Developer docs
API playgroundTry for free, no card

Search company profiles

The Cyber AB

Full company profile

uuid00qbjtc

Namestring
The Cyber AB
Legal namestring
Cybersecurity Maturity Model Certification Accreditation Body, Inc.
Websiteurl
cyberab.org
Company typeenum
Private
Founded yearint
2020
Descriptiontext

The Cyber AB (legally Cybersecurity Maturity Model Certification Accreditation Body, Inc.) is a 501(c)(3) nonprofit organization founded in January 2020 and headquartered in National Harbor, Maryland. It operates under a no-cost contract with the U.S. Department of Defense as the sole authorized non-governmental accreditation body for the Cybersecurity Maturity Model Certification (CMMC) program, which verifies that defense contractors meet cybersecurity requirements for protecting Controlled Unclassified Information (CUI) and Federal Contract Information (FCI). The organization accredits Certified Third-Party Assessment Organizations (C3PAOs), Licensed Training Providers (LTPs/ATPs), Licensed Publishing Partners (LPPs), and Registered Practitioners (RPOs), and oversees individual professional credentials (CCP, CCA, LCCA, CCI) through its wholly owned subsidiary CAICO, now operated in partnership with ISACA.

The Cyber AB's core technology consists of digital marketplace platforms — the CMMC Marketplace, SCF Marketplace, and SCA Marketplace — that connect the approximately 80,000+ Defense Industrial Base contractors seeking certification with authorized service providers. The 2026 partnership with RAMPxchange extends this with CMMC Marketplace 2.0, adding multi-language international support and improved functionality. The organization generates revenue through C3PAO authorization fees ($6,000 application + $15,000 authorization/re-authorization), individual certification registration and annual renewal fees, ecosystem membership dues, and training/content licensing. The go-to-market combines event-driven engagement (annual CS5 Conference, monthly Town Halls since 2021, webinars) with channel-partner distribution through the authorized C3PAO and ATP networks. The organization is pursuing ISO 17011 accreditation by end of FY2026 to operate under both DoD and international accreditation requirements, and has expanded beyond CMMC into the Secure Controls Framework (SCF) and Supply Chain Assurance (SCA) ecosystems.

Short descriptiontext

The Cyber AB is the sole U.S. Department of Defense-authorized nonprofit accreditation body for the CMMC cybersecurity certification program, serving defense industrial base contractors through its C3PAO, training, and professional certification ecosystem across CMMC, SCF, and SCA verticals.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
11–50
akta.pro rankint
HeadquartersBethesda, United States
HQ citystring
Bethesda
HQ countrystring
United States
HQ regionstring
North America
Markets served

Serves global market

Offices1 record

Each record includes

City, Country, Type, Description, Source

Keyword5 values
cybersecurity accreditation services, CMMC certification programs, defense industrial base compliance, third-party assessment authorization, professional certification credentials
Industry2 codes
1Information Technology (IT) & Cybersecurity Certifications
CodeEDAAANAAPrimaryYes
2Secure Browser, Device Lockdown & Exam Security Tools
CodeEDAFADAIPrimaryNo
Product category
Cybersecurity Accreditation Services
No data
GTM motion3 records

Each record includes

Type, Description, Source

Revenue model4 records
1C3PAO Authorization Fees
TypeProfessional Services
Description

Organizations seeking to become Certified Third-Party Assessment Organizations pay application fees of $6,000 and authorization/re-authorization fees of $15,000. These organizations are then authorized to conduct CMMC assessments for defense contractors.

cyberab.org
2Individual Certification Fees
TypeSubscription Recurring
Description

Certification fees for individual professionals including CMMC Certified Professional (CCP) registration ($200 one-time) plus exam fee ($275), annual renewal ($250); CMMC Certified Assessor (CCA) registration ($50) plus exam fee ($350), annual renewal ($500); Lead CCA registration ($100) plus renewal ($100).

cyberab.org
3Membership and Ecosystem Fees
TypeSubscription Recurring
Description

The organization generates revenue through membership fees for ecosystem participants including Registered Practitioners Organizations (RPOs), Registered Practitioners, and other ecosystem members seeking to participate in the CMMC marketplace.

cyberab.org
4Training and Content Licensing
TypeLicensing Royalties
Description

Revenue generated through Licensed Training Providers (LTPs) and Licensed Publishing Partners (LPPs) who deliver formal CMMC training curricula and professional certification preparation programs.

cyberab.org
Marketing channels6 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels4 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components6 values
Personnel, Operations, Technology or R&D, Marketing or Sales, Infrastructure, Others
Pricing details4 tiers
1C3PAO Organization Authorization
ModelOtherBilling cadenceMulti-year contract
Notes

$6,000 Application fee + $15,000 Authorization/Re-authorization fee. Annual renewal and accreditation included in C3PAO Agreement. Registration duration approximately 6 months.

cyberab.org
2CMMC Certified Professional (CCP) Individual
ModelSubscriptionBilling cadenceAnnual
Notes

$200 Registration (one-time CPN) + $275 Exam Fee. Annual renewal fee $250. Prerequisites include DoD CUI Awareness Training.

cyberab.org
3CMMC Certified Assessor (CCA) Individual
ModelSubscriptionBilling cadenceAnnual
Notes

$50 Registration fee + $350 Exam Fee. Annual renewal fee $500. Requires active CCP certification, 3 years cybersecurity experience, 1 year assessment/audit experience, and qualifying certifications.

cyberab.org
4Lead CCA Individual
ModelSubscriptionBilling cadenceAnnual
Notes

$100 Registration fee. Annual renewal fee $100. Requires meeting DoD Experience and 8140 requirements.

cyberab.org
GTM typeB2B
B2B
Offering typeServices
Services
Core offering1 text field

The Cyber AB is the sole authorized non-governmental accreditation body for the U.S. Department of Defense's CMMC program. It accredits Certified Third-Party Assessment Organizations (C3PAOs), authorizes training and publishing partners, certifies individual cybersecurity professionals (CCP, CCA, Lead CCA, CCI), and operates digital marketplaces that connect Defense Industrial Base contractors with authorized assessors, consultants, and training providers.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 2 values shown
  • Fewer than 100 authorized C3PAOs serving 80,000+ defense contractors requiring CMMC certification
+1 more record
Product overview1 text field

The Cyber AB is an accreditation body offering a platform-based ecosystem approach to cybersecurity certification for the Defense Industrial Base. The core offering consists of the CMMC Marketplace connecting organizations with authorized service providers, supported by professional certification programs (CCP, CCA, Lead CCA) administered through CAICO, and C3PAO organization certifications. The organization has expanded beyond CMMC to encompass the SCF Ecosystem (with SCF Marketplace and SCF Certifications) and SCA Ecosystem, each with their own marketplaces. A wholly owned subsidiary, The Cyber EF (Cyber Engagement Forum), drives sustained stakeholder engagement through training and market facilitation. The organization also hosts the annual CS5 Conference and monthly Town Halls as community engagement vehicles.

Product and service10 records
1CMMC Marketplace
Categorymarketplace platform
Description

Digital marketplace where defense contractors can find and engage with authorized CMMC service providers including C3PAOs, assessors, consultants, and training providers, with visibility into provider credentials and services.

2C3PAO Organization Authorization
Categoryorganization accreditation
Description

Organization-level accreditation for entities seeking authorization to conduct CMMC Level 2 third-party assessments for defense contractors. Includes $6,000 application fee plus $15,000 authorization/re-authorization fee, with annual renewal and accreditation included in the C3PAO Agreement.

3Certified CMMC Professional (CCP) Certification
Categoryindividual certification
Description

Entry-level individual certification for professionals responsible for assessment, examination, verification, and review of organizations for CMMC compliance. Requires DoD CUI Awareness Training prerequisite; $200 registration, $275 exam fee, $250 annual renewal.

4CMMC Certified Assessor (CCA) Certification
Categoryindividual certification
Description

Individual certification for professionals qualified to work on CMMC Level 2 assessments as part of a C3PAO assessment team. Requires active CCP certification, 3 years cybersecurity experience, 1 year assessment/audit experience, and qualifying certifications; $50 registration, $350 exam fee, $500 annual renewal.

5Lead CMMC Certified Assessor (Lead CCA) Certification
Categoryindividual certification
Description

Advanced certification for lead assessors who can make final determinations on CMMC assessments. Requires meeting DoD Experience and 8140 requirements; $100 registration fee, $100 annual renewal.

6SCF Marketplace
Categorymarketplace platform
Description

Marketplace for Secure Controls Framework related services and providers, supporting the SCF Conformity Assessment Program for company-level certification.

7SCA Marketplace
Categorymarketplace platform
Description

Marketplace for Supply Chain Assurance services and providers, supporting cybersecurity requirements across supply chains.

8SCF Certifications
Categorycertification program
Description

Certification programs under the SCF Conformity Assessment Program, including SCF Certified - NIST CSF 2.0 and other framework-based certifications for company-level conformity assessment.

9CMMC Central
Categoryplatform
Description

Centralized hub providing access to CMMC marketplace, resources, and ecosystem information for defense contractors navigating CMMC requirements.

10CMMC Marketplace 2.0 (Powered by RAMPxchange)
Categorymarketplace platform
Description

Next-generation version of the CMMC Marketplace with enhanced functionality, dynamic customer-provider matching, and international multi-language support.

Scale indicator5 records

Each record includes

Type, Value, Description, Source

Partnership5 partners
Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-04-16
Description

Strategic partnership at CS5 West to develop and deploy an enhanced version of the Cybersecurity Maturity Model Certification (CMMC) marketplace. The enhanced marketplace provides improved functionality, better structure, visibility, and a revamped interface to streamline how organizations identify and engage with authorized CMMC service providers. The partnership aims to reduce delays in customer-provider relationships and support the program's global reach.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2024-12-18
Description

The Cyber AB appointed as the exclusive Accreditation Body for the SCF Conformity Assessment Program (SCF CAP), a new partnership marking significant advancement in the global landscape of compliance and certification. The SCF CAP uses the Secure Controls Framework as the control set to provide company-level certification. The Cyber AB accredits SCF Third-Party Assessment Organizations (SCF 3PAOs) and oversees conflict-of-interest governance throughout the program.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

ISACA is now the Authorized CAICO (Cybersecurity Assessor and Instructor Certification Organization) for the CMMC program. ISACA manages the CCP, CCA, LCCA, and CCI credentials and examination processes for CMMC professionals.

Strategic tierMinorTypeOthers
Description

The GAO issued a report recommending that the Defense Department better manage external risk factors affecting the CMMC program, including ecosystem capacity, program demand, and costs that could affect contractor participation. DoD agreed to assess and document these external factors as it phases in CMMC requirements.

Strategic tierCoreTypeOthers
Description

DCSA conducts DIBCAC (Defense Industrial Base Cybersecurity Assessment Center) assessments for C3PAO candidates. FOCI (Foreign Ownership, Control, or Influence) reviews are conducted by DCSA as part of the C3PAO application process.

Recent move8 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight6 records

Each record includes

Type, Description

Peers10 records
TypeBroad incumbent
Description

UKAS is the national accreditation body for the United Kingdom, providing ISO 17011 accreditation services across industries. It is comparable as an internationally recognized accreditation body, relevant to The Cyber AB's ISO 17011 pursuit and potential international expansion ambitions.

TypeDirect peer
Description

CompTIA is a leading nonprofit trade association offering vendor-neutral IT and cybersecurity certifications (Security+, CySA+, etc.). It is comparable as a nonprofit certification body with vendor-neutral credentials and industry-recognized professional certification programs.

TypeBroad incumbent
Description

ANSI is a major U.S. accreditation body that oversees standards and conformity assessment across multiple industries. It is comparable to The Cyber AB as a nonprofit accreditation organization, though ANSI operates broadly across industries while The Cyber AB specializes exclusively in cybersecurity/CMMC.

4SCF Council (Secure Controls Framework)
TypeDirect peer
Description

The SCF Council is the strategic partner that appointed The Cyber AB as exclusive Accreditation Body for the SCF Conformity Assessment Program. It is comparable as the framework owner for a competing/parallel cybersecurity conformity assessment program and a direct ecosystem peer.

TypeRegional player
Description

SANS Institute is a major cybersecurity training and certification organization offering GIAC credentials. It is comparable through the connection to Cyber AB board member Mathew Newfield (SANS instructor) and as a cybersecurity training and certification provider that feeds into the CMMC ecosystem.

TypeBroad incumbent
Description

A2LA is a nonprofit accreditation body providing ISO 17025 and other conformity assessment services. It is comparable as a nonprofit accreditation body pursuing ISO 17011 recognition, though it focuses on laboratory and testing accreditation rather than cybersecurity.

TypeDirect peer
Description

ISACA is a global professional association for IT governance, risk, and cybersecurity professionals offering CISA, CISM, and other certifications. It is comparable as both a strategic partner (now Authorized CAICO for CMMC) and a peer in cybersecurity professional certification and credentialing.

TypeDirect peer
Description

(ISC)² is a major nonprofit cybersecurity professional certification organization offering CISSP and other credentials. It is comparable to The Cyber AB's CAICO subsidiary as a professional cybersecurity certification body, with similar individual certification and renewal fee models.

9NVLAP (National Voluntary Laboratory Accreditation Program)
TypeBroad incumbent
Description

NVLAP is a NIST-administered accreditation program providing laboratory and testing accreditation. It is comparable as a government-affiliated accreditation body relevant to The Cyber AB's conformity assessment mandate and its pursuit of federal recognition standards.

10NIAS (National Institute for Automotive Service Excellence)
TypeBroad incumbent
Description

ASE is a nonprofit organization that provides professional certification for automotive service professionals. It is comparable as a nonprofit certification body with professional credentialing programs and assessment-based credentials, though in the automotive rather than cybersecurity domain.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses5 records

Each record includes

Headline, Details, Source

Competitive moat5 records

Each record includes

Type, Details

Key risks6 records

Each record includes

Headline, Details, Source

Key highlights7 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers1 record

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment4 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile4 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
No
API detail
Has APIbool
No

Docs URL, Description

AI maturity
App detail

Has app

Feature3 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles15 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

Subsidiaries2 records

Each record includes

Name, Acquired on, Relationship type, Type, Business focus

Compliance5 records

Each record includes

Name, Class, Description

Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

The Cyber AB

Cybersecurity Accreditation Servicescyberab.org

The Cyber AB is the sole U.S. Department of Defense-authorized nonprofit accreditation body for the CMMC cybersecurity certification program, serving defense industrial base contractors through its C3PAO, training, and professional certification ecosystem across CMMC, SCF, and SCA verticals.

What The Cyber AB does

The Cyber AB (legally Cybersecurity Maturity Model Certification Accreditation Body, Inc.) is a 501(c)(3) nonprofit organization founded in January 2020 and headquartered in National Harbor, Maryland. It operates under a no-cost contract with the U.S. Department of Defense as the sole authorized non-governmental accreditation body for the Cybersecurity Maturity Model Certification (CMMC) program, which verifies that defense contractors meet cybersecurity requirements for protecting Controlled Unclassified Information (CUI) and Federal Contract Information (FCI). The organization accredits Certified Third-Party Assessment Organizations (C3PAOs), Licensed Training Providers (LTPs/ATPs), Licensed Publishing Partners (LPPs), and Registered Practitioners (RPOs), and oversees individual professional credentials (CCP, CCA, LCCA, CCI) through its wholly owned subsidiary CAICO, now operated in partnership with ISACA.

The Cyber AB's core technology consists of digital marketplace platforms — the CMMC Marketplace, SCF Marketplace, and SCA Marketplace — that connect the approximately 80,000+ Defense Industrial Base contractors seeking certification with authorized service providers. The 2026 partnership with RAMPxchange extends this with CMMC Marketplace 2.0, adding multi-language international support and improved functionality. The organization generates revenue through C3PAO authorization fees ($6,000 application + $15,000 authorization/re-authorization), individual certification registration and annual renewal fees, ecosystem membership dues, and training/content licensing. The go-to-market combines event-driven engagement (annual CS5 Conference, monthly Town Halls since 2021, webinars) with channel-partner distribution through the authorized C3PAO and ATP networks. The organization is pursuing ISO 17011 accreditation by end of FY2026 to operate under both DoD and international accreditation requirements, and has expanded beyond CMMC into the Secure Controls Framework (SCF) and Supply Chain Assurance (SCA) ecosystems.

The Cyber AB firmographics

Firmographics
Name
The Cyber AB
Legal name
Cybersecurity Maturity Model Certification Accreditation Body, Inc.
Website
https://cyberab.org
Company type
Private
Founded year
2020
Operating status
Operating
Headcount range
11–50 employees
Short description
The Cyber AB is the sole U.S. Department of Defense-authorized nonprofit accreditation body for the CMMC cybersecurity certification program, serving defense industrial base contractors through its C3PAO, training, and professional certification ecosystem across CMMC, SCF, and SCA verticals.
Ownership category
akta.pro rank

The Cyber AB industry classification

Industry
Product category
Cybersecurity Accreditation Services
akta.pro primary industry
Information Technology (IT) & Cybersecurity Certifications (EDAAANAA)
akta.pro secondary industry
Secure Browser, Device Lockdown & Exam Security Tools (EDAFADAI)

Keywords

  • Cybersecurity accreditation services
  • CMMC certification programs
  • Defense industrial base compliance
  • Third-party assessment authorization
  • Professional certification credentials

Where The Cyber AB is headquartered

Location

Headquarters

HQ city
Bethesda
HQ country
United States
HQ region
North America

Offices1 record

Markets served

The Cyber AB business model

Business model
GTM type
B2B
Offering type
Services
Cost components
Personnel, Operations, Technology or R&D, Marketing or Sales, Infrastructure, Others

Revenue model

  1. C3PAO Authorization Fees: Organizations seeking to become Certified Third-Party Assessment Organizations pay application fees of $6,000 and authorization/re-authorization fees of $15,000. These organizations are then authorized to conduct CMMC assessments for defense contractors.
  2. Individual Certification Fees: Certification fees for individual professionals including CMMC Certified Professional (CCP) registration ($200 one-time) plus exam fee ($275), annual renewal ($250); CMMC Certified Assessor (CCA) registration ($50) plus exam fee ($350), annual renewal ($500); Lead CCA registration ($100) plus renewal ($100).
  3. Membership and Ecosystem Fees: The organization generates revenue through membership fees for ecosystem participants including Registered Practitioners Organizations (RPOs), Registered Practitioners, and other ecosystem members seeking to participate in the CMMC marketplace.
  4. Training and Content Licensing: Revenue generated through Licensed Training Providers (LTPs) and Licensed Publishing Partners (LPPs) who deliver formal CMMC training curricula and professional certification preparation programs.

Pricing tiers

ModelBillingPrice
OtherMulti-year contractC3PAO Organization Authorization
SubscriptionAnnualCMMC Certified Professional (CCP) Individual
SubscriptionAnnualCMMC Certified Assessor (CCA) Individual
SubscriptionAnnualLead CCA Individual

Go-to-market motion3 records

Distribution channels4 records

Marketing channels6 records

The Cyber AB product offering

Product offering

Core offering

The Cyber AB is the sole authorized non-governmental accreditation body for the U.S. Department of Defense's CMMC program. It accredits Certified Third-Party Assessment Organizations (C3PAOs), authorizes training and publishing partners, certifies individual cybersecurity professionals (CCP, CCA, Lead CCA, CCI), and operates digital marketplaces that connect Defense Industrial Base contractors with authorized assessors, consultants, and training providers.

Product overview

The Cyber AB is an accreditation body offering a platform-based ecosystem approach to cybersecurity certification for the Defense Industrial Base. The core offering consists of the CMMC Marketplace connecting organizations with authorized service providers, supported by professional certification programs (CCP, CCA, Lead CCA) administered through CAICO, and C3PAO organization certifications. The organization has expanded beyond CMMC to encompass the SCF Ecosystem (with SCF Marketplace and SCF Certifications) and SCA Ecosystem, each with their own marketplaces. A wholly owned subsidiary, The Cyber EF (Cyber Engagement Forum), drives sustained stakeholder engagement through training and market facilitation. The organization also hosts the annual CS5 Conference and monthly Town Halls as community engagement vehicles.

Differentiator

Problem solved

Functional benefit

Products and services

  • CMMC Marketplace Digital marketplace where defense contractors can find and engage with authorized CMMC service providers including C3PAOs, assessors, consultants, and training providers, with visibility into provider credentials and services.
  • C3PAO Organization Authorization Organization-level accreditation for entities seeking authorization to conduct CMMC Level 2 third-party assessments for defense contractors. Includes $6,000 application fee plus $15,000 authorization/re-authorization fee, with annual renewal and accreditation included in the C3PAO Agreement.
  • Certified CMMC Professional (CCP) Certification Entry-level individual certification for professionals responsible for assessment, examination, verification, and review of organizations for CMMC compliance. Requires DoD CUI Awareness Training prerequisite; $200 registration, $275 exam fee, $250 annual renewal.
  • CMMC Certified Assessor (CCA) Certification Individual certification for professionals qualified to work on CMMC Level 2 assessments as part of a C3PAO assessment team. Requires active CCP certification, 3 years cybersecurity experience, 1 year assessment/audit experience, and qualifying certifications; $50 registration, $350 exam fee, $500 annual renewal.
  • Lead CMMC Certified Assessor (Lead CCA) Certification Advanced certification for lead assessors who can make final determinations on CMMC assessments. Requires meeting DoD Experience and 8140 requirements; $100 registration fee, $100 annual renewal.
  • SCF Marketplace Marketplace for Secure Controls Framework related services and providers, supporting the SCF Conformity Assessment Program for company-level certification.
  • SCA Marketplace Marketplace for Supply Chain Assurance services and providers, supporting cybersecurity requirements across supply chains.
  • SCF Certifications Certification programs under the SCF Conformity Assessment Program, including SCF Certified - NIST CSF 2.0 and other framework-based certifications for company-level conformity assessment.
  • CMMC Central Centralized hub providing access to CMMC marketplace, resources, and ecosystem information for defense contractors navigating CMMC requirements.
  • CMMC Marketplace 2.0 (Powered by RAMPxchange) Next-generation version of the CMMC Marketplace with enhanced functionality, dynamic customer-provider matching, and international multi-language support.

Quantifiable outcome

  • Fewer than 100 authorized C3PAOs serving 80,000+ defense contractors requiring CMMC certification
  • +1 more outcomes

Companies that use The Cyber AB

Customer profile

Named customers1 record

Segments4 records

Ideal customer profiles4 records

The Cyber AB technology and API

Technology

Technology focussed No

API detail

Has API
No
API docs
API detail

Core technology

AI maturity

App detail

Feature3 records

The Cyber AB partnerships and signals

Strategic signal

Partnerships

Five partnerships are on record, tiered core and minor.

  • RAMPxchangecoreStrategic or Co-development Partner · 16 April 2026Strategic partnership at CS5 West to develop and deploy an enhanced version of the Cybersecurity Maturity Model Certification (CMMC) marketplace. The enhanced marketplace provides improved functionality, better structure, visibility, and a revamped interface to streamline how organizations identify and engage with authorized CMMC service providers. The partnership aims to reduce delays in customer-provider relationships and support the program's global reach.
  • SCF CouncilcoreStrategic or Co-development Partner · 18 December 2024The Cyber AB appointed as the exclusive Accreditation Body for the SCF Conformity Assessment Program (SCF CAP), a new partnership marking significant advancement in the global landscape of compliance and certification. The SCF CAP uses the Secure Controls Framework as the control set to provide company-level certification. The Cyber AB accredits SCF Third-Party Assessment Organizations (SCF 3PAOs) and oversees conflict-of-interest governance throughout the program.
  • ISACAcoreStrategic or Co-development PartnerISACA is now the Authorized CAICO (Cybersecurity Assessor and Instructor Certification Organization) for the CMMC program. ISACA manages the CCP, CCA, LCCA, and CCI credentials and examination processes for CMMC professionals.
  • GAO (Government Accountability Office)minorOthersThe GAO issued a report recommending that the Defense Department better manage external risk factors affecting the CMMC program, including ecosystem capacity, program demand, and costs that could affect contractor participation. DoD agreed to assess and document these external factors as it phases in CMMC requirements.
  • DCSA (Defense Counterintelligence and Security Agency)coreOthersDCSA conducts DIBCAC (Defense Industrial Base Cybersecurity Assessment Center) assessments for C3PAO candidates. FOCI (Foreign Ownership, Control, or Influence) reviews are conducted by DCSA as part of the C3PAO application process.

Scale indicators5 records

Recent moves8 records

Expansion highlights6 records

The Cyber AB competitors and assessment

Company assessment

Broad incumbents

  • UKAS (United Kingdom Accreditation Service): UKAS is the national accreditation body for the United Kingdom, providing ISO 17011 accreditation services across industries. It is comparable as an internationally recognized accreditation body, relevant to The Cyber AB's ISO 17011 pursuit and potential international expansion ambitions.
  • ANSI (American National Standards Institute): ANSI is a major U.S. accreditation body that oversees standards and conformity assessment across multiple industries. It is comparable to The Cyber AB as a nonprofit accreditation organization, though ANSI operates broadly across industries while The Cyber AB specializes exclusively in cybersecurity/CMMC.
  • A2LA (American Association for Laboratory Accreditation): A2LA is a nonprofit accreditation body providing ISO 17025 and other conformity assessment services. It is comparable as a nonprofit accreditation body pursuing ISO 17011 recognition, though it focuses on laboratory and testing accreditation rather than cybersecurity.
  • NVLAP (National Voluntary Laboratory Accreditation Program): NVLAP is a NIST-administered accreditation program providing laboratory and testing accreditation. It is comparable as a government-affiliated accreditation body relevant to The Cyber AB's conformity assessment mandate and its pursuit of federal recognition standards.
  • NIAS (National Institute for Automotive Service Excellence): ASE is a nonprofit organization that provides professional certification for automotive service professionals. It is comparable as a nonprofit certification body with professional credentialing programs and assessment-based credentials, though in the automotive rather than cybersecurity domain.

Direct peers

  • CompTIA: CompTIA is a leading nonprofit trade association offering vendor-neutral IT and cybersecurity certifications (Security+, CySA+, etc.). It is comparable as a nonprofit certification body with vendor-neutral credentials and industry-recognized professional certification programs.
  • SCF Council (Secure Controls Framework): The SCF Council is the strategic partner that appointed The Cyber AB as exclusive Accreditation Body for the SCF Conformity Assessment Program. It is comparable as the framework owner for a competing/parallel cybersecurity conformity assessment program and a direct ecosystem peer.
  • ISACA: ISACA is a global professional association for IT governance, risk, and cybersecurity professionals offering CISA, CISM, and other certifications. It is comparable as both a strategic partner (now Authorized CAICO for CMMC) and a peer in cybersecurity professional certification and credentialing.
  • (ISC)²: (ISC)² is a major nonprofit cybersecurity professional certification organization offering CISSP and other credentials. It is comparable to The Cyber AB's CAICO subsidiary as a professional cybersecurity certification body, with similar individual certification and renewal fee models.

Regional players

  • SANS Institute: SANS Institute is a major cybersecurity training and certification organization offering GIAC credentials. It is comparable through the connection to Cyber AB board member Mathew Newfield (SANS instructor) and as a cybersecurity training and certification provider that feeds into the CMMC ecosystem.

Market position

Strengths5 records

Weaknesses5 records

Competitive moat5 records

Key risks6 records

Key highlights7 records

Customer concentration

The Cyber AB compliance and trust

Trust signal

Compliance5 records

The Cyber AB financial estimates

Financial estimate

Revenue estimate

Valuation estimate

The Cyber AB leadership team

Management profile

Number of profiles

Profiles15 records

The Cyber AB subsidiaries and ownership

Company hierarchy

Subsidiaries2 records

The Cyber AB funding detail

Funding detail

Funding overview

Funding rounds

Investors

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

The Cyber AB M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about The Cyber AB

What does The Cyber AB do?

The Cyber AB is the sole authorized non-governmental accreditation body for the U.S. Department of Defense's CMMC program. It accredits Certified Third-Party Assessment Organizations (C3PAOs), authorizes training and publishing partners, certifies individual cybersecurity professionals (CCP, CCA, Lead CCA, CCI), and operates digital marketplaces that connect Defense Industrial Base contractors with authorized assessors, consultants, and training providers.

Is The Cyber AB a public or private company?

The Cyber AB is a private company. It is classified as nonprofit foundation owned and is currently operating.

When was The Cyber AB founded?

The Cyber AB was founded in 2020. It employs 11 to 50 people.

Where is The Cyber AB based?

The Cyber AB is headquartered in Bethesda, United States, in the North America region.

How does The Cyber AB make money?

Four revenue lines are on record. C3PAO Authorization Fees are the primary driver. The others are individual Certification Fees, membership and Ecosystem Fees and training and Content Licensing.

Who are The Cyber AB's main competitors?

Broad incumbents on record are UKAS (United Kingdom Accreditation Service), ANSI (American National Standards Institute), A2LA (American Association for Laboratory Accreditation), NVLAP (National Voluntary Laboratory Accreditation Program) and NIAS (National Institute for Automotive Service Excellence). Direct peers are CompTIA, SCF Council (Secure Controls Framework), ISACA and (ISC)². SANS Institute is listed as a regional player.

Does The Cyber AB have an API?

No public API is recorded for The Cyber AB.

What industry is The Cyber AB in?

The Cyber AB's product category is Cybersecurity Accreditation Services. Its primary akta.pro industry code is EDAAANAA, Information Technology (IT) & Cybersecurity Certifications, with a secondary code of EDAFADAI, Secure Browser, Device Lockdown & Exam Security Tools.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
Federal News NetworkCyber AB’s Matt Travis on CMMC reformCyber AB's Matt Travis urged the Pentagon to adopt a transition plan for CMMC reform, citing burdens on small businesses and lack of continuous monitoring. He proposed continuous monitoring, smaller assessment teams, and clarifying FedRAMP integration. Travis said existing Level 2 certifications should be preserved.citybizThe Cyber AB Names Mathew Newfield Executive Vice President and COOThe Cyber AB, the accreditation body for the Department of Defense's Cybersecurity Maturity Model Certification (CMMC) program, has appointed Mathew Newfield as executive vice president and chief operating officer in a newly created role. Newfield will oversee day-to-day operations, scale organizational capabilities, and advance customer success initiatives as the organization responds to growing demand for cybersecurity compliance across the defense industrial base. The appointment reflects the organization's maturation as CMMC requirements are expected to affect thousands of contractors and the certification pipeline needs to function efficiently.citybizThe Cyber AB Names Mathew Newfield EVP and Chief Operating OfficerThe Cyber AB has appointed Mathew Newfield as Executive Vice President and Chief Operating Officer, transitioning him from his board role where he served as Vice Chair since 2021 to an executive operating position. The appointment is intended to strengthen day-to-day operations and organizational scaling as the Cybersecurity Maturity Model Certification program enters its second year of implementation. Newfield brings extensive cybersecurity leadership experience from previous roles at One Diversified, Unisys Corporation, and IBM, and will oversee business operations, customer success, and growth across the CMMC and Secure Controls Framework ecosystems.Business Wire BlogThe Cyber AB Appoints Mathew Newfield as Executive Vice President and Chief Operating OfficerThe Cyber AB appointed Mathew Newfield as Executive Vice President and Chief Operating Officer, effective immediately. He will oversee daily operations, strategic scaling, and customer success, with a background at One Diversified, Unisys, IBM, and RSA. His tenure begins now as the CMMC Program enters its first official year of implementation.GlobeNewswireRAMPxchange and The Cyber AB form exclusive partnership to deliver the next generation CMMC marketplaceRAMPxchange and The Cyber AB announced a partnership to develop an enhanced CMMC marketplace, unveiled at CS5 West. The alliance aims to improve functionality, structure, and visibility for CMMC providers and users. Details and timelines will be discussed at an upcoming CMMC Town Hall.GlobeNewswireRAMPxchange and The Cyber AB form exclusive partnership to deliver the next generation CMMC marketplaceRAMPxchange and The Cyber AB announced a strategic partnership at CS5 West to develop and deploy an enhanced version of the Cybersecurity Maturity Model Certification (CMMC) marketplace. The enhanced marketplace will provide improved functionality, better structure, visibility, and a revamped interface to streamline how organizations identify and engage with authorized CMMC service providers. The partnership aims to reduce delays in customer-provider relationships and support the program's global reach, with details to be discussed at an upcoming CMMC Town Hall.PR NewswireVeteran-Owned Perezdiaz, LLC Achieves C3PAO Authorization, Joins Fewer Than 100 Authorized Assessment Bodies Serving 80,000+ Defense ContractorsPerezdiaz Federal, the independent assessment division of veteran-owned Perezdiaz, LLC, announced its authorization as a CMMC Third-Party Assessment Organization (C3PAO) by The Cyber AB on February 24, 2026, making it among the first 100 organizations to achieve this designation. The authorization enables Perezdiaz Federal to perform official CMMC Level 2 certification assessments for Defense Industrial Base contractors under 32 CFR Part 170, with fewer than 100 authorized C3PAOs currently serving more than 80,000 contractors. Operating under strict independence requirements, Perezdiaz Federal functions exclusively as an assessment body during certification engagements, verifying that security controls are implemented, functioning as intended, and protecting Controlled Unclassified Information.Business Wire BlogThe Cyber AB Announces Election of Board Officers and New Board AppointmentsThe Cyber AB announced the re-election of its board officers for 2026-2027, with Paul Michaels continuing as Chairman, Debbie Taylor Moore elected as Vice Chair, Katherine Hennessey as Secretary, and Wayne Boline as at-large Executive Committee member. Four new directors—Michele Iversen, Beth Leonard, Kemba Walden, and Sounil Yu—were appointed to the Board, each bringing backgrounds in cybersecurity, government services, and compliance from organizations including The Chertoff Group, R3 LLC, Paladin Global Institute, and Knostic. The new officers assumed duties on January 1st and will serve two-year terms, while new directors will serve initial four-year terms.Federal News NetworkRisk & Compliance Exchange: Cyber AB’s Matt Travis on scaling the CMMC ecosystemThe Cyber AB is taking on the responsibility of building a network of assessors to evaluate defense contractors' cybersecurity as part of the Cybersecurity Maturity Model Certification (CMMC) program. The implementation of CMMC, which requires contractors to protect controlled unclassified information, began on November 10, with over 80,000 companies eventually needing assessments. The Cyber AB emphasizes the urgency for defense contractors to prepare for certification to avoid delays given the anticipated demand for assessments.EIN PresswireMatthew Titcombe selected to serve as an Assessment Guidance Committee Member on The Cyber AB's C3PAO Advisory CouncilMatthew Titcombe, President of Ascend Cyber LLC, was selected on October 23, 2025, to serve as an Assessment Guidance Committee Member on The Cyber AB's C3PAO Advisory Council, which shapes guidance for Cybersecurity Maturity Model Certification assessments of Defense Industrial Base organizations. Titcombe brings experience working with the DIB since 2016 and involvement with The Cyber AB since 2019, including serving on the original Standards Working Group that drafted CMMC Assessment Guides. As CCA #17, he led Ascend Cyber to become the 13th Authorized C3PAO in 2022.