What Is a CMMC Registered Practitioner?
Roles, Scope & How an RP Helps You Prepare
A CMMC Registered Practitioner (RP) is an individual credentialed by the Cyber Accreditation Body (Cyber AB) to provide non-certified advisory services to defense contractors preparing for CMMC compliance. RPs help organizations understand requirements, identify gaps, prepare evidence, and build readiness — but they do not conduct official assessments. With CMMC requirements now appearing in applicable DoD solicitations and contracts, understanding the RP's role is the first step toward choosing the right compliance partner.
By Dan Pitre, CMMC Registered Practitioner · Cloud Solutions Consulting · Published March 2026
What Does a CMMC RP Do?
From the practitioner's perspective, here's the practical scope of RP advisory services. An RP works alongside your team to prepare your organization for CMMC — at whichever level applies to your contracts.
Gap analysis against CMMC assessment objectives at your required level
Scoping assistance — identifying your FCI vs. CUI boundary and in-scope systems
Evidence preparation and documentation guidance for each control family
System Security Plan (SSP) and Plan of Action & Milestones (POA&M) development support
SPRS submission readiness and affirming official attestation preparation
Annual reaffirmation planning and ongoing compliance monitoring
The Advisory Boundary
An RP advises — we help you prepare, document, and build the evidence base. We do not conduct official CMMC assessments. Official Level 2 certification assessments are conducted by a C3PAO assessment team in accordance with 32 CFR Part 170 requirements. This separation means there is no conflict of interest between the team preparing you and the organization that will ultimately assess you.
The CMMC Ecosystem — Who Does What
Think of RPs as your coach and C3PAOs as your referee. You want the coach to prepare you thoroughly before the referee arrives.
2026 update: ISACA has been authorized as the CAICO (Certified Assessment and Certification Infrastructure Organization) for CMMC professional certifications (CCP, CCA, LCCA), with full transition completing April 1, 2026. This is a credential-administration change — it does not change CMMC contracting requirements under 32 CFR or 48 CFR. RP and RPA credentials remain under Cyber AB.
| Role | Type | What They Do | Can Assess? | Credential / Authorization Authority |
|---|---|---|---|---|
| RPRegistered Practitioner | Individual | Advisory, gap analysis, readiness preparation | No | Cyber AB |
| RPARegistered Practitioner Advanced | Individual | Advanced implementation guidance (NIST 800-171 depth) | No | Cyber AB |
| RPORegistered Practitioner Organization | Organization | Delivers non-certified advisory services through employment of RPs/RPAs | No | Cyber AB |
| CCPCertified CMMC Professional | Individual | Assessment participation, Level 1 & Level 2 support | Yes | Administered by CAICO (ISACA; transition completing April 1, 2026) |
| CCACertified CMMC Assessor | Individual | Lead assessor for Level 2 certification assessments | Yes | Administered by CAICO (ISACA; transition completing April 1, 2026) |
| C3PAOCertified Third-Party Assessment Organization | Organization | Conducts official Level 2 certification assessments | Yes | Accredited by Accreditation Body (Cyber AB) under DoD CMMC PMO oversight* DIBCAC is the government assessment body for Level 3 and is referenced in certain C3PAO-related process requirements. |
| LTPLicensed Training Provider | Organization | Delivers approved credential training | N/A | Cyber AB |
Advisory, gap analysis, readiness preparation
Advanced implementation guidance (NIST 800-171 depth)
Delivers non-certified advisory services through employment of RPs/RPAs
Assessment participation, Level 1 & Level 2 support
Lead assessor for Level 2 certification assessments
Conducts official Level 2 certification assessments
* DIBCAC is the government assessment body for Level 3 and is referenced in certain C3PAO-related process requirements.
Delivers approved credential training
Why Hire an RP Before Your Assessment
Engaging an RP early in your CMMC journey is a strategic investment — not an overhead cost. Here's the business case.
Avoid Costly Surprises
Independent Level 2 certification assessments represent a significant investment that varies widely by scope and organizational complexity. An RP identifies documentation gaps and remediation needs before you engage a C3PAO — so your assessment investment isn't wasted on a preventable failure.
Navigate Complex Requirements
Level 1 requires meeting 59 assessment-objective statements across 15 controls aligned to FAR 52.204-21. Level 2 scales to 320 NIST SP 800-171A (June 2018) assessment objectives. An RP translates federal regulatory prose into practical actions for your specific environment. (Note: CMMC Level 2 assessments follow the NIST SP 800-171A edition incorporated by reference in 32 CFR Part 170, even though NIST has since published newer revisions.)
Reduce Attestation Risk
CMMC requires an affirming official to submit affirmations in the Supplier Performance Risk System (SPRS) after assessments and annually. Inaccurate certifications to the government can create serious contractual and legal exposure. An RP helps ensure your attestation is thorough and defensible. This is not legal advice — consult qualified counsel for legal guidance on your specific situation.
Accelerate Your Timeline
Phase 2 begins November 10, 2026 — one year after Phase 1 began — broadening the expected use of Level 2 certification assessments in applicable solicitations and contracts. Contractors who wait until Q3 2026 to start readiness preparation will face a crowded marketplace of RPs and C3PAOs. Starting now provides margin.
What to Look for When Hiring a CMMC RP
Not all RPs are the same. Here are four criteria to evaluate before engaging a compliance advisor.
Verify the Credential
Verify an RP's status via the Cyber AB Marketplace directory (cyberab.org) or request proof of current listing.
Ask About Specialization
Some RPs focus on Level 1 for small contractors; others handle Level 2 CUI environments. Match the RP's experience to your compliance level and organizational complexity.
Look for Practitioner, Not Just Platform
SaaS tools help with workflow, but CMMC readiness requires human judgment — evidence evaluation, scoping decisions, remediation prioritization. Look for practitioner-led engagement.
Check for Adjacent Expertise
Contractors often face overlapping compliance requirements — HIPAA, FTC Safeguards, DFARS 252.204-7012. An RP with cross-compliance experience reduces total advisory cost and avoids duplicated effort.
CSC's CMMC RP Approach
Dan Pitre, CMMC Registered Practitioner
Cyber AB Credentialed · Cloud Solutions Consulting
CSC's CMMC advisory services are led by a CMMC Registered Practitioner credentialed through the Cyber AB. Our approach combines RP expertise with vCISO-level strategic oversight — CMMC readiness isn't just a compliance checkbox exercise, it's an opportunity to build a durable security posture that serves your organization beyond the certification.
We cover Level 1 self-attestation support and Level 2 readiness preparation, leveraging compliance tooling that maps directly to CMMC assessment objectives. For organizations with overlapping compliance requirements — HIPAA, FTC Safeguards, DFARS 252.204-7012 — our cross-framework experience means less duplicated effort and a unified compliance strategy.
Frequently Asked Questions
Common questions about CMMC Registered Practitioners and the advisory process.
No. RPs provide non-certified advisory and readiness support. Official Level 2 certification assessments are conducted by a C3PAO assessment team in accordance with 32 CFR Part 170 requirements. The RP's role is to prepare you so the assessment goes smoothly — gap analysis, evidence preparation, and remediation guidance.
As of December 2025, Cyber AB Town Hall reporting indicated approximately 1,900+ Registered Practitioners. Not all are actively practicing, and specializations vary widely. The Cyber AB Marketplace at cyberab.org is the authoritative directory for verifying current RP credentials and finding practitioners.
An RP (Registered Practitioner) is an individual credential — one person who has completed Cyber AB-approved training and passed the exam. An RPO (Registered Practitioner Organization) delivers non-certified advisory services through employment of RPs or RPAs. RPOs do not conduct Certified CMMC Assessments.
Level 1 is a self-assessment — no third-party certification assessment is required. Organizations may engage third parties to assist, but Level 1 remains a self-assessment and does not result in certification. That said, Level 1 still requires meeting 15 controls across 59 assessment-objective statements and an affirming official's attestation. An RP helps ensure your self-assessment is thorough, your evidence is defensible, and your SPRS submission is accurate.
Costs vary widely based on scope, required certification level, and organizational complexity. Level 1 readiness engagements for small contractors are generally a focused engagement. Level 2 preparations involve significantly more scope. A consultation with a CMMC Registered Practitioner can help scope your specific environment and provide a tailored estimate before any commitment.
Ready to Start Your CMMC Journey?
Schedule a consultation with CSC's CMMC Registered Practitioner to evaluate your compliance posture, identify gaps, and build a readiness roadmap — before Phase 2 broadens Level 2 certification requirements in November 2026.