CMMC Consultant for DoD Contractors
A Cyber AB Registered Practitioner Organization (RPO #1449) guiding defense contractors through CMMC Level 1, Level 2, and Level 3 readiness. Gap assessments, System Security Plans, POA&M management, and mock C3PAO assessments performed by a fully credentialed CMMC-RP team based in Raleigh, North Carolina.
The Short Version
- A CMMC consultant is not a certifier. Consultants prepare you. Only a C3PAO can certify you. Anyone blurring that line is a red flag.
- RPO status is the first filter. Petronella Technology Group is Registered Practitioner Organization #1449 with the Cyber AB. Generic IT firms without RPO listing should not be authoring your SSP.
- Petronella consults all three CMMC levels (Level 1 self-assessment, Level 2 third-party, Level 3 government-led) and authors the artifacts a C3PAO will actually score against.
- A typical engagement runs Discovery (week 1), Gap Analysis (weeks 2-4), Remediation Sprint (weeks 5-12), and C3PAO Readiness Handoff (weeks 13-14).
- Pricing is custom. Scope depends on enclave size, CUI flow, asset count, and starting SPRS score. Use the SPRS calculator to estimate where you are today, then call (919) 348-4912 for a fixed-scope quote.
What a CMMC Consultant Actually Does (and Doesn't Do)
There is widespread confusion about which firm does which job inside the CMMC ecosystem. Get this wrong and you will hire the wrong type of partner for the wrong stage of work.
CMMC Consultant (RPO / RP)
Prepares the contractor to be assessed. Authors policies, builds the System Security Plan, manages Plans of Action and Milestones, runs internal gap analysis, coaches engineering and compliance staff, and rehearses the assessment with a mock walkthrough.
- Petronella Technology Group performs this role for CMMC Levels 1, 2, and 3
- Credentialed as Cyber AB RPO #1449
- Cannot legally certify the contractor
C3PAO (Certified Third Party Assessor)
Performs the formal CMMC Level 2 assessment that yields a certification status with the DoD. Independence rules prevent a single firm from both preparing and assessing the same contractor for Level 2 within the same window.
- Listed in the Cyber AB Marketplace under "C3PAO"
- Assessors hold the CCA (Certified CMMC Assessor) credential
- Petronella maintains working relationships and refers clients
Managed Service Provider (MSP)
Operates the IT and security stack day-to-day. An MSP can implement controls but does not author the compliance program. Hiring only an MSP for CMMC almost always produces a thin SSP, missing artifacts, and weak SPRS scoring.
- Petronella performs MSP and MSSP work in addition to consulting
- If a generic MSP says "we do CMMC" but has no RPO listing, this is a red flag
- Implementation without an assessor-grade SSP fails at the C3PAO door
Concrete deliverables a CMMC consultant should produce
If a prospective consultant cannot quote against this list, the engagement is undersized. Anything labeled "we will help you with CMMC" without enumerated deliverables and time estimates is sales copy, not a scope of work. Below is the floor for a CMMC Level 2 readiness engagement. Level 1 is lighter; Level 3 is significantly heavier and overlays NIST SP 800-172.
- Asset inventory and CUI flow map. Every endpoint, server, cloud tenant, SaaS app, and movable medium that processes, stores, or transmits Controlled Unclassified Information, with a diagram of how CUI moves through the environment.
- System Security Plan (SSP). One authoritative document covering all 110 NIST SP 800-171 controls (for Level 2), each with a description of how the control is implemented in your environment, by whom, and with what evidence.
- Plan of Action and Milestones (POA&M). A live register of open control gaps with owners, target dates, and dependency notes. Properly maintained POA&Ms are required at assessment.
- Policy library. 14 NIST 800-171 control family policies plus an overarching information security policy, an acceptable use policy, a media protection policy, and an incident response plan tested at least annually.
- SPRS score authoring and submission. A defensible score posted to the Supplier Performance Risk System reflecting the current state of the SSP, not an optimistic one.
- Mock assessment. A C3PAO-style walkthrough using the actual CMMC Assessment Process (CAP) to surface gaps in evidence, interview readiness, and artifact organization before the real assessment.
- Control implementation guidance. Technical assistance with multifactor authentication scope, FIPS-validated cryptography, audit logging coverage, configuration baselines, and identity lifecycle hardening.
- Training and tabletop facilitation. Annual security awareness training, role-based privileged user training, and incident response tabletop exercises with after-action reports.
What a CMMC consultant should not do
An honest consultant will tell you up front what falls outside the engagement. Petronella does not perform Level 2 third-party assessments for clients we have prepared, because Cyber AB independence rules prohibit it. We do not promise "guaranteed pass" outcomes; the C3PAO is the only authority and any guarantee is a sales fiction. We do not paper over real engineering gaps with policy text. And we do not bill for "compliance" while leaving the underlying technical stack unprepared to actually meet a control under interview.
The RPO #1449 Difference
Anyone can call themselves a "CMMC consultant." The Cyber AB Marketplace is the only authoritative list of firms credentialed to prepare contractors for assessment. Petronella Technology Group is listed there as Registered Practitioner Organization #1449.
Cyber AB Registered Practitioner Organization
An RPO is a company authorized by the Cyber AB (the official accreditation body of the CMMC ecosystem) to provide implementation, consulting, and advisory services to organizations preparing for CMMC. RPOs sign a code of professional conduct and their practitioners individually hold the CMMC-RP (Registered Practitioner) credential. Confirm any consultant's status at the official Cyber AB Marketplace.
What RPO status actually means
RPO is not a one-time badge. It is an active listing maintained by the Cyber AB that includes a code of professional conduct, a complaints process, and recognition that the firm's practitioners have taken the CMMC-RP training and exam. When you hire a non-RPO consultant, none of these guardrails apply. There is no professional body holding them accountable for misrepresenting CMMC requirements, and there is no path to escalate when an engagement underdelivers.
The CMMC-RP is the entry-level practitioner credential. Above it sit Certified CMMC Professional (CCP) and Certified CMMC Assessor (CCA). RPs prepare; CCPs and CCAs assess. A CMMC consultant should be staffed primarily with RPs and CCPs because preparation is the work product, not assessment.
Why Petronella is staffed for this work
Every practitioner on the Petronella compliance team holds the CMMC-RP designation, not just the principal. That includes Blake Rea, Justin Summers, and Jonathan Wood. Craig Petronella, the firm's founder, holds CMMC-RP alongside CCNA, CWNE, Digital Forensic Examiner (DFE) #604180, and is MIT-Certified in AI and Blockchain. The forensic background matters: CMMC Level 2 requires audit logging, incident response, and evidence preservation that mirror the chain-of-custody discipline used in digital forensics work. A consultant who has never collected an evidentiary disk image will write a thinner Incident Response Plan than one who has.
Petronella has operated as a North Carolina IT and security firm since 2002 with a BBB A+ rating, headquartered at 5540 Centerview Dr., Suite 200, Raleigh, NC 27606. That 23-plus-year operating history is itself a control input: CMMC assessors look at organizational maturity, not just paperwork. Firms that stood up an "RPO division" in the last 18 months to chase the CMMC dollar are working from a thinner bench than a firm that has been engineering, defending, and forensically investigating networks for two decades.
What changes when your consultant is an RPO
- Cyber AB listed and verifiable. Your procurement team can pull the listing as an objective credential.
- Code of professional conduct. Limits what the consultant can claim about your readiness publicly or in proposals.
- Trained practitioners. The team has taken the CMMC-RP coursework and exam, not just an internal CMMC overview.
- Curriculum-aligned vocabulary. The SSP, POA&M, and CAP language used in your documentation aligns with what assessors are trained to read.
- Cleaner referral path to C3PAOs. RPOs work alongside C3PAOs constantly and know which assessors fit your contract type, geography, and CUI profile.
For a side-by-side view of how this differs from template-only providers and from boutique alternatives, see our 2026 CMMC consultant roundup, the ComplianceForge alternative comparison, and the Summit7 alternative comparison.
Petronella's 4-Phase CMMC Engagement
A typical CMMC Level 2 readiness engagement runs 12 to 14 weeks for a mid-size contractor. Larger enclaves, multi-site environments, or Level 3 scopes extend that timeline. Below is the phase structure with concrete deliverables.
Discovery & Scoping
Kickoff workshop with executive sponsor, IT lead, and compliance owner. Identify which DoD contracts impose CMMC, the contract clauses involved, and the realistic target level and date.
- Contract clause inventory (DFARS 252.204-7012, 7019, 7020, 7021)
- Stakeholder identification
- Preliminary CUI footprint sketch
- Engagement charter and signed scope of work
Gap Analysis
Control-by-control assessment against NIST SP 800-171 (for Level 2). Asset inventory, CUI flow mapping, evidence collection, interview-based control walkthroughs, and a baselined SPRS score.
- Asset inventory and CUI scope diagram
- 110-control assessment matrix with current state
- Baseline SPRS score and supporting calculation
- Prioritized remediation backlog
Remediation Sprint
Authoring of all 14 policy families, full SSP build-out, live POA&M, and engineering work to close technical gaps including MFA scope, FIPS-validated crypto, audit logging coverage, and configuration baselines.
- SSP authored to assessor standard
- POA&M with owners and target dates
- Policy library (14 families plus IRP and AUP)
- Technical control implementation guidance
- Annual training delivered, IR tabletop facilitated
C3PAO Readiness Handoff
Mock assessment using the Cyber AB Assessment Process (CAP). Evidence package staging, interview rehearsal, final SPRS score posting, and a curated C3PAO referral aligned to your contract type and CUI profile.
- Mock CAP walkthrough with findings memo
- Evidence package indexed by control
- Final SPRS score posted
- C3PAO shortlist and warm introductions
How the deliverables stack at the end
By the end of a Petronella engagement, the contractor walks into the C3PAO with a binder (digital or physical) containing the SSP, the POA&M, the 14-family policy library, an asset inventory, a CUI flow diagram, the SPRS calculation, an evidence index organized by control, the most recent IR tabletop after-action report, and the latest annual training completion records. Every artifact is named consistently with the control family and the practitioner who authored it. That is the operational definition of "assessment ready."
A note on retainer continuation
CMMC compliance is not a one-time project. NIST SP 800-171 requires continuous monitoring, the SSP must be a living document, and the POA&M is reviewed at least quarterly. Most clients continue with Petronella post-certification under a maintenance retainer that covers quarterly control reviews, policy refresh, training delivery, and incident response capacity. For productized continuous-control coverage between annual reviews, see ComplianceArmor.
What we look at during the first call
The discovery call is structured around a small number of high-leverage questions. We want to know which active and pipeline DoD contracts impose CMMC, which DFARS clauses appear in those contracts, where Controlled Unclassified Information lives today (on-premises file servers, Microsoft 365 GCC tenants, AWS GovCloud, contractor laptops, removable media), how many employees and contractors touch CUI, what your current SPRS score is, whether you have an existing SSP and POA&M, and what your contractual deadline is for the target CMMC level. Twenty minutes of that conversation typically gives us enough to size a fixed-scope quote within two business days.
The role of the CUI enclave
Most cost-efficient CMMC Level 2 readiness engagements rely on enclaving Controlled Unclassified Information into a narrowly scoped boundary so that the 110 controls do not have to apply across the entire enterprise network. A well-designed enclave reduces audit surface, shortens timelines, and lowers ongoing operational cost. Petronella's discovery phase identifies whether your existing environment is enclave-ready or whether the remediation sprint needs to include enclave construction, typically in a GCC High tenant or a dedicated cloud landing zone. Either path is workable; the cost and time differ significantly, and the difference is one of the biggest drivers of quote variance.
CMMC Level 1, 2, or 3 - Which Do You Need?
The level you must achieve is determined by your DoD contract clauses, the type of information you handle, and the criticality of the program. Petronella consults at all three levels.
Foundational
Applies to contractors that handle only Federal Contract Information (FCI), not Controlled Unclassified Information. Anchored in 17 basic safeguarding practices drawn from FAR 52.204-21.
- Annual self-assessment
- Affirmation by a senior official
- Light SSP and basic policies
Advanced
Required when CUI is processed, stored, or transmitted. Aligns to NIST SP 800-171 Rev 2. Most defense contracts that flow CUI require Level 2 with a triennial third-party assessment.
- Triennial C3PAO assessment
- Full SSP, POA&M, and policy library
- SPRS score posted
Expert
Applies to the most sensitive programs where Advanced Persistent Threats are a credible risk. Overlays NIST SP 800-172 on top of 800-171. Assessed by the government (DIBCAC), not a C3PAO.
- Government-led assessment
- Enhanced security requirements
- Threat hunting and deception controls
How to determine your required level
Pull every active and pipeline DoD contract and look for the following DFARS clauses. Each one signals a different aspect of CMMC scope.
- DFARS 252.204-7012 mandates safeguarding of Covered Defense Information (a category that includes CUI) and reporting of cyber incidents. Presence of this clause is the strongest single signal that CMMC Level 2 will apply.
- DFARS 252.204-7019 requires posting a current NIST SP 800-171 self-assessment score in SPRS.
- DFARS 252.204-7020 requires that the contractor allow DoD access to verify the NIST SP 800-171 implementation and flow down requirements to subcontractors.
- DFARS 252.204-7021 is the CMMC contract clause itself, naming the required CMMC level and certification cadence.
If you handle only FCI (basic contract performance information that is not for public release) and never receive a covered data marking, Level 1 is likely your destination. If you receive markings such as "CUI//SP-PROP," "CUI//SP-PRVCY," or "CUI//SP-CTI," or your contract names CMMC Level 2, you need Level 2. Level 3 is rare and almost always pre-identified by the contracting officer. When in doubt, run the SPRS calculator for a current-state estimate and then call (919) 348-4912 to walk the clause inventory with a CMMC-RP.
What Makes a Bad CMMC Consultant (Red Flags)
The CMMC market has attracted a meaningful number of firms repositioning as compliance experts without the credentialing, methodology, or assessor relationships to back it up. These are the patterns to filter on.
No RPO listing
If a consultant cannot be found in the Cyber AB Marketplace as a Registered Practitioner Organization, no professional body is holding them accountable. Ask for the exact RPO number and verify it.
No team-wide CMMC-RP designations
One credentialed principal supported by uncredentialed staff produces inconsistent work product. Ask which practitioners hold the CMMC-RP credential and which will be assigned to your engagement.
Generic IT firm pivoting to "CMMC services"
A helpdesk or break-fix firm that recently added a CMMC service line typically lacks the audit, forensics, and compliance discipline the work requires. Ask how long the firm has performed regulated-industry work (HIPAA, PCI, ISO 27001) before CMMC.
No SPRS score experience
Ask the consultant to walk through their last five SPRS score calculations. If they cannot describe the scoring methodology (110 controls, 1, 3, or 5 point weights, deductions for unmet controls) without notes, they have not done the work.
"Guaranteed pass" or "100% certification" claims
No consultant can guarantee a C3PAO outcome. The C3PAO is independent. Guarantees of this type are a sales fiction and a signal the firm does not understand the ecosystem rules.
Fabricated certifications or credentials
"CMMC-CCA" and "CMMC Certified Assessor" are real Cyber AB credentials with public listings. Phrases like "CMMC Certified Practitioner" are not. Verify each cited credential on the Cyber AB site before signing.
No real C3PAO relationships
A consultant who cannot name three C3PAOs they have referred clients to recently has not been through the assessment side of a real engagement. The handoff is part of the deliverable; weak handoffs produce poor assessment experiences.
Template-only delivery with no engineering depth
Some providers ship a policy template pack and call the engagement done. Templates without environment-specific implementation, evidence, and engineering work cannot pass a C3PAO assessment. The policy is the easy part; the proof that the policy is operating is the hard part.
Choosing a CMMC Consultant: FAQ
Eight questions buyers should be asking every CMMC consultant before signing a statement of work.
How is a CMMC consultant different from a C3PAO?
A CMMC consultant (Registered Practitioner Organization) prepares the contractor for assessment by authoring the System Security Plan, building the Plan of Action and Milestones, implementing or guiding implementation of controls, and rehearsing the assessment. A C3PAO (Certified Third Party Assessor Organization) performs the formal assessment that yields a CMMC certification with the Department of Defense. Cyber AB independence rules generally prevent the same firm from doing both for the same client in the same window for Level 2 assessments. Petronella Technology Group is an RPO and refers to C3PAOs for the formal assessment.
How long does a typical CMMC Level 2 engagement take?
A mid-size contractor with a defined CUI enclave typically runs 12 to 14 weeks from kickoff through C3PAO readiness. Larger enclaves, multi-site environments, or organizations starting from a low SPRS score extend the timeline. Level 1 engagements are lighter and often complete inside four to six weeks. Level 3 engagements are significantly heavier because of the NIST SP 800-172 overlay and the government-led assessment process.
How much does a CMMC consultant cost?
Pricing is custom and depends on enclave size, CUI flow complexity, asset count, current SPRS score, and the target CMMC level. Petronella quotes fixed-scope engagements after a no-cost discovery call and an enclave-sizing conversation. Start by running the SPRS estimator and then call (919) 348-4912 to walk through the variables that drive the quote.
Do I need an MSP, an MSSP, and a CMMC consultant?
Possibly. An MSP runs IT day to day. An MSSP runs security operations (SIEM, EDR, threat detection). A CMMC consultant authors and manages the compliance program. Petronella performs all three roles under one engagement so the SSP, the operating environment, and the security telemetry are aligned and the same team owns the evidence. Hiring three separate vendors is possible but produces handoff seams that assessors notice.
What if my SPRS score is currently negative?
Many contractors discover their first honest score is negative. That is not unusual. The scoring scale runs from 110 down through negative numbers, with point deductions for each unmet control. A negative score is a starting position, not a verdict. The remediation sprint is designed to climb to a defensible posted score before the C3PAO assessment.
What is included in the System Security Plan you author?
For CMMC Level 2, the SSP covers all 110 NIST SP 800-171 controls. For each control, the SSP describes the implementation in your specific environment, names the control owner, identifies the technology and process that satisfies it, and points to the evidence an assessor will be shown. The SSP is the single most important document the C3PAO reads and is the spine of the entire assessment.
Do you work with subcontractors and small contractors?
Yes. Many small contractors carry the same CMMC obligation as their prime because flow-down requirements pass CUI handling responsibility to subcontractors. Petronella sizes engagements appropriately and frequently works with firms in the 5 to 50 employee range that have a single CUI enclave. The SPRS calculator gives you a quick read on your current state regardless of size.
What happens after certification?
CMMC Level 2 certification lasts three years with an annual affirmation. Continuous monitoring of NIST SP 800-171 controls is required throughout. Most Petronella clients continue on a maintenance retainer covering quarterly control reviews, policy refresh, annual training delivery, IR tabletop facilitation, and incident response capacity. For productized continuous-control coverage between annual reviews, see ComplianceArmor.
Hire a Cyber AB Registered CMMC Consultant
Petronella Technology Group is Registered Practitioner Organization #1449. Schedule a no-cost discovery call to walk your DFARS clauses, scope your CUI enclave, and produce a fixed-scope CMMC Level 1, 2, or 3 readiness quote.