The Verification Problem Most Contractors Skip
The CMMC ecosystem has created a new category of professional services for the defense industrial base. Contractors pursuing Level 2 certification need practitioners who can guide them through readiness, build their documentation, configure their technical controls, and prepare them for a C3PAO assessment. The demand for these services is growing faster than the supply of credentialed practitioners, and that imbalance has created an environment where it is difficult for a contractor to distinguish between a qualified consultant and one who is not what they claim to be.
The consequences of selecting the wrong consultant are not limited to wasted fees. An engagement with an unqualified or conflicted practitioner can result in documentation that does not survive assessment scrutiny, technical configurations that must be reworked, delayed contract eligibility while the organization starts over with a credible practitioner, or in the most serious cases, an assessment that is later invalidated due to conflict of interest violations. These are business risks, not just compliance inconveniences. The reassuring part is that verification takes less than two minutes and requires no technical expertise. The contractor simply has to know where to look.
The Credential Determines the Role
The Cyber AB, formerly the CMMC Accreditation Body, is the sole organization authorized by the Department of Defense to credential individuals and accredit organizations within the CMMC ecosystem. Every legitimate CMMC credential traces back to the Cyber AB, and understanding the roles is the first step in evaluating whether a consultant is operating within their authorized scope. The Registered Practitioner and Registered Practitioner Advanced are the enablement credentials. They exist for the specific purpose of helping contractors with readiness, implementation, and preparation for assessment. The distinction between RP and RPA reflects depth of demonstrated knowledge, not a change in the type of work the practitioner is authorized to perform.
The Certified CMMC Assessor and the Certified CMMC Professional operate on the assessment side. The CCA conducts the formal assessments that determine whether an organization meets the requirements for certification, and the CCP carries foundational knowledge and may serve in support or advisory roles. The C3PAO is not an individual at all. It is the organization accredited to conduct official assessments, and only a C3PAO can issue the results that lead to certification. No individual practitioner, regardless of credential, can certify an organization alone. This structural separation exists to protect the integrity of the certification process, and it is the reason a single practitioner should not both build an organization's controls and judge whether those controls are adequate.
The credential names the role. An RP or RPA is authorized to provide readiness, enablement, and implementation services. A CCA or CCP operates on the assessment side. A consultant who cannot or will not state which specific credential they hold has told you something.
No one on the enablement side can guarantee certification. Certification is determined by an independent C3PAO assessment team. A consultant who guarantees the outcome is either misrepresenting the process or does not understand it.
One Public Registry, One Code of Conduct
The CyberAB maintains a public, searchable registry called the Marketplace, accessible at cyberab.org, and it is the only authoritative source for confirming whether an individual holds a current CMMC credential. It lists the practitioner's name, credential type, and status. Before any engagement, search the Marketplace and confirm that what you find matches what the consultant has represented. There are legitimate reasons a credentialed practitioner may not yet appear, including the Tier 3 background investigation backlog, the December 2024 delta training suspension, the ISACA credential transition that took effect on April 1, 2026, and the ordinary few-day gap between passing an exam and being listed. A credible practitioner in any of these situations can describe exactly where they are in the process and name their training provider. What should concern a contractor is a practitioner who has claimed a credential for months, cannot be found, and cannot explain why in specific, verifiable terms.
Every credentialed practitioner is also bound by the CyberAB Code of Professional Conduct, which requires practitioners to operate within the scope of their credential, to represent their qualifications accurately, to protect client confidentiality, and to disclose conflicts of interest. The code does not merely discourage conflicts. It requires practitioners to disclose them and, depending on their nature, to mitigate or avoid them. Misrepresenting a credential, whether by claiming one never issued or by presenting a lapsed credential as active, is a direct violation that the CyberAB will accept a complaint on.
The C3PAO Consulting and Referral Question
Some contractors report being approached by a C3PAO that offers to prepare the organization for assessment, with the understanding that a different C3PAO, described as a colleague or associate, will then conduct the formal assessment. This arrangement deserves careful scrutiny. The Code of Professional Conduct prohibits a C3PAO and all of its assessment team members from assessing an organization they previously served as a consultant, and the prohibition extends for three years. The referral version is one step removed, but it raises the same concern, because the referring organization holds a reputational and financial interest in the assessment going well, and a reciprocal referral relationship creates a mutual dependency that undermines the independence the ecosystem was built to protect.
The code resolves this through disclosure. A referral relationship between two C3PAOs is a business relationship, and the failure to disclose it is itself a violation regardless of whether the underlying arrangement would have been permissible if transparent. If a consultant tells you they can get you assessed faster through a relationship with another C3PAO, ask direct questions about the nature of the relationship, whether it is reciprocal, and whether it has been disclosed to the CyberAB. Assessment results do not exist in a vacuum. They are submitted into the CMMC instantiation of eMASS, where the Department of Defense has direct visibility, and an assessment later found to have been conducted under a conflict can be invalidated, taking the certification the contractor relied upon with it.
Six verification steps, none requiring technical expertise. Search the Marketplace by name. Confirm the credential type matches the service. Ask about organizational affiliation and how any C3PAO conflict is managed. Ask for references. Ask a question specific to your environment. Verify any outside credentials such as CISSP, CISA, or CISM through the issuing body.
The red flags. A practitioner who cannot be found and cannot explain why, who offers both readiness and assessment to the same organization, who guarantees certification, who is vague about their credential type, who lists certifications that cannot be independently verified, who recommends a specific product without disclosing a financial relationship, or who cannot describe implementation specifics for your environment.
What a Credible Engagement Looks Like
For comparison, a legitimate readiness engagement has a recognizable shape. The practitioner's credential is verifiable in the Marketplace and matches the services offered. The engagement opens with a scoping discussion of CUI flows, asset inventory, and network architecture before any work begins. The practitioner explains the separation between enablement and assessment and does not promise a specific outcome. The work produces tangible deliverables, a System Security Plan, a Plan of Action and Milestones, supporting policies, and evidence artifacts, rather than general advice. The practitioner is transparent about fees, affiliation, and any vendor relationships, and is willing to explain their approach to specific controls. None of these characteristics require the contractor to have technical expertise to evaluate. They are observable through normal business due diligence, and a credible practitioner will welcome the scrutiny.
Download the Full White Paper
The full paper details each of the five credentialed roles, the regulatory basis for the enablement and assessment boundary under 32 CFR Part 170, the full C3PAO conflict and referral analysis with the Code of Professional Conduct citations, the legitimate processing gaps that explain a Marketplace absence, the six verification steps in full, the complete set of red flags, and the characteristics of a credible engagement. All claims are sourced to the CMMC Final Rule and the CyberAB Code of Professional Conduct v2.0.
The CMMC Decision, Second Edition
Strategic guide for CEOs and senior executives of small and mid-sized defense contractors. Level determination, enforcement timelines, certification economics, and the governance questions executives cannot delegate to the IT organization.
Read More →