Back to blog
Certification Deep Dives11 min read

Is the CMMC CCP Certification Still Worth It in 2026? What the Phase 2 Suspension Changes

The Pentagon suspended CMMC Phase 2 on 13 July 2026, days before the 10 November deadline. Here is what it actually changes for the Certified CMMC Professional credential, and whether the CCP is still worth your money.

Owen Gallagher

Owen Gallagher · Study Skills & Careers Editor

25 July 2026

If you booked a Certified CMMC Professional course this year, you spent the middle of July watching your investment wobble in real time. On 13 July 2026 the Department of War announced the immediate suspension of Phase 2 of the Cybersecurity Maturity Model Certification programme, less than four months before the requirements were due to bite. So is the CMMC CCP worth it in 2026, or did the Pentagon just delete the market you were training for?

The short answer: the CCP is still worth it, but for a different reason than the one most training providers sold you on. The mandatory third-party assessment wave that justified the credential has been paused, not cancelled, and the underlying legal obligations that create demand for CMMC skills never went away. What has changed is the timeline, the urgency, and who is realistically going to hire you in the next twelve months.

This guide covers exactly what was suspended, what is still enforced, what the CCP exam involves under its new ISACA ownership, what it costs, and the three candidate profiles for whom the maths still works.

What Actually Happened on 13 July 2026

The Department of War suspended Phase 2 of CMMC implementation with immediate effect. Phase 2 was scheduled to begin on 10 November 2026 and would have required third-party assessments, conducted by a Certified Third-Party Assessment Organisation (C3PAO), on all applicable contracts involving Controlled Unclassified Information.

The reason was arithmetic. Somewhere north of 100,000 companies in the Defense Industrial Base needed a Level 2 third-party assessment. The ecosystem had fewer than 100 authorised C3PAOs to deliver them. One official summed the problem up bluntly to DefenseScoop: "The math just simply doesn't math."

Alongside the suspension, the department stood up a CMMC Reform Task Force to run a 60 day review of the whole programme.

Key dates: Industry comments on the CMMC request for information are due by 12:00 PM ET on Friday 14 August 2026. The Reform Task Force must deliver its final report by mid-September 2026.

That second date matters more than anything else in this article. Mid-September is when the market finds out whether CMMC returns on a longer runway, returns in a lighter form, or is replaced by something else entirely. Anyone deciding on CCP training right now is really deciding whether to move before or after that report.

What Is Still Enforced (This Is the Part People Are Missing)

The suspension applies to the Phase 2 implementation schedule. It does not repeal the underlying contractual cybersecurity obligations, and this distinction is where most of the panic on r/CMMC and LinkedIn has gone wrong.

RequirementStatus after 13 July 2026
CMMC Phase 2 third-party (C3PAO) assessments from 10 November 2026Suspended
CMMC Phase 1 Level 1 and Level 2 self-assessmentsStill required
Annual affirmation of complianceStill required
Posting SPRS scores (DFARS 252.204-7019 and -7020)Still in force
DFARS 252.204-7012 safeguarding clauseUnaffected
NIST SP 800-171 Rev. 2 implementation (110 controls)Still enforced
Government-led assessments of selected contractorsContinuing

Read that table again. Every contractor handling CUI still has to implement NIST SP 800-171, still has to score itself, still has to post that score to the Supplier Performance Risk System, and still has to sign an affirmation that a senior official personally attests to. The department has explicitly said it will enforce the standard through self-assessments and selected government-led assessments during the suspension.

In other words: the audit stopped, the homework did not. Tens of thousands of small and mid-sized defence suppliers still need people who can scope a CUI environment, map 800-171 controls, and defend a score under government scrutiny. That work is exactly what the CCP body of knowledge covers.

What the CCP Exam Actually Is in 2026

Before assessing value, get the current facts straight. Most CCP guides you will find on page one of Google still describe the Cyber AB process, which is out of date.

Certification moved to ISACA. ISACA was authorised as the CMMC Assessor and Instructor Certification Organisation (CAICO), with the transition of services completing on 1 April 2026. If you are applying today, you apply through ISACA.

Exam format

  • 170 multiple choice questions
  • 3.5 hours (210 minutes), roughly 70 to 80 seconds per question
  • Scaled scoring from 200 to 800
  • A scaled score of 500 is required to pass

Exam Tip: At 170 questions in 210 minutes, the CCP punishes rereading. Most failures are pacing failures, not knowledge failures. Practise full-length timed sets, not just topic quizzes, or you will run out of clock in the Assessment Process domain where the scenarios are longest.

Domain weights

DomainWeight
CMMC Model Construct and Implementation Evaluation35%
CMMC Assessment Process (CAP)25%
CMMC Governance and Source Documents15%
Scoping15%
CMMC Ecosystem5%
Code of Professional Conduct (Ethics)5%

Sixty per cent of the exam sits in just two domains: Model Construct and the Assessment Process. If your study time is limited, that is where it goes. Ecosystem and Ethics are worth 5% each, which is roughly eight or nine questions apiece, and candidates routinely over-study them because they are the easiest chapters to read.

Prerequisites and training

CCP training must be delivered by a CAICO Approved Training Provider. The curriculum runs 40 hours. Self-study alone does not qualify you to sit the exam, which is unusual among IT certifications and is a large part of why the total cost is what it is.

Candidates submit education verification, work experience details, identity and background information, and pay an application fee to obtain a CMMC Professional Number. Once you complete the training course, you have 12 months to sit the exam.

Most Approved Training Providers recommend a foundational security certification first, typically CompTIA Security+ or equivalent. If you do not have one yet, start there: our Security+ SY0-801 study plan is a faster and far cheaper on-ramp than jumping straight at a $3,000 CMMC course.

The Real Cost of the CCP

This is where the "is the CMMC CCP worth it" question gets uncomfortable, because the exam fee is the small part.

ItemCost
CCP exam fee$275
Application fee (CMMC Professional Number)$200
Mandatory 40-hour ATP training$2,000 to $4,000
Realistic total$2,475 to $4,475

Certification is valid for three years. Under ISACA's model, continuing professional education aligns to 20 CPE hours per year and 120 hours across the three year cycle, plus an annual maintenance fee.

Compare that to a $404 ISACA CISA sitting or a roughly $400 Security+ voucher and the CCP is one of the most expensive mid-tier credentials in cyber, driven almost entirely by the compulsory training requirement. That cost structure is precisely why the Phase 2 suspension hurt: people had committed thousands on the assumption that November 2026 would trigger a hiring scramble.

CCP vs CCA: Which One Are You Actually Aiming At?

A lot of the salary figures circulating online belong to the Certified CMMC Assessor, not the Certified CMMC Professional. Do not confuse the two when you build your business case.

CCP (Certified CMMC Professional)CCA (Certified CMMC Assessor)
PurposeSupports compliance, readiness and implementation workConducts formal CMMC assessments
PrerequisitesATP training, application, background informationActive CCP, CAICO-approved CCA training, a qualifying DoD 8140 certification
Role on an assessmentTeam member, working under CCA supervisionLeads or performs the assessment
Typical progressionEntry point to the ecosystem1 to 3 years after CCP for most people
Reported payVaries widely by consulting roleMid-level CCAs commonly reported at $125,000 to $165,000 base

Fewer than 500 active CCAs exist. That scarcity was the whole investment thesis, and it is also exactly what broke the programme: too few assessors, far too many companies. The suspension is an admission that the assessor pipeline could not be built fast enough.

Here is the nuance worth holding onto. If the Reform Task Force comes back in September recommending a phased restart with a longer runway, the assessor shortage does not disappear, it just gets a later deadline. Everyone who quit the pipeline in July becomes a competitive advantage for everyone who did not.

So Is the CMMC CCP Worth It in 2026?

It depends on which of these three people you are.

Worth it: you already work in or sell to the Defense Industrial Base

If you are an internal security lead, an IT manager at a defence supplier, or an MSP serving DIB clients, the CCP is still a strong buy. Your employer or clients still have live DFARS 252.204-7012 obligations, still have to post SPRS scores, and still face government-led assessments. Nothing about your day job changed on 13 July. The credential formalises knowledge you need regardless of whether a C3PAO ever knocks.

Worth it with patience: you want a consulting or assessor career

The demand is real but the timeline moved. The honest expectation is that hiring stays flat until the September report, then reprices based on what the task force recommends. If you can absorb the cost now and sit the exam while the market is quiet, you enter a less crowded field with a credential in hand rather than a course booking. That is a genuine first-mover position, just a slower one than advertised.

Not worth it yet: you are changing careers into cyber

If you are trying to break into security and someone is selling you a $3,000 CMMC course as your entry ticket, walk away. The CCP is a specialist compliance credential that assumes you already understand security controls, and its hiring market is currently under review by the government. Build the base first. Security+ and then a GRC credential such as ISACA CRISC or ISC2 CGRC will open more doors for a fraction of the cost, and both transfer to commercial employers rather than the defence sector alone.

Bottom line: The CCP is worth it if CMMC work is already adjacent to your job. It is worth it with patience if you are building a compliance consulting career. It is not the right first certification for a career changer, and the July suspension makes that more true, not less.

How to Study for the CCP If You Are Going Ahead

Assuming you are in one of the first two groups, structure your preparation around the domain weights rather than the course running order.

  1. Weeks 1 to 2: source documents. Read 32 CFR Part 170 and NIST SP 800-171 Rev. 2 properly. The exam tests where a requirement comes from, not just what it says. This underpins the 15% Governance domain and half the questions in the heavier domains.
  2. Weeks 3 to 4: Model Construct and implementation evaluation. The single biggest domain at 35%. Drill the difference between met, not met and not applicable, and how objective evidence is judged.
  3. Week 5: the CMMC Assessment Process. Second biggest at 25%. Learn the phases in order and what happens at each decision point.
  4. Week 6: scoping. Worth 15% and heavily scenario-based. Practise classifying assets: CUI assets, security protection assets, contractor risk managed assets, specialised assets, out of scope.
  5. Week 7: ecosystem and ethics. Only 10% combined. Two evenings, not two weeks.
  6. Week 8: full-length timed mocks. Two or three complete 170 question sittings at 210 minutes. Review every wrong answer against the source document, not against the practice question explanation alone.

The technique that moves the needle here is the same one that works for CISA and CISM: retrieval practice under exam conditions rather than passive rereading. If you want the method rather than the content, our post on why most people fail certification exams covers it, and the 12-week CISA study plan uses an almost identical structure for a similarly audit-heavy exam.

What to Watch Between Now and September

Three things will tell you whether to accelerate or hold:

  • 14 August 2026: the RFI comment deadline. The volume and tone of industry submissions signals how hard the sector is pushing to soften the programme.
  • Mid-September 2026: the Reform Task Force final report. This is the decision point for the entire ecosystem.
  • C3PAO authorisation numbers: if the count starts climbing again after the report, assessor demand is back on.

Until then, treat CMMC as paused rather than dead. Phase 1 obligations are still live, contracts still carry the 7012 clause, and the 110 controls in NIST SP 800-171 have not moved an inch.

Ready to Start Practising?

Whether you are heading for the CCP, or building the security and GRC foundation you need before you get there, passing comes down to practice under exam conditions rather than reading more material.

CertCrush gives you realistic practice questions, detailed explanations for every answer, and progress tracking across the certifications that feed into compliance and audit careers, including Security+, CISA, CISM, CRISC and CGRC.

Create your free CertCrush account and start practising today, or browse the full course catalogue to see which certification fits your next move.

CMMCCCPISACAGRCcompliancedefence contractingNIST 800-171certification
Owen Gallagher

Written by

Owen Gallagher · Study Skills & Careers Editor

Owen spent years as an IT trainer watching smart people fail exams they should have passed — usually because of how they studied, not what they knew. He writes about study technique, exam psychology, career strategy and the service-management certifications (ITIL, PRINCE2, APM). His articles are the ones to read before you open a single practice question.

All articles by Owen

Want a CMMC practice course?

We don’t cover this exam yet — we build the most-requested courses first. One click tells us you want it.

Practising for something nearby?

Try real exam-style questions free — no account needed, full explanations included.