CMMC consulting became a crowded market very quickly. A rule that touches tens of thousands of defense contractors attracted a lot of new entrants, and their websites look alike. The differences that matter are verifiable, and most of them can be checked in an afternoon.

The credentials, and what each one means

Three terms get used loosely and mean different things.

TermWhat it actually is
C3PAOAn organisation authorised to conduct third-party CMMC assessments. They assess. They cannot also prepare you and then assess you.
RPO (Registered Provider Organisation)An organisation registered with the accreditation body to provide advice and preparation. This is what a consultant should be.
RP (Registered Practitioner)An individual credential, held by a person rather than a firm.

All three are listed publicly by the accreditation body. Ask for the firm’s registered name and check it. A consultant who is genuinely registered will tell you where to look without hesitating.

Good to know: a C3PAO cannot both prepare you for assessment and then assess you. That is an independence conflict. If a firm offers both for the same engagement, that alone is disqualifying.

The five questions that separate real capability from a template

  1. “Show me a redacted System Security Plan you have written.” Not a template you license — one you produced. Firms who have done the work produce this in a day. Firms who have not will offer a capability statement instead.
  2. “Who implements the technical controls?” Many CMMC consultants write documentation and stop. Somebody still has to configure identity, logging, encryption and endpoint. If it is not them, it is you or a third party, and you need to know that before signing.
  3. “How do you handle scoping?” Scope is where CMMC costs are decided. A consultant who does not push hard on what touches Controlled Unclassified Information will over-scope you and charge accordingly.
  4. “What happens after we are compliant?” Compliance decays. Ask what sustained governance looks like and what it costs, because that is the real long-term number.
  5. “What is your position on the current pause?” A consultant who says the obligations went away in July 2026 does not understand the rule. See what still applies.

Documentation versus implementation

This is the largest and most expensive misunderstanding in the market.

CMMC at Level 2 requires all 110 controls of NIST SP 800-171 to be implemented and evidenced, not described. A firm that produces a beautiful System Security Plan for an environment where multi-factor authentication is not actually enforced has not made you compliant. They have documented your non-compliance, in writing, with your signature on it.

When comparing proposals, sort them into three buckets: documentation only, implementation only, or both. Then compare like with like. A cheaper documentation-only engagement is not cheaper if you then need somebody else to do the technical work.

Warning signs
  • A guarantee of certification. Nobody can guarantee an assessment outcome.
  • A fixed price quoted before scoping. Scope decides cost; a price before scope is a guess or a bait.
  • Templates presented as deliverables, with your company name inserted.
  • The same firm offering to prepare you and assess you.
  • No answer on who implements the technical controls.

How CMMC engagements are usually structured

Most competent engagements follow the same sequence, whatever the firm calls it.

  1. Scoping. Define what handles Federal Contract Information and Controlled Unclassified Information, and draw the boundary.
  2. Gap analysis. Score honestly against all 110 controls with evidence, not optimism.
  3. Remediation roadmap. Ranked, costed, sequenced by dependency.
  4. Implementation. The technical work. The longest phase and the one most often out of scope.
  5. Documentation. System Security Plan, POA&M, policies and evidence.
  6. Sustained governance. Keeping it true after the consultant leaves.

Ask which of these six a proposal includes. Proposals that look dramatically cheaper usually stop at step three.

Local versus national

CMMC work can be done remotely, and much of it is. Where a local firm has an advantage is in the parts that are not technical: understanding what the primes in your region are actually asking for, and being able to appear in person when something needs it.

If you are in Virginia, our guide to CMMC requirements for Virginia contractors covers the regional picture.

Where IP Consulting fits

We are CMMC Registered and CJIS Certified, both verifiable. We work with defense contractors across Virginia and Michigan, and we do both the documentation and the technical implementation, which is the combination most organisations discover they need after the first proposal. Our CMMC compliance services page covers the detail.

Frequently asked questions

What is the difference between a C3PAO, an RPO and an RP?

A C3PAO is authorised to conduct third-party CMMC assessments. An RPO, or Registered Provider Organisation, is a firm registered to advise and prepare you. An RP, or Registered Practitioner, is an individual credential. All three are listed publicly by the accreditation body, so ask for the registered name and verify it.

Can the same firm prepare us for CMMC and assess us?

No. A C3PAO cannot both prepare an organisation and then assess it, because that is an independence conflict. If a firm offers both for the same engagement, treat it as disqualifying.

What should a CMMC consulting engagement include?

Six phases: scoping, gap analysis against all 110 NIST SP 800-171 controls, a remediation roadmap, technical implementation, documentation including the System Security Plan and POA&M, and sustained governance. Proposals that look dramatically cheaper usually stop after the roadmap and leave implementation to you.

Is documentation alone enough for CMMC compliance?

No. Level 2 requires the 110 controls to be implemented and evidenced, not described. A System Security Plan written for an environment where the controls are not actually operating documents your non-compliance rather than fixing it. Always confirm who implements the technical controls.

Keep exploring

Ready for a clear path forward?

Start with a Navigate Clarity Conversation. A free 30 minute review of where you stand and what to do first.

Start with a Clarity Conversation