An independent organization authorized by the Cyber AB and approved by the Department of Defense to conduct official CMMC assessments. C3PAOs evaluate whether contractors have implemented the necessary practices and processes at the required maturity level, most notably for Level 2 certifications. Only C3PAO assessments uploaded to the DoD’s Supplier Performance Risk System (SPRS) are recognized as valid proof of compliance.