25+ Years Security Experience•Enterprise Security Leadership
Written by a CMMC Registered Practitioner

What Is a CMMC Registered Practitioner?

Roles, Scope & How an RP Helps You Prepare

A CMMC Registered Practitioner (RP) is an individual credentialed by the Cyber Accreditation Body (Cyber AB) to provide non-certified advisory services to defense contractors preparing for CMMC compliance. RPs help organizations understand requirements, identify gaps, prepare evidence, and build readiness — but they do not conduct official assessments. With CMMC requirements now appearing in applicable DoD solicitations and contracts, understanding the RP's role is the first step toward choosing the right compliance partner.

By Dan Pitre, CMMC Registered Practitioner · Cloud Solutions Consulting · Published March 2026

What Does a CMMC RP Do?

From the practitioner's perspective, here's the practical scope of RP advisory services. An RP works alongside your team to prepare your organization for CMMC — at whichever level applies to your contracts.

Gap analysis against CMMC assessment objectives at your required level

Scoping assistance — identifying your FCI vs. CUI boundary and in-scope systems

Evidence preparation and documentation guidance for each control family

System Security Plan (SSP) and Plan of Action & Milestones (POA&M) development support

SPRS submission readiness and affirming official attestation preparation

Annual reaffirmation planning and ongoing compliance monitoring

The Advisory Boundary

An RP advises — we help you prepare, document, and build the evidence base. We do not conduct official CMMC assessments. Official Level 2 certification assessments are conducted by a C3PAO assessment team in accordance with 32 CFR Part 170 requirements. This separation means there is no conflict of interest between the team preparing you and the organization that will ultimately assess you.

The CMMC Ecosystem — Who Does What

Think of RPs as your coach and C3PAOs as your referee. You want the coach to prepare you thoroughly before the referee arrives.

2026 update: ISACA has been authorized as the CAICO (Certified Assessment and Certification Infrastructure Organization) for CMMC professional certifications (CCP, CCA, LCCA), with full transition completing April 1, 2026. This is a credential-administration change — it does not change CMMC contracting requirements under 32 CFR or 48 CFR. RP and RPA credentials remain under Cyber AB.

RPRegistered Practitioner
Individual

Advisory, gap analysis, readiness preparation

✗ Advisory onlyCyber AB
RPARegistered Practitioner Advanced
Individual

Advanced implementation guidance (NIST 800-171 depth)

✗ Advisory onlyCyber AB
RPORegistered Practitioner Organization
Organization

Delivers non-certified advisory services through employment of RPs/RPAs

✗ Advisory onlyCyber AB
CCPCertified CMMC Professional
Individual

Assessment participation, Level 1 & Level 2 support

✓ Can assessAdministered by CAICO (ISACA; …
CCACertified CMMC Assessor
Individual

Lead assessor for Level 2 certification assessments

✓ Can assessAdministered by CAICO (ISACA; …
C3PAOCertified Third-Party Assessment Organization
Organization

Conducts official Level 2 certification assessments

✓ Can assessAccredited by Accreditation Bo…

* DIBCAC is the government assessment body for Level 3 and is referenced in certain C3PAO-related process requirements.

LTPLicensed Training Provider
Organization

Delivers approved credential training

N/ACyber AB

Why Hire an RP Before Your Assessment

Engaging an RP early in your CMMC journey is a strategic investment — not an overhead cost. Here's the business case.

Avoid Costly Surprises

Independent Level 2 certification assessments represent a significant investment that varies widely by scope and organizational complexity. An RP identifies documentation gaps and remediation needs before you engage a C3PAO — so your assessment investment isn't wasted on a preventable failure.

Navigate Complex Requirements

Level 1 requires meeting 59 assessment-objective statements across 15 controls aligned to FAR 52.204-21. Level 2 scales to 320 NIST SP 800-171A (June 2018) assessment objectives. An RP translates federal regulatory prose into practical actions for your specific environment. (Note: CMMC Level 2 assessments follow the NIST SP 800-171A edition incorporated by reference in 32 CFR Part 170, even though NIST has since published newer revisions.)

Reduce Attestation Risk

CMMC requires an affirming official to submit affirmations in the Supplier Performance Risk System (SPRS) after assessments and annually. Inaccurate certifications to the government can create serious contractual and legal exposure. An RP helps ensure your attestation is thorough and defensible. This is not legal advice — consult qualified counsel for legal guidance on your specific situation.

Accelerate Your Timeline

Phase 2 begins November 10, 2026 — one year after Phase 1 began — broadening the expected use of Level 2 certification assessments in applicable solicitations and contracts. Contractors who wait until Q3 2026 to start readiness preparation will face a crowded marketplace of RPs and C3PAOs. Starting now provides margin.

What to Look for When Hiring a CMMC RP

Not all RPs are the same. Here are four criteria to evaluate before engaging a compliance advisor.

Verify the Credential

Verify an RP's status via the Cyber AB Marketplace directory (cyberab.org) or request proof of current listing.

Ask About Specialization

Some RPs focus on Level 1 for small contractors; others handle Level 2 CUI environments. Match the RP's experience to your compliance level and organizational complexity.

Look for Practitioner, Not Just Platform

SaaS tools help with workflow, but CMMC readiness requires human judgment — evidence evaluation, scoping decisions, remediation prioritization. Look for practitioner-led engagement.

Check for Adjacent Expertise

Contractors often face overlapping compliance requirements — HIPAA, FTC Safeguards, DFARS 252.204-7012. An RP with cross-compliance experience reduces total advisory cost and avoids duplicated effort.

CSC's CMMC RP Approach

Dan Pitre, CMMC Registered Practitioner

Cyber AB Credentialed · Cloud Solutions Consulting

CSC's CMMC advisory services are led by a CMMC Registered Practitioner credentialed through the Cyber AB. Our approach combines RP expertise with vCISO-level strategic oversight — CMMC readiness isn't just a compliance checkbox exercise, it's an opportunity to build a durable security posture that serves your organization beyond the certification.

We cover Level 1 self-attestation support and Level 2 readiness preparation, leveraging compliance tooling that maps directly to CMMC assessment objectives. For organizations with overlapping compliance requirements — HIPAA, FTC Safeguards, DFARS 252.204-7012 — our cross-framework experience means less duplicated effort and a unified compliance strategy.

Frequently Asked Questions

Common questions about CMMC Registered Practitioners and the advisory process.

No. RPs provide non-certified advisory and readiness support. Official Level 2 certification assessments are conducted by a C3PAO assessment team in accordance with 32 CFR Part 170 requirements. The RP's role is to prepare you so the assessment goes smoothly — gap analysis, evidence preparation, and remediation guidance.

As of December 2025, Cyber AB Town Hall reporting indicated approximately 1,900+ Registered Practitioners. Not all are actively practicing, and specializations vary widely. The Cyber AB Marketplace at cyberab.org is the authoritative directory for verifying current RP credentials and finding practitioners.

An RP (Registered Practitioner) is an individual credential — one person who has completed Cyber AB-approved training and passed the exam. An RPO (Registered Practitioner Organization) delivers non-certified advisory services through employment of RPs or RPAs. RPOs do not conduct Certified CMMC Assessments.

Level 1 is a self-assessment — no third-party certification assessment is required. Organizations may engage third parties to assist, but Level 1 remains a self-assessment and does not result in certification. That said, Level 1 still requires meeting 15 controls across 59 assessment-objective statements and an affirming official's attestation. An RP helps ensure your self-assessment is thorough, your evidence is defensible, and your SPRS submission is accurate.

Costs vary widely based on scope, required certification level, and organizational complexity. Level 1 readiness engagements for small contractors are generally a focused engagement. Level 2 preparations involve significantly more scope. A consultation with a CMMC Registered Practitioner can help scope your specific environment and provide a tailored estimate before any commitment.

CMMC Registered Practitioner · Cyber AB Credentialed

Ready to Start Your CMMC Journey?

Schedule a consultation with CSC's CMMC Registered Practitioner to evaluate your compliance posture, identify gaps, and build a readiness roadmap — before Phase 2 broadens Level 2 certification requirements in November 2026.