Skip to main content
Greypike's CMMC Knowledge Base

If you cannot find information about a compliance topic, please contact us for free support.

< All Topics
Print

RPO vs C3PAO vs Consultant: Who Does What in CMMC

The RPO vs C3PAO distinction matters for a blunt commercial reason: one of those acronyms appears in federal regulation and one does not. Both appear on sales decks with equal confidence, and a small manufacturer choosing a partner has no obvious way to tell which is a legal category and which is a paid listing.

This page separates them, along with the independent consultant that neither label covers. If you are about to sign a proposal, the twenty minutes it takes to read this is the cheapest diligence available. It sits under How to Compare CMMC Compliance Options: Enclave, Full Environment, or Managed Service.

RPO vs C3PAO: what the regulation defines, and what it does not

LabelDefined in 32 CFR Part 170?What it can do
C3PAOYes. Defined as an organisation authorised or accredited by the accreditation body to conduct Level 2 certification assessmentsConduct Level 2 certification assessments and issue certificates of status
ESPYes. External people, technology or facilities used to provide and manage IT or cybersecurity services on your behalfOperate systems for you, and land inside your assessment scope when they do
CCA and CCPReferenced with requirements attached, including a background investigationServe on assessment teams. A lead assessor carries higher experience thresholds
RPO and RPNo. Neither appears anywhere in the ruleAdvise and implement. They cannot assess and cannot certify

Sit with that last row, because it is the whole of RPO vs C3PAO. Registered Provider Organisation is an accreditation body commercial construct with no regulatory standing whatsoever. You cannot satisfy any requirement by hiring one, and hiring one is not evidence of anything to an assessor.

What an RPO listing actually attests to

Registration reportedly requires United States ownership, signing the accreditation body agreement, an organisational background check, at least one trained registered practitioner on the roster, and fees in the region of six thousand dollars initially with a five thousand dollar annual renewal. Those figures come from industry sources rather than a published fee schedule, so treat them as approximate.

Now read what that list does not contain. It does not require that the firm has ever taken a client through a successful assessment. It does not require more than one trained person regardless of firm size. It does not test the quality of the work. A listing confirms an organisation completed a registration process and paid for it.

None of which makes RPOs bad. Many are excellent. The point is narrower and more useful: the label carries no information about competence, so it should carry no weight in your decision. Judge the firm, not the acronym.

The conflict rule that shapes your vendor strategy

This is the part with real commercial consequences, and it is worth quoting close to the source. The rule requires the accreditation body’s code of professional conduct to prohibit ecosystem members from participating in the Level 2 certification assessment process for an assessment in which they previously served as a consultant to prepare that organisation for any CMMC assessment within three years.

Three practical consequences:

  • Plan for two relationships, not one. The firm that prepares you generally cannot be the firm that assesses you. Budget accordingly and do not be surprised late.
  • Be sceptical of one stop offers. A firm may lawfully hold both a C3PAO authorisation and a consulting practice, but the individuals who prepared you cannot sit on your assessment team. If a proposal implies a seamless path from readiness to certificate with the same people, ask precisely how they intend to comply.
  • Sequence matters. If you know which C3PAO you want, do not hire their advisory arm first. You may disqualify the assessor you wanted.

What it takes to become a C3PAO

Worth knowing, because it explains both the price and the scarcity. A C3PAO must obtain authorisation from the accreditation body, clear a foreign ownership, control or influence review including submission to the Defense Counterintelligence and Security Agency, and then undergo a Level 2 assessment of itself conducted by DCMA DIBCAC. Personnel involved in assessments require background investigations. The organisation must reach ISO/IEC 17020 compliance within twenty seven months, field an assessment team of at least two certified assessors including a lead, and have quality assurance performed by a certified assessor who is not on the team.

As of early 2026 there were roughly one hundred authorised C3PAOs. The Department’s own analysis contemplated thousands of entities eventually requiring certification assessments. That ratio is why assessment slots have been scarce and why price has held.

If you are still deciding whether to hire anyone at all, CMMC platform vs consultant vs doing it in house prices the three routes against each other.

Where the independent consultant fits

There is no legal barrier to hiring an uncredentialed independent. The rule constrains who may assess, not who may prepare. Readiness work, gap analysis, writing the System Security Plan, implementing controls and remediation can all be done by anyone competent.

What you give up is thin: no accreditation body background check behind the firm, no marketplace listing to point to, and no ethics process to complain to if it goes badly. What you keep is full capacity to reach a defensible self assessment, and usually a better rate.

Given that the RPO label certifies registration rather than quality, the gap between a good independent and an RPO is much smaller than the marketing suggests. The diligence question is identical either way, and it is not about credentials.

Five questions that matter more than RPO vs C3PAO

  1. How many clients have you taken through a completed assessment, and may I speak to two of them? This one question outperforms every credential on the page.
  2. Who specifically will do the work? Firms sell with senior people and deliver with junior ones. Get names in the proposal.
  3. Will you also operate any of our systems? If yes, they become an external service provider, which means their services fall inside your assessment scope and must be documented in your plan. A firm that only advises does not. This distinction catches a lot of managed providers selling both.
  4. What exactly do we own when you leave? Ask for the deliverable list in writing. A report is not a System Security Plan and neither is a spreadsheet.
  5. If we later pursue certification, does this engagement disqualify you from assessing us? The honest answer is usually yes, and a firm that says otherwise without explanation has not read the rule.

What the suspension changed for the RPO vs C3PAO market

Since third party certification stopped being a condition of award in July 2026, the C3PAO market has moved from compelled demand to voluntary demand. C3PAOs remain authorised, assessments are still being conducted, and some contractors are choosing to complete them anyway because a successful assessment is a defensible record if a reported score is ever questioned.

Whoever you hire, the architecture decision comes first, and it is set out in enclave vs full remediation. For most small manufacturers, though, the practical answer today is a well executed self assessment with documentation that would survive scrutiny. That is a readiness engagement, not an assessment engagement, and it is worth being clear about which you are buying. What the assessment itself involves is covered in CMMC Level 2 C3PAO Assessment: What to Expect, and the difference between the two routes in What is the Difference Between a Self-Assessment and C3PAO Certification?.

Frequently asked

Questions about this topic

Do we have to hire an RPO?
No. Registered Provider Organisation is not defined anywhere in 32 CFR Part 170 and satisfies no regulatory requirement. It is a registration with the accreditation body. Hire on demonstrated track record instead.
Can a C3PAO help us get ready and then assess us?
Not with the same people. The rules require a prohibition on ecosystem members participating in a Level 2 certification assessment for an organisation they consulted to prepare within the previous three years. A firm may hold both lines of business, but the individuals cannot cross over.
In RPO vs C3PAO, is an RPO listing evidence of quality?
No. It confirms the organisation completed a registration process, cleared an organisational background check and has at least one trained practitioner. It says nothing about whether the firm has ever completed a successful engagement. Ask for references instead.
Can an independent consultant with no credential do this work?
Yes. Nothing in the rule requires readiness work to be performed by a credentialed party. What you forgo is the accreditation body’s background check and complaint process. What you retain is full capacity to reach a defensible position, usually at a better rate.
How many C3PAOs are there?
Roughly one hundred were authorised as of early 2026, against a population of contractors that the Department’s analysis anticipated would eventually number in the thousands for certification assessments. That imbalance is the reason slots have been scarce and prices firm.
Does our managed service provider become part of our assessment?
If they process, store or transmit controlled information, or provide security protection for the systems that do, they meet the definition of an external service provider. Their relationship to you and the services they provide must be documented in your System Security Plan, and their services fall within your assessment scope. A firm that only gives advice does not trigger this.

The audit is gone. The liability isn't.

Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.

Talk to Greypike about SPRS Attestation Assurance

Greypike Inc.

SBA-certified Veteran-Owned Small Business

Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff

CAGE 9WVS6 · UEI N6CJNGDARFM5

(703) 214-9246 info@greypike.com greypike.com

Table of Contents