Cyber AB Certified CMMC Assessor (CCA) Exam CMMC-CCA Question # 49 Topic 5 Discussion

Cyber AB Certified CMMC Assessor (CCA) Exam CMMC-CCA Question # 49 Topic 5 Discussion

CMMC-CCA Exam Topic 5 Question 49 Discussion:
Question #: 49
Topic #: 5

An OSC has recently obtained an ISO 27001 certification and a FedRAMP Authorization to Operate (ATO) for its information systems. During the initial stages of the CMMC Assessment Process, the OSC claims that these certifications should grant them automatic credit or exemption from certain CMMC requirements. As the Lead Assessor, what should be your response?


A.

Proceed with the CMMC Assessment as planned, disregarding the OSC’s claim about their ISO 27001 and FedRAMP certifications.


B.

Request the OSC to provide evidence of their ISO 27001 and FedRAMP certifications and then consult with the CMMC Accreditation Body to determine if any credit or exemption can be granted.


C.

Accept the OSC’s claim and grant them appropriate credit or exemption based on their ISO 27001 and FedRAMP certifications.


D.

Inform the OSC that their ISO 27001 and FedRAMP certifications do not bestow any status or credit towards their CMMC assessment or certification.


Get Premium CMMC-CCA Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.