This is the main content of the page.


Our PoliciesPrivacy Policy

Legal Disclaimer


Policy Section

Policy Overview

The Cybersecurity Maturity Model Certification Accreditation Body, Inc. (“CMMC-AB,” “us,” or “we”) is committed to respecting and protecting your privacy. We want you to understand how we may collect information about you through our website, and how that information may be used, maintained, and in some cases shared. This privacy policy (“Privacy Policy”) sets forth the privacy practices and policies governing our data collection practices including relating to data collected via the websites that we operate and that link to this Privacy Policy (including,,, , and, and any mobile version, portal, interface, or application used in connection with such websites (referred to collectively, as the “Website”).

Information We Collect

The following describes the types of personal and other information we may collect about you, and how we use and maintain that information:

  • Information You Provide to Us
    CMMC-AB may gather and retain personally identifiable information about you, including name, email address, physical address, phone number, or other personal or background information (“Personal Information”), when you voluntarily submit it to us, including for the purpose of accessing certain features of the Website. We may use any information that you provide for our general purposes, and may share it with third parties only as described in this Privacy Policy.

    If you provide us with a telephone number, address or an email address, you expressly agree that we, or our authorized agents, can use that information to contact you about CMMC-AB and its associated activities.

    To the extent permitted by applicable law, we may keep any information that you provide to us indefinitely.

  • Site Use Information
    Our web servers may collect technical information, including IP address, browser type, domain names, access times and referring website addresses of visitors to our Website. We may use this information to measure the use of our Website, including number of visits, average time spent on the Website, pages viewed, etc., and to improve the content we offer.

    However, we do use technology that recognizes a “do-not-track” signal from your web browser, which allows us to exclude you from any analytics that collects information about your online activities over time and across third-party websites if your settings indicate that to be your preference.

  • Use of Cookies
    Like most websites, we employ “cookies” or similar technologies on certain pages of our Website. Cookies make the use of the Website easier by, among other things, saving your preferences. We may also use cookies to deliver content tailored to your interests. For more information about how we use cookies and similar technologies, please see our Cookie Notice.

  • Financial Transactions
    When you engage in any financial transaction through our Website, you will be asked to provide certain financial information, such as your credit card and billing address. We will only keep this information as long as necessary to complete the transaction or series of recurring transactions authorized by you.

How We Use This Information

We may process your Personal Information for the following purposes in line with this Privacy Policy:

  • to fulfill your requests;
  • to create and maintain your certification or accreditation;
  • to manage the Website;
  • to communicate with you about certification, registrations, products, services, events and education;
  • to detect and prevent fraud or other financial crime;
  • to monitor and protect the security of our information, systems and network;
  • to notify you about changes to our Website or other services; and
  • to conduct research and analysis.

CMMC-AB does not sell, rent or lease Personal Information to third parties. CMMC-AB may, from time to time, contact you on behalf of external business partners about a particular offering that may be of interest to you. In those cases, your Personal Information (e-mail, name, address, telephone number) is not transferred to the third party.

Opting Out of Communications

If you have subscribed to or are otherwise receiving CMMC-AB news or similar information from us by email and no longer want to receive such information in the future, you may opt-out of receiving certain types of emails by clicking the "unsubscribe" link at the bottom of those emails you receive or, if you have an online account, logging in to your account and making changes thereto your communication preferences. Please allow ample time for us to process your request. If you are having difficulty unsubscribing, please contact us directly at the email or phone number listed below under Contact.

Please note that even if you opt-out of receiving emails, you may still receive communications related to your interaction with CMMC-AB (such as confirmation of a registration or form submission) or otherwise as required by law. Also, note that we may need to keep information we have collected about you for record-keeping, research and other purposes.

Disclosing Information to Third-Parties

We will not share, rent, sell or otherwise disclose any Personal Information that we collect about you through our Website, except in any of the following situations:

  • You request or authorize the release of your Personal Information.
  • We may disclose Personal Information that we collect about you to our third-party contractors and payment processors who perform services for us in connection with the Website, or to complete or confirm a transaction or series of transactions that you conduct with us. We may also disclose Personal Information to service providers or suppliers if the disclosure will enable that party to perform business, professional or technical support for us (e.g., creation of application programming interfaces between the Website and third party applications).
  • We may disclose Personal Information about you as part of a merger, acquisition or other sale or transfer of the assets or business of CMMC-AB. We do not guarantee that any entity receiving such information in connection with one of these transactions will comply with all terms of this Privacy Policy.
  • We may disclose Personal Information about you to comply with the law, applicable regulations, governmental and quasi-governmental requests, court orders or subpoenas, to enforce our Terms of Use or other agreements, or to protect our rights, property or safety or the rights, property or safety of our users or others. We reserve the right to release information that we collect to law enforcement or other government officials, as we, in our sole and absolute discretion, deem necessary or appropriate.

We may also share aggregated or anonymous information that cannot identify you with third parties. For example, we may disclose the number of visitors to our Website or the number of people who have downloaded a particular document, and we may disclose statistical information based on responses to online surveys and other data collection tools on our website.


You should keep in mind that the Website is run on software, hardware and networks, any component of which may, from time to time, require maintenance or experience problems or breaches of security beyond our control.

While we take steps to protect your Personal Information and keep it secure, you also play a role in protecting your information. You must maintain the security of your online transactions by not sharing your account information and passwords with any unauthorized parties.

Please also be aware that despite our best intentions and the guidelines outlined in this Privacy Policy, no data transmission over the Internet or encryption method can be guaranteed to be 100% secure. CMMC-AB cannot guarantee the security of any information you transmit to us or from our Website.

EU/UK-Specific Notice

These terms apply to Personal Information collected by CMMC-AB if you are an EU or UK resident. “Personal Information” as used in this section means any information that enables us to identify you, either directly or indirectly. Where CMMC-AB processes Personal Information about you, such information is controlled by the Cybersecurity Maturity Model Certification Accreditation Body, Inc., which is headquartered in the United States at 137 National Plaza, Suite 300, National Harbor, MD 20745-1153.

We process your Personal Information for purposes described in this Privacy Policy where we have a legal basis under applicable European and UK data protection law. We will store your Personal Information, in a form that permits us to identify you, for no longer than is necessary for the purpose for which the Personal Information is processed.

Subject to applicable law, in certain circumstances, you may have the right to access, correct, restrict the processing of, delete or transfer the Personal Information we hold about you. We will generally ask for your consent in line with the applicable law before sending you direct marketing communications related to third party products and services. You can choose to stop receiving direct marketing communications from us at any time by following the “Unsubscribe” link at the bottom of any promotional email.

Where you believe that we have not complied with our obligations under this Privacy Policy or applicable law, we ask that you contact us first to see if we can resolve the issue. However, you may have the right to lodge a complaint with an appropriate supervisory authority.

California-Specific Notice

These terms apply to Personal Information collected by CMMC-AB if you are a California resident. Under California law, a California resident with whom we have an established relationship has the right to request certain information with respect to the types of Personal Information we have shared with third parties for their direct marketing purposes, and the identities of those third parties, within the immediately preceding calendar year, subject to certain exceptions. All requests for such information must be in writing and sent to us at the following mailing address: 137 National Plaza, Suite 300, National Harbor, MD 20745-1153.

Links to Other Websites

Our Website contains links to other websites. However, this Privacy Policy only addresses CMMC-AB’s use and disclosure of your information collected on our Website, if any. If you choose to visit an external website linked from our Website, you will leave our Website. We are not responsible for the privacy practices of any third parties or the content of linked websites. We encourage you to read the applicable privacy policies and terms and conditions of such parties or websites.

Child Privacy

This website is not intended for children. It is not our intention to collect Personal Information from anyone under 18 years of age, and we will not knowingly do so. If we are made aware that we have collected any Personal Information from children under the age of 18, and are asked to delete such information from our databases, we will promptly do so.

Access from Outside the United States

If you access the Website from outside of the United States, information that we collect about you will be transferred to servers inside the United States, which may involve the transfer of information out of your country of origin. By allowing us to collect information about you, you consent to such transfer and processing of your data.

Governing Law

By choosing to visit our Website or provide information to us, you agree that any dispute over privacy or the terms contained in this Privacy Policy will be governed by the law of the State of Maryland. You also agree to abide by any limitation on damages contained in our Terms of Use, or other agreement that we have with you.

Changes to this Privacy Policy

We may occasionally amend this Privacy Policy to reflect CMMC-AB activities and user feedback, and we reserve the right to make changes to this Privacy Policy at any time. The use of your information is subject to the Privacy Policy and Terms of Use in effect at the time of use. The provisions contained in this Privacy Policy supersede all previous notices or policies regarding our privacy practices with respect to our Website. Please check the “Last Updated” legend at the top of this page to see when this Privacy Policy was last revised. We encourage you to check frequently to see the current Privacy Policy to be informed of how CMMC-AB is committed to protecting your information and providing you with improved content on our Website to enhance your experience.