CMMC Authorized Training

Certified CMMC Professional (CCP) Training

A CMMC Certified Professional (CCP) is the foundational certification for anyone seeking to work within the implementation and assessment ecosystem of the US Department of War’s (DoW) Cybersecurity Maturity Model Certification (CMMC) program. It validates that you are ready to help organizations achieve assessment-ready cybersecurity programs or participate on a CMMC Assessment Team during official CMMC assessments.

LevelIntermediate
Duration5 Days
Experience2 years: IT Experience
Average Salary$112,398
LabsYes

CMMC Certified Professional (CCP)

Course Overview

CCP develops the practical, job-ready skills needed to work effectively within the CMMC framework. It strengthens your eligibility for roles that support readiness, advisory work, and compliance oversight across the DIB. Because a CCP is the required first step toward becoming a CCA, it also provides a clear advancement pathway into assessment and higher-level consulting roles.

In this course, you will learn about the CMMC Model, framework, context, and application within the DoW, as well as the expectations and requirements imposed upon organizations that do business with the DoW. It will also help students to identify threats to cybersecurity and privacy within an IoT ecosystem and implement appropriate countermeasures.

You will:

  • Identify the threats to the Defense Supply Chain and the established regulations and standards for managing the risk.
  • Identify the sensitive information that needs to be protected within the Defense Supply Chain and how to manage it.
  • Describe how the CMMC Model ensures compliance with federal acquisitions regulations.
  • Identify responsibilities of the Certified CMMC Professional, including appropriate ethical behavior.
  • Establish the Certification and Assessment scope boundaries for evaluating the systems that protect regulated information.
  • Prepare the OSC for an Assessment by evaluating readiness.
  • Use the CMMC Assessment Guides to determine and assess the Evidence for practices.
  • Implement and evaluate practices required to meet CMMC Level 1.
  • Identify the practices required to meet CMMC Level 2.
  • As a CCP, work through the CMMC Assessment process.
Course Outline
  • Lesson 1: Managing Risk within the Defense Supply Chain Topic A: Identify Threats to the Defense Supply Chain
    • Topic B: Identify Regulatory Responses against Threats
  • Lesson 2: Handling Sensitive Information
    • Topic A: Identify Sensitive Information
    • Topic B: Manage the Sensitive Information
  • Lesson 3: Ensuring Compliance through CMMC
    • Topic A: Describe the CMMC Model Architecture
    • Topic B: Define the CMMC Program and Its Ecosystem
    • Topic C: Define Self-Assessments
  • Lesson 4: Performing CCP Responsibilities
    • Topic A: Identify Responsibilities of the CCP
    • Topic B: Demonstrate Appropriate Ethics and Behavior
  • Lesson 5: Scoping Certification and Assessment Boundaries
    • Topic A: Use the CMMC Assessment Scope Documentation
    • Topic B: Get Oriented to the OSC Environment
    • Topic C: Determine How Sensitive Information Moves
    • Topic D: Identify Systems in Scope
    • Topic E: Limit Scope
  • Lesson 6: Preparing the OSC
    • Topic A: Foster a Mature Cybersecurity Culture
    • Topic B: Evaluate Readiness
  • Lesson 7: Determining and Assessing Evidence
    • Topic A: Determine Evidence
    • Topic B: Assess the Practices Using the CMMC Assessment Guides
  • Lesson 8: Implementing and Evaluating Level 1
    • Topic A: Identify CMMC Level 1 Domains and Practices
    • Topic B: Perform a CMMC Level 1 Gap Analysis
    • Topic C: Assess CMMC Level 1 Practices
  • Lesson 9: Identifying Level 2 Practices
    • Topic A: Identify CMMC Level 2 Practices
  • Lesson 10: Working through an Assessment
    • Topic A: Identify Assessment Roles and Responsibilities
    • Topic B: Plan and Prepare the Assessment
    • Topic C: Conduct the Assessment
    • Topic D: Report the Assessment Results
    • Topic E: Conduct the CMMC POA&M Close-Out Assessment
Intended Audience

This course is a prerequisite for the CMMC Certified Professional program, and it prepares students for the CMMC Certified Professional (CCP) certification exam. Students might consider taking this course to learn how to perform CMMC certification readiness checks within their own organization, or as a consultant to other Organizations Seeking Certification (OSC). The CCP certification is also a required step toward becoming a CMMC Certified Assessor (CCA), so students might take this course to begin down the path toward CCA certification.

Prerequisites

To ensure your success in this course, you should have some foundational education or experience in cybersecurity. The CMMC has established prerequisites for those who wish to apply for CCP certification, such as:

  • College degree in a cyber or information technical field with 2+ years of experience; or
  • 2+ years of equivalent experience (including military) in a cyber, information technology, or assessment field.
Follow-on Courses

Related training topics

Get approved to attend

Justify your training

Use this sample request letter — copy it into an email to your manager and personalize the bracketed details to make the case for the time and budget.

Sample training request letter

Subject: Request for Governance, Risk & Compliance training from Applied Technology Academy

[Decision Maker Name],

I'm writing to request time and budget approval to complete Applied Technology Academy's course, Certified CMMC Professional (CCP) Training. The information below outlines how this training benefits our organization, the tasks I'll be able to perform after completing it, and relevant cost and funding details.

Course Description
A CMMC Certified Professional (CCP) is the foundational certification for anyone seeking to work within the implementation and assessment ecosystem of the US Department of War’s (DoW) Cybersecurity Maturity Model Certification (CMMC) program. It validates that you are ready to help organizations achieve assessment-ready cybersecurity programs or participate on a CMMC Assessment Team during official CMMC assessments. Applied Technology Academy is an award-winning, SBA-certified woman-owned training provider (est. 2008) whose instructors are active practitioners; the course is hands-on with virtual labs and a learn-by-doing methodology.

Course Objectives
Once I've completed the course, I'll have hands-on, job-ready skills in governance, risk & compliance that I can apply immediately to our work.

Expected Organizational Benefits
After completing this course, I will be better equipped to apply these skills directly to our projects, reduce our reliance on outside expertise, strengthen our team's capabilities, and share what I learn with colleagues.

Expected Cost & Funding
Course fee: [request an itemized quote at the link below]. Applied Technology Academy supports multiple funding paths that may reduce or cover this cost: GSA MAS purchasing and government purchase orders, military credentialing funding (Army CA, AF COOL, CG COOL), VA GI Bill and VR&E, ATA Flexible Spending, and student financing. Private team cohorts are available if colleagues should attend with me.

Conclusion
This training provides practical, hands-on experience I can apply immediately to strengthen our work in governance, risk & compliance. Additional course information is available at https://appliedtechnologyacademy.com/isaca-training/certified-cmmc-professional-ccp/.

Thank you for your consideration,
[Your Name]

Design training around your team, not the other way around.

Talk to a training advisor about private cohorts, funding paths and program management.

Request a Quote Call 800.674.3550