How do I choose a CMMC consultant?
Choose a CMMC consultant by verifying their listing in The Cyber AB's CMMC Marketplace at cyberab.org, confirming they will not also act as your assessor, and testing their delivery with sample SSPs, a named lead and a scope tied to the 110 NIST SP 800-171 requirements. Under 32 CFR 170, anyone who prepared you cannot join your certification assessment for three years.
Know the roles before you compare firms
The CMMC ecosystem separates people who help you prepare from people who assess you. The Cyber AB, the CMMC accreditation body, lists credentialed individuals and organizations in its CMMC Marketplace, which is the place to verify any claim a consultant makes.
- Registered Practitioner (RP) and RP Advanced: trained individuals who provide consultative preparation services.
- Registered Practitioner Organization (RPO): a firm that delivers advisory services through RPs. The Cyber AB states RPOs do not conduct certified CMMC assessments.
- Certified CMMC Professional (CCP): under 32 CFR 170.13, provides advice, consulting and recommendations and can serve on assessment teams under a certified assessor.
- C3PAO: an accredited organization that conducts Level 2 certification assessments with Certified CMMC Assessors.
The independence rule
32 CFR 170.8 requires the accreditation body's conflict-of-interest policy to prohibit ecosystem members from taking part in a Level 2 certification assessment where they served as a consultant preparing that organization for any CMMC assessment within the previous three years. In practice: hire your consultant and your C3PAO separately, and be wary of any firm that offers both for the same engagement.
While Phase 2 is suspended, new DoD solicitations call only for self-assessments, so you may not need a C3PAO now. The rule still matters, because choosing a consultant today can rule that firm out as your assessor later.
Questions to ask
- Which of your people are listed in the CMMC Marketplace, and who will lead our project?
- Can we see a redacted SSP, POA&M and scoping diagram you produced?
- How do you scope CUI and decide between an enclave and an enterprise boundary?
- Will you implement controls or only advise, and who operates them afterward?
- How do you score against the DoD methodology, and how do you treat partially met requirements?
- What exactly do we receive, and in what form, at the end?
Red flags
- A promise that you will pass or be certified
- An offer to prepare you and then certify you
- Selling a software tool or template pack as compliance by itself
- Treating NIST SP 800-171 Rev 3 as the CMMC baseline, when the rule uses Rev 2
- Pressure tactics built on deadlines that the July 2026 suspension has changed
- Wanting to submit your SPRS score or sign the affirmation, which belong to your senior official
Common follow-up questions
Is a Registered Practitioner the same as a certified assessor?
No. Registered Practitioners provide preparation and advisory services. Certified CMMC Assessors work for C3PAOs and conduct Level 2 certification assessments. A Certified CMMC Professional can advise clients and can join an assessment team, but the conflict-of-interest rules apply.
Can my managed IT provider be my CMMC consultant?
Yes, and keeping documentation and operations in one team can help. Confirm that its people hold Marketplace credentials or equivalent experience, that its own tools meet NIST SP 800-171 because they sit in your scope, and that it will not be your C3PAO.
How do I verify a consultant's credentials?
Search The Cyber AB's CMMC Marketplace at cyberab.org for the individual and the organization, and check that the listing is current. Ask for the names of the people who will do your work, not just the firm's status.
LAN Service Group provides ISSO-led CMMC readiness for small and mid-size defense suppliers, from CUI scoping and gap assessment to SSP and POA&M development, remediation and assessment preparation.
Talk to LAN Service Group (888) 281-7243