guiding principles and practices of the CMMC-AB Code of Professional Conduct (CoPC)/ISO/IEC/DOW requirements.
15% DOMAIN 3 – CMMC Governance and Source Documents
A—Demonstrate understanding of Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) in nonfederal unclassified networks.
B—Determine the appropriate roles/responsibilities/authority for FCI and CUI.
C—Demonstrate understanding of the CMMC source and supplementary documents.
35% DOMAIN 4 – CMMC Model Construct and Implementation Evaluation
A—Given a scenario, apply the appropriate CMMC source documents as an aid to evaluate the implementation/review of CMMC practices. (At a minimum CCP candidate must be evaluated on CMMC L1 Practices during CCP exam.)
B—Apply knowledge of the CMMC assessment criteria and methodology to the appropriate CMMC practices.
C—Analyze the adequacy/sufficiency around the location/collection/quality/usage of evidence.
25% DOMAIN 5 – CMMC Assessment Process (CAP)
A—Choose the appropriate roles of the CCP in the CMMC Assessment Process when developing the assessment plan (Phase 1 Plan and Prepare Assessment).
B—Apply CMMC Assessment Process requirements pertaining to the role of the CCP as an Assessment Team Member while conducting a CMMC assessment (Phase 2 Conduct Assessment).
C—Demonstrate comprehension of the CCP role in the preparation of assessment report (Phase 3 Report Assessment Results).
D—Demonstrate comprehension of the CCP role in the process of evaluating outstanding assessment issues on plan of action and milestones (POA&M) (Phase 4 Evaluation of Outstanding Assessment POA&M Items).
E—Given a scenario, determine the appropriate phases/steps to assist in the reparation/conducting/reporting on a CMMC Level 2 Assessment.
15% DOMAIN 6 – Scoping
A—Understand CMMC high-level scoping as described in the CMMC Assessment Process.
B—Given a scenario, analyze the organization environment to generate an appropriate scope for FCI Assets.
Getting ready for the exam
CCP training is available through an ATP on the CyberAB Marketplace.