The Case for Strict Separation Between Registered Practitioner Organizations and Certified Third Party Assessment Organizations Under 32 CFR Part 170
ElasticD3M, LLC respectfully submits this position statement urging the Cyber AB and the Department of Defense to affirm, clarify, and where necessary strengthen the strict separation between Registered Practitioner Organization (RPO) functions and Certified Third Party Assessment Organization (C3PAO) functions as established under 32 CFR § 170.8(b)(17), § 170.9, and § 170.11, and grounded in the impartiality requirements of ISO/IEC 17020:2012(E) incorporated by reference therein.
The integrity of the CMMC Level 2 certification regime depends entirely on this separation. Any policy drift, interpretive softening, or affiliated entity structuring that permits the same corporate enterprise to deliver both readiness services and assessment services, even to nominally different clients, materially undermines the public interest purpose of the program and the protection of Controlled Unclassified Information across the Defense Industrial Base.
ElasticD3M operates Enclave AI™ as a CMMC compliance software platform. We are not an RPO. We are not a C3PAO. We do not hold and will not seek either authorization. Our business model, corporate structure, and long term strategy are designed to keep us permanently on the readiness side of the 32 CFR Part 170 firewall as a software vendor serving OSAs, RPOs, and C3PAOs. We submit this statement as a market participant whose interests are directly aligned with the regulatory intent of the rule.
32 CFR Part 170 establishes the Cybersecurity Maturity Model Certification program. The ecosystem it creates depends on three functionally separated roles:
Each of the latter two categories is bound by the Accreditation Body's Conflict of Interest, Code of Professional Conduct, and Ethics policies established under 32 CFR § 170.8(b)(17). C3PAOs are further required to achieve and maintain compliance with ISO/IEC 17020:2012(E) within 27 months of authorization, a standard whose core requirement is organizational impartiality.
The resulting firewall is unambiguous in application to single entity arrangements: a C3PAO cannot assess a client to whom it has previously delivered consulting or readiness services. Industry practice, Cyber AB guidance, and DoD expectation have uniformly treated this as the governing principle since the program's inception.
The firewall faces a foreseeable stress test. The DoD’s own Regulatory Impact Analysis (DOD-2023-OS-0063-0003, page 12) identifies 76,598 entities as requiring CMMC Level 2 Certification through an authorized C3PAO. The Cyber AB Marketplace lists 103 authorized C3PAOs. The RIA forecasts (page 26) 17,127 new Level 2 Certifications in Year 4 of phase-in and 32,121 in Year 7, or 166 to 312 assessments per authorized C3PAO per year. The DoD itself acknowledges (page 8) that “the cost of CMMC Level 2 activities is driven by multiple factors, including market forces that govern availability of C3PAOs.”
This capacity crisis creates economic pressure for ecosystem consolidation. Large C3PAO organizations have strong incentive to capture the adjacent readiness services revenue by:
Each of these structures, absent specific Cyber AB guidance, tests the impartiality requirement of ISO/IEC 17020:2012(E) not in its letter but in its substance. The rule's protection of OSAs and of the DoD's assurance interest depends on the substance, not the form.
ElasticD3M respectfully recommends that the Cyber AB, in coordination with the Office of the DoD Chief Information Officer, issue binding interpretive guidance affirming and operationalizing the following principles:
1. Common Ownership Threshold. Any RPO and C3PAO sharing common beneficial ownership of 25 percent or more, or sharing any common officer, director, or principal, should be deemed a single enterprise for conflict-of-interest purposes. Readiness services provided by the RPO to an OSA should disqualify the affiliated C3PAO from conducting the subsequent assessment of that OSA, regardless of corporate separation.
2. Mandatory Affiliation Disclosure. Every C3PAO should be required to disclose, on the Cyber AB Marketplace and in each engagement letter with an OSA, all affiliated RPO or readiness services entities under common ownership or control. OSAs are entitled to this transparency before selecting an assessor.
3. Independent Board Governance. Where a single corporate enterprise holds both RPO and C3PAO authorizations through separate subsidiaries, the Cyber AB should require documented board level independence between the subsidiaries, with no overlapping directors, officers, or compensation committees, and with separate external audit and compliance reporting.
4. Referral and Revenue Transparency. Any revenue sharing, referral fee, or captive provider arrangement between a C3PAO and an RPO, whether affiliated or not, should be disclosed to OSAs and to the Cyber AB as part of standard market conduct reporting.
5. Public Conflict-of-Interest Attestation Registry. The Cyber AB should publish, on the Marketplace, each Assessment Team Conflict of Interest Attestation submitted under 32 CFR Part 170, enabling OSAs, the DoD, and the public to verify compliance with the firewall in every engagement.
6. Reaffirmation of the ISO/IEC 17020 Substance Test. Impartiality under ISO/IEC 17020:2012(E) should be interpreted substantively. A C3PAO that cannot demonstrate, on the facts, genuine independence from any readiness services entity providing services to the OSA should be ineligible to conduct the assessment, without regard to corporate form arguments to the contrary.
ElasticD3M, LLC affirms that Enclave AI™ and the broader ElasticD3M Agent as a Service platform operate exclusively as readiness side software infrastructure. We are not an RPO. We are not a C3PAO. We do not assess. We will not assess. Our corporate governance documents, platform architecture, and commercial agreements are structured to make that commitment enforceable and auditable.
ElasticD3M, LLC is a compliance software vendor. We do not provide consulting, advisory, or readiness services as defined under 32 CFR Part 170. The AaaS architecture, the validator agent, the sampled human review layer, and our binding Policy Position firewall commitment are in place and operating today.
We welcome inspection of this structure by the Cyber AB and the DoD at any time.
We believe the firewall is the single most important structural protection in the CMMC program. We believe the market will test it. We believe the time to affirm it is before the test, not after.
The CMMC program exists to protect Controlled Unclassified Information across the Defense Industrial Base. Its credibility depends on certifications that mean what they say. Certifications mean what they say only when the entity issuing them is structurally, operationally, and economically independent of the entity that prepared the OSA for assessment.
ElasticD3M urges the Cyber AB Board and the DoD CIO to use this pre Phase-2 window to affirm that principle in specific, operational, and enforceable terms. We stand ready to participate in any working group, public comment process, or industry consultation the Cyber AB convenes on this matter.