A CMMC consultant helps a defense contractor get ready for its Cybersecurity Maturity Model Certification assessment: mapping where sensitive contract information lives, finding security gaps, and planning fixes. Level 2 work can include writing the System Security Plan. Consulting alone does not certify you. Whether you need one depends on your contract's required level, the information you handle, and who will actually do the technical work.
For many small shops, the right first purchase is smaller than the sales pitch. The table below shows what to buy first. Further down, a copy-ready buying brief turns any proposal into something you can check line by line.
Status checked September 26, 2026: The Department's Chief Information Officer (CIO) still lists the July 13 suspension of the planned November 10, 2026 move to CMMC Phase 2. Its implementing memo limits new program-office designations to Level 1 (Self) or Level 2 (Self) and directs amendments or modifications removing third-party Level 2 and government Level 3 requirements. The memo does not itself rewrite your contract. Applicable self-assessments, Supplier Performance Risk System (SPRS) entries, annual affirmations, and Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 duties remain. Sources: CIO CMMC page and implementing memo. Read what the Phase 2 suspension changed.
This page is for you if you're a Department of Defense (DoD) prime or subcontractor, your contract or a prime's flow-down mentions CMMC, Controlled Unclassified Information (CUI), or DFARS 252.204-7012, and you're deciding whether to hire outside help.
It's not for you if you want to become a CMMC consultant (start with how to become a CMMC Certified Professional (CCP)), you're ready for the formal assessment itself (see how to find an authorized CMMC Third-Party Assessment Organization (C3PAO)), or you want a list of firms to compare (see CMMC consulting firms compared).
Do you need a CMMC consultant right now?
Only if you need expertise or capacity your team doesn't have — for a contractual requirement or a deliberate readiness goal. The CMMC program does not require you to hire a consultant: your own company conducts Level 1 and Level 2 self-assessments, and a senior official from your company makes the required affirmation (32 CFR 170.15, 170.16(c)(1), 170.22(a)(1)). The useful question is which piece of work you're missing.
One honest limit first. No web page — including this one — can tell you your CMMC level. Your contract does. Here's where to look, in three quick checks:
- Does your contract or subcontract include DFARS 252.204-7012? If yes, read its safeguarding and incident-reporting duties. The July implementing memo says those cybersecurity requirements remain in effect during the suspension.
- Does it name a CMMC level and assessment type, such as "Level 2 (Self)"? The published November 2025 versions of DFARS 252.204-7021(d)(1) and 252.204-7025(b)(1) provide places for the required level. Check the clause version and any deviation, amendment, or modification actually incorporated into your instrument; a generic clause page is not a substitute for that text.
- Do drawings or files from your customer carry CUI markings? Ask the government or prime to clarify the information category when it is uncertain; missing markings are not a safe basis for assuming there is no CUI. If you're not sure what counts, read FCI vs. CUI.
Two terms before the table. Federal Contract Information (FCI) is information not intended for public release that is provided by or generated for the government under a contract to develop or deliver a product or service; it excludes public information and simple transactional information needed for payments. CUI is government information, or information created or held for or on behalf of the government, subject to safeguarding or dissemination controls under law, regulation, or government-wide policy. It is not simply anything that looks sensitive. Sources: FAR 52.204-21(a) and 32 CFR 170.4.
| Your situation | Sensible first step — or no purchase | Ask for | Don't assume |
|---|---|---|---|
| You can't confirm your contract's CMMC level or whether you handle CUI | Get the requirement in writing before buying a program. A short scoping review can help. | Written questions for your prime or contracting officer, and a fixed-scope scoping exercise | That "unknown" means Level 1, or no CUI |
| Your contract says Level 1 (Self), you handle only FCI, and your team can do the work | Probably no consultant. Use the Level 1 self-assessment checklist and buy a few hours only for real gaps. | Evidence for all 15 Level 1 requirements, plus owners for the annual self-assessment and affirmation | That you need a Registered Practitioner Organization (RPO) or a Level 2 package |
| Your contract says Level 2 (Self), and your scope, System Security Plan, or evidence is incomplete | A bounded readiness engagement | An agreed scope, ranked findings, and a named owner for every fix | That "self-assessment" makes the security work optional |
| Your managed service provider (MSP) runs IT, but nobody owns the compliance evidence | Pair a readiness specialist with your MSP, or expand the MSP's contract in writing | A written split between advice, technical changes, evidence, and ongoing upkeep | That buying advice includes the engineering |
| Your prime just says "Level 2" (a flow-down is the part of your subcontract that passes the prime's requirement to you) | Ask in writing which type: Level 2 (Self) or Level 2 (C3PAO) | The clause or subcontract section it comes from | That "Level 2" automatically means a C3PAO assessment |
| A signed contract or subcontract still names Level 2 (C3PAO) or Level 3 | Ask the contracting officer or prime whether a modification has been issued, and keep preparing | Written confirmation of the requirement as it stands today. The July memo directs existing-contract changes before the next option exercise or next scheduled administrative modification. | That the July memo changed your contract by itself |
| You want a formal C3PAO assessment anyway, for a prime or competitive reasons, and can show you're ready | Confirm the purpose; then scope the assessment separately. Our buying recommendation is to use a different firm from your recent readiness provider. | Current Cyber AB authorization and a written conflict check | That a consulting engagement produces certification, or that a different team automatically fixes an organizational conflict |
The first-step recommendations are ours; the requirements behind them come from 32 CFR 170.14–170.16 and the July implementing memo. Ready to ask for proposals? Jump to the copy-ready buying brief.
The right engagement isn't the same for every contractor. Whether you need an individual consultant — such as a Registered Practitioner (RP) — or an RPO for readiness work, an MSP or managed security service provider (MSSP) to run the controls, a CUI enclave to limit where controlled information is handled, or — only when you're truly ready — a separate C3PAO depends on your required level, whether you handle FCI or CUI, your assessment type, your IT and cloud setup, and your contract timeline. The contract clause sets your level, not a checklist. Because a general answer can't settle those for you, use The Defense Compliance Report's Find My CMMC Path tool to map your situation to the right kind of help before you request proposals — and do not submit CUI, drawings, or sensitive contract details.
Find My CMMC Path asks a few questions about your contract, the information you handle, your IT setup, your timeline, and your budget, then shows which kind of help fits. It points to a category; it does not determine your binding contract requirement.
Should you still hire a CMMC consultant during the Phase 2 pause?
Yes, if your contract requires a CMMC self-assessment or includes DFARS 252.204-7012 and your team can't do the work alone. The July 13, 2026 suspension changed which assessments new contracts may require. It did not remove the security requirements underneath.
| Paused by the July 13, 2026 memo | Still in force |
|---|---|
| The November 10, 2026 move to Phase 2 | Level 1 (Self) and Level 2 (Self) requirements |
| New Level 2 (C3PAO) and Level 3 (DIBCAC) designations | DFARS 252.204-7012, which the memo says remains in effect |
| — | The applicable safeguarding baseline: 15 Federal Acquisition Regulation (FAR) safeguards for Level 1; 110 National Institute of Standards and Technology (NIST) SP 800-171 Revision 2 requirements for CMMC Level 2 |
| — | SPRS postings and yearly affirmations (32 CFR 170.22) |
Sources: Implementing Suspension of CMMC Phase II, Attachment 1 and 32 CFR 170.14(c)(2)–(3), checked September 26, 2026. The review's reporting deadline was not, by itself, an instruction to resume Phase 2.
Think of it like a building inspector's visit being postponed. The building code still applies, and a sloppy job is still a sloppy job.
What you can stop paying for: rush pricing and "sign this week" pressure justified only by the suspended November 10 transition. A separate written contract deadline still needs checking. What you shouldn't stop: work that makes your posted results true. Your self-assessment carries real weight right now. The rule lets DoD send the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center (DCMA DIBCAC) to check a Level 2 (Self) status, and contradictory investigative results take precedence over the existing status (32 CFR 170.16(a)(1)(iv)).
What should CMMC consulting services actually deliver?
Judge a consultant by work you can inspect, not by the thickness of a policy binder. A good proposal says what the consultant will produce, what your team must supply, and how you'll know each piece is done.
Three terms you'll see. The System Security Plan (SSP) describes your system's boundary, environment, how security requirements are implemented, and connections to other systems; it must describe the real system, not a hoped-for one. The Supplier Performance Risk System (SPRS) holds assessment records, applicable scores, CMMC status, and affirmations. A Plan of Action and Milestones (POA&M) lists open gaps and the dates you'll close them. NIST SP 800-171 Rev. 2, 3.12.2 and 3.12.4; SPRS guidance.
The SSP, 110-point scoring, and Level 2 scoping rows below concern Level 2. They are not extra requirements imposed on a contractor solely by Level 1.
| Work you're buying | What you should be able to inspect at the end | Who owns what | The rule behind it |
|---|---|---|---|
| Scope definition | An asset list sorted into the rule's categories, a network diagram of the assessment scope, a list of outside providers, and a reason for anything left out | Consultant drafts; your team confirms the facts; your IT or MSP confirms the architecture | 32 CFR 170.19(c) |
| System Security Plan, new or repaired | An editable SSP that describes your real boundary, your environment, how each requirement is implemented, and your connections to other systems, including outside providers | Consultant writes or revises as agreed; the people who run each system confirm it's accurate | NIST SP 800-171 Rev. 2, 3.12.4; 170.19(c)(2)(ii) |
| Gap and evidence review | Findings tied to specific requirements and assessment objectives, the evidence examined, open questions, and an evidence index; agreed readiness testing can use document examination, interviews, and tests | Consultant reviews the agreed scope; your team supplies real records | NIST SP 800-171A, June 2018, section 2.1, used by 170.16(c)(1) for Level 2 self-assessments |
| Fix plan and technical work | A ranked task list with a named owner for each fix, plus a separate list of changes the supplier will actually make | Split in writing among the consultant, your IT staff, and your MSP | Our buying recommendation |
| Level 2 score calculation and submission preparation | A score with a maximum of 110 using the weighted CMMC scoring method, with the required SPRS record information: assessment type, status date, scope, associated Commercial and Government Entity (CAGE) codes, score, and POA&M usage | Consultant supports the calculation; your company verifies the assessment, and an appropriately authorized SPRS user enters the record | 170.16(a)(1)(i), (c)(1); 170.24; SPRS entry guidance |
| Affirmation prep | A plain summary your senior official can read before signing | Your senior official affirms — not the consultant | 170.22(a)(1) |
| Handover | Agreed editable or exportable copies, a list of open items, and who maintains what | You and your ongoing providers; agree ownership and license rights in the contract | Our buying recommendation; Level 2 (Self) assessment evidence must be retained six years from the CMMC Status Date (170.16(c)(4)) |
Two things this table is not. It isn't a government-required statement of work — it's our suggested buying standard, and not every project needs every row. And a fix-it list is not automatically a POA&M that qualifies for Conditional status.
For Conditional Level 2, the minimum score is 88 out of 110 (0.8 × 110), but the score alone is not enough. Only permitted gaps may remain; the SSP requirement, for example, cannot be deferred. The remaining requirements must be met and the required closeout assessment completed within 180 days of the Conditional CMMC Status Date. A missed closeout means the conditional status expires. Level 1 allows no POA&M. These are CMMC status rules, not a waiver of other contract duties. 32 CFR 170.21(a); 170.16(a)(1)(ii).
Also check which SPRS record you're buying help with. A NIST SP 800-171 DoD Basic Assessment record is not a CMMC Level 2 (Self) status. SPRS has separate entry processes for NIST assessments and CMMC self-assessments; a number copied from an SSP is not a completed assessment. SPRS Cyber Reports guidance.
Advice is not the same as implementation
A consultant can tell your IT team what needs to change without being hired to make the change. Before you approve a proposal, put a name beside every configuration change, every piece of evidence, and every recurring task.
Here's a hypothetical. A consultant writes a clean procedure for removing a departing employee's accounts. Someone still has to turn those accounts off on the person's last day, every time, and keep proof it happened. If the proposal doesn't say who does that, the proposal hasn't assigned the job.
For the scoping side, see our CMMC scoping guide. If your contract is specifically Level 2, CMMC Level 2 consulting services goes deeper.
How much does a CMMC consultant cost?
There's no official price list for CMMC consultants. Prices come in different shapes — hourly, monthly, managed service — so compare the same work over the same period before you compare dollars. Keep any formal assessment fee on its own line.
Here's what two firms publish about their own pricing:
| Firm (its own website) | What it publishes | What that does — and doesn't — tell you |
|---|---|---|
| E-N Computers, which describes itself as an RPO and also sells managed IT | Consulting at $325 an hour or project-based. Its FAQ puts consulting for a small defense contractor at about $800–$1,500 a month. A separate CMMC managed IT add-on is $2,250 a month plus tooling, on top of a base managed IT plan. | One firm, different pricing models and service scopes. The monthly figure is that firm's own estimate, not a market average. Ask how many hours a month buys, and for how many months. |
| Kieri Solutions, which says its consultants are CMMC Certified Assessors (CCAs) | No dollar rates. You buy hours as needed; a documentation review usually runs about 25 hours; no monthly program is required; the firm quotes after scoping. | Work can be bought in small, bounded pieces. "Quote on request" isn't free — and don't guess a rate from the hours. |
Prices as each company states them on its own site, checked September 26, 2026. These are examples, not recommendations, not quotes we obtained, and not a market survey. A pricing example is not an endorsement of the provider's claims about assessment independence.
Disclosure: Provider-related forms on this site may generate referral or lead-routing compensation. See our Editorial & Advertising Policy.
Compare proposals in five buckets
Ask every bidder to price the same five buckets. A low headline number isn't a saving if essential work was simply left out.
- Advice and documents — scoping, SSP, gap review
- Hands-on technical work — the changes someone actually makes
- Recurring tools and services — licenses, monitoring, managed services
- Your own staff's time — hours your people will spend
- Formal assessment, if any — separately scoped and priced, with the independence check below
Here's a hypothetical of why this matters. Three proposals land on your desk:
| Proposal | Price shape | Stated or estimated fees over 12 months | What it covers |
|---|---|---|---|
| A | $300 an hour, 60 hours estimated | $18,000 estimated | Scope, SSP rewrite, gap list — advice only |
| B | $1,000 a month for 12 months | $12,000 | One advisory meeting a month — advice only |
| C | $2,000 a month for 12 months, plus your base IT plan | $24,000 + base plan | Advice plus the technical fixes |
B looks cheapest. But it may not include the SSP rewrite, and neither A nor B includes anyone making the fixes. Put all three on the same 12 months and the same five buckets before you pick. The base IT plan in C is unknown, not $0. Add genuinely separate costs, but do not count work or licenses twice when they are already included in a quoted fee.
These examples can't tell you what your company should pay. That takes an agreed scope, a deliverables list, and a clear split between your team's work and the supplier's.
Scope questions that can change a quote: CUI spread across many systems, no current SSP, several locations, a mix of cloud setups, and a tight deadline. Work worth checking for reuse: CUI kept in a few places, existing documentation from an ISO 27001 information-security program or SOC 2 examination, and an MSP already doing much of the technical work. Reusable records can reduce duplicated effort; they do not replace the required CMMC assessment or prove that a NIST requirement is met.
For quote models and a line-by-line scorecard, see our CMMC consulting cost breakdown. If budget is the blocker, ask your local APEX Accelerator which CMMC education or assistance it currently offers; services and eligibility need confirming locally.
RP, RPO, MSP or C3PAO: who does which job?
A label tells you something about a person or firm. A statement of work tells you what you're buying. One business can hold several labels, so match the job to the provider, not the acronym.
| The job | Who usually does it | What to put in writing |
|---|---|---|
| Readiness advice and documents (scoping, SSP, gap review) | A qualified consultant, which may be an RP, Registered Practitioner Advanced (RPA), CCP, CCA, or part of an RPO firm | Named people, the deliverables, and what "done" means |
| Hands-on technical changes (accounts, multifactor login, logging, settings) | Your IT staff, an MSP, or an MSSP — some are also RPOs | Exactly which changes they'll make and what evidence they'll hand over |
| Running security tools day to day | An MSP or MSSP | Which requirements they operate, and their customer responsibility matrix — the written split of provider and customer duties. In Level 2, provider services handling your Security Protection Data (SPD) on provider assets are in scope; when they handle SPD but no CUI, those services are assessed as Security Protection Assets. CUI introduces the separate cloud/non-cloud rules below. (170.19(c)(2)) |
| Records and workflow software | A governance, risk, and compliance (GRC) platform | What people still have to implement, and your right to export everything |
| Shrinking what's in scope | A CUI enclave provider | Where the boundary sits and how CUI stays inside it |
| Leadership and oversight | A virtual chief information security officer (vCISO) | Hours, which decisions they own, and who does the hands-on work |
| Formal Level 2 certification assessment | A C3PAO for the independent third-party assessment; under the program rule, Level 3 is performed by DCMA DIBCAC after Final Level 2 (C3PAO) for the relevant scope | Current authorization, the reason for purchasing this assessment, and a written conflict check. (170.9; 170.18) |
A CUI enclave works like a locked room inside the building where the CUI work happens. A properly designed boundary can narrow the assessment, but supporting security systems and relevant provider services do not disappear from scope just because they sit outside that room (32 CFR 170.19(c)). See our RPO consulting roles guide and RPO vs. MSP comparison for more.
What RP, RPA, RPO and CCP credentials actually prove
A CMMC credential shows that someone met a particular registration or certification standard — not, by itself, that they've done your kind of work. The biggest surprise in the Cyber AB's published training outline: the basic Registered Practitioner modules center on FCI and Level 1, while the advanced RPA outline explicitly covers CUI and Level 2. That describes the programs, not every course or project an individual RP has completed.
| Credential | Who issues it | Key requirements, not a complete eligibility checklist | What it tells you | What it doesn't tell you |
|---|---|---|---|---|
| RP — Registered Practitioner (a person) | Cyber AB | A commercial background check, Cyber AB online training and exams, and the Code of Professional Conduct and RP agreement. The listed modules cover CMMC basics, FCI, Level 1 implementation, and FCI-boundary scoping. | The person completed the RP program and agreed to its conduct rules. | Whether they also have CUI or Level 2 training and relevant project experience outside that registration |
| RPA — Registered Practitioner Advanced (a person) | Cyber AB | RP status and the program's eligibility conditions, including implementation of at least 50 cybersecurity framework controls that correlate to the 110 Level 2 requirements; advanced training and an exam covering CUI, Level 2 scoping, the 14 families, the assessment process, and POA&Ms | Level 2–focused training and a published experience requirement | How good their past work was |
| RPO — Registered Practitioner Organization (a firm) | Cyber AB | An organizational background check, at least one RP associated with the firm, and a signed Code of Professional Conduct and RPO agreement | The firm is registered, has at least one RP, and agreed to the conduct rules | Who will work on your project, whether any of them is an RPA, or how good the firm's work is. None of the listed requirements reviews client work. |
| CCP — CMMC Certified Professional (a person) | The CMMC Assessor and Instructor Certification Organization (CAICO), now ISACA | CAICO training and exam plus the rule's background requirements: a Tier 3 investigation, or a DoD-determined equivalent for those ineligible for Tier 3. Certification lasts three years and has ongoing maintenance requirements. | The CMMC rule describes CCPs as giving clients advice, consulting, and recommendations. CCPs can participate on assessment teams, but a CCA makes the final assessment determinations. | Proven hands-on implementation skill, or authority to independently certify your company |
| CCA — CMMC Certified Assessor (a person) | CAICO (ISACA) | CCP certification; at least three years of cybersecurity experience and one year of assessment or audit experience; the required foundational qualification; CCA training and exam; and Tier 3 or permitted equivalent background requirements | Trained and certified to assess for a C3PAO. Some consulting firms staff CCAs. | That they can assess you later. Prior preparation work triggers the three-year restriction, and other independence rules still apply. |
| C3PAO — CMMC Third-Party Assessment Organization (a firm) | Cyber AB | Authorization or accreditation, including a DCMA DIBCAC assessment of the firm's relevant systems, a foreign-ownership/control/influence review, and the required background checks for assessment personnel | Authorization to conduct third-party Level 2 certification assessments and issue Certificates of CMMC Status | That it is independent of your readiness work. The organizational three-year restriction and other impartiality rules still apply. |
| No CMMC credential claimed (IT firm, MSP, vCISO) | — | — | Nothing about CMMC by itself. The program does not require every readiness helper to hold a Cyber AB registration. | Whether they understand your requirements or can do the work — ask for named personnel, relevant experience, sample work, and verification of any credentials they do claim |
Sources, checked September 26, 2026: Cyber AB, Consulting and Implementation; 32 CFR 170.9, 170.11, and 170.13; ISACA CMMC credentialing. A Tier 3 determination in this program is not a security clearance.
An RPO listing works like a registration with named program conditions: it confirms participation and a conduct commitment, not the quality of your eventual project. For CUI work, ask who on your project has relevant Level 2 training and experience; an RPA, CCP, or CCA credential can be one piece of that evidence.
Check the people named in the proposal
Use the Cyber AB Marketplace for claimed RP, RPA, RPO, and C3PAO roles. Search the exact person or legal entity named in the proposal and check the claimed status, not just whether a listing exists. For CCP and CCA certification, request current issuer evidence and verify through ISACA, which now administers those certifications. Its verification page accepts certification details and also explains how to request verification with the individual's consent. If a record cannot be verified online, seek issuer confirmation rather than treating a missing search result as proof that the claim is false. Save dated evidence with your proposal file. Our Cyber AB Marketplace guide walks through the Cyber AB search.
Now you know what the labels mean. Which one fits your company depends on your contract, the information you handle, and your IT setup — and that's a question about your situation, not the acronyms.
Can your CMMC consultant also assess your company?
Not within three years of the relevant preparation work. 32 CFR 170.8(b)(17)(ii)(G) prohibits CMMC Ecosystem members from participating in a Level 2 certification assessment when they previously served as a consultant to prepare that organization for any CMMC assessment within the preceding three years. Time alone is not the whole independence test.
There is also an organizational rule. The Cyber AB's R2002 C3PAO Accreditation Requirements, C.4.1.8 prohibits a C3PAO from conducting your Level 2 certification assessment within three years of providing you consulting, implementation, or product sales/services. C.4.1.9–C.4.1.11 require continuing attention to relationships and impartiality risks. R2002 permits both Type A and Type C inspection bodies; being Type C does not waive the three-year restriction.
Here's a hypothetical. Say an RPO rewrote your SSP this year, and the same company also runs a C3PAO. For your certification assessment, hire a different C3PAO. Don't assume a different team inside the same company fixes the problem — R2002 C.4.1.8 applies to the C3PAO, not just its individual assessors. Get a written conflict review before signing anything that bundles preparation and assessment.
Ask it in writing: "Who would perform our readiness work, who would conduct any formal assessment, and what relationships or prior services affect independence?" Section 5 of the buying brief below asks for those facts and the applicable conflict checks, including any affiliate relationships. For the full comparison, see RPO vs. C3PAO and our list of authorized C3PAOs.
Supporting you is different from assessing you. Your readiness consultant does not necessarily have to disappear when assessment starts. The CMMC Assessment Process (CAP) v2.0, section 2.4, allows the organization to include consultants at its in-brief meeting. Attending on your side does not make the consultant a member of the independent assessment team or permit the assessing C3PAO to advise you during the assessment.
What we verified. On September 26, 2026, we checked the CIO's program notice and signed July suspension memo; the relevant 32 CFR Part 170 provisions and Federal Register rule; the published FAR/DFARS clauses cited here; NIST's Rev. 2 SSP requirement and June 2018 assessment methods; Cyber AB registration requirements, R2002 independence provisions, and CAP in-brief rules; ISACA's role and verification instructions; SPRS guidance; and both suppliers' published offerings. We read the Find My CMMC Path landing page, but did not test its complete question-and-result flow. The full text of DFARS class deviation 2026-O0025 Revision 3 was not retrievable in this check, so we do not interpret its detailed clause changes or assign a restart date. Check the version incorporated into your own contract. The purchasing recommendations and buying brief are our editorial judgment, not government requirements.
Use this CMMC Consultant Buying Brief before requesting proposals
Give every supplier the same brief so you compare the work, not the sales presentation. Mark anything you don't know as unknown — those are questions to resolve with the appropriate contract or technical owner, not blanks for a supplier to fill with guesses. The fill-in fields below belong to the reusable brief, not an online intake form.
CMMC CONSULTANT BUYING BRIEF Company: [name] Date: [date] Please send a scoped proposal for the work below. Keep advice, hands-on technical work, ongoing services, and any formal assessment on separate lines. 1. REQUIREMENT AND GOAL Required CMMC level and assessment type: [e.g., Level 2 (Self) / unknown] Where the requirement comes from: [clause or subcontract section, no sensitive details / unknown] What we want from this work: [confirm our scope / review our evidence / fix our SSP / plan fixes / make agreed technical changes / other] Deadline: [date and non-sensitive reason / none known] Tell us what you need to confirm before you can price the work. Do not fill in anything we marked unknown with an assumption. 2. OUR SETUP (HIGH LEVEL ONLY) Information we handle: [FCI / CUI / both / unknown] People and locations that touch it: [rough numbers] IT environment: [e.g., Microsoft 365 commercial or GCC High, on-site servers, mix / unknown] Who runs IT today: [internal staff / MSP / both / unknown] Existing documents: [SSP yes / no / unknown; last updated if known] SPRS record: [NIST Basic / CMMC Level 1 / CMMC Level 2 / unknown] Assessment date and current affirmation: [known details / unknown] 3. WORK AND DELIVERABLES For each piece of work, tell us: - The deliverable and its format (editable files we keep) - What "done" looks like and how we can check it - What you need from us, and who approves the result - Whether you will advise, implement, test, or maintain it 4. PEOPLE Name the people who will do the work, their CMMC credentials (RP, RPA, CCP, CCA), and where we can verify them. Tell us how you handle staff substitutions. 5. INDEPENDENCE Disclose whether you or an affiliate is a C3PAO, employs assessors, or has provided us consulting, implementation, or product sales/services. Identify who would conduct any Level 2 certification assessment and document the applicable three-year restrictions and other conflicts. Do not propose an assessing C3PAO or assessment-team member barred by those rules. Describe any customer-side assessment support separately. List products you resell (cloud, software, enclave) that you may recommend. 6. PRICE AND EXCLUSIONS Separate one-time fees, recurring fees, and the hours you expect from our staff. List rates for extra work, licenses, third-party costs, travel, and any assumption that could change the price. Do not bundle a formal assessment fee into this proposal. 7. RECORDS AND EXIT Confirm we own, or have full use of, every deliverable in editable form, and can export our records if we end the engagement. We must keep our Level 2 assessment evidence for six years from the CMMC Status Date. For other records, identify the retention requirement that applies. Explain how you will receive and protect sensitive information once we approve a secure channel. 8. PROMISES Confirm that you do not guarantee any assessment result. Do not send CUI, drawings, passwords, network diagrams, or sensitive contract details with this brief. Share them only through a secure channel after you choose a provider.
Worked example: Ridgeline Machine (fictional)
Say a fictional 30-person machine shop, Ridgeline Machine, gets a flow-down from its prime. The owner asks in writing which Level 2 type applies, and the prime answers: Level 2 (Self). Here's the brief, filled in:
| Brief field | Ridgeline Machine (hypothetical) |
|---|---|
| Required level and type | Level 2 (Self), confirmed in writing by the prime |
| Where it comes from | The subcontract's flow-down clause |
| Goal | Confirm scope, fix the SSP, find and rank gaps |
| Deadline | None known |
| Information handled | FCI, plus CUI in the form of marked drawings |
| People and locations | 30 employees at one shop; six people open CUI drawings |
| IT environment | Microsoft 365, an on-site file server, and shop-floor machines on the same network — not yet reviewed |
| Who runs IT | An MSP under a monthly contract |
| Existing documents | An SSP that's two years old; an older NIST Basic Assessment score in SPRS that has not been checked against the current environment |
| Consultant's work | Scope memo, SSP rewrite, gap list tied to requirements, score calculation |
| MSP's work | Only the technical changes named in a signed change order |
| Formal assessment | None planned |
| Open items | The MSP's remote-management tool; whether the shop-floor machines can reach the file server |
The lesson: six people is not a six-device scope. If the file server and laptops process, store, or transmit the drawings, they are CUI Assets. The firewall and remote-management service need review for their security functions and the data they handle; the MSP's relevant services can be in scope too. Shop-floor operational technology may qualify as Specialized Assets under the rule, but "hard to secure" is not a catch-all exception for any old computer. Those assets still need the required inventory, network-diagram and SSP treatment, including documented risk-based practices. 32 CFR 170.4; 170.19(c), Table 3.
The consultant's first job is to check the proposed scope and whether the old score still matches the shop — not assume that an existing NIST Basic record gives Ridgeline a CMMC status. After the company conducts its Level 2 self-assessment with supporting evidence, an authorized SPRS user enters the required CMMC record. Ridgeline's president, acting as its designated Affirming Official in this example, reviews the result and makes the required affirmation. The president need not personally perform the data entry. SPRS entry and affirmation guidance; 32 CFR 170.22.
How to check a CMMC consultant before you sign
Check the people who will do the work, not just the company's sales credentials. These five buying checks make the proposal easier to evaluate before the first invoice, and each one fits in an email.
| Check | What good looks like |
|---|---|
| Credentials | Each claimed Cyber AB registration or C3PAO authorization is checked with Cyber AB; each claimed CCP/CCA certification is checked with ISACA or confirmed by its issuer |
| People | The proposal names who does the work, not "our team" |
| Proof of work | A redacted sample deliverable or a reference with similar scope. If confidentiality limits references, ask for another way to show it — that alone isn't a red flag. |
| Ownership | A written split of advice, technical work, evidence, and upkeep |
| Terms | Price assumptions, exit terms, records access, any product resale, and a written conflict check |
For the full selection process, see how to choose a CMMC consultant and questions to ask a CMMC consultant. To build a shortlist, compare CMMC consulting firms. Prefer someone local? See our guides for Huntsville, Colorado Springs, Dayton, San Diego, and Washington, DC.
What the sales pitch says vs. what the rules say
| What you may hear | What the source actually says | Source |
|---|---|---|
| "We'll get you ready, then certify you." | Recent readiness consulting conflicts with performing your Level 2 certification assessment. The three-year restriction applies to ecosystem members; R2002 separately restricts the C3PAO that supplied consulting, implementation, or product sales/services. | 32 CFR 170.8(b)(17)(ii)(G); R2002 C.4.1.8 |
| "We're Cyber AB–certified CMMC consultants." | RP, RPA, and RPO are registrations. The Cyber AB lets RPs and RPOs present themselves as familiar with the basic constructs of the CMMC standard. The rule bars ecosystem members from misrepresenting credentials. | Cyber AB; 170.8(b)(17)(ii)(E) |
| "Guaranteed pass." | A consultant cannot promise the independent assessment result. CMMC Ecosystem members must represent their services honestly; R2002 also expressly prohibits C3PAO result guarantees and result-contingent incentives. | 170.8(b)(17)(ii)(E)–(F); R2002 C.4.1.6 |
| "You're required to hire a consultant." | The CMMC program does not require one. Your company conducts its own self-assessments, and its designated senior official affirms. | 170.15; 170.16(c)(1); 170.22(a)(1) |
| "Sign this week or miss November 10." | The CIO's program page still describes the November 10, 2026 Phase 2 transition as suspended as of September 26, 2026. Check any separate contract deadline; do not buy urgency based only on the old rollout date. | CIO CMMC page |
| "You need to implement Revision 3 now." | CMMC Level 2 incorporates NIST SP 800-171 Revision 2. A newer NIST publication alone does not change that CMMC baseline; separately check any additional contract obligation. | 170.14(c)(3) |
| "We only manage your IT, so we're outside your CMMC scope." | In Level 2, an External Service Provider (ESP) whose assets handle your Security Protection Data but no CUI has the relevant services assessed as Security Protection Assets. SPD includes security-relevant configuration, log, vulnerability, or password data used to protect the assessed environment. A non-cloud ESP handling CUI has its relevant services assessed within your scope; a cloud offering handling CUI follows the separate Federal Risk and Authorization Management Program (FedRAMP) requirements. | 170.4, SPD/ESP definitions; 170.19(c)(2), Table 4 |
If a vendor tells you something that doesn't match this table, ask for the rule citation. For the MSP question in depth, see is my MSP actually CMMC compliant? and CMMC external service provider requirements.
What happens after the consultant finishes?
Your obligations keep running after the consultant leaves. Your designated senior official must affirm after each assessment, including any POA&M closeout, and annually thereafter. Level 1 self-assessment is annual. Level 2 (Self) assessment repeats every three years, while the evidence used for that Level 2 assessment must be kept for six years from its CMMC Status Date, not from the end of the consulting project (32 CFR 170.15, 170.16, 170.22).
That's why the rule's definition matters: the Affirming Official is "the senior level representative from within" your company (170.22(a)(1)). A consultant can help you prepare. They can't sign for you.
Plan the project by milestones, not a promised month count:
- Scope agreed and signed off by your team
- Evidence reviewed against each requirement
- Fixes assigned, done, and proven
- Records checked for accuracy against the real system
- Appropriate self-assessment results entered in SPRS and affirmed — or a separately scoped formal assessment when that is the justified next step. Level 1 does not use a 110-point score.
Before you accept the project as finished, make sure you hold the agreed files, the list of open items, and the name of whoever keeps each control running. For the yearly signature itself, see our CMMC annual affirmation guide and SPRS score guide.
What if you switch consultants?
Don't assume a consulting fee gives you every file and right you'll need later. Before you sign, get in writing which records you receive, in what editable format, what you're allowed to reuse, how you keep access if the engagement ends, and how they'll hand back your sensitive information.
Those are terms you negotiate. They don't come automatically with a CMMC credential.
Other questions buyers ask
Can I hire a CMMC consultant who isn't in the Cyber AB Marketplace? Yes. The CMMC program does not require a Marketplace-listed readiness consultant. But nobody may falsely claim a Cyber AB or CAICO credential. A missing listing does not, by itself, tell you whether someone has ever signed a conduct agreement or holds a certification administered elsewhere. Ask for named personnel and evidence of relevant work, and verify any claimed registration or certification with its issuer. 32 CFR 170.8(b)(17)(ii)(E); Cyber AB role requirements.
Is it safe to share CUI with a consultant? A contract and a secure channel alone are not enough: the recipient must be authorized to receive the information, and its handling environment must meet the applicable requirements. Our buying recommendation is to keep CUI out of the initial proposal request and agree the access, scope, and secure-sharing arrangements before transferring it. If a non-cloud consultant's systems process, store, or transmit your CUI as part of its IT or cybersecurity service, those services fall within your Level 2 assessment scope. A cloud service handling CUI must meet the applicable FedRAMP Moderate authorization or equivalency requirements. 32 CFR 170.16(c)(2)–(3); 170.19(c)(2).
How long does a CMMC consulting engagement take? It depends on your scope and how much is already in place, so plan by the milestones above rather than a fixed month count. E-N Computers states that most of its clients reach compliance in 12 to 18 months; that is one firm's statement checked September 26, 2026, not a verified outcome study or a rule. Ask your consultant to name the work, dependencies, and completion criteria behind its proposed schedule.
Still not sure which CMMC path fits your company? Use The Defense Compliance Report's Find My CMMC Path tool to see which path and kind of help fit your contract, CUI, environment, and timeline — before you hire anyone.
Sources
Checked September 26, 2026. Supplier claims are identified separately from program requirements.
- CIO, CMMC program notice and Implementing Suspension of CMMC Phase II, including Attachment 1 (signed July 13, 2026).
- Department of Defense, CMMC Program final rule, 89 FR 83092, October 15, 2024; current eCFR 32 CFR Part 170.
- eCFR: 170.4 definitions; 170.8 conduct and conflicts; 170.9 C3PAOs; 170.11 CCAs; 170.13 CCPs.
- eCFR: 170.14 baselines; 170.15 Level 1; 170.16 Level 2 self-assessment; 170.17 Level 2 certification assessment; 170.18 Level 3; 170.19 scope; 170.21 POA&Ms; 170.22 affirmation; 170.24 scoring.
- Acquisition.gov, FAR 52.204-21; DFARS 252.204-7012; published November 2025 versions of 252.204-7021 and 252.204-7025. Read the versions and deviations incorporated into the actual contract.
- NIST, SP 800-171 Revision 2, requirements 3.12.2–3.12.4, and SP 800-171A, June 2018, section 2.1 and assessment procedures. These are the incorporated editions relevant here, not a claim that they are the newest NIST publications.
- Cyber AB, Consulting and Implementation roles and Marketplace.
- Cyber AB, R2002 C3PAO Accreditation Requirements, January 2026 file, version 1.0, definitions and C.4.1.6–C.4.1.11; CMMC Assessment Process v2.0, section 2.4.
- ISACA, CMMC credentialing, April 20, 2026 transition announcement, and certification verification instructions.
- SPRS, official entry, affirmation, and NIST-assessment FAQs.
- E-N Computers, CMMC consulting services (company-stated prices, service conditions, and timeline).
- Kieri Solutions, CMMC consulting (company-stated staffing and engagement options).
About The Defense Compliance Report
The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source citation on every claim and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they spend six figures.
We are not affiliated with the Cyber AB, DoD, DCMA DIBCAC, NIST, or any U.S. government agency. This page is educational research, not legal, contractual, or compliance advice — confirm scope and applicability with a CMMC Registered Practitioner (RP) or a qualified federal-contracts attorney. See our Editorial & Advertising Policy.