C3PAO Governance

Assessment Appeals Process

Init Cyber's formal appeals process for Organizations Seeking Certification (OSCs) who dispute CMMC Level 2 assessment results

Assessment Results Appeals Process

Init Cyber maintains a formal appeals process for Organizations Seeking Certification (OSCs) who dispute the results of a CMMC Level 2 assessment. This process is compliant with ISO/IEC 17020, 32 CFR Part 170, the CMMC Assessment Process (CAP), and the Cyber-AB Code of Professional Conduct. A copy of this policy is available upon request.

Who May File an Appeal

Any OSC that has entered into a signed engagement agreement with Init Cyber for a CMMC Level 2 certifying assessment and has received a final assessment report may file an appeal. An appeal is a formal request disputing specific findings, it is not a general expression of dissatisfaction with the assessment outcome.

Valid Grounds for Appeal

Appeals must be grounded in one of the following three bases. Appeals submitted on any other grounds will not be accepted.

Error
A mistake by an assessor during the assessment, such as improperly interpreting assessment objectives, incorrectly recording evidence, or misapplying the CAP to a specific control.
Malfeasance
Intentional conduct by Init Cyber assessment personnel contrary to CMMC standards, including conducting an assessment outside authorized methods or neglecting to complete a full evidence review.
Unethical Conduct
Conduct that violates the Cyber-AB Code of Professional Conduct, such as inappropriate use of OSC data or violation of a Non-Disclosure Agreement.

Disagreement with a MET or NOT MET determination is not, by itself, a valid basis for appeal. The appeal must identify a specific error, act of malfeasance, or ethical violation.

How to File an Appeal

An OSC must submit a written appeal to the Lead Assessor assigned to their engagement within 14 calendar days of receiving the final assessment report. The written appeal must include:

  • The specific control or controls being disputed
  • The grounds for the appeal (error, malfeasance, or unethical conduct)
  • A clear description of why the OSC believes the grounds apply
  • Any supporting information or evidence the OSC wishes to include

Appeals submitted after the 14-calendar-day window will not be accepted. The window does not extend for weekends, holidays, or delays in reading the report.

Appeals may also be submitted via email to appeals@initcyber.com.

How Appeals Are Reviewed

Upon receiving a valid appeal, Init Cyber will complete the following within 21 calendar days:

  • Acknowledge receipt of the appeal in writing and confirm next steps
  • Record the appeal in CMMC eMASS
  • Assign an independent Appeal QA Reviewer: a current CCA or LCCA who was not a member of the original assessment team and did not serve as QA Reviewer on the original assessment
  • Conduct a reevaluation of the disputed controls, which may include review of previously hashed evidence, consultation with the original assessment team, and communication with OSC personnel
  • Provide at least one interim status update if the reevaluation is expected to extend beyond 10 calendar days
  • Produce and deliver a formal written decision stating the outcome and rationale

The reevaluation is conducted independently. The Appeal QA Reviewer's determination is not subject to influence from the original assessment team, business development personnel, or the OSC.

Timeline Summary

Day 0

OSC receives final assessment report.

Within 14 Days

OSC must file written appeal from Day 0.

Within 21 Days

Init Cyber completes reevaluation and delivers written decision from appeal receipt.

Within 15 Business Days

OSC may elevate to Cyber-AB if dissatisfied with Init Cyber's decision.

Escalation to the Cyber-AB

If the OSC disagrees with Init Cyber's appeal decision, the OSC may escalate the matter to the Cyber-AB within 15 business days of receiving Init Cyber's written decision. All appeal decisions rendered by the Cyber-AB are final. Init Cyber will cooperate fully with any Cyber-AB review.

Corrective Actions

If the reevaluation determines that an error, act of malfeasance, or ethical violation occurred, Init Cyber will implement corrective actions. These may include amendments to the assessment report, retraining of involved personnel, updates to assessment procedures, disciplinary action, or disclosure to the Cyber-AB where required by program rules.

Non-Retaliation

Init Cyber's reassessment decisions will not result in discriminatory actions against any individual or organization that files an appeal in good faith.

Contact

To file an appeal or request a copy of this policy, contact the Lead Assessor assigned to your engagement or email appeals@initcyber.com.