APTSecurity Management

RP, RPO and C3PAO: The CMMC Ecosystem

Cody D. Martin//Updated August 9, 2026

A Registered Practitioner and a Registered Provider Organization help you prepare for CMMC. A C3PAO conducts the third party assessment. The roles are deliberately separated so nobody assesses work they prepared. C3PAO assessments are suspended as of July 2026.

The CMMC ecosystem has more acronyms than it needs, and contractors reasonably struggle to tell who does what. The distinction that matters is between the people who help you prepare and the people who assess you.

The roles

RP, Registered Practitioner. An individual who has completed CMMC training and registered with the accreditation body. They advise and help you prepare. They do not assess or certify.

RPO, Registered Provider Organization. A company employing RPs, offering preparation services. Same boundary: advisory, not assessment.

CCP and CCA, Certified CMMC Professional and Certified CMMC Assessor. Individuals qualified to participate in formal assessments, with the CCA being the more senior.

C3PAO, CMMC Third Party Assessment Organization. An accredited company that conducts Level 2 certification assessments. This is the only party that can certify.

DIBCAC, Defense Industrial Base Cybersecurity Assessment Center. The government body that conducts Level 3 assessments and audits C3PAOs.

Why preparation and assessment are separated

Because an organization that built your program cannot credibly judge whether it meets the requirement. It is the same principle that stops an auditor auditing their own firm’s bookkeeping.

The practical consequence: your RPO cannot certify you, and your C3PAO should not have prepared you. A provider offering both is a signal worth asking hard questions about.

We hold Registered Practitioner status. We prepare organizations. We cannot certify anyone, and we would not want to be in a position where we could.

What the July 2026 suspension did to this

It suspended the assessment half.

On 13 July 2026 the Department of War paused CMMC Phase 2, freezing Level 2 (C3PAO) assessments and Level 3 (DIBCAC) assessments pending a reform review. During the suspension, contracts may specify only Level 1 (Self) or Level 2 (Self), and solicitations carrying a C3PAO requirement are being amended to remove it.

Capacity was one of the stated reasons. Roughly one hundred authorised C3PAOs against a population above one hundred thousand companies was never going to work on the original timetable.

So a C3PAO cannot currently assess you against a contractual requirement, because no contract can currently impose one.

What has not changed

The preparation side. RPs and RPOs still do the same work, and that work is still required, because DFARS 252.204-7012 and 7021 were not suspended. You still self assess against NIST SP 800-171, maintain an SSP and a POA&M, post an SPRS score and affirm annually.

If anything the advisory role matters more during a suspension than during enforcement, because the obligations are less visible and easier to drop.

What to ask a provider

  • Are you an RPO, and are your people RPs?
  • Do you also conduct assessments? If yes, how do you handle the separation?
  • What happens to our engagement if the reform review changes the requirements?
  • Who owns the SSP when the engagement ends?

That last one catches people. A plan you cannot maintain without the consultant who wrote it is a plan that goes stale the moment they leave.

  • CMMC
  • C3PAO
  • Registered Practitioner
  • Cyber AB

More on compliance