The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

Readiness provider review · primary-sourced · last reviewed August 2026

GuidePoint Security CMMC Review: What They Can and Can't Do (2026)

Last updated:

Last verified: against CMMC rules, DFARS, NIST publications, Cyber AB records, and GuidePoint public service, company, contract-vehicle, and educational materials.

GuidePoint Security CMMC review illustration showing a readiness roadmap, evidence folders, a scoped contractor boundary, and separate assessment checkpoint

Public-source provider review

By The Defense Compliance Report Editorial Team

Last reviewed: August 2026 · Last verified: August 28, 2026

Evaluation depth: Public-source review + primary-source regulatory mapping

Compensation relationship with GuidePoint Security: None


If you're searching for a GuidePoint Security CMMC review, here's the answer before you scroll: GuidePoint Security describes itself as a CMMC Registered Provider Organization (RPO) — a readiness and advisory firm. We found no public material identifying GuidePoint as a C3PAO. Under the RPO role it publishes, it cannot conduct your Level 2 certification assessment or issue a Certificate of CMMC Status. Its published CMMC services cover scoping, gap assessment, documentation, remediation support, training, staff augmentation, and assessment liaison work. Good fit for contractors with real internal ownership and a complicated environment. Not the right first call if you only need the formal certification assessment or your primary need is a turnkey CUI enclave and full-service help desk.

That's the short version. Here's the part nobody else has written.

We pulled every public GuidePoint CMMC asset we could find on August 28, 2026 and read it against the actual regulation — 32 CFR Part 170, the DFARS clauses, and NIST SP 800-171 Revision 2. What we found is that the question "is GuidePoint good at CMMC?" is the wrong question. GuidePoint sells advisory work, staff augmentation, security operations, managed offerings, and technology. Some relationships never put GuidePoint's systems in contact with your Controlled Unclassified Information or Security Protection Data. Others can put the provider inside your assessment scope and create SSP, service-description, and Customer Responsibility Matrix work.

Nobody sells you "GuidePoint." They sell you one of several very different relationships. Which one you buy changes your scope, your documentation burden, and what an assessor eventually asks you to prove.

That's what this page maps.


Disclosure and independence

Disclosure: The Defense Compliance Report is an independent trade publication on CMMC and Defense Industrial Base compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or status verification.

Specific to this page: We have no compensation relationship of any kind with GuidePoint Security — no affiliate, referral, sponsorship, or partner arrangement. No commercial CTA or tracked referral link on this page routes to GuidePoint. We are not affiliated with GuidePoint Security, the Cyber AB, the Department of War, the Department of Defense, DCMA DIBCAC, NIST, or any U.S. government agency.

The Defense Compliance Report exists to map a contractor's required level, CUI scope, assessment type, environment, and contract timing to the right provider category before that contractor spends six figures on the wrong problem. Read our editorial standards and research methodology.


What we actually verified

Item — What we verified
ItemWhat we verified
Provider categoryGuidePoint calls itself a CMMC RPO on its readiness page and February 2026 data sheet. The Cyber AB's current role page expands RPO as Registered Practitioner Organization; GuidePoint's prose uses Registered Provider Organization, while the badge in its data sheet says Registered Practitioner Organization. Whatever expansion is used, the role is implementation and readiness — not certification.
Cyber AB Marketplace statusThe Cyber AB Marketplace is JavaScript-dependent. We could not independently retrieve a current GuidePoint entity record through public-source retrieval on August 28, 2026. Verify the live record, exact legal entity, profile identifier, and expiration status before signing.
Published CMMC servicesCMMC Scoping Exercise, CMMC Gap Assessment, Advisory Services, and CMMC Compliance Program Implementation Support. GuidePoint also publishes staff augmentation, managed security, SOC, incident-response, technology-reselling, and multiple "as a service" offerings outside the four-item CMMC catalog.
Compensation relationshipNone.
Evaluation depthDocumentary review of GuidePoint pages, its February 2026 data sheet, blog posts, company announcements, and public contract-vehicle records, read against 32 CFR Part 170, DFARS 252.204-7012 / -7019 / -7020 / -7021, NIST SP 800-171 Revision 2, NIST SP 800-171A, and the February 2021 version of NIST SP 800-172 incorporated into the CMMC rule.
Last verifiedAugust 28, 2026.
What we could not verifyThe exact current Cyber AB Marketplace record; the names and current credentials of the people who would staff your engagement; whether either GuidePoint legal entity holds a CMMC Status or current SPRS score; commercial CMMC pricing; a published Microsoft GCC High migration or turnkey CUI-enclave offer; client outcomes; or a current primary-source employee count.

We did not buy GuidePoint's services, test them, interview the company, review a client engagement, or accept anything from them. This is a public-source review. Its value is that it separates what GuidePoint says from what the regulation requires and hands you the questions needed to close the gap yourself.


Is CMMC still required after the July 2026 Phase II suspension?

Answer capsule: Yes, but the buying clock changed. Phase 1 began November 10, 2025, and its original first-year period ran through November 9, 2026. On July 13, 2026, the Department of War suspended Phase II, which had been scheduled to begin November 10, 2026. All Phase I self-assessment requirements remain in place. DFARS 252.204-7012, NIST SP 800-171 Revision 2, applicable SPRS posting, and annual CMMC affirmations remain live. No replacement Phase II date was posted as of August 28, 2026.

This matters before you read another word about any vendor, because it changes what you should be buying.

Here is the current state, dated and sourced:

  • November 10, 2025 — the CMMC acquisition rule became effective, starting Phase 1. The original rule made Phase 2 begin one calendar year later. (Federal Register acquisition final rule; 32 CFR § 170.3(e))
  • July 13, 2026 — the Department announced the immediate suspension of Phase II and pending and future CMMC implementation milestones across solicitations and contracts. The same announcement says all Phase I self-assessment requirements remain firmly in place. (Department announcement)
  • Still in force: the current Department CMMC page says the program is paused in Phase 1 and that the Department will enforce NIST SP 800-171 Revision 2 through self-assessments and select government-led assessments. (Current CMMC program page)
  • Still in force: DFARS 252.204-7012 continues to require safeguarding of covered defense information and 72-hour cyber-incident reporting when the clause applies.
  • Still in force: 32 CFR § 170.22 requires affirmations after the applicable assessment and annually thereafter, completed in SPRS.
  • The rule text is still the rule text. The current eCFR still contains the four-phase schedule. The July action is an implementation suspension, not an amendment deleting that schedule from 32 CFR Part 170.

Do not buy against a November 10, 2026 certification countdown. It is suspended. Buy against the solicitation or contract in front of you, the requirement flowed down by your prime or upper-tier contractor, the current SPRS posture you must maintain, and a proposal or option date you can point to.

And do not improvise around contract language. If a clause or CMMC status requirement is already in an awarded contract, act on the signed contract, a written modification, and written direction from the responsible contracting channel — not on a vendor webinar.

Real urgency still exists. Manufactured urgency should end the sales conversation.


Is GuidePoint Security a C3PAO?

Answer capsule: No public GuidePoint material we reviewed identifies the company as a C3PAO. GuidePoint identifies itself as an RPO, an implementation and readiness role. Under 32 CFR § 170.9, only an authorized or accredited CMMC Third-Party Assessment Organization may conduct a Level 2 certification assessment. GuidePoint can prepare you for that assessment. It cannot be the organization issuing your Level 2 Certificate of CMMC Status.

This is the single most consequential fact on the page, and it is the one buyers get wrong most often — usually because firms in this category use the word "assessment" for readiness work. A readiness assessment and a certification assessment are different products with different consequences. One tells you where you stand. The other establishes the CMMC Status used for contractual eligibility.

Quick definitions, because these acronyms get thrown around loosely:

  • RPO (Registered Practitioner Organization) — the Cyber AB's current official name for a company providing CMMC implementation consulting through Registered Practitioners. GuidePoint uses "Registered Provider Organization" in its prose. An RPO is not an assessment organization. (Cyber AB role page)
  • C3PAO (CMMC Third-Party Assessment Organization) — an organization authorized or accredited to conduct Level 2 certification assessments. (32 CFR definition)
  • DCMA DIBCAC — the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center. It conducts Level 3 certification assessments under 32 CFR § 170.18.
  • SPRS — the Supplier Performance Risk System, where applicable assessment information, CMMC Status records, and affirmations are maintained.

The part that works in GuidePoint's favor

Here's an angle almost nobody covers, and it is genuinely good news.

Hiring a readiness-only firm does not consume the C3PAO you may later need. GuidePoint is not presenting itself as the assessment organization in the first place, so you are not paying an assessor to consult and then discovering that the same assessment team cannot certify you.

But the actual rule is more precise than the usual sales summary. 32 CFR § 170.8(b)(5)(ii)(G) requires the Cyber AB's professional-conduct policy to prohibit CMMC ecosystem members from participating in a Level 2 certification assessment when they served as a consultant preparing that organization for a CMMC assessment within the previous three years. That lookback applies to the people and ecosystem relationships involved, not just the logo at the top of the proposal.

So the buyer question is not merely, "Are you an RPO or a C3PAO?" Ask whether any named consultant, affiliate, subcontractor, or proposed assessment partner could create a three-year conflict for the assessment you intend to book.

One credential note for precision: GuidePoint's data sheet uses "CMMC Certified Professional." The term defined in the rule is CMMC-Certified Professional (CCP). If credentialed staff matter to your decision, ask for names, credential numbers or Marketplace profiles, expiration dates, and the role each person will perform. A badge is not a staffing plan.

➤ Not sure whether you need a readiness firm or an assessor?

That is the most expensive category mistake to make, and it takes about two minutes to prevent. Use The Defense Compliance Report's Find My CMMC Path — tell us your level, CUI scope, assessment type, environment, and timeline, and we will map you to the provider category that fits before you request a quote.

Find My CMMC Path →

Category routing only. Not a score, ranking, endorsement, or compliance opinion. Do not submit CUI, drawings, system diagrams, credentials, or sensitive contract details.


What CMMC services does GuidePoint Security actually offer?

Answer capsule: GuidePoint's February 2026 CMMC data sheet names four service groups: a CMMC Scoping Exercise, a CMMC Gap Assessment, Advisory Services, and CMMC Compliance Program Implementation Support. That is a more specific published catalog than many readiness firms provide. What the catalog does not publish is price, engagement length, named staff, a deliverable inventory, or acceptance criteria.

Let's take them one at a time, in the company's own framing, with the buyer question attached to each. The source is GuidePoint's February 2026 CMMC Compliance Services data sheet.

CMMC Scoping Exercise. GuidePoint describes identifying and documenting the people, technology, facilities, and external service providers that process, store, or transmit FCI or CUI, or are otherwise in scope under 32 CFR Part 170.

What to demand: a boundary diagram, asset inventory with categorization, data-flow map, external-service-provider register, and written scope decision memo listing assumptions and exclusions. If a scoping proposal does not name those artifacts, you are buying a workshop, not a defensible scope.

CMMC Gap Assessment. GuidePoint describes identifying the in-scope environment, identifying applicable requirements, validating coverage of CMMC assessment objectives, and defining remediation activity.

What to demand: findings at the assessment-objective level, not merely the requirement level. CMMC Level 2 uses 110 NIST SP 800-171 Revision 2 requirements across 14 families, and those requirements decompose into 320 assessment objectives in NIST SP 800-171A. Under 32 CFR § 170.24, a requirement is MET only when all applicable objectives are satisfied and the evidence is in final form. Draft policies and plans do not count as final evidence.

A gap report that stops at "3.1.1 partially implemented" hides the exact determination statement that will fail you.

Advisory Services. GuidePoint describes on-demand consultants, staff augmentation, and Compliance Program Implementation Support.

What to demand: named people, role descriptions, a bounded hour count, rate card, minimum commitment, response-time expectation, and a clear statement of whether work is advisory or hands-on implementation.

CMMC Compliance Program Implementation Support. GuidePoint describes developing or revising documentation, educating personnel on their roles and responsibilities, building an ongoing program, and participating in the formal audit on the client's side as a liaison and advocate.

What to demand: clarity on where client-side liaison support ends and the C3PAO's independent work begins. Having an experienced person on your side of the table can be valuable. The SOW should say who speaks to the assessor, who owns evidence corrections, what meeting support is included, what happens during a POA&M closeout, and whether support is fixed-fee or billed by the hour.

The service-to-deliverable test

Use this table on any proposal, from any firm. It is the difference between "assist with documentation" and something you can actually hold someone to.

Published service — Deliverable to name in the SOW — How you know it is done
Published serviceDeliverable to name in the SOWHow you know it is done
ScopingBoundary diagram, asset inventory, data-flow map, ESP register, written scope assumptionsEvery asset and service is categorized, justified, and tied to a data flow
Gap assessmentObjective-level findings with evidence references and scoring rationaleEvery MET / NOT MET conclusion maps to a stated assessment objective
Remediation supportPrioritized remediation registerEach item has an owner, dependency, estimate, target date, and retest method
DocumentationNamed SSP, policies, procedures, plans, and responsibility matricesThe artifact list is explicit — no undefined "documentation support"
TrainingRole-based materials plus attendance and completion evidenceAudience, frequency, content owner, and evidence format are defined
Program supportCadence, status reporting, evidence-maintenance workflowOngoing duties, response times, and included hours are bounded
Assessment liaisonReadiness package and defined meeting-support boundariesThe C3PAO's independence and the client's ownership of answers are preserved

The deferral you should read before you request any proposal

The right provider is not the same for every contractor. The category you need — C3PAO, RPO, MSP/MSSP, GRC platform, government-cloud specialist, or CUI enclave — depends on your required CMMC Status, whether you handle FCI or CUI, the assessment type inserted into the solicitation or contract, your technical environment, and your deadline.

The solicitation, contract, or flow-down tells you what applies. A checklist does not set your level. DoD program managers or requiring activities select the status for a procurement, and primes or upper-tier contractors determine the appropriate flow-down under the rule. Start with our CMMC levels guide and who-to-hire-first decision guide before you request a large proposal.


Which GuidePoint services land inside your CMMC assessment boundary?

Answer capsule: The service name does not decide. The data flow does. Under 32 CFR § 170.19(c)(2), a provider is an External Service Provider for CMMC when CUI or Security Protection Data is processed, stored, or transmitted on that provider's assets. CUI on a non-cloud ESP's systems puts the service in your assessment scope. Security Protection Data without CUI puts the service in scope as a Security Protection Asset. If neither CUI nor Security Protection Data touches the provider's assets, the provider does not meet the CMMC definition of an ESP.

This is the section that took us the longest to build, and it is the reason this page exists.

The easy version of this map is wrong. It treats ongoing security support as enough, by itself, to make a provider an ESP. The rule does not stop at the label "managed service." It asks whether the provider's assets process, store, or transmit CUI or Security Protection Data — data such as security configuration data and log data.

When the answer is yes, § 170.19(c)(2)(ii) requires the relationship and service to be documented in the organization's SSP and described in the provider's service description and Customer Responsibility Matrix. When the answer is no, the company may still be a vendor or consultant, but it is not an ESP under the CMMC definition.

We keep the full mechanics on our CMMC scoping guide. What follows is the GuidePoint-specific application.

The "which GuidePoint are you buying" map

Everything in the final three columns is a contract question, not a claim about GuidePoint's unseen SOW. We have not reviewed your architecture or their contract.

GuidePoint offering — What the relationship usually involves — The CUI / SPD question — Likely treatment if GuidePoint assets receive neither CUI nor SPD — What the SOW should prove
GuidePoint offeringWhat the relationship usually involvesThe CUI / SPD questionLikely treatment if GuidePoint assets receive neither CUI nor SPDWhat the SOW should prove
CMMC Scoping ExerciseProject consultingWill diagrams, inventories, screenshots, exports, or CUI samples be uploaded to GuidePoint systems?Consultant, not an ESPApproved data types, transfer method, storage location, retention, deletion
CMMC Gap AssessmentEvidence reviewWill logs, configurations, SSP evidence, vulnerability data, or CUI be stored on GuidePoint assets?Consultant, not an ESPEvidence-handling plan and explicit prohibition on unnecessary CUI
Advisory / staff augmentationEmbedded peopleDo staff work only inside contractor-controlled systems, or on GuidePoint devices and platforms?Depends on the access architectureDevice ownership, remote access path, export controls, support tooling
Compliance Program Implementation SupportDocumentation, training, liaisonWhere are working files, evidence, and assessment packages stored?Consultant, not an ESPRepository owner, final artifact ownership, deletion and offboarding
Compliance Management as a ServiceOngoing compliance operationsDoes the service platform receive configuration, evidence, tickets, or log data?Not an ESP only if neither CUI nor SPD is on GuidePoint assetsService description and CRM if CUI or SPD is processed
CISO as a ServiceOngoing governanceDo GuidePoint systems receive security reports, risk registers, incident records, or CUI?Depends on actual data flowNamed systems, data classes, access model, retention
Security Analytics as a ServiceSecurity telemetry and analysisAre logs or configuration data processed on GuidePoint assets?Unlikely to remain out of scope if GuidePoint processes the telemetrySecurity Protection Asset treatment, service description, CRM
Vulnerability Management as a ServiceScan data and remediation workflowAre scan results, configurations, credentials, or asset data on GuidePoint systems?Depends on architectureScanner ownership, data location, credential handling, CRM
Next-Generation Firewall as a ServiceManaged security device administrationDoes GuidePoint process traffic, configurations, or logs?Depends on architectureManagement plane, logging path, administrator location, CRM
Identity as a ServiceIdentity platform administrationAre identity records, configurations, privileged-session data, or logs on GuidePoint assets?Depends on architectureSystem boundary, privileged access, data residency, CRM
Incident Response retainerOn-demand responseDuring an incident, will CUI, images, logs, malware, or forensic data move to GuidePoint systems?May stay outside scope before activation; reassess the incident workflowActivation data flow, reporting roles, evidence preservation, deletion
Penetration testing / red teamProject testingWill test data, credentials, results, or security telemetry be stored on provider assets?Depends on the test architectureRules of engagement, data classification, report storage, deletion
Technology resellingProcurementDoes GuidePoint merely sell the product, or also operate and monitor it?Resale alone does not create an ESP relationshipName the actual operator and every party receiving CUI or SPD
Managed Detection & ResponseGuidePoint says it helps select and negotiate with MDR providersWhich legal entity actually runs the platform and SOC, and does GuidePoint also receive telemetry or case data?The operating MDR provider is the primary ESP; GuidePoint may also be one if its assets receive CUI or SPDOperating entity, data path, analyst locations, service description, CRM

The MDR finding, which surprised us

GuidePoint's Managed Detection and Response page is framed as "Advising You on the Right MDR Provider." It says GuidePoint helps customers understand the MDR market, evaluate providers, and negotiate. Its site navigation also places MDR under "Third-Party Managed Services."

That does not prove GuidePoint lacks security operations. Its broader site separately says GuidePoint offers 24/7 monitoring, managed security, incident response, and Security Operations Center services. The narrow, defensible finding is this:

For the MDR product described on that page, get the operating provider's exact legal name. The company operating the MDR platform and SOC is the obvious ESP candidate when its systems process your logs or other Security Protection Data. GuidePoint also becomes relevant to scope if GuidePoint assets receive, process, store, or transmit CUI or Security Protection Data outside the operator's environment.

Do not put the salesperson's brand in your SSP because it is the name you remember. Put the operating legal entity and the actual data flow in writing.

The paragraph that costs people the most money

Under DFARS 252.204-7012(c), the contractor must rapidly report a covered cyber incident to the Department through DIBNet. The clause defines "rapidly report" as within 72 hours of discovery.

Not your consultant. Not your reseller. Not the MDR analyst watching the network at 3 a.m.

You can contract for a provider to detect, investigate, preserve evidence, draft the report, or perform submission mechanics when properly authorized. You do not contract away the contractor's clause obligation. Fast containment is not the same event as a regulatory report.

➤ Check the boundary before you price the remediation

Use our CMMC scoping guide to classify CUI Assets, Security Protection Assets, Specialized Assets, Contractor Risk Managed Assets, ESPs, CSPs, and out-of-scope systems. Then use the CMMC Readiness Checklist to see what the scoped environment actually has to prove.

Do not submit CUI, drawings, system diagrams, credentials, or sensitive contract details to a public form.


The honest problem: GuidePoint's buyer-facing CMMC content contains verified rule errors

Answer capsule: GuidePoint reacted quickly to the July 13, 2026 Phase II suspension, publishing a dedicated article on July 15. Its practice is active. But the CMMC readiness page, February 2026 data sheet, Education Center explainer, and May 2026 blog post still contain several buyer-facing statements that do not match 32 CFR Part 170. The biggest is a diagram that assigns Level 2 self-assessment to "non-DoW CUI" and Level 2 certification to "DoW CUI." The rule does not use that split.

This is our damaging admission, and we're going to give you the whole thing rather than a soft version.

The source audit

GuidePoint asset — What it gets right — What a buyer should not rely on without checking
GuidePoint assetWhat it gets rightWhat a buyer should not rely on without checking
CMMC readiness pageReadiness positioning, scope-first sequence, advisory versus implementation framingIt calls CUI "Confidential Unclassified Information," describes CMMC as three "certification levels," and uses broad certification language that blurs self-assessment and certification assessment
February 2026 CMMC data sheetFour named services, objective-level gap work, implementation and liaison language, visible RPO badgeIt says commercial organizations doing business directly or indirectly with the Department are required to hold CMMC, which is too broad; its Level 2 diagram uses a DoW-CUI versus non-DoW-CUI split that is not in the rule
Education Center, "What is CMMC?"Useful coverage of scoping, CUI, flow-down, assessment cadence, POA&Ms, affirmations, and Level 3It says Level 1 has 17 NIST SP 800-171A requirements; says ESPs must hold at least the same certification level as the OSA/OSC; and still describes the original phase schedule as if Phase II were advancing normally
May 29, 2026, "A 3-Step Path" postCorrectly emphasizes 320 assessment objectives and all-objective implementationIt states 17 Level 1 requirements, describes the Level 2 conditional threshold as 88 compliant requirements, and incompletely describes which requirements may go on a POA&M
July 15, 2026, Phase II suspension postPublished two days after the announcement; correctly says Phase I remains and Level 2 self-assessments continue in the bodyOne opening bullet says all components relating to Level 2 assessments are on hold, which conflicts with the same article's later statement that Level 2 self-assessments continue
August 13, 2026, POA&M postShows the practice continued publishing advanced CMMC material after the suspensionIt is not a substitute for correcting the buyer-facing landing page, data sheet, and evergreen explainer

The Level 2 diagram error nobody should copy

The February 2026 data sheet puts these labels beside its four-level diagram:

  • Level 2 Self Assessment: entities that process, store, or transmit non-DoW CUI
  • Level 2 Certification Assessment: entities that process, store, or transmit DoW CUI

That is not how 32 CFR Part 170 assigns Level 2 assessment type. The rule makes both Level 2 self-assessment and Level 2 C3PAO assessment possible CMMC Statuses for CUI environments. The DoD program manager or requiring activity selects the status for the procurement; the applicable solicitation, contract, or flow-down tells the contractor which assessment type is required. "DoW CUI" versus "non-DoW CUI" is not the decision rule.

A buyer who copies that diagram can make the most expensive category error on this page: assuming any DoD CUI automatically requires a C3PAO assessment, or assuming some other CUI label automatically makes self-assessment sufficient.

The three regulatory slips in the May 2026 post

GuidePoint's "A 3-Step Path to Achieving CMMC Compliance" is useful writing. It also contains three statements that do not survive a line-by-line read of the rule.

What the post says — What 32 CFR Part 170 says — Why a buyer should care
What the post saysWhat 32 CFR Part 170 saysWhy a buyer should care
Level 1 requires 17 requirements derived from NIST SP 800-171Level 1 uses 15 safeguarding requirements from FAR 52.204-21(b)(1), incorporated through 32 CFR §§ 170.14 and 170.15A Level 1 contractor using the wrong list builds the wrong evidence package
At least 88 of 110 requirements must be compliantThe conditional gate is a weighted assessment score of at least 88 points, not a count of 88 implemented requirements. Requirements carry 1-, 3-, or 5-point deductions under § 170.24You can meet more than 88 requirements and still miss the score gate if the missing requirements carry large deductions
No 3- or 5-point requirement may be noncompliant§ 170.21 allows one narrow 3-point encryption exception when encryption is deployed but not FIPS-validated, and it separately names six 1-point requirements that can never go on a POA&MThe shorthand is stricter than the rule in one direction and looser in another

Credit where it is earned: the same post correctly says that the 110 Level 2 requirements decompose into 320 assessment objectives and that all applicable objectives must be satisfied. That is the difference between an actual gap assessment and a 110-row checkbox sheet.

The ESP statement that would inflate a vendor's burden

GuidePoint's Education Center correctly quotes the CMMC definition requiring CUI or Security Protection Data to be processed, stored, or transmitted on provider assets. The next sentence says ESPs "must hold at least the same CMMC certification level" as the OSA or OSC.

Table 4 in § 170.19(c)(2) does not impose that blanket rule. It says the service is in the customer's assessment scope and is assessed according to the actual CUI/SPD relationship. An ESP may voluntarily undergo its own certification assessment to reduce the work during the customer's assessment. Voluntary certification and mandatory same-level certification are not the same claim.

The pivot, and why we're not telling you to walk away

Four things keep this in perspective.

First, GuidePoint responded to the suspension faster than most enterprise websites move. The July 15 article appeared two days after the Department announcement. That matters. Any review claiming all GuidePoint CMMC material predated the suspension would be wrong.

Second, the evergreen errors are still real. A fast blog post does not repair a data sheet used in sales conversations or an Education Center page that appears in search. Buyers need to know which source is current and which statement is wrong.

Third, GuidePoint's stronger material is better than ordinary marketing copy. Its service data sheet promises objective-level validation. Its Education Center covers scoping, eMASS-to-SPRS transmission, evidence retention, POA&Ms, affirmations, and flow-down. Its August 13 post deals with temporary deficiencies and enduring exceptions. Somebody in the practice understands the program.

Fourth — and this is the practical takeaway — the errors give you leverage. Marketing copy is not the methodology the delivery team has to use. Make the methodology contractual:

Ask GuidePoint, or any firm you are considering, to state in writing which version of 32 CFR Part 170, which assessment guide, which scoping guide, which NIST publication, and which scoring methodology will govern the engagement — and require final deliverables to cite the controlling primary source.

That version question matters more now than it did a year ago. NIST published SP 800-171 Revision 3 in May 2024 and SP 800-172 Revision 3 in May 2026. But the current CMMC rule still incorporates NIST SP 800-171 Revision 2 and the February 2021 version of SP 800-172. NIST's newest general publication is not automatically the controlling CMMC publication. The Department would have to amend the controlling rule or otherwise change the contractual basis. (Current eCFR incorporation by reference; NIST SP 800-171 Revision 2; NIST SP 800-172 Revision 3)

Then ask one more question: what changed on July 13, 2026, and how does it affect this scope, schedule, and price? Judge the answer, not the landing page.

➤ Build your own gap baseline before you grade a proposal

Our CMMC Readiness Checklist maps the 110 Revision 2 requirements across 14 families, shows the weighted scoring logic, and identifies the POA&M restrictions that decide whether a conditional status is even available.

Open the CMMC Readiness Checklist →


Who is GuidePoint Security, and which legal entity are you hiring?

Answer capsule: GuidePoint Security LLC is a cybersecurity advisory, consulting, implementation, managed-services, and technology-reselling company founded in 2011 and headquartered in Reston, Virginia. A separate entity, GuidePoint Security Government Solutions LLC, holds the public GSA Multiple Award Schedule contract we verified. The name on your SOW matters. If the provider becomes an in-scope ESP, the entity in your SSP and responsibility documents should match the entity actually delivering and operating the service.

We found two legal entities in GuidePoint's own material and federal contract records:

  • GuidePoint Security LLC — 1900 Reston Metro Plaza, Suite 701, Reston, Virginia 20190. This is the entity named in the site footer and CMMC data sheet.
  • GuidePoint Security Government Solutions LLC — the entity listed in GSA eLibrary for Multiple Award Schedule contract 47QTCA26D0006. GSA lists a current option-period end date of October 2, 2030 and an ultimate contract end date of October 2, 2045, with SINs 511210, 518210C, 54151HACS, 54151S, 611420, and OLM.

GuidePoint also publishes SeaPort-NxG and OASIS+ among its contract vehicles.

Why you should care. Ask which legal entity signs, who invoices, who employs the delivery team, who operates any managed platform, and which CAGE code applies. If your SOW, responsibility matrix, and SSP use different legal names for the same relationship, you created a discrepancy for no benefit.

Recent leadership change: on July 7, 2026, GuidePoint announced that Scott Rachford became Chief Executive Officer and founder Michael Volk moved to Executive Chairman. Rachford had spent more than a decade with the company and most recently served as Regional Partner for the North Central region. (GuidePoint announcement)

On scale, use GuidePoint's current number, not a stale aggregator. The company says it is trusted by 5,900+ businesses and government agencies, including all U.S. cabinet-level agencies, and that it vets 800+ technology vendors. Those are company-stated claims, not independently audited customer or partner counts. GuidePoint does not publish a current employee total we could verify from a primary source, so this review does not invent one.

Read that customer profile carefully. It tells you something about fit.


Which contractors is GuidePoint Security actually a fit for?

Answer capsule: GuidePoint's published breadth suits contractors with complex, multi-site, mixed-cloud, or heavily integrated security environments that need scope through implementation and can manage a custom professional-services engagement. Contractors who only need the formal certification assessment, a small turnkey enclave, or a CMMC-focused MSP to own daily IT should compare a different provider category first.

This is editorial judgment drawn from the verified facts above — GuidePoint's published service catalog, managed-services breadth, company-stated customer profile, and what is absent from its CMMC catalog. It is not a prediction about your outcome.

Your situation — GuidePoint fit — Why — Compare this first
Your situationGuidePoint fitWhyCompare this first
Multi-site contractor, mixed cloud and on-prem, CUI flows unclearStrong shortlist candidateScoping, data flow, gap, implementation, and broad security depth are where a large advisory firm can earn its feeAnother broad RPO or CMMC integrator
Mid-market firm needing scope through implementationStrong shortlist candidateThe published catalog covers the readiness sequence from scoping through program supportA CMMC-focused MSP/MSSP if you also need recurring operations
10–25 person shop, one bounded enclave, no internal ITCompare carefully firstCustom consulting may be more than a small footprint needs; GuidePoint publishes managed security, but not a simple turnkey CMMC package in its CMMC catalogSmall-business CMMC providers
You need a GCC High migration or turnkey CUI enclaveNot the published CMMC offerWe found no named GCC High migration or CUI-enclave product in the CMMC materials reviewedGCC High for CMMC or a managed-enclave specialist
Controls are mature and you only need the formal assessmentWrong categoryAn RPO cannot conduct your Level 2 certification assessmentA verified C3PAO through the Cyber AB Marketplace
You need ongoing IT and security operations run for youScope-dependentGuidePoint publishes managed security and SOC services, but you need to confirm the operating model, help-desk responsibility, CUI architecture, and CMMC evidence ownershipA CMMC-focused MSP/MSSP
You mainly need evidence workflow and control mappingProbably not firstConsulting is not a GRC platform, and a platform is not complianceA CMMC GRC platform, then targeted consulting
You do not yet know whether you hold FCI, CUI, or bothDo not request a large proposal yetLevel, assessment type, and scope have to come before a serious quoteFind My CMMC Path
You have a documented contract or proposal deadlinePotentially usefulBreadth and staffing depth may help, but capacity, milestones, and named staff must be in the contractCompare at least one equivalent readiness provider

If you are in the "wrong category" row, please go. Seriously. The most expensive mistake in this process is not picking the wrong firm. It is picking the wrong kind of firm and finding out four months and six figures later. We would rather lose your click than watch that happen.


What does GuidePoint Security charge for CMMC work?

Answer capsule: GuidePoint does not publish commercial CMMC pricing. Its CMMC services are sold as scoped professional engagements. The only public rate source we verified is the price-list function attached to GuidePoint Security Government Solutions LLC's GSA Multiple Award Schedule record. Those are federal schedule terms and ceiling rates, not a commercial CMMC quote.

Let's be straight about what we can and cannot tell you.

We found no published commercial CMMC price. Not on the readiness page, in the February data sheet, or in the public resource material reviewed. That is normal for custom consulting. It also means the statement of work is the product, and a lower total with vague deliverables can cost more than a higher bounded proposal.

We will not print an invented "typical GuidePoint cost." Unsourced estimates for private consulting engagements become fake benchmarks the moment somebody copies them. If you see a specific GuidePoint CMMC price without a proposal, public schedule document, invoice, or other source behind it, treat it as unverified.

What does exist: the GSA eLibrary record for contract 47QTCA26D0006 provides access to terms and a price list for federal purchasing. Two caveats matter. Those are not commercial DIB prices. And SIN 54151HACS covers Highly Adaptive Cybersecurity Services broadly, not GuidePoint CMMC readiness alone. Use the schedule as a reality check on labor categories and ceiling rates — not as the quote you think you will receive.

Separate these buckets or you cannot compare two proposals

Cost bucket — The question to ask
Cost bucketThe question to ask
Discovery and scopingFixed fee? How many workshops? Which artifacts? Which sites and business units?
Gap assessmentRequirement-level or objective-level? Full population or sampling? Which evidence methods?
DocumentationWhich documents, by name? New documents or revisions? Any page, template, or review-cycle limits?
Remediation adviceHours, rate, cap, and prioritization method?
Technical implementationIncluded, estimated, or a separate project and team?
Software and licensesResold by the provider? Recurring term? Margin or compensation disclosure? Alternatives evaluated?
Program supportRetainer? Included hours? Service levels? Do unused hours roll over?
RetestingOne validation cycle or more? What counts as a retest?
Assessment liaisonIncluded? Which meetings, artifacts, and response windows?
TravelIncluded or pass-through? Approval threshold?
Change ordersWhat triggers one, who approves it, and what is the rate basis?
OffboardingDo you own every artifact? Export format? Data deletion? Transition support?

For the broader program budget, use our CMMC Level 2 cost breakdown. It separates readiness consulting, technical remediation, managed services, software, cloud, and the eventual assessment instead of hiding all of them under one number.

➤ Do not price one proposal in isolation

Compare providers in the same category against the same scope and deliverable list. Tell us your level, scope, environment, and timeline, and we will route you to source-checked provider options that can be compared on the same problem.

Request comparable CMMC provider options →

We may receive compensation for qualified introductions, disclosed at the point of recommendation. No guaranteed certification, ranking, or outcome. Do not submit CUI, drawings, credentials, or sensitive contract details.


GuidePoint is also a reseller. Does that change anything?

Answer capsule: GuidePoint sells and implements security technology alongside consulting and describes its approach as vendor-objective or vendor-agnostic. That combination is ordinary in this market and can be useful. It also means the organization recommending a product may benefit from selling or implementing it. The remedy is contractual, not moral.

The facts from GuidePoint's own site: the company says it vets 800+ technology vendors, helps with product evaluation and selection, implements and manages technology, and offers flexible financing for hardware, software, services, and support.

Now the fair framing, because we are not interested in insinuation. Many CMMC-focused MSPs, MSSPs, integrators, and RPOs also resell products. The integrated model is often the reason they can close a technical gap instead of handing you a PDF and walking away. A pure-advice firm that cannot touch the environment has its own limitation.

Here is the fix, and it is three questions:

  1. Are the gap assessment and all product recommendations priced as separate line items?
  2. Is anyone assigned to this engagement compensated on product, license, financing, or implementation revenue?
  3. Can you show at least one defensible path to closing each material gap that does not require buying a product from you?

A firm that answers those cleanly is fine. A firm that dodges them has told you something useful for free.


What should you ask GuidePoint before you sign?

Answer capsule: Fifteen questions a proposal-ready provider should be able to answer in writing. They cover legal entity, current status, named staff, scope assumptions, evidence depth, ESP consequences, commercial incentives, and the handoff to whoever eventually performs the certification assessment.

Copy this. Send it. Use it on every firm you are considering, not just GuidePoint — that is the point.

Entity and status

  1. Which exact GuidePoint legal entity will sign our statement of work — GuidePoint Security LLC, GuidePoint Security Government Solutions LLC, or another entity — and what CAGE code applies?
  2. Are you currently listed as an RPO in the Cyber AB Marketplace, under which exact legal entity name, profile identifier, and expiration date?
  3. Which named people will staff our engagement, what current CMMC credentials do they hold, and what role will each person perform?
  4. Does the contracting entity hold a current CMMC Status or current SPRS assessment score? What assessment scope and legal entity does that status cover?

Scope and deliverables

  1. What exact solicitation, contract, flow-down, CMMC Status, and assessment type is this engagement preparing us for?
  2. What assumptions define the CMMC Assessment Scope you quoted, and what would change the price?
  3. Which artifacts will you deliver, by name, and what are the acceptance criteria for each?
  4. Will the gap assessment test every applicable assessment objective, or stop at the 110-requirement level?
  5. Which version of 32 CFR Part 170, which assessment guide, which scoping guide, which NIST publication, and which scoring methodology will govern this engagement — and will final deliverables cite the primary source?

Scoping consequences

  1. Will any GuidePoint or subcontractor asset process, store, or transmit our CUI or Security Protection Data?
  2. For every in-scope provider relationship, will you provide a service description and Customer Responsibility Matrix suitable for our SSP?
  3. If you place us with an MDR, cloud, managed-security, or other service provider, who is the actual operating legal entity and what data does each party receive?

Commercial boundaries and handoff

  1. Which proposed products, licenses, financing arrangements, or services do you resell or receive compensation on, and is anyone assigned to us compensated on those sales?
  2. What triggers a change order, how many remediation-validation cycles are included, and who owns the artifacts and evidence repository if we part ways?
  3. What changed on July 13, 2026, and how does the Phase II suspension change this engagement's scope, schedule, staffing, and price?

If a firm cannot answer questions 1 through 4 before the proposal becomes a contract, the proposal is not ready to become a contract.

➤ Bring the questions with you, then compare like with like

Our request-a-quote path starts with provider category, scope, and timeline so you do not compare an RPO proposal with a C3PAO assessment quote or an MSP bundle as though they were the same product.

Do not submit CUI, drawings, system diagrams, credentials, or sensitive contract details. High-level counts and categories only.


How does GuidePoint compare with other CMMC provider categories?

Answer capsule: GuidePoint's published CMMC position is broad readiness and implementation, not formal assessment. The comparison that matters is not feature-by-feature. It is what each provider category should own, what it cannot replace, and what commercial failure mode you need to control before signing.

Provider category — Best when — What it should own — What it cannot replace — Main commercial risk
Provider categoryBest whenWhat it should ownWhat it cannot replaceMain commercial risk
Broad RPO / security integrator — GuidePoint's published positionComplex scope, broad implementation needs, multiple security disciplinesScope, objective-level gap analysis, roadmap, documentation, implementation coordinationThe C3PAO certification assessmentCustom scope expanding under time-and-materials work
Boutique RPO / Registered PractitionerNarrow environment, focused readiness helpScoping, documentation, evidence review, gap adviceManaged operations or certificationLimited implementation capacity or key-person dependence
CMMC-focused MSP / MSSPYou need IT and security operated for youTechnical implementation, recurring operations, evidence maintenanceYour contractual accountability or the independent assessmentLong recurring bundles that are hard to unwind
CUI enclave providerCUI can be tightly isolated from the rest of the businessA bounded technical environment and responsibility matrixBusiness process, governance, and data-owner decisionsWorkflow mismatch, hidden integrations, and scope leakage
GRC platformYour internal team can run the programEvidence, workflow, assignments, control mappingTechnical implementation or independent assessmentMistaking software for compliance
C3PAOYour environment is genuinely ready for Level 2 certificationThe independent certification assessmentConsulting or remediation for the same organization inside the three-year conflict windowBooking too early and paying to document failure
Federal-contracts attorneyClause, flow-down, marking, or contractual interpretation disputesLegal and contractual adviceTechnical implementation or assessment evidenceAsking a technical consultant to make legal conclusions

One structural rule belongs in every provider plan: readiness help and formal assessment must stay separated. The binding rule uses a three-year consultant lookback for ecosystem members participating in the Level 2 certification assessment. Build around that before you select the readiness team, not when you are trying to schedule the assessor.

Related reading: CMMC provider categories explained · Who to hire first · CMMC self-assessment vs. C3PAO assessment


Frequently asked questions

Is GuidePoint Security a CMMC RPO?

GuidePoint Security says it is a CMMC RPO on its readiness page and February 2026 data sheet. The Cyber AB's current official role page calls the designation a Registered Practitioner Organization, while GuidePoint's prose says Registered Provider Organization and its data-sheet badge says Registered Practitioner Organization. We could not independently retrieve GuidePoint's exact current legal-entity record from the JavaScript-dependent Cyber AB Marketplace on August 28, 2026. Verify the live listing before engagement. A Marketplace record is a status record, not a quality ranking.

Is GuidePoint Security a C3PAO?

No public GuidePoint material we reviewed claims C3PAO status. GuidePoint positions itself for readiness and advisory work. Under 32 CFR § 170.9, only an authorized or accredited C3PAO may conduct a Level 2 certification assessment.

Can GuidePoint Security certify my company for CMMC?

Not in the role it publishes. An RPO can help prepare you, but it cannot conduct the Level 2 certification assessment or issue the resulting Certificate of CMMC Status. A Level 2 certification assessment is conducted by a C3PAO. A Level 3 certification assessment is conducted by DCMA DIBCAC.

What CMMC services does GuidePoint Security offer?

GuidePoint's February 2026 data sheet names a CMMC Scoping Exercise, CMMC Gap Assessment, Advisory Services, and CMMC Compliance Program Implementation Support. The published support includes objective-level validation, documentation development or revision, personnel education, staff augmentation, ongoing program support, and participation in the formal assessment on the client's side as liaison and advocate. Price, engagement length, named staff, and acceptance criteria are not published.

How much does GuidePoint Security charge for CMMC readiness?

GuidePoint publishes no commercial CMMC price. Its public GSA Multiple Award Schedule record includes access to federal schedule terms and a price list, but those are not a commercial CMMC quote. Get a scoped SOW and separate scoping, gap work, documentation, implementation, software, recurring services, retesting, and assessment-liaison costs.

Does GuidePoint Security run its own MDR security operations center?

GuidePoint's dedicated MDR page describes helping customers identify, evaluate, and negotiate with MDR providers and places MDR under third-party managed services. GuidePoint's broader site separately says it operates Security Operations programs and offers 24/7 monitoring and managed security. Do not answer the scoping question from the brand alone. Ask which legal entity operates your MDR service and which parties receive your CUI or Security Protection Data.

Does GuidePoint Security go in my System Security Plan?

Only when the actual relationship triggers the rule. Under 32 CFR § 170.19(c)(2), a provider is an ESP when CUI or Security Protection Data is processed, stored, or transmitted on provider assets. If that occurs, document the relationship and service in the SSP and obtain the provider's service description and Customer Responsibility Matrix. If neither CUI nor Security Protection Data touches GuidePoint assets, GuidePoint does not meet the CMMC ESP definition merely because it advised you.

Does hiring GuidePoint for readiness disqualify an assessor later?

Hiring GuidePoint does not consume a C3PAO because GuidePoint is not presenting itself as the assessment organization. But 32 CFR § 170.8 requires a three-year conflict lookback for CMMC ecosystem members who consulted for the organization and later seek to participate in its Level 2 certification assessment. Ask about named people, affiliates, subcontractors, and any proposed assessment partner.

Does GuidePoint Security offer GCC High migration or a CUI enclave?

We found no named Microsoft GCC High migration service or turnkey CUI-enclave product in the GuidePoint CMMC materials and navigation reviewed on August 28, 2026. That is not proof the capability does not exist. Ask directly and compare a government-cloud or managed-enclave specialist when that is your primary need.

Is CMMC still required after the July 2026 suspension?

Yes, in Phase 1. The Department suspended Phase II, originally scheduled for November 10, 2026, and says all Phase I self-assessment requirements remain. The current Department program page says NIST SP 800-171 Revision 2 will be enforced through self-assessments and select government-led assessments. DFARS 252.204-7012 remains in force when included in the contract, and applicable SPRS and annual-affirmation requirements continue.

Does CMMC Level 2 still use NIST SP 800-171 Revision 2?

Yes. The current CMMC rule incorporates NIST SP 800-171 Revision 2 for Level 2 — 110 requirements across 14 families — and the February 2021 version of NIST SP 800-172 for the selected Level 3 enhanced requirements. NIST has published newer revisions, but those newer publications do not become the controlling CMMC versions automatically.

How many security requirements does CMMC Level 1 have?

Fifteen. CMMC Level 1 uses the 15 basic safeguarding requirements from FAR 52.204-21(b)(1), with annual self-assessment and annual affirmation in SPRS. No POA&M is permitted at Level 1. The number 17 belongs to the retired CMMC 1.0 practice count, not the current Level 1 rule.

Does GuidePoint hold its own CMMC Status or SPRS score?

We found no public primary-source record establishing a current CMMC Status or SPRS score for either GuidePoint legal entity. SPRS data is not generally a public directory. Ask the contracting entity directly, ask what assessment scope the status covers, and do not assume a corporate status covers the specific managed service you are buying.

Is this a hands-on review of GuidePoint Security?

No. This is a public-source review. We read GuidePoint's published pages, data sheet, blog posts, company announcements, and public contract-vehicle records against current CMMC and DFARS primary sources. We did not purchase the service, interview GuidePoint, inspect a proposal, test an implementation, or validate a client outcome.


How we researched this review

We work from primary sources, and we tell you which ones.

GuidePoint sources read directly: the CMMC Readiness page; February 2026 CMMC Compliance Services data sheet; Education Center "What is CMMC?" explainer; May 29, 2026, "A 3-Step Path" post; July 15, 2026, Phase II suspension post; August 13, 2026, POA&M post; Managed Detection and Response page; company homepage and service navigation; July 7, 2026, CEO announcement; and public GSA eLibrary contractor record.

Regulatory sources read directly:

What we did not do: buy the service, test it, interview GuidePoint, inspect a customer environment, review a live proposal, validate a customer outcome, or accept compensation from anyone connected to this page.

Update triggers: a new Department reform decision or Phase II date; an amendment to 32 CFR Part 170; a change to the controlling NIST version; a GuidePoint correction to the pages identified above; a Cyber AB Marketplace status change; or a material change to GuidePoint's service catalog, legal entities, or compensation relationship with this publication.

Corrections: if you have documentation that changes anything above — particularly a current Cyber AB Marketplace record, a GuidePoint SOW, a Customer Responsibility Matrix, or corrected GuidePoint content — send it through our corrections policy. We will update the page when the evidence changes.


GuidePoint Security CMMC review verdict

Answer capsule: GuidePoint Security belongs on a CMMC readiness shortlist for contractors with complex environments that need scoping through implementation from one broad cybersecurity firm. The public record we verified supports treating GuidePoint as an RPO, not as your C3PAO. Before signing, verify the live Cyber AB record, get the exact contracting and operating entities, demand objective-level deliverables, map every CUI and Security Protection Data flow, and find out which services put GuidePoint or a subcontractor inside your assessment scope.

Shortlist GuidePoint when your environment is genuinely complicated, your scope is not defensible yet, you need more than templates, and the statement of work survives the fifteen questions above.

Compare another category first when you only need the certification assessment, when your CUI footprint is small and bounded, when you need a turnkey government-cloud enclave, when what you actually need is full-service CMMC IT operations, or when the proposal cannot name its deliverables, data flows, exclusions, and acceptance criteria.

The buyer-facing content errors are real. So is the breadth behind the practice. Do not ignore either one. Make the current rule and the delivery methodology contractual.

And whatever you do, do not hire against a Phase II deadline that is currently suspended. Hire against the requirement actually attached to your business.


Need help deciding what type of CMMC provider you need?

Tell us your level, scope, assessment type, environment, and timeline, and we will route you to the right provider category before you compare named firms.

Find My CMMC Path →

Do not submit CUI, drawings, system diagrams, credentials, or sensitive contract details.

The Find My CMMC Path tool routes by provider category. It is not a score, certification decision, legal opinion, or guaranteed outcome. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed at the point of recommendation.


The Defense Compliance Report is an independent trade publication on CMMC and Defense Industrial Base compliance. We are not affiliated with GuidePoint Security, the Cyber AB, the Department of War, the Department of Defense, DCMA DIBCAC, NIST, or any U.S. government agency. This page is educational research, not legal, contractual, cybersecurity, or compliance advice. Your solicitation, contract, flow-down, information handling, system architecture, and current government direction determine what applies. Confirm legal or contractual questions with a qualified federal-contracts attorney and technical or assessment questions with appropriately credentialed CMMC professionals.

By The Defense Compliance Report Editorial Team · Last reviewed: August 2026 · Last verified: August 28, 2026