CCA CCA Ethics, Standards & Professional Conduct 2 — Questions and Answers
Question 1: What continuing education requirement must CCAs fulfill to maintain their certification?
- No continuing education is required once certified
- CCAs must complete Cyber AB-required continuing professional education (CPE) credits each year (Correct answer)
- CCAs must retake the full CCA exam every two years
- CCAs must conduct a minimum of 10 assessments per year
Correct answer: CCAs must complete Cyber AB-required continuing professional education (CPE) credits each year
CCAs must complete continuing professional education credits as required by the Cyber AB to maintain current knowledge of CMMC requirements, assessment methodologies, and cybersecurity developments.
Question 2: What is the significance of the CCA oath or attestation taken at certification?
- It is a formality with no legal significance
- It commits the CCA to uphold the Cyber AB Code of Professional Conduct and perform assessments with integrity and objectivity (Correct answer)
- It transfers liability for assessment findings to the Cyber AB
- It certifies the CCA as a licensed cybersecurity attorney
Correct answer: It commits the CCA to uphold the Cyber AB Code of Professional Conduct and perform assessments with integrity and objectivity
The CCA attestation is a formal commitment to uphold professional standards, objectivity, and the Cyber AB's Code of Professional Conduct throughout the assessor's certification period.
Question 3: How should a CCA respond if an OSC representative attempts to coach or influence the assessor's findings during the assessment?
- Accept the guidance if it comes from a senior executive
- Politely decline and document the attempt, maintaining independent judgment based on evidence (Correct answer)
- Incorporate the feedback as additional context in the findings
- Terminate the assessment immediately and report to DoD IG
Correct answer: Politely decline and document the attempt, maintaining independent judgment based on evidence
Assessors must maintain independence; any attempt to influence findings should be declined and documented, as it represents a potential integrity issue that must be recorded.
Question 4: What is the consequence for a CCA who knowingly certifies an OSC that does not meet CMMC requirements?
- A formal warning from the Cyber AB
- Potential decertification, civil liability under the False Claims Act, and possible criminal charges (Correct answer)
- Required additional training on CMMC requirements
- Temporary suspension of assessment privileges for 30 days
Correct answer: Potential decertification, civil liability under the False Claims Act, and possible criminal charges
A CCA who fraudulently certifies non-compliant organizations faces decertification by the Cyber AB, civil liability under the False Claims Act, and potentially criminal prosecution for fraud against the government.
Question 5: What does 'professional skepticism' mean for a CCA assessor?
- Distrusting everything the OSC says during the assessment
- Maintaining a questioning mind and critically assessing evidence rather than accepting all representations at face value (Correct answer)
- Refusing to conduct assessments for OSCs with prior compliance issues
- Requiring external legal counsel to verify all evidence
Correct answer: Maintaining a questioning mind and critically assessing evidence rather than accepting all representations at face value
Professional skepticism means critically evaluating evidence and not simply accepting OSC assertions as fact, seeking corroborating evidence to ensure findings are based on objective observation rather than trust.
Question 6: Under what circumstances may a CCA share OSC assessment findings with parties outside the C3PAO and OSC?
- Whenever requested by other government contractors
- Only when required by law, court order, or explicitly authorized by the OSC (Correct answer)
- When sharing would benefit the broader cybersecurity community
- When the information is more than 90 days old
Correct answer: Only when required by law, court order, or explicitly authorized by the OSC
CCA confidentiality obligations restrict sharing of assessment findings to situations required by law, compelled by court order, or explicitly authorized by the OSC, protecting the OSC's sensitive security information.
What continuing education requirement must CCAs fulfill to maintain their certification?