Cyber AB Registered Provider Organization

CMMC RPO Registered Provider Organization

A CMMC RPO is a Registered Provider Organization: a firm the Cyber AB has authorized to prepare defense contractors for CMMC assessment. An RPO builds the System Security Plan, the Plan of Action and Milestones and the evidence; only a C3PAO can assess and certify Level 2. Petronella Technology Group, Inc. is RPO #1449 and has served regulated businesses from Raleigh, North Carolina since 2002, with remote-first delivery across all 50 states.

Cyber AB RPO #1449 | BBB A+ Since 2003 | Every Practitioner CMMC-RP

Definition

What Is a CMMC RPO?

The Cyber AB marketplace is the only authoritative list of firms credentialed to prepare contractors for a CMMC assessment. Everything an RPO may and may not do follows from that listing.

A Registered Provider Organization (RPO) is a company authorized by the Cyber AB to provide implementation, consulting, and advisory services to organizations preparing for CMMC. This authorization enables RPOs to guide contractors and subcontractors in the Defense Industrial Base through the process of achieving CMMC compliance.

RPOs are bound by a code of professional conduct and are subject to a complaints process, ensuring that they maintain high standards in their work. Furthermore, practitioners within an RPO must individually hold the CMMC Registered Practitioner (CMMC-RP) credential, which is obtained after completing CMMC-RP training and passing an exam.

Role of an RPO

An RPO prepares contractors for CMMC assessment, and its authority stops there. An RPO cannot conduct the assessment or issue a certificate. This responsibility falls to a C3PAO, which can issue a CMMC Level 2 certificate after submitting results to eMASS, with the certificate then being stored in SPRS.

Petronella Technology Group, Inc. is listed on the Cyber AB marketplace as RPO #1449 and adheres to Cyber AB independence rules by not performing Level 2 assessments for clients it has prepared.

The compliance team at Petronella Technology Group consists of practitioners who all hold the CMMC-RP credential. For a comprehensive overview of the CMMC program and its requirements, visitors can refer to our CMMC compliance hub.

The practical test of an RPO is whether the people on the listing are the people who show up. Ask which practitioners will be assigned to your engagement and which of them hold the CMMC-RP credential, then check those names against the marketplace record before you sign.


Key Takeaways

CMMC RPO Essentials

Key Takeaways

  • An RPO prepares a contractor for CMMC; a C3PAO assesses and certifies Level 2. The two roles never sit inside one engagement for the same client.
  • Level 1 covers Federal Contract Information with 15 FAR 52.204-21 requirements, an annual self-assessment and an annual senior official affirmation. Level 2 covers CUI with all 110 NIST SP 800-171 Rev 2 practices in 14 domains and a C3PAO assessment for most programs.
  • The CMMC Program rule (32 CFR Part 170) took effect 2024-12-16; the acquisition rule (48 CFR, DFARS 252.204-7021) took effect 2025-11-10. On 2026-07-13 the DoD CIO suspended the 2026-11-10 Phase II deadline; Phase I self-assessments remain in force.
  • Verify any provider on the Cyber AB marketplace before signing. Petronella Technology Group, Inc. is RPO #1449, and every practitioner on its compliance team holds the CMMC-RP credential.
  • Start with the free SPRS score calculator, then a free 30-minute scoping call at 919-348-4912.

Roles

RPO vs C3PAO vs CCA vs RP: Who Does What

Four terms get mixed up constantly, and the mix-up costs contractors money when they hire the wrong kind of firm for the stage they are in.

Five terms get used interchangeably in proposals, and the mix-up costs contractors money when they hire the wrong kind of firm for the stage they are in. An RPO prepares. A C3PAO assesses. CCAs and CCPs are the people inside the C3PAO; RPs are the people inside the RPO. Here is what each one does for a Defense Industrial Base supplier.

RPO Responsibilities

An RPO, such as Petronella Technology Group, Inc., prepares contractors for CMMC assessments by authoring policies, building System Security Plans, managing Plans of Action and Milestones, conducting internal gap analyses, and rehearsing assessments with mock walkthroughs. An RPO cannot certify a contractor; its product is the readiness the assessor will test.

C3PAO Assessment Role

A C3PAO performs the formal CMMC Level 2 assessment, submitting results to eMASS, with the certificate stored in SPRS. Due to independence rules, one firm cannot both prepare and assess the same contractor for Level 2. The list of authorized C3PAOs can be found on the Cyber AB marketplace. Notably, Level 3 assessments are conducted by the government, specifically DCMA DIBCAC, rather than a C3PAO.

CCA and CCP Credentials

C3PAO assessors hold the Certified CMMC Assessor (CCA) credential, while the Certified CMMC Professional (CCP) credential sits between the Registered Practitioner (RP) and CCA. These assessors are responsible for evaluating a contractor's compliance but do not create the System Security Plan (SSP). Their role is distinct from that of RPOs, which prepare contractors for assessment.

Registered Practitioner Role

A Registered Practitioner (RP) holds an entry-level credential and is involved in preparing contractors for CMMC assessments. Given that preparation is a significant part of the work, a CMMC consultant should primarily be staffed with RPs and CCPs. Every practitioner on our compliance team holds the CMMC-RP credential, ensuring we are well-equipped to support contractors in their CMMC journey. For the full scope of our CMMC preparation services, visit our CMMC compliance consultant services page.


What RPO #1449 Delivers

What RPO #1449 Does for a Defense Industrial Base Supplier

The deliverables below are the floor for a Level 2 readiness engagement. A provider who cannot quote against a list like this is selling hours, not readiness.

As a Cyber AB Registered Provider Organization, Petronella Technology Group, Inc. helps Defense Industrial Base suppliers prepare for a CMMC Level 1 self-assessment or a Level 2 C3PAO assessment. Founder Craig Petronella holds the CMMC-RP, the CCNA and the CWNE, is an NC Licensed Digital Forensic Examiner (#604180) and holds an MIT AI certificate, and every practitioner on the compliance team holds the CMMC-RP credential, so the people who write your SSP are the people who rehearse the assessment with you.

Scoping and Enclave Design

We identify where Controlled Unclassified Information (CUI) enters, lives, and leaves a supplier's network, and decide whether to enclave it into a narrowly scoped boundary, such as a GCC High tenant or dedicated cloud landing zone. Enclaving keeps the 110 controls from applying across the entire enterprise network; it reduces audit surface, shortens timelines, and is one of the biggest drivers of quote variance. Learn more about our CMMC enclave design services.

Gap Analysis and SPRS Baseline

We conduct a 110-control assessment against NIST SP 800-171 Rev 2, and baseline your Supplier Performance Risk System (SPRS) score on the minus 203 to 110 scale, where each control weighs 1, 3 or 5 points. To get started, use our free SPRS score calculator to understand your current standing.

System Security Plan and POA&M

We write a System Security Plan (SSP) covering all 110 controls with owners and evidence pointers, along with a live Plan of Action and Milestones (POA&M). POA&Ms are allowed only for not-met requirements within the limits of 32 CFR 170.21, with a 180-day closeout, and the register is built to those rules.

Policy Library and Training

We write a policy library of 14 control-family policies, an incident response plan, acceptable use policy, and media protection policy. Additionally, we provide annual awareness training and conduct an incident response tabletop exercise with an after-action report.

Mock Assessment and C3PAO Handoff

We conduct a mock assessment using the Cyber AB CMMC Assessment Process (CAP), prepare an evidence package indexed by control, and post the final SPRS score. You also receive a C3PAO shortlist with warm introductions; we do not assess clients we have prepared, because Cyber AB independence rules prohibit it.

Documentation that Stays Current

We use our ComplianceArmor® compliance documentation platform to automate SSP authoring, POA&M tracking, and evidence repository organization. The SSP stays a living document, the POA&M is reviewed at least quarterly, and re-assessment occurs every three years.


Level 1 or Level 2

Level 1 Self-Assessment vs Level 2 Certification

The level your contracts name decides everything that follows: the information you protect, the number of requirements, who assesses you and how often.

CMMC 2.0 has three levels, which simplified the original five-level model and aligned Level 2 directly with NIST SP 800-171 Revision 2 (110 controls). Each level protects a different class of information and is verified a different way. The table shows what changes.

Factor Level 1 Level 2 Level 3
Information protected Federal Contract Information (FCI) Controlled Unclassified Information (CUI) CUI on the most sensitive programs
Requirements 15 basic safeguarding requirements from FAR 52.204-21 All 110 practices of NIST SP 800-171 Rev 2 in 14 domains Level 2 plus selected NIST SP 800-172 controls
Who assesses Annual self-assessment C3PAO assessment for most programs Government, DCMA DIBCAC
Cadence Annual self-assessment and annual senior official affirmation Triennial reassessment and annual senior official affirmation Government-led
Where results live SPRS C3PAO submits to eMASS, certificate stored in SPRS Government
What an RPO does Self-assessment package and affirmation support Full readiness through C3PAO handoff Readiness against the enhanced requirements

One wording matters here: Level 1 does not produce a certificate. Level 1 is a self-assessment with an annual affirmation by a senior official, and an RPO supports the self-assessment package and that affirmation. Level 2 is where a C3PAO assesses and a certificate is issued, and where an RPO carries a contractor through the full readiness build to the C3PAO handoff. Level 3 is rare and almost always pre-identified by the contracting officer; the CMMC Level 3 readiness page covers what changes above Level 2.

For those seeking more in-depth guidance on CMMC compliance, our CMMC Level 1 self-assessment guide covers the 15 requirements and the affirmation; our CMMC Level 2 compliance page covers the 110 practices, SPRS scoring, POA&M rules and the C3PAO assessment flow.

Not Sure Which Level Your Contracts Require?

A CMMC Registered Practitioner reads your DFARS clauses with you on a free 30-minute scoping call and tells you whether Level 1 or Level 2 applies. Twenty minutes of discovery is usually enough for a fixed-scope quote within two business days.


Rules and Dates

The 48 CFR Phase-In and the 2026 Phase II Suspension

Two rules, two effective dates, and one suspension. Here is the sequence a supplier needs to keep straight.

The CMMC Program rule, 32 CFR Part 170, was published on 2024-10-15 and took effect on 2024-12-16, defining the levels, assessment types, and POA&M limits. This rule established the foundation for the CMMC program.

A subsequent rule, the CMMC acquisition rule in 48 CFR (DFARS 252.204-7021), was published in the Federal Register on 2025-09-10 and took effect on 2025-11-10. When this clause appears in a contract or solicitation, contractors must hold a valid CMMC status at the specified level before award.

Phase II Suspension and Ongoing Requirements

On 2026-07-13, the DoD CIO announced the suspension of the 2026-11-10 Phase II deadline. Despite this change, Phase I self-assessments remain in force, and contractors must still adhere to existing requirements.

Certain requirements remain unchanged, including DFARS 252.204-7012, which still requires adequate security, including the 110 controls, and 72-hour cyber incident reporting through dibnet.dod.mil with a DoD-approved medium assurance certificate obtained in advance. Additionally, DFARS 252.204-7019 still requires a current NIST SP 800-171 assessment score in SPRS when an offer is submitted.

The SPRS score guide explains how that score is calculated and posted. The consequences of a false claim are real regardless of the CMMC calendar: DOJ Civil Cyber-Fraud Initiative settlements include Verizon ($4.09M, 2023), Penn State ($1.25M, 2024), Raytheon ($8.4M, May 2025) and Georgia Tech ($875K, 2025-09-30).

The scale of the CMMC program is significant, with a DoD-estimated 220,966 entities affected. As of the March 2026 Town Hall, there were 103 C3PAOs, and Level 2 certifications grew from 773 in January 2026 to 1,391 in May 2026, demonstrating the program's ongoing progression.


Verify Before You Sign

How to Check a CMMC RPO on the Cyber AB Marketplace

Anyone can call themselves a CMMC consultant. The marketplace listing is the objective credential your procurement team can pull.

When evaluating a CMMC Registered Provider Organization (RPO), verify the listing before you sign. The marketplace record is the objective credential your procurement team can pull, and it takes five steps:

1

Step 1: Search the Catalog: Open the Cyber AB RPO catalog and search for the provider's legal name to find their listing.

2

Step 2: Verify the RPO Number: Confirm the RPO number on the listing matches the number in the proposal, and ask for the exact number to verify it, such as our RPO #1449 listed at our RPO #1449 listing on the Cyber AB marketplace.

3

Step 3: Check Practitioner Credentials: Ask which practitioners will be assigned to your engagement and which of them hold the CMMC-RP credential, as one credentialed principal supported by uncredentialed staff can produce inconsistent work.

4

Step 4: Check for Conflicts of Interest: Check the C3PAO list separately at cyberab.org/marketplace to ensure that the firm is not both your RPO and your proposed C3PAO for the same Level 2 engagement, which would be a conflict.

5

Step 5: Be Cautious of Unrealistic Promises: Walk away from guaranteed-pass or 100 percent certification promises, and from credentials that do not exist on the Cyber AB site. The C3PAO is the only authority on the outcome, and a guarantee is a sign the firm does not understand the ecosystem rules.


Engagement

How an Engagement with RPO #1449 Runs

A typical CMMC Level 2 readiness engagement runs 12 to 14 weeks for a mid-size contractor. Larger enclaves, multi-site environments and Level 3 scopes extend that.

Here is how a readiness engagement with Petronella Technology Group, Inc. runs from the first call to life after certification. The calendar fits a mid-size contractor with a defined CUI enclave; larger or multi-site environments extend it.

1

Step 1: Free Scoping Consultation: A CMMC Registered Practitioner walks your contracts, the DFARS clauses in them, where CUI lives today, how many people touch it and your current SPRS score; twenty minutes of that is usually enough to size a fixed-scope quote within two business days.

2

Step 2: Discovery: We conduct a contract clause inventory, identify stakeholders, and create a preliminary CUI footprint during the first week of engagement.

3

Step 3: Gap Analysis: Our team performs an asset inventory, creates a CUI flow map, and develops a prioritized remediation backlog over weeks 2-4.

4

Step 4: Remediation Sprint: We work on creating an SSP, live POA&M, and 14-family policy library, and complete technical work on MFA scope, FIPS-validated cryptography, and audit logging coverage during weeks 5-12.

5

Step 5: C3PAO Readiness Handoff: Our team conducts a mock CAP walkthrough, prepares an evidence package, and posts the final SPRS score over weeks 13-14.

6

Step 6: After Certification: The SSP remains a living document, the POA&M is reviewed at least quarterly, the senior official affirms annually, re-assessment occurs every three years, and most clients continue under a maintenance retainer covering control reviews, policy refresh, training, and incident response capacity after certification.


AI and Cybersecurity Combined

Private AI and 24/7 Detection Inside a CMMC Boundary

Petronella Technology Group, Inc. leads with AI and cybersecurity combined, and the CMMC boundary is where that matters most: the data cannot leave.

Petronella Technology Group, Inc. designs, builds, and operates private AI clusters for regulated businesses (see the AI services hub), so a supplier can use AI on Controlled Unclassified Information (CUI) without sending it to a public model.

The need for a private AI boundary is driven by regulatory requirements. NIST SP 800-171 mandates FIPS-validated cryptography to protect CUI, while DFARS 252.204-7012 requires cloud service providers handling covered defense information to meet FedRAMP Moderate or equivalency standards. Furthermore, the DoD CIO FAQ clarifies that encrypted CUI is still considered CUI and necessitates FedRAMP Moderate or equivalency even in a cloud environment. For more information on private AI solutions, visit our private AI solutions page.

Detection and Response

The company's private AI cluster and 24/7 AI-plus-human hybrid threat analysis stack support managed detection and response for Defense Industrial Base and healthcare clients. The hybrid SOC runs ten-plus production AI agents; the AI never closes a ticket on its own, never touches production systems without human authorization, and every action is logged for CMMC and HIPAA audit. Learn more about our managed detection and response capabilities.

The team that writes your incident response plan also runs the detection that produces the audit-log and incident evidence a C3PAO asks for, including the 72-hour DoD reporting path and the 90-day preservation of affected system images.

Private AI, managed detection and response, and ComplianceArmor® documentation come from one firm, which means the SSP, the operating environment and the security telemetry describe the same system when the assessor compares them.


Why Petronella Technology Group, Inc.

Experience Behind RPO #1449

A Registered Provider Organization is only as good as the people on the listing.

Petronella Technology Group, Inc. has been based in Raleigh, North Carolina since 2002, earning a BBB A+ rating continuously since 2003. Some clients who started in 2003 are still clients. You can learn more about our company history and values on our about page.

Our founder, Craig Petronella, has 30+ years of experience and holds the CMMC-RP credential, the CCNA and the CWNE, an NC Licensed Digital Forensic Examiner license (#604180), and an MIT AI certificate. The forensic credential matters more for CMMC than it first appears.

Forensics in CMMC

Level 2 CMMC requirements include audit logging, incident response, and evidence preservation. Similarly, DFARS 252.204-7012 mandates preserving system images and monitoring data for at least 90 days after an incident, as well as submitting isolated malicious software to the government. A consultant with forensic experience can craft a more effective incident response plan, having collected and analyzed evidentiary disk images in the past.

Every engineer assigned to a defense client holds the CMMC-RP credential, and we do not promise guaranteed certification outcomes, as only a C3PAO can grant certification. Our role is to prepare contractors for assessment, not to certify them.

If you are still unsure whether your organization handles Controlled Unclassified Information (CUI), we recommend reviewing our Controlled Unclassified Information guide to determine your obligations under CMMC and other relevant regulations.



FAQ

CMMC RPO Questions

What is a CMMC RPO?

A CMMC RPO is a Registered Provider Organization authorized by the Cyber AB to provide implementation, consulting and advisory services to organizations preparing for CMMC, with practitioners holding the CMMC-RP credential, such as Petronella Technology Group, Inc., which is RPO #1449.

What is the difference between an RPO and a C3PAO?

An RPO prepares a contractor for CMMC assessment by developing an SSP, POA&M, and performing gap analysis and mock assessments, while a C3PAO performs the actual Level 2 assessment, submits results to eMASS, and has the certificate stored in SPRS, with independence rules keeping these roles separate.

Can a CMMC RPO certify my company?

No, only a C3PAO can issue a Level 2 certificate, and Level 3 is assessed by DCMA DIBCAC, while Level 1 is an annual self-assessment with a senior official affirmation, not a certification.

How do I verify that a company is really a CMMC RPO?

To verify, search the Cyber AB marketplace RPO catalog, match the RPO number to the proposal, and ask which assigned practitioners hold the CMMC-RP credential, such as our RPO #1449.

Do I need an RPO for a CMMC Level 1 self-assessment?

An RPO is not required for a CMMC Level 1 self-assessment, which involves 15 FAR 52.204-21 requirements, but an RPO can help scope FCI systems and produce the self-assessment package and affirmation support.

What does a CMMC RPO engagement cost?

The first call is a free 30-minute scoping consultation, and twenty minutes of discovery typically produces a fixed-scope quote within two business days, driven by factors like enclave size, CUI flow, asset count, and starting SPRS score.

How long does CMMC Level 2 readiness take with an RPO?

CMMC Level 2 readiness with an RPO typically takes 12 to 14 weeks for a mid-size contractor, with the full path from gap assessment to C3PAO-ready taking 6 to 18 months, depending on starting posture and CUI environment complexity.

Is CMMC still required after the 2026 Phase II suspension?

Yes, despite the 2026-07-13 suspension of the Phase II deadline, Phase I self-assessments remain in force, and DFARS 252.204-7012, 7019, and 7020 still apply, with the 48 CFR rule having taken effect on 2025-11-10.

Does Petronella Technology Group, Inc. work with contractors outside North Carolina?

Yes, Petronella Technology Group, Inc. delivers services remote-first across all 50 states from its Raleigh headquarters, and can be reached at 919-348-4912 for more information.

Work with Cyber AB RPO #1449

Petronella Technology Group, Inc., 5540 Centerview Dr., Suite 200, Raleigh, NC 27606. CMMC readiness for defense suppliers nationwide since 2002. Last updated September 10, 2026.