APTSecurity Management

Choosing a CMMC Advisory Partner

Cody D. Martin//Updated August 9, 2026

Ask whether they hold Registered Practitioner status, whether they also assess, who owns the System Security Plan when the engagement ends, and what they did when CMMC Phase 2 was suspended. That last answer tells you more than the first three.

The CMMC advisory market grew quickly, then had its main deadline removed. Both of those facts are useful when choosing who to work with.

The credential questions

Are you a Registered Provider Organization, and are your people Registered Practitioners? RP status means individual training and registration with the accreditation body. It is a floor rather than a differentiator, and its absence is a reasonable disqualifier.

Do you also perform assessments? The ecosystem deliberately separates preparation from assessment, because a firm cannot credibly judge whether the program it built meets the requirement. A provider offering both should have a clear answer about how they keep those apart.

The questions that actually separate providers

Who owns the System Security Plan when the engagement ends?

The most revealing question on this list. The SSP has to be maintained. Systems change, the affirmation is annual, and a plan that goes stale is worse than no plan because someone attested it was accurate.

If the answer involves their platform, their template license, or a retainer to keep it current, you are renting compliance rather than building it.

Can we see a redacted SSP you produced?

You are looking for whether it describes a specific environment or a generic company. If it reads like it could belong to anyone, it will not survive an assessor asking one follow up question.

How do you handle scoping?

If the answer is quick and confident, be careful. Scoping is the most consequential part of the work and the part that takes longest. An oversized boundary means paying to secure systems that never needed it. An undersized one fails before an assessor reaches a control.

What do you do when we disagree with a finding?

You want someone who will hold a position and explain it, not someone who marks everything compliant to keep the relationship comfortable. Your affirmation is signed by your officer, not theirs.

The question the suspension made available

What did you tell clients when Phase 2 was suspended in July 2026?

This is now the most informative question you can ask, and it has three common answers.

“We told them nothing changed.” Wrong, and it suggests they were not reading the rule. Third party assessment genuinely was paused.

“We told them to stop.” Also wrong, and worse. DFARS 252.204-7012 was never suspended. A client who stopped is out of compliance and does not know it.

“We told them the audit paused and the obligations did not.” Correct, and it means they read 32 CFR 170 rather than the headlines.

Practical shape of an engagement

A reasonable one usually looks like:

  • Scoping and gap assessment as a defined piece of work with a fixed deliverable
  • Remediation support you can scale up or down
  • SSP and POA&M development, handed over in a format you can maintain
  • Optional ongoing review, priced separately, that you could decline

Be wary of anything sold as an all inclusive package where the components are not separable. That structure exists to make leaving expensive.

One honest note

We hold Registered Practitioner status and we prepare organizations. We are not a C3PAO and we cannot certify anyone, which is the correct separation and worth saying plainly. If you want certification when it returns, that is a different provider, and we will happily tell you what to ask them.

  • CMMC
  • vendor selection
  • RPO
  • SSP

More on compliance