The ISACA CMMC Certified Assessor (ISACA CCA™) is one of the most specialized credentials in defense cybersecurity. It qualifies you to assess defense contractors as part of an official CMMC Level 2 certification assessment. That makes it a real career step, and it also means the path to get there has more requirements than most exams.

Below, we’ll cover who the CCA is for, the current eligibility requirements, how long to study, where the credential can take you, and how to keep it once you earn it.

Who Should Take the ISACA CCA Exam?

The CCA is built for experienced cybersecurity and audit professionals who want to evaluate other organizations against CMMC Level 2. It’s a strong fit if you are:

  • A CCP who wants to move into assessment work: The CMMC Certified Professional (CCP) is the required first step, and the CCA is the natural next one.
  • An IT auditor or security control assessor: Your experience with evidence, sampling, and objective findings transfers directly.
  • A compliance or GRC professional in the Defense Industrial Base (DIB): You may already implement NIST SP 800-171 and want to work on the assessment side.
  • A consultant or employee of a Certified Third-Party Assessment Organization (C3PAO): C3PAOs need certified assessors on their assessment teams.

You might wait if you don’t yet hold the CCP, lack a qualifying DoD 8140 certification, or can’t yet show a year of assessment or audit experience. Those gaps will stop your application even if you pass the exam.

What Are the CCA Eligibility Requirements?

ISACA now administers the CCA as the CMMC Assessor and Instructor Certification Organization (CAICO). According to the ISACA “Earn a CCA” page and the ISACA CMMC page, you need to:

  • Complete mandatory CCA training through a CAICO-approved training provider (ATP) before you sit for the exam.
  • Hold an active CCP certification.
  • Hold a qualifying DoD 8140 certification at the Intermediate or Advanced proficiency level for Work Role 612, Security Control Assessor. ISACA notes that its CISA and CISM are two of the options.
  • Show experience: at least three years of cybersecurity experience and one year of assessment or audit experience.
  • Obtain a Tier 3 determination from the DoW. You don’t need it before testing. The Cyber AB coordinates the Tier 3 investigation after you apply.
  • Pass the CCA exam and submit your certification application within ISACA’s application window.
  • Agree to follow ISACA’s Code of Professional Ethics and CPE policy.

What Does It Cost?

ISACA lists the CCA exam at US$575 for members and US$760 for non-members, plus a US$50 application processing fee after you pass. Training through an ATP is a separate cost set by the provider. Fees can change, so check the ISACA CCA page before you register.

How Do You Apply?

  1. Earn your CCP and a qualifying 8140 certification.
  2. Complete CCA training with an ATP.
  3. Register and pay for the exam, then schedule with PSI within your six-month registration period.
  4. Pass the exam, pay the application fee, and submit your application with experience documentation.
  5. Complete the Tier 3 process and receive your certification.

How Long Should You Study for the ISACA CCA Exam?

Most candidates take the exam soon after finishing CCA training, while the material is fresh. Plan on 6 to 10 weeks of focused study after training. Experienced auditors who assess against NIST SP 800-171 every day may need less. If you’re newer to hands-on assessment, lean toward the longer end.

Here’s a sample 8-week plan weighted by the blueprint:

  • Week 1: Take a mixed baseline. Reread the CMMC Level 2 Scoping Guide and the ecosystem roles in 32 CFR Part 170.
  • Weeks 2 and 3: Domains 1 and 2 (35% combined). Drill the five asset categories, separation techniques, FCI versus CUI scopes, and External Service Providers.
  • Weeks 3 and 4: Domain 3, the CMMC Assessment Process (25%). Walk through each phase and know which activities, artifacts, and decisions belong where.
  • Weeks 5 and 6: Domain 4 (40%). Work through the 14 families in the Level 2 Assessment Guide, a few families per day, focusing on assessment objectives and what evidence proves them.
  • Weeks 7 and 8: Timed, mixed practice at exam pace, plus review of your missed questions by domain.

If you’re coming from implementation rather than audit, spend extra time on examine, interview, and test methods and on judging evidence sufficiency. If you’re an experienced auditor, focus on CMMC-specific rules like scoping categories, POA&M limits, and CAP phase details.

What Careers Can the CCA Support?

CCAs typically work for or contract with C3PAOs on Level 2 certification assessment teams. The credential can also strengthen roles such as:

  • CMMC assessor or assessment team member
  • IT auditor or security control assessor
  • Cybersecurity compliance manager at a defense contractor
  • GRC consultant supporting DIB companies

Demand depends on how CMMC rolls out. ISACA’s CAICO director has noted that nearly 120,000 contractors will need Level 2 certification once the program is fully operational. However, on July 13, 2026, the DoW suspended Phase 2 of CMMC implementation, which was set to require C3PAO assessments starting November 10, 2026, while a reform task force reviews the program. C3PAOs can still conduct Level 2 certification assessments, and Phase 1 self-assessment requirements remain in force. Watch for the task force’s final determinations before you plan around a specific timeline.

What Is the Salary for CMMC Assessors?

The U.S. Bureau of Labor Statistics (BLS) doesn’t track CMMC assessors separately, but the closest occupation is information security analyst. BLS reports a median annual wage of $129,180 for information security analysts in May 2025. Employment is projected to grow 21% from 2025 to 2035, much faster than average, with about 14,100 openings each year.

Pay for assessors varies with clearance status, experience, whether you work as an employee or contractor, and whether you hold the Lead CCA designation. Treat the BLS figure as a benchmark for the broader field, not a promise for any specific assessor role.

The credential also builds transferable skills. Scoping a CUI environment, judging evidence against assessment objectives, and writing defensible findings are valuable in internal audit, federal compliance, and security leadership roles, even outside formal C3PAO work.

How Do You Maintain the CCA?

The CCA runs on a three-year cycle. Under ISACA’s CPE policy, you must:

  • Earn at least 120 CPE hours every three years, with a minimum of 20 each year.
  • Make at least 90 of those hours relevant to the certification, including at least 2 on CMMC rules.
  • Keep your CCP active, since it is a CCA prerequisite.
  • Follow ISACA’s Code of Professional Ethics and pay any required maintenance fees.

What Certifications Stack Well With the CCA?

  • Lead CCA (LCCA): ISACA’s senior designation for CCAs who lead Level 2 assessments and make final determinations for C3PAOs. It’s the most direct next step.
  • CMMC Certified Instructor (CCI): A fit if you want to teach CCP and CCA courses through an ATP.
  • ISACA Certified Information Systems Auditor (CISA): Strengthens audit credibility and is one of the qualifying 8140 options for Work Role 612.
  • ISC2 Certified in Governance, Risk and Compliance (CGRC): Pairs well if you also work with the NIST Risk Management Framework in federal environments.

Start Preparing for the ISACA CCA Exam With Pocket Prep

Once your training is done, Pocket Prep’s ISACA CCA™ practice questions help you lock it in with 500 exam-style questions and a detailed explanation for every answer. Use Quick 10 to squeeze in practice between meetings and Missed Questions quizzes to turn weak spots into strengths. Consistent studying can open the door to a new assessment career.