If you cannot find information about a compliance topic, please contact us for free support.
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
SPRS & Self-Assessment
-
CMMC Fundamentals
-
Contract Clauses & Flowdown
- DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires
- What DFARS 252.204-7012 Requires, in Plain English
- DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
- DFARS flowdown requirements: Which Clauses You Must Pass to Your Subcontractors
- Flowdown: Which Clauses You Must Pass to Your Subcontractors
- Who Is Exempt from CMMC, and Why "We Only Make Parts" Usually Isn't
- What to Do When a DFARS Clause Appears in a Contract You Already Signed
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
-
Trigger Events & Urgent Situations
- Cybersecurity Questionnaire From Your Prime? Do This
- CUI Marked Drawings You Were Not Expecting? Do This
- Expired SPRS Score and a Bid Due? Fix It This Week
- Dropped Without CMMC? What a Prime Can Actually Do
- 90 Days to CMMC Compliance: What Is Really Possible
- DFARS 7021 Clause Found After Award? Read This First
- CMMC Compliant MSP? How to Verify What Yours Claims
- CUI in Commercial Microsoft 365: What to Do Now
- CMMC Level 2 Certification an RFP Wants? Bid Anyway
- CMMC Trigger Events: A Triage Guide for Contractors
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
-
Artificial Intelligence (AI)
-
Comparisons & Alternatives
- GCC High vs GCC vs Commercial Microsoft 365 for CUI
- CMMC Compliance Options: Enclave, Environment or Service
- Enclave vs Full Remediation: Which CMMC Path Fits
- PreVeil vs GCC High for Small Defense Contractors
- CMMC Platform vs Consultant vs Doing It In House
- RPO vs C3PAO vs Consultant: Who Does What in CMMC
- CMMC Compliance Software for Small Manufacturers
- Azure Government vs AWS GovCloud for CUI Workloads
- Virtual Desktop Enclave vs Managed Laptops for CUI
- Free NIST 800-171 Tools vs Paid Platforms: The Gaps
- Build vs Buy Enclave: What In House Actually Costs
RPO vs C3PAO vs Consultant: Who Does What in CMMC
The RPO vs C3PAO distinction matters for a blunt commercial reason: one of those acronyms appears in federal regulation and one does not. Both appear on sales decks with equal confidence, and a small manufacturer choosing a partner has no obvious way to tell which is a legal category and which is a paid listing.
This page separates them, along with the independent consultant that neither label covers. If you are about to sign a proposal, the twenty minutes it takes to read this is the cheapest diligence available. It sits under How to Compare CMMC Compliance Options: Enclave, Full Environment, or Managed Service.
RPO vs C3PAO: what the regulation defines, and what it does not
| Label | Defined in 32 CFR Part 170? | What it can do |
|---|---|---|
| C3PAO | Yes. Defined as an organisation authorised or accredited by the accreditation body to conduct Level 2 certification assessments | Conduct Level 2 certification assessments and issue certificates of status |
| ESP | Yes. External people, technology or facilities used to provide and manage IT or cybersecurity services on your behalf | Operate systems for you, and land inside your assessment scope when they do |
| CCA and CCP | Referenced with requirements attached, including a background investigation | Serve on assessment teams. A lead assessor carries higher experience thresholds |
| RPO and RP | No. Neither appears anywhere in the rule | Advise and implement. They cannot assess and cannot certify |
Sit with that last row, because it is the whole of RPO vs C3PAO. Registered Provider Organisation is an accreditation body commercial construct with no regulatory standing whatsoever. You cannot satisfy any requirement by hiring one, and hiring one is not evidence of anything to an assessor.
What an RPO listing actually attests to
Registration reportedly requires United States ownership, signing the accreditation body agreement, an organisational background check, at least one trained registered practitioner on the roster, and fees in the region of six thousand dollars initially with a five thousand dollar annual renewal. Those figures come from industry sources rather than a published fee schedule, so treat them as approximate.
Now read what that list does not contain. It does not require that the firm has ever taken a client through a successful assessment. It does not require more than one trained person regardless of firm size. It does not test the quality of the work. A listing confirms an organisation completed a registration process and paid for it.
None of which makes RPOs bad. Many are excellent. The point is narrower and more useful: the label carries no information about competence, so it should carry no weight in your decision. Judge the firm, not the acronym.
The conflict rule that shapes your vendor strategy
This is the part with real commercial consequences, and it is worth quoting close to the source. The rule requires the accreditation body’s code of professional conduct to prohibit ecosystem members from participating in the Level 2 certification assessment process for an assessment in which they previously served as a consultant to prepare that organisation for any CMMC assessment within three years.
Three practical consequences:
- Plan for two relationships, not one. The firm that prepares you generally cannot be the firm that assesses you. Budget accordingly and do not be surprised late.
- Be sceptical of one stop offers. A firm may lawfully hold both a C3PAO authorisation and a consulting practice, but the individuals who prepared you cannot sit on your assessment team. If a proposal implies a seamless path from readiness to certificate with the same people, ask precisely how they intend to comply.
- Sequence matters. If you know which C3PAO you want, do not hire their advisory arm first. You may disqualify the assessor you wanted.
What it takes to become a C3PAO
Worth knowing, because it explains both the price and the scarcity. A C3PAO must obtain authorisation from the accreditation body, clear a foreign ownership, control or influence review including submission to the Defense Counterintelligence and Security Agency, and then undergo a Level 2 assessment of itself conducted by DCMA DIBCAC. Personnel involved in assessments require background investigations. The organisation must reach ISO/IEC 17020 compliance within twenty seven months, field an assessment team of at least two certified assessors including a lead, and have quality assurance performed by a certified assessor who is not on the team.
As of early 2026 there were roughly one hundred authorised C3PAOs. The Department’s own analysis contemplated thousands of entities eventually requiring certification assessments. That ratio is why assessment slots have been scarce and why price has held.
If you are still deciding whether to hire anyone at all, CMMC platform vs consultant vs doing it in house prices the three routes against each other.
Where the independent consultant fits
There is no legal barrier to hiring an uncredentialed independent. The rule constrains who may assess, not who may prepare. Readiness work, gap analysis, writing the System Security Plan, implementing controls and remediation can all be done by anyone competent.
What you give up is thin: no accreditation body background check behind the firm, no marketplace listing to point to, and no ethics process to complain to if it goes badly. What you keep is full capacity to reach a defensible self assessment, and usually a better rate.
Given that the RPO label certifies registration rather than quality, the gap between a good independent and an RPO is much smaller than the marketing suggests. The diligence question is identical either way, and it is not about credentials.
Five questions that matter more than RPO vs C3PAO
- How many clients have you taken through a completed assessment, and may I speak to two of them? This one question outperforms every credential on the page.
- Who specifically will do the work? Firms sell with senior people and deliver with junior ones. Get names in the proposal.
- Will you also operate any of our systems? If yes, they become an external service provider, which means their services fall inside your assessment scope and must be documented in your plan. A firm that only advises does not. This distinction catches a lot of managed providers selling both.
- What exactly do we own when you leave? Ask for the deliverable list in writing. A report is not a System Security Plan and neither is a spreadsheet.
- If we later pursue certification, does this engagement disqualify you from assessing us? The honest answer is usually yes, and a firm that says otherwise without explanation has not read the rule.
What the suspension changed for the RPO vs C3PAO market
Since third party certification stopped being a condition of award in July 2026, the C3PAO market has moved from compelled demand to voluntary demand. C3PAOs remain authorised, assessments are still being conducted, and some contractors are choosing to complete them anyway because a successful assessment is a defensible record if a reported score is ever questioned.
Whoever you hire, the architecture decision comes first, and it is set out in enclave vs full remediation. For most small manufacturers, though, the practical answer today is a well executed self assessment with documentation that would survive scrutiny. That is a readiness engagement, not an assessment engagement, and it is worth being clear about which you are buying. What the assessment itself involves is covered in CMMC Level 2 C3PAO Assessment: What to Expect, and the difference between the two routes in What is the Difference Between a Self-Assessment and C3PAO Certification?.
Frequently asked
Questions about this topic
Do we have to hire an RPO?
Can a C3PAO help us get ready and then assess us?
In RPO vs C3PAO, is an RPO listing evidence of quality?
Can an independent consultant with no credential do this work?
How many C3PAOs are there?
Does our managed service provider become part of our assessment?
Keep reading
More in Comparisons & Alternatives
- Azure Government vs AWS GovCloud for CUI Workloads →
- Build vs Buy Enclave: What In House Actually Costs →
- CMMC Compliance Options: Enclave, Environment or Service →
- CMMC Compliance Software for Small Manufacturers →
- CMMC Platform vs Consultant vs Doing It In House →
- Enclave vs Full Remediation: Which CMMC Path Fits →
- Free NIST 800-171 Tools vs Paid Platforms: The Gaps →
- GCC High vs GCC vs Commercial Microsoft 365 for CUI →
- PreVeil vs GCC High for Small Defense Contractors →
- Virtual Desktop Enclave vs Managed Laptops for CUI →
Free tools
Get to an honest number faster
You will run this more than once: after any material change to your environment, and again before every annual affirmation. Both are free, and both are yours to keep.
Neither is a certified assessment, and neither pretends to be.
Official sources
The audit is gone. The liability isn't.
Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.
Talk to Greypike about SPRS Attestation AssuranceGreypike Inc.
SBA-certified Veteran-Owned Small Business
Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff
CAGE 9WVS6 · UEI N6CJNGDARFM5