How to Choose a CMMC Consultant (and RPO)
A practicing RPO's guide to choosing a CMMC consultant. What they actually do, why your consultant cannot also be your assessor, the questions to ask, and the red flags to walk away from.
To choose a CMMC consultant, check that the firm is a Cyber-AB Registered Practitioner Organization, confirm credentials like CISSP, CCP, RP, and RPA, and ask for two or three references. Confirm they are an RPO that prepares you, not your assessor. Your C3PAO must be a separate, accredited firm. Avoid anyone who guarantees a pass.
You hold a DoD contract, or you want one, and the data that comes with it puts you in CMMC scope. Now your inbox is full of “CMMC experts.” Some are excellent. Some have never sat through an assessment. Telling them apart is hard when you are new to the language, and the clock is real.
Starting November 10, 2026, a C3PAO Level 2 assessment becomes a condition of award in applicable DoD contracts. So how do you pick the right partner, and how do you avoid the ones who will cost you time and money you do not have?
This article, written by a practicing Registered Practitioner Organization, will tell you how to vet anyone in this space, including us.
A CMMC consultant is an advisor who prepares your organization to meet the Cybersecurity Maturity Model Certification requirements, from scoping the data through getting you ready for the assessment. That is the job.
The rest of this article is how to tell who can actually do it.
What a CMMC consultant (and RPO) actually does
A good consultant starts by scoping your boundary, the exact systems, people, and data flows that touch Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). They run a gap assessment against the standard, which for Level 2 is the 110 controls in NIST SP 800-171 Revision 2.
They build your System Security Plan (SSP), the document that says how you meet each control. They build and manage your Plan of Action and Milestones (POA&M), the list of gaps with owners and dates. They compute and improve your SPRS score, the number you report to the government. And they run a mock assessment so problems surface on your terms, not the assessor’s.
Which level applies to you depends on your data, not your size. If you handle Federal Contract Information, you sit at Level 1, a self-assessment against 15 requirements. If you handle Controlled Unclassified Information, you move to Level 2, and for most contracts that means a third-party assessment.
One correction is worth making early, because the opposite belief shows up all over the market. Handling CUI does not automatically push you to Level 3. Level 3 is also a CUI level. It covers only the most sensitive slice of CUI on high-risk programs facing advanced persistent threats, and the government assesses it directly instead of a C3PAO. For the large majority of contractors who handle CUI, the target is Level 2.
Most of this work begins with one step. A CMMC readiness assessment measures where you stand and tells you the size of the job before you spend real money on remediation. Ask any consultant where they would start. If the answer is not some version of “let us scope and baseline first,” keep looking.
RPO vs C3PAO vs RP, and why your consultant cannot be your assessor
Here is the distinction that trips up most organizations seeking CMMC compliance, and the one a good partner explains before you ask. The roles are defined by the Cyber AB, the accreditation body for the program.
| Role | What it is | Can it assess you for certification? |
|---|---|---|
| RPO (Registered Practitioner Organization) | A firm registered with the Cyber AB that provides prep and advisory work | No. It prepares you. |
| RP / RPA (Registered Practitioner / Advanced) | Registered individuals who deliver that advisory work | No. |
| C3PAO (Certified Third-Party Assessment Organization) | An accredited firm authorized to run the official Level 2 assessment | Yes. This is your assessor. |
Why does this matter so much? Because the firm that prepares you cannot be the firm that grades you, at least not on the same engagement. That separation is required, not a nicety.
It protects the integrity of your result, and it protects you. The rule has a clear line. A C3PAO cannot assess a client it has consulted for within the previous three years, so a partner who offers to get you ready and then certify you on the same job is either confused about the rules or willing to ignore them. Neither is who you want in the room.
A firm can hold both roles across different clients, but the one that builds your environment is not the one that should sign off on it. InterSec is an RPO. We prepare you. A separate, accredited C3PAO runs your assessment.
Questions to ask a Compliance Consultant before you hire
You do not need to be a CMMC expert to vet one. You need a short list of questions and a sense of what a good answer sounds like.
Ask these before you sign anything:
- Are you a Cyber-AB RPO? A good answer points you to the CyberAB Marketplace (you can check the credentials on CyberAB Marketplace). Vague answers are a problem.
- Will you also be my assessor? The correct answer is no, with an explanation of the RPO and C3PAO separation. Having said that, an RPO may refer you to a few C3PAOs if required. Any other answer is disqualifying.
- Can you give me two or three references? A good RPO consultant offers them without hesitation. If they cannot produce references, that tells you something.
- What do I own when we are done? You should own your SSP, your POA&M, your SPRS evidence, and your documentation. If the artifacts live only with the vendor, you are renting compliance, not building it.
- How do you scope, and how do you keep my environment small? A good answer talks about isolating CUI and reducing what falls in scope. A weak answer assumes your whole company is in scope by default.
- Do you default everyone to the highest-security cloud? A good consultant scopes the cloud to your data. Pushing every client to the most expensive tier regardless of need is a cost you can avoid.
- How do you price, and what is included? You want a clear scope and a clear number, not a fog.
- What happens if I am not ready by my assessment date? A good answer is honest about timelines and POA&M limits, not a promise that everything will be fine.
The answers tell you more than any brochure. You are listening for candor, specifics, and a willingness to tell you something you did not want to hear.
Red flags to look for
Some signals should end the conversation. None of these is subtle once you know to look for it.
- A guaranteed pass. No one can guarantee a CMMC result. Only an independent C3PAO (or the government, at Level 3) determines the outcome. A guarantee is a sales tactic, not a capability.
- A firm that cannot separate the RPO and C3PAO roles. If they will not explain why they cannot both prep and assess you, they do not understand the program or do not respect it.
- Over-scoping by default. A consultant who puts your entire enterprise in scope, or defaults you to the most expensive cloud tier when a small enclave would do, is building a bigger bill, not a better program. Scope is the single biggest cost lever in CMMC. Watch who pulls it in the wrong direction.
- Expensive tools with little CMMC value. Be wary of anyone selling a stack of products that is operationally heavy, costly, and only loosely tied to the controls you actually have to meet.
- No references and one-size packages. A real practitioner has clients who will talk and a program that flexes to your size. A fixed package that ignores your CUI footprint is a template, not a plan.
- Vague pricing. If you cannot get a clear scope and a clear number, you will not get a clear outcome either.
What good looks like, the deliverables
Forget the sales deck for a moment. Judge a consultant by what they leave behind. A strong engagement produces a defined and right-sized scope with a CUI boundary diagram, so everyone agrees what is in and what is out. A gap assessment against all controls. A complete SSP written to your actual environment. A POA&M with real owners and real dates. A SPRS score with the evidence behind it. And a mock assessment readout that tells you, plainly, what an assessor will find.
That is also how to read a firm’s experience. InterSec is a Cyber-AB RPO with ISO 27001, 42001, and 9001 certifications, staff who hold CISSP, CCP, RP, and RPA credentials, and CMMC contracts with GENEDGE, George Mason University, and the University of South Carolina, plus a GENEDGE CMMC Blanket Purchase Agreement. The proof that matters most is in the work.
We have taken a multi-site Navy prime from a deeply negative SPRS score toward assessment-ready, built a Level 2 program for a specialty metals supplier around a four-user CUI enclave, and right-sized a Level 2 program for a solo consultant carrying all 110 controls.
If you want the full service picture, see our CMMC compliance consulting overview. Whoever you hire, ask to see deliverables like these from real engagements.
How pricing models work
CMMC pricing comes in a few shapes, and the right one depends on your cash flow and how much you want to run yourself. Fixed-fee scoped engagements give you a known number for a defined scope. Hourly or advisory models work when you have internal capacity and want expert guidance on call. Managed or ongoing models hand the heavy lifting to the partner, including the work that continues after you certify. None is automatically right. The wrong one is whichever does not match how your business actually pays for things.
For an estimate of real ranges by level and by starting point, see what CMMC certification costs.
How InterSec works
We are a Cyber-AB RPO, which means we are your prep and advisory partner, not your assessor. We scope your CUI tightly, build the artifacts you own (SSP, POA&M, defensible SPRS, evidence), and run a mock assessment before the C3PAO arrives. We size the work honestly to your environment and your budget, and we keep the RPO and C3PAO roles separate the way the program requires. If that is the kind of partner you are looking for, the next step is a conversation, not a contract.
Frequently Asked Questions
Is a CMMC consultant the same as a C3PAO?
No. A CMMC consultant, usually working as a Registered Practitioner Organization (RPO), prepares you for your assessment. A C3PAO is the accredited firm that runs the official Level 2 assessment. The same firm cannot do both for you. That separation is required by the Cyber AB and protects the integrity of your result.
How much does a CMMC consultant cost?
It depends on your CMMC level, the size of your CUI footprint, your starting SPRS score, and whether you want a fixed-fee, advisory, or managed model. There is no single sticker price. For real ranges, see our guide on what CMMC certification costs.
Can a consultant guarantee I pass my CMMC assessment?
No, and a guarantee is a red flag. Only an independent C3PAO determines a Level 2 outcome, and the government determines Level 3. A good consultant raises your odds by closing gaps and running a mock assessment, but no partner promises a pass.
What is a Cyber-AB RPO?
A Registered Practitioner Organization is a firm registered with the CyberAB to provide CMMC prep and advisory services, staffed by Registered Practitioners. An RPO gets you ready for your assessment. It is not a C3PAO and does not run the assessment itself.
What credentials should a CMMC consultant have?
Look for Cyber-AB RPO registration and Registered Practitioners (RP or RPA) on staff, backed by recognized security credentials like CISSP and the Certified CMMC Professional (CCP). Credentials are not everything, but a firm with none, and no references, is a firm to question. Ask to see real deliverables from past engagements.
What are red flags when hiring a CMMC consultant?
The big ones. A guaranteed pass, because no one can promise a CMMC result. A firm that offers to both prepare and assess you, which is not allowed. Over-scoping your whole company when an enclave would do. Expensive tools with little CMMC value. No references, and vague pricing. Any of these is a reason to keep looking.
Talk to a Cyber-AB RPO, not a sales rep
If you are vetting CMMC partners, vet us too. Book a 30-minute consultation and we will tell you where you stand, what the job looks like, and what it should cost. No guaranteed-pass promises, just an honest read.