CCA Compliance & Reporting 1 — Questions and Answers
Question 1: What is the purpose of CMMC compliance?
- To reduce software licenses
- To lower taxes
- To protect sensitive government information (Correct answer)
- To simplify billing processes
Correct answer: To protect sensitive government information
CMMC compliance ensures that contractors handling federal contract information and controlled unclassified information implement required cybersecurity practices.
Question 2: Who is responsible for submitting CMMC assessment results?
- Contracting officer
- C3PAO (Correct answer)
- Any employee
- System administrator
Correct answer: C3PAO
Certified Third-Party Assessment Organizations (C3PAOs) are responsible for submitting results to the DoD for validation and certification.
Question 3: What happens if a company is found non-compliant during a CMMC assessment?
- They receive provisional approval
- They are disqualified until remediation is complete (Correct answer)
- They are given lifetime certification
- They can skip further assessments
Correct answer: They are disqualified until remediation is complete
If a company is non-compliant, it may be required to address deficiencies before receiving certification.
Question 4: How long is a CMMC certification valid?
- 1 year
- 2 years
- 3 years (Correct answer)
- 5 years
Correct answer: 3 years
CMMC certifications are valid for 3 years, after which reassessment is required.
Question 5: Which organization oversees the CMMC assessment ecosystem?
- NIST
- CMMC-AB (Correct answer)
- NSA
- ISO
Correct answer: CMMC-AB
The CMMC Accreditation Body (CMMC-AB) manages the training, certification, and performance of assessors and C3PAOs.
Question 6: Which of the following is part of reporting compliance status?
- Client satisfaction survey
- Marketing materials
- Assessment findings and remediation actions (Correct answer)
- Training certificates
Correct answer: Assessment findings and remediation actions
Compliance status reporting includes detailed documentation, including practices met and those requiring remediation.
What is the purpose of CMMC compliance?