The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

CMMC Consultant: What They Do and What You Actually Need

By The Defense Compliance Report Editorial Team — an independent trade publication on CMMC 2.0 and DIB compliance · Last verified September 2026

A CMMC consultant helps a defense contractor get ready for its Cybersecurity Maturity Model Certification assessment: mapping where sensitive contract information lives, finding security gaps, and planning fixes. Level 2 work can include writing the System Security Plan. Consulting alone does not certify you. Whether you need one depends on your contract's required level, the information you handle, and who will actually do the technical work.

For many small shops, the right first purchase is smaller than the sales pitch. The table below shows what to buy first. Further down, a copy-ready buying brief turns any proposal into something you can check line by line.

Status checked September 26, 2026: The Department's Chief Information Officer (CIO) still lists the July 13 suspension of the planned November 10, 2026 move to CMMC Phase 2. Its implementing memo limits new program-office designations to Level 1 (Self) or Level 2 (Self) and directs amendments or modifications removing third-party Level 2 and government Level 3 requirements. The memo does not itself rewrite your contract. Applicable self-assessments, Supplier Performance Risk System (SPRS) entries, annual affirmations, and Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 duties remain. Sources: CIO CMMC page and implementing memo. Read what the Phase 2 suspension changed.

This page is for you if you're a Department of Defense (DoD) prime or subcontractor, your contract or a prime's flow-down mentions CMMC, Controlled Unclassified Information (CUI), or DFARS 252.204-7012, and you're deciding whether to hire outside help.

It's not for you if you want to become a CMMC consultant (start with how to become a CMMC Certified Professional (CCP)), you're ready for the formal assessment itself (see how to find an authorized CMMC Third-Party Assessment Organization (C3PAO)), or you want a list of firms to compare (see CMMC consulting firms compared).

Do you need a CMMC consultant right now?

Only if you need expertise or capacity your team doesn't have — for a contractual requirement or a deliberate readiness goal. The CMMC program does not require you to hire a consultant: your own company conducts Level 1 and Level 2 self-assessments, and a senior official from your company makes the required affirmation (32 CFR 170.15, 170.16(c)(1), 170.22(a)(1)). The useful question is which piece of work you're missing.

One honest limit first. No web page — including this one — can tell you your CMMC level. Your contract does. Here's where to look, in three quick checks:

  • Does your contract or subcontract include DFARS 252.204-7012? If yes, read its safeguarding and incident-reporting duties. The July implementing memo says those cybersecurity requirements remain in effect during the suspension.
  • Does it name a CMMC level and assessment type, such as "Level 2 (Self)"? The published November 2025 versions of DFARS 252.204-7021(d)(1) and 252.204-7025(b)(1) provide places for the required level. Check the clause version and any deviation, amendment, or modification actually incorporated into your instrument; a generic clause page is not a substitute for that text.
  • Do drawings or files from your customer carry CUI markings? Ask the government or prime to clarify the information category when it is uncertain; missing markings are not a safe basis for assuming there is no CUI. If you're not sure what counts, read FCI vs. CUI.

Two terms before the table. Federal Contract Information (FCI) is information not intended for public release that is provided by or generated for the government under a contract to develop or deliver a product or service; it excludes public information and simple transactional information needed for payments. CUI is government information, or information created or held for or on behalf of the government, subject to safeguarding or dissemination controls under law, regulation, or government-wide policy. It is not simply anything that looks sensitive. Sources: FAR 52.204-21(a) and 32 CFR 170.4.

Your situation — Sensible first step — or no purchase — Ask for — Don't assume
Your situationSensible first step — or no purchaseAsk forDon't assume
You can't confirm your contract's CMMC level or whether you handle CUIGet the requirement in writing before buying a program. A short scoping review can help.Written questions for your prime or contracting officer, and a fixed-scope scoping exerciseThat "unknown" means Level 1, or no CUI
Your contract says Level 1 (Self), you handle only FCI, and your team can do the workProbably no consultant. Use the Level 1 self-assessment checklist and buy a few hours only for real gaps.Evidence for all 15 Level 1 requirements, plus owners for the annual self-assessment and affirmationThat you need a Registered Practitioner Organization (RPO) or a Level 2 package
Your contract says Level 2 (Self), and your scope, System Security Plan, or evidence is incompleteA bounded readiness engagementAn agreed scope, ranked findings, and a named owner for every fixThat "self-assessment" makes the security work optional
Your managed service provider (MSP) runs IT, but nobody owns the compliance evidencePair a readiness specialist with your MSP, or expand the MSP's contract in writingA written split between advice, technical changes, evidence, and ongoing upkeepThat buying advice includes the engineering
Your prime just says "Level 2" (a flow-down is the part of your subcontract that passes the prime's requirement to you)Ask in writing which type: Level 2 (Self) or Level 2 (C3PAO)The clause or subcontract section it comes fromThat "Level 2" automatically means a C3PAO assessment
A signed contract or subcontract still names Level 2 (C3PAO) or Level 3Ask the contracting officer or prime whether a modification has been issued, and keep preparingWritten confirmation of the requirement as it stands today. The July memo directs existing-contract changes before the next option exercise or next scheduled administrative modification.That the July memo changed your contract by itself
You want a formal C3PAO assessment anyway, for a prime or competitive reasons, and can show you're readyConfirm the purpose; then scope the assessment separately. Our buying recommendation is to use a different firm from your recent readiness provider.Current Cyber AB authorization and a written conflict checkThat a consulting engagement produces certification, or that a different team automatically fixes an organizational conflict

The first-step recommendations are ours; the requirements behind them come from 32 CFR 170.14–170.16 and the July implementing memo. Ready to ask for proposals? Jump to the copy-ready buying brief.

The right engagement isn't the same for every contractor. Whether you need an individual consultant — such as a Registered Practitioner (RP) — or an RPO for readiness work, an MSP or managed security service provider (MSSP) to run the controls, a CUI enclave to limit where controlled information is handled, or — only when you're truly ready — a separate C3PAO depends on your required level, whether you handle FCI or CUI, your assessment type, your IT and cloud setup, and your contract timeline. The contract clause sets your level, not a checklist. Because a general answer can't settle those for you, use The Defense Compliance Report's Find My CMMC Path tool to map your situation to the right kind of help before you request proposals — and do not submit CUI, drawings, or sensitive contract details.

Find My CMMC Path asks a few questions about your contract, the information you handle, your IT setup, your timeline, and your budget, then shows which kind of help fits. It points to a category; it does not determine your binding contract requirement.

Should you still hire a CMMC consultant during the Phase 2 pause?

Yes, if your contract requires a CMMC self-assessment or includes DFARS 252.204-7012 and your team can't do the work alone. The July 13, 2026 suspension changed which assessments new contracts may require. It did not remove the security requirements underneath.

Paused by the July 13, 2026 memo — Still in force
Paused by the July 13, 2026 memoStill in force
The November 10, 2026 move to Phase 2Level 1 (Self) and Level 2 (Self) requirements
New Level 2 (C3PAO) and Level 3 (DIBCAC) designationsDFARS 252.204-7012, which the memo says remains in effect
—The applicable safeguarding baseline: 15 Federal Acquisition Regulation (FAR) safeguards for Level 1; 110 National Institute of Standards and Technology (NIST) SP 800-171 Revision 2 requirements for CMMC Level 2
—SPRS postings and yearly affirmations (32 CFR 170.22)

Sources: Implementing Suspension of CMMC Phase II, Attachment 1 and 32 CFR 170.14(c)(2)–(3), checked September 26, 2026. The review's reporting deadline was not, by itself, an instruction to resume Phase 2.

Think of it like a building inspector's visit being postponed. The building code still applies, and a sloppy job is still a sloppy job.

What you can stop paying for: rush pricing and "sign this week" pressure justified only by the suspended November 10 transition. A separate written contract deadline still needs checking. What you shouldn't stop: work that makes your posted results true. Your self-assessment carries real weight right now. The rule lets DoD send the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center (DCMA DIBCAC) to check a Level 2 (Self) status, and contradictory investigative results take precedence over the existing status (32 CFR 170.16(a)(1)(iv)).

What should CMMC consulting services actually deliver?

Judge a consultant by work you can inspect, not by the thickness of a policy binder. A good proposal says what the consultant will produce, what your team must supply, and how you'll know each piece is done.

Three terms you'll see. The System Security Plan (SSP) describes your system's boundary, environment, how security requirements are implemented, and connections to other systems; it must describe the real system, not a hoped-for one. The Supplier Performance Risk System (SPRS) holds assessment records, applicable scores, CMMC status, and affirmations. A Plan of Action and Milestones (POA&M) lists open gaps and the dates you'll close them. NIST SP 800-171 Rev. 2, 3.12.2 and 3.12.4; SPRS guidance.

The SSP, 110-point scoring, and Level 2 scoping rows below concern Level 2. They are not extra requirements imposed on a contractor solely by Level 1.

Work you're buying — What you should be able to inspect at the end — Who owns what — The rule behind it
Work you're buyingWhat you should be able to inspect at the endWho owns whatThe rule behind it
Scope definitionAn asset list sorted into the rule's categories, a network diagram of the assessment scope, a list of outside providers, and a reason for anything left outConsultant drafts; your team confirms the facts; your IT or MSP confirms the architecture32 CFR 170.19(c)
System Security Plan, new or repairedAn editable SSP that describes your real boundary, your environment, how each requirement is implemented, and your connections to other systems, including outside providersConsultant writes or revises as agreed; the people who run each system confirm it's accurateNIST SP 800-171 Rev. 2, 3.12.4; 170.19(c)(2)(ii)
Gap and evidence reviewFindings tied to specific requirements and assessment objectives, the evidence examined, open questions, and an evidence index; agreed readiness testing can use document examination, interviews, and testsConsultant reviews the agreed scope; your team supplies real recordsNIST SP 800-171A, June 2018, section 2.1, used by 170.16(c)(1) for Level 2 self-assessments
Fix plan and technical workA ranked task list with a named owner for each fix, plus a separate list of changes the supplier will actually makeSplit in writing among the consultant, your IT staff, and your MSPOur buying recommendation
Level 2 score calculation and submission preparationA score with a maximum of 110 using the weighted CMMC scoring method, with the required SPRS record information: assessment type, status date, scope, associated Commercial and Government Entity (CAGE) codes, score, and POA&M usageConsultant supports the calculation; your company verifies the assessment, and an appropriately authorized SPRS user enters the record170.16(a)(1)(i), (c)(1); 170.24; SPRS entry guidance
Affirmation prepA plain summary your senior official can read before signingYour senior official affirms — not the consultant170.22(a)(1)
HandoverAgreed editable or exportable copies, a list of open items, and who maintains whatYou and your ongoing providers; agree ownership and license rights in the contractOur buying recommendation; Level 2 (Self) assessment evidence must be retained six years from the CMMC Status Date (170.16(c)(4))

Two things this table is not. It isn't a government-required statement of work — it's our suggested buying standard, and not every project needs every row. And a fix-it list is not automatically a POA&M that qualifies for Conditional status.

For Conditional Level 2, the minimum score is 88 out of 110 (0.8 × 110), but the score alone is not enough. Only permitted gaps may remain; the SSP requirement, for example, cannot be deferred. The remaining requirements must be met and the required closeout assessment completed within 180 days of the Conditional CMMC Status Date. A missed closeout means the conditional status expires. Level 1 allows no POA&M. These are CMMC status rules, not a waiver of other contract duties. 32 CFR 170.21(a); 170.16(a)(1)(ii).

Also check which SPRS record you're buying help with. A NIST SP 800-171 DoD Basic Assessment record is not a CMMC Level 2 (Self) status. SPRS has separate entry processes for NIST assessments and CMMC self-assessments; a number copied from an SSP is not a completed assessment. SPRS Cyber Reports guidance.

Advice is not the same as implementation

A consultant can tell your IT team what needs to change without being hired to make the change. Before you approve a proposal, put a name beside every configuration change, every piece of evidence, and every recurring task.

Here's a hypothetical. A consultant writes a clean procedure for removing a departing employee's accounts. Someone still has to turn those accounts off on the person's last day, every time, and keep proof it happened. If the proposal doesn't say who does that, the proposal hasn't assigned the job.

For the scoping side, see our CMMC scoping guide. If your contract is specifically Level 2, CMMC Level 2 consulting services goes deeper.

How much does a CMMC consultant cost?

There's no official price list for CMMC consultants. Prices come in different shapes — hourly, monthly, managed service — so compare the same work over the same period before you compare dollars. Keep any formal assessment fee on its own line.

Here's what two firms publish about their own pricing:

Firm (its own website) — What it publishes — What that does — and doesn't — tell you
Firm (its own website)What it publishesWhat that does — and doesn't — tell you
E-N Computers, which describes itself as an RPO and also sells managed ITConsulting at $325 an hour or project-based. Its FAQ puts consulting for a small defense contractor at about $800–$1,500 a month. A separate CMMC managed IT add-on is $2,250 a month plus tooling, on top of a base managed IT plan.One firm, different pricing models and service scopes. The monthly figure is that firm's own estimate, not a market average. Ask how many hours a month buys, and for how many months.
Kieri Solutions, which says its consultants are CMMC Certified Assessors (CCAs)No dollar rates. You buy hours as needed; a documentation review usually runs about 25 hours; no monthly program is required; the firm quotes after scoping.Work can be bought in small, bounded pieces. "Quote on request" isn't free — and don't guess a rate from the hours.

Prices as each company states them on its own site, checked September 26, 2026. These are examples, not recommendations, not quotes we obtained, and not a market survey. A pricing example is not an endorsement of the provider's claims about assessment independence.

Disclosure: Provider-related forms on this site may generate referral or lead-routing compensation. See our Editorial & Advertising Policy.

Compare proposals in five buckets

Ask every bidder to price the same five buckets. A low headline number isn't a saving if essential work was simply left out.

  1. Advice and documents — scoping, SSP, gap review
  2. Hands-on technical work — the changes someone actually makes
  3. Recurring tools and services — licenses, monitoring, managed services
  4. Your own staff's time — hours your people will spend
  5. Formal assessment, if any — separately scoped and priced, with the independence check below

Here's a hypothetical of why this matters. Three proposals land on your desk:

Proposal — Price shape — Stated or estimated fees over 12 months — What it covers
ProposalPrice shapeStated or estimated fees over 12 monthsWhat it covers
A$300 an hour, 60 hours estimated$18,000 estimatedScope, SSP rewrite, gap list — advice only
B$1,000 a month for 12 months$12,000One advisory meeting a month — advice only
C$2,000 a month for 12 months, plus your base IT plan$24,000 + base planAdvice plus the technical fixes

B looks cheapest. But it may not include the SSP rewrite, and neither A nor B includes anyone making the fixes. Put all three on the same 12 months and the same five buckets before you pick. The base IT plan in C is unknown, not $0. Add genuinely separate costs, but do not count work or licenses twice when they are already included in a quoted fee.

These examples can't tell you what your company should pay. That takes an agreed scope, a deliverables list, and a clear split between your team's work and the supplier's.

Scope questions that can change a quote: CUI spread across many systems, no current SSP, several locations, a mix of cloud setups, and a tight deadline. Work worth checking for reuse: CUI kept in a few places, existing documentation from an ISO 27001 information-security program or SOC 2 examination, and an MSP already doing much of the technical work. Reusable records can reduce duplicated effort; they do not replace the required CMMC assessment or prove that a NIST requirement is met.

For quote models and a line-by-line scorecard, see our CMMC consulting cost breakdown. If budget is the blocker, ask your local APEX Accelerator which CMMC education or assistance it currently offers; services and eligibility need confirming locally.

RP, RPO, MSP or C3PAO: who does which job?

A label tells you something about a person or firm. A statement of work tells you what you're buying. One business can hold several labels, so match the job to the provider, not the acronym.

The job — Who usually does it — What to put in writing
The jobWho usually does itWhat to put in writing
Readiness advice and documents (scoping, SSP, gap review)A qualified consultant, which may be an RP, Registered Practitioner Advanced (RPA), CCP, CCA, or part of an RPO firmNamed people, the deliverables, and what "done" means
Hands-on technical changes (accounts, multifactor login, logging, settings)Your IT staff, an MSP, or an MSSP — some are also RPOsExactly which changes they'll make and what evidence they'll hand over
Running security tools day to dayAn MSP or MSSPWhich requirements they operate, and their customer responsibility matrix — the written split of provider and customer duties. In Level 2, provider services handling your Security Protection Data (SPD) on provider assets are in scope; when they handle SPD but no CUI, those services are assessed as Security Protection Assets. CUI introduces the separate cloud/non-cloud rules below. (170.19(c)(2))
Records and workflow softwareA governance, risk, and compliance (GRC) platformWhat people still have to implement, and your right to export everything
Shrinking what's in scopeA CUI enclave providerWhere the boundary sits and how CUI stays inside it
Leadership and oversightA virtual chief information security officer (vCISO)Hours, which decisions they own, and who does the hands-on work
Formal Level 2 certification assessmentA C3PAO for the independent third-party assessment; under the program rule, Level 3 is performed by DCMA DIBCAC after Final Level 2 (C3PAO) for the relevant scopeCurrent authorization, the reason for purchasing this assessment, and a written conflict check. (170.9; 170.18)

A CUI enclave works like a locked room inside the building where the CUI work happens. A properly designed boundary can narrow the assessment, but supporting security systems and relevant provider services do not disappear from scope just because they sit outside that room (32 CFR 170.19(c)). See our RPO consulting roles guide and RPO vs. MSP comparison for more.

What RP, RPA, RPO and CCP credentials actually prove

A CMMC credential shows that someone met a particular registration or certification standard — not, by itself, that they've done your kind of work. The biggest surprise in the Cyber AB's published training outline: the basic Registered Practitioner modules center on FCI and Level 1, while the advanced RPA outline explicitly covers CUI and Level 2. That describes the programs, not every course or project an individual RP has completed.

Credential — Who issues it — Key requirements, not a complete eligibility checklist — What it tells you — What it doesn't tell you
CredentialWho issues itKey requirements, not a complete eligibility checklistWhat it tells youWhat it doesn't tell you
RP — Registered Practitioner (a person)Cyber ABA commercial background check, Cyber AB online training and exams, and the Code of Professional Conduct and RP agreement. The listed modules cover CMMC basics, FCI, Level 1 implementation, and FCI-boundary scoping.The person completed the RP program and agreed to its conduct rules.Whether they also have CUI or Level 2 training and relevant project experience outside that registration
RPA — Registered Practitioner Advanced (a person)Cyber ABRP status and the program's eligibility conditions, including implementation of at least 50 cybersecurity framework controls that correlate to the 110 Level 2 requirements; advanced training and an exam covering CUI, Level 2 scoping, the 14 families, the assessment process, and POA&MsLevel 2–focused training and a published experience requirementHow good their past work was
RPO — Registered Practitioner Organization (a firm)Cyber ABAn organizational background check, at least one RP associated with the firm, and a signed Code of Professional Conduct and RPO agreementThe firm is registered, has at least one RP, and agreed to the conduct rulesWho will work on your project, whether any of them is an RPA, or how good the firm's work is. None of the listed requirements reviews client work.
CCP — CMMC Certified Professional (a person)The CMMC Assessor and Instructor Certification Organization (CAICO), now ISACACAICO training and exam plus the rule's background requirements: a Tier 3 investigation, or a DoD-determined equivalent for those ineligible for Tier 3. Certification lasts three years and has ongoing maintenance requirements.The CMMC rule describes CCPs as giving clients advice, consulting, and recommendations. CCPs can participate on assessment teams, but a CCA makes the final assessment determinations.Proven hands-on implementation skill, or authority to independently certify your company
CCA — CMMC Certified Assessor (a person)CAICO (ISACA)CCP certification; at least three years of cybersecurity experience and one year of assessment or audit experience; the required foundational qualification; CCA training and exam; and Tier 3 or permitted equivalent background requirementsTrained and certified to assess for a C3PAO. Some consulting firms staff CCAs.That they can assess you later. Prior preparation work triggers the three-year restriction, and other independence rules still apply.
C3PAO — CMMC Third-Party Assessment Organization (a firm)Cyber ABAuthorization or accreditation, including a DCMA DIBCAC assessment of the firm's relevant systems, a foreign-ownership/control/influence review, and the required background checks for assessment personnelAuthorization to conduct third-party Level 2 certification assessments and issue Certificates of CMMC StatusThat it is independent of your readiness work. The organizational three-year restriction and other impartiality rules still apply.
No CMMC credential claimed (IT firm, MSP, vCISO)——Nothing about CMMC by itself. The program does not require every readiness helper to hold a Cyber AB registration.Whether they understand your requirements or can do the work — ask for named personnel, relevant experience, sample work, and verification of any credentials they do claim

Sources, checked September 26, 2026: Cyber AB, Consulting and Implementation; 32 CFR 170.9, 170.11, and 170.13; ISACA CMMC credentialing. A Tier 3 determination in this program is not a security clearance.

An RPO listing works like a registration with named program conditions: it confirms participation and a conduct commitment, not the quality of your eventual project. For CUI work, ask who on your project has relevant Level 2 training and experience; an RPA, CCP, or CCA credential can be one piece of that evidence.

Check the people named in the proposal

Use the Cyber AB Marketplace for claimed RP, RPA, RPO, and C3PAO roles. Search the exact person or legal entity named in the proposal and check the claimed status, not just whether a listing exists. For CCP and CCA certification, request current issuer evidence and verify through ISACA, which now administers those certifications. Its verification page accepts certification details and also explains how to request verification with the individual's consent. If a record cannot be verified online, seek issuer confirmation rather than treating a missing search result as proof that the claim is false. Save dated evidence with your proposal file. Our Cyber AB Marketplace guide walks through the Cyber AB search.

Now you know what the labels mean. Which one fits your company depends on your contract, the information you handle, and your IT setup — and that's a question about your situation, not the acronyms.

Can your CMMC consultant also assess your company?

Not within three years of the relevant preparation work. 32 CFR 170.8(b)(17)(ii)(G) prohibits CMMC Ecosystem members from participating in a Level 2 certification assessment when they previously served as a consultant to prepare that organization for any CMMC assessment within the preceding three years. Time alone is not the whole independence test.

There is also an organizational rule. The Cyber AB's R2002 C3PAO Accreditation Requirements, C.4.1.8 prohibits a C3PAO from conducting your Level 2 certification assessment within three years of providing you consulting, implementation, or product sales/services. C.4.1.9–C.4.1.11 require continuing attention to relationships and impartiality risks. R2002 permits both Type A and Type C inspection bodies; being Type C does not waive the three-year restriction.

Here's a hypothetical. Say an RPO rewrote your SSP this year, and the same company also runs a C3PAO. For your certification assessment, hire a different C3PAO. Don't assume a different team inside the same company fixes the problem — R2002 C.4.1.8 applies to the C3PAO, not just its individual assessors. Get a written conflict review before signing anything that bundles preparation and assessment.

Ask it in writing: "Who would perform our readiness work, who would conduct any formal assessment, and what relationships or prior services affect independence?" Section 5 of the buying brief below asks for those facts and the applicable conflict checks, including any affiliate relationships. For the full comparison, see RPO vs. C3PAO and our list of authorized C3PAOs.

Supporting you is different from assessing you. Your readiness consultant does not necessarily have to disappear when assessment starts. The CMMC Assessment Process (CAP) v2.0, section 2.4, allows the organization to include consultants at its in-brief meeting. Attending on your side does not make the consultant a member of the independent assessment team or permit the assessing C3PAO to advise you during the assessment.

What we verified. On September 26, 2026, we checked the CIO's program notice and signed July suspension memo; the relevant 32 CFR Part 170 provisions and Federal Register rule; the published FAR/DFARS clauses cited here; NIST's Rev. 2 SSP requirement and June 2018 assessment methods; Cyber AB registration requirements, R2002 independence provisions, and CAP in-brief rules; ISACA's role and verification instructions; SPRS guidance; and both suppliers' published offerings. We read the Find My CMMC Path landing page, but did not test its complete question-and-result flow. The full text of DFARS class deviation 2026-O0025 Revision 3 was not retrievable in this check, so we do not interpret its detailed clause changes or assign a restart date. Check the version incorporated into your own contract. The purchasing recommendations and buying brief are our editorial judgment, not government requirements.

Use this CMMC Consultant Buying Brief before requesting proposals

Give every supplier the same brief so you compare the work, not the sales presentation. Mark anything you don't know as unknown — those are questions to resolve with the appropriate contract or technical owner, not blanks for a supplier to fill with guesses. The fill-in fields below belong to the reusable brief, not an online intake form.

CMMC CONSULTANT BUYING BRIEF
Company: [name]          Date: [date]

Please send a scoped proposal for the work below. Keep advice, hands-on
technical work, ongoing services, and any formal assessment on separate
lines.

1. REQUIREMENT AND GOAL
Required CMMC level and assessment type: [e.g., Level 2 (Self) / unknown]
Where the requirement comes from: [clause or subcontract section, no
sensitive details / unknown]
What we want from this work: [confirm our scope / review our evidence /
fix our SSP / plan fixes / make agreed technical changes / other]
Deadline: [date and non-sensitive reason / none known]
Tell us what you need to confirm before you can price the work. Do not
fill in anything we marked unknown with an assumption.

2. OUR SETUP (HIGH LEVEL ONLY)
Information we handle: [FCI / CUI / both / unknown]
People and locations that touch it: [rough numbers]
IT environment: [e.g., Microsoft 365 commercial or GCC High, on-site
servers, mix / unknown]
Who runs IT today: [internal staff / MSP / both / unknown]
Existing documents: [SSP yes / no / unknown; last updated if known]
SPRS record: [NIST Basic / CMMC Level 1 / CMMC Level 2 / unknown]
Assessment date and current affirmation: [known details / unknown]

3. WORK AND DELIVERABLES
For each piece of work, tell us:
- The deliverable and its format (editable files we keep)
- What "done" looks like and how we can check it
- What you need from us, and who approves the result
- Whether you will advise, implement, test, or maintain it

4. PEOPLE
Name the people who will do the work, their CMMC credentials (RP, RPA,
CCP, CCA), and where we can verify them. Tell us how you handle staff
substitutions.

5. INDEPENDENCE
Disclose whether you or an affiliate is a C3PAO, employs assessors,
or has provided us consulting, implementation, or product sales/services.
Identify who would conduct any Level 2 certification assessment and
document the applicable three-year restrictions and other conflicts.
Do not propose an assessing C3PAO or assessment-team member barred by
those rules. Describe any customer-side assessment support separately.
List products you resell (cloud, software, enclave) that you may recommend.

6. PRICE AND EXCLUSIONS
Separate one-time fees, recurring fees, and the hours you expect from
our staff. List rates for extra work, licenses, third-party costs,
travel, and any assumption that could change the price. Do not bundle
a formal assessment fee into this proposal.

7. RECORDS AND EXIT
Confirm we own, or have full use of, every deliverable in editable
form, and can export our records if we end the engagement. We must keep
our Level 2 assessment evidence for six years from the CMMC Status Date.
For other records, identify the retention requirement that applies. Explain how you
will receive and protect sensitive information once we approve a secure
channel.

8. PROMISES
Confirm that you do not guarantee any assessment result.

Do not send CUI, drawings, passwords, network diagrams, or sensitive
contract details with this brief. Share them only through a secure
channel after you choose a provider.
Download blank brief

Worked example: Ridgeline Machine (fictional)

Say a fictional 30-person machine shop, Ridgeline Machine, gets a flow-down from its prime. The owner asks in writing which Level 2 type applies, and the prime answers: Level 2 (Self). Here's the brief, filled in:

Brief field — Ridgeline Machine (hypothetical)
Brief fieldRidgeline Machine (hypothetical)
Required level and typeLevel 2 (Self), confirmed in writing by the prime
Where it comes fromThe subcontract's flow-down clause
GoalConfirm scope, fix the SSP, find and rank gaps
DeadlineNone known
Information handledFCI, plus CUI in the form of marked drawings
People and locations30 employees at one shop; six people open CUI drawings
IT environmentMicrosoft 365, an on-site file server, and shop-floor machines on the same network — not yet reviewed
Who runs ITAn MSP under a monthly contract
Existing documentsAn SSP that's two years old; an older NIST Basic Assessment score in SPRS that has not been checked against the current environment
Consultant's workScope memo, SSP rewrite, gap list tied to requirements, score calculation
MSP's workOnly the technical changes named in a signed change order
Formal assessmentNone planned
Open itemsThe MSP's remote-management tool; whether the shop-floor machines can reach the file server

The lesson: six people is not a six-device scope. If the file server and laptops process, store, or transmit the drawings, they are CUI Assets. The firewall and remote-management service need review for their security functions and the data they handle; the MSP's relevant services can be in scope too. Shop-floor operational technology may qualify as Specialized Assets under the rule, but "hard to secure" is not a catch-all exception for any old computer. Those assets still need the required inventory, network-diagram and SSP treatment, including documented risk-based practices. 32 CFR 170.4; 170.19(c), Table 3.

The consultant's first job is to check the proposed scope and whether the old score still matches the shop — not assume that an existing NIST Basic record gives Ridgeline a CMMC status. After the company conducts its Level 2 self-assessment with supporting evidence, an authorized SPRS user enters the required CMMC record. Ridgeline's president, acting as its designated Affirming Official in this example, reviews the result and makes the required affirmation. The president need not personally perform the data entry. SPRS entry and affirmation guidance; 32 CFR 170.22.

How to check a CMMC consultant before you sign

Check the people who will do the work, not just the company's sales credentials. These five buying checks make the proposal easier to evaluate before the first invoice, and each one fits in an email.

Check — What good looks like
CheckWhat good looks like
CredentialsEach claimed Cyber AB registration or C3PAO authorization is checked with Cyber AB; each claimed CCP/CCA certification is checked with ISACA or confirmed by its issuer
PeopleThe proposal names who does the work, not "our team"
Proof of workA redacted sample deliverable or a reference with similar scope. If confidentiality limits references, ask for another way to show it — that alone isn't a red flag.
OwnershipA written split of advice, technical work, evidence, and upkeep
TermsPrice assumptions, exit terms, records access, any product resale, and a written conflict check

For the full selection process, see how to choose a CMMC consultant and questions to ask a CMMC consultant. To build a shortlist, compare CMMC consulting firms. Prefer someone local? See our guides for Huntsville, Colorado Springs, Dayton, San Diego, and Washington, DC.

What the sales pitch says vs. what the rules say

What you may hear — What the source actually says — Source
What you may hearWhat the source actually saysSource
"We'll get you ready, then certify you."Recent readiness consulting conflicts with performing your Level 2 certification assessment. The three-year restriction applies to ecosystem members; R2002 separately restricts the C3PAO that supplied consulting, implementation, or product sales/services.32 CFR 170.8(b)(17)(ii)(G); R2002 C.4.1.8
"We're Cyber AB–certified CMMC consultants."RP, RPA, and RPO are registrations. The Cyber AB lets RPs and RPOs present themselves as familiar with the basic constructs of the CMMC standard. The rule bars ecosystem members from misrepresenting credentials.Cyber AB; 170.8(b)(17)(ii)(E)
"Guaranteed pass."A consultant cannot promise the independent assessment result. CMMC Ecosystem members must represent their services honestly; R2002 also expressly prohibits C3PAO result guarantees and result-contingent incentives.170.8(b)(17)(ii)(E)–(F); R2002 C.4.1.6
"You're required to hire a consultant."The CMMC program does not require one. Your company conducts its own self-assessments, and its designated senior official affirms.170.15; 170.16(c)(1); 170.22(a)(1)
"Sign this week or miss November 10."The CIO's program page still describes the November 10, 2026 Phase 2 transition as suspended as of September 26, 2026. Check any separate contract deadline; do not buy urgency based only on the old rollout date.CIO CMMC page
"You need to implement Revision 3 now."CMMC Level 2 incorporates NIST SP 800-171 Revision 2. A newer NIST publication alone does not change that CMMC baseline; separately check any additional contract obligation.170.14(c)(3)
"We only manage your IT, so we're outside your CMMC scope."In Level 2, an External Service Provider (ESP) whose assets handle your Security Protection Data but no CUI has the relevant services assessed as Security Protection Assets. SPD includes security-relevant configuration, log, vulnerability, or password data used to protect the assessed environment. A non-cloud ESP handling CUI has its relevant services assessed within your scope; a cloud offering handling CUI follows the separate Federal Risk and Authorization Management Program (FedRAMP) requirements.170.4, SPD/ESP definitions; 170.19(c)(2), Table 4

If a vendor tells you something that doesn't match this table, ask for the rule citation. For the MSP question in depth, see is my MSP actually CMMC compliant? and CMMC external service provider requirements.

What happens after the consultant finishes?

Your obligations keep running after the consultant leaves. Your designated senior official must affirm after each assessment, including any POA&M closeout, and annually thereafter. Level 1 self-assessment is annual. Level 2 (Self) assessment repeats every three years, while the evidence used for that Level 2 assessment must be kept for six years from its CMMC Status Date, not from the end of the consulting project (32 CFR 170.15, 170.16, 170.22).

That's why the rule's definition matters: the Affirming Official is "the senior level representative from within" your company (170.22(a)(1)). A consultant can help you prepare. They can't sign for you.

Plan the project by milestones, not a promised month count:

  1. Scope agreed and signed off by your team
  2. Evidence reviewed against each requirement
  3. Fixes assigned, done, and proven
  4. Records checked for accuracy against the real system
  5. Appropriate self-assessment results entered in SPRS and affirmed — or a separately scoped formal assessment when that is the justified next step. Level 1 does not use a 110-point score.

Before you accept the project as finished, make sure you hold the agreed files, the list of open items, and the name of whoever keeps each control running. For the yearly signature itself, see our CMMC annual affirmation guide and SPRS score guide.

What if you switch consultants?

Don't assume a consulting fee gives you every file and right you'll need later. Before you sign, get in writing which records you receive, in what editable format, what you're allowed to reuse, how you keep access if the engagement ends, and how they'll hand back your sensitive information.

Those are terms you negotiate. They don't come automatically with a CMMC credential.

Other questions buyers ask

Can I hire a CMMC consultant who isn't in the Cyber AB Marketplace? Yes. The CMMC program does not require a Marketplace-listed readiness consultant. But nobody may falsely claim a Cyber AB or CAICO credential. A missing listing does not, by itself, tell you whether someone has ever signed a conduct agreement or holds a certification administered elsewhere. Ask for named personnel and evidence of relevant work, and verify any claimed registration or certification with its issuer. 32 CFR 170.8(b)(17)(ii)(E); Cyber AB role requirements.

Is it safe to share CUI with a consultant? A contract and a secure channel alone are not enough: the recipient must be authorized to receive the information, and its handling environment must meet the applicable requirements. Our buying recommendation is to keep CUI out of the initial proposal request and agree the access, scope, and secure-sharing arrangements before transferring it. If a non-cloud consultant's systems process, store, or transmit your CUI as part of its IT or cybersecurity service, those services fall within your Level 2 assessment scope. A cloud service handling CUI must meet the applicable FedRAMP Moderate authorization or equivalency requirements. 32 CFR 170.16(c)(2)–(3); 170.19(c)(2).

How long does a CMMC consulting engagement take? It depends on your scope and how much is already in place, so plan by the milestones above rather than a fixed month count. E-N Computers states that most of its clients reach compliance in 12 to 18 months; that is one firm's statement checked September 26, 2026, not a verified outcome study or a rule. Ask your consultant to name the work, dependencies, and completion criteria behind its proposed schedule.

Still not sure which CMMC path fits your company? Use The Defense Compliance Report's Find My CMMC Path tool to see which path and kind of help fit your contract, CUI, environment, and timeline — before you hire anyone.

Sources

Checked September 26, 2026. Supplier claims are identified separately from program requirements.

About The Defense Compliance Report

The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source citation on every claim and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they spend six figures.

We are not affiliated with the Cyber AB, DoD, DCMA DIBCAC, NIST, or any U.S. government agency. This page is educational research, not legal, contractual, or compliance advice — confirm scope and applicability with a CMMC Registered Practitioner (RP) or a qualified federal-contracts attorney. See our Editorial & Advertising Policy.

All guides in this topic: Consultants & managed services