Skip to main content

CMMC Pause: What DoW & Primes Still Require

  • blog
  • CMMC RPO: How Registered Practitioners Can Help You Implement Cybersecurity Requirements

CMMC RPO: How Registered Practitioners Can Help You Implement Cybersecurity Requirements

  • August 06, 2026
Author

Anna Fitzgerald

Senior Content Marketing Manager

Reviewer

Rob Gutierrez

Senior Cybersecurity and Compliance Manager, CISA, CCSK, CMMC RP

The DoW rollout of CMMC third-party assessment requirements is on hold for now, but the work of implementing and maintaining NIST 800-171 is still required to do business with the DoW and primes. For most contractors and subcontractors, that work remains as costly and complex as it’s always been.

Implementation can be a huge burden, especially for small businesses. Without the right help, the process can be hampered by technical complexity, high costs, wasted time, and missed bids and contracts.

That is where CMMC Registered Practitioner Organizations (RPOs) come in.

RPOs serve as trusted advisors to organizations seeking assessment (OSAs). They do not perform CMMC assessments. They provide strategic guidance, readiness support, and hands-on help implementing required cybersecurity practices so an organization can prepare for a successful assessment, self or third-party.

This guide covers what an RPO is, what the designation requires, how to evaluate one, and what is changing in the Registered Practitioner program over the next several quarters.

What is a CMMC RPO?

A CMMC Registered Practitioner Organization is a company authorized by the Cyber AB to provide consulting services to organizations pursuing CMMC certification. RPOs advise and implement. They cannot assess.

While RPOs are not authorized to conduct CMMC assessments, they are trained and registered to help organizations:

RPOs must employ at least one Registered Practitioner (RP), an individual who has completed official Cyber AB training, passed course exams, and met other requirements. An RPO may also employ a Registered Practitioner Advanced (RPA), an RP who has met additional experience requirements and completed advanced training and exams.

One point of frequent confusion: as of April 2026, ISACA serves as the Cybersecurity Assessor and Instructor Certification Organization (CAICO) and manages the Certified CMMC Professional (CCP) and Certified CMMC Assessor (CCA) credentials.

The Cyber AB continues to own the RP, RPA, and RPO programs, the CMMC Marketplace, and Tier 3 background checks. If you are hiring help rather than becoming an assessor, the RP and RPO side is the side that matters to you.

Recommended reading

CMMC Consultant Guide: How to Choose the Right Partner

RPO vs C3PAO: What is the difference between these organizations in the CMMC ecosystem?

An RPO advises and implements. A Certified Third-Party Assessment Organization (C3PAO) assesses and certifies. The same organization cannot do both for the same client, and only the C3PAO side of that pair is affected by the pause.

There are many roles in the CMMC ecosystem, including CMMC consulting organizations (RPOs) and assessment organizations known as Certified Third-Party Assessment Organizations (C3PAOs). Understanding the difference lets you find and select the right partner at the right time in your CMMC compliance journey.

An RPO acts as an advisory firm or Managed Service Provider (MSP) to help prepare defense contractors for implementing CMMC requirements and eventually undergoing a CMMC assessment. A C3PAO is an organization that actually performs the assessment.

Many OSAs work with both an RPO and a C3PAO. The RPO helps them prepare for the assessment conducted by a C3PAO.

While an RPO and C3PAO can employ individuals holding multiple designations, including RP/RPA and assessor certifications, those individuals cannot assess a company if they previously assisted with CMMC implementation for that same company in their role as RP or RPA.

Here is a breakdown of the different roles and responsibilities of an RPO and C3PAO in the Cyber AB ecosystem:

Role and responsibilitiesCMMC RPOC3PAO
Provides guidance and preparation supportYesNo
Performs official CMMC assessmentsNoYes
Must be listed in the Cyber AB MarketplaceYesYes
Required for CMMC certificationOptional but highly recommendedYes
May offer tools and templatesYesNo

Recommended reading

Can You Outsource CMMC? MSP & MSSP Options

Do you still need an RPO right now?

Yes. The requirements an RPO helps you implement are already in your contracts and are unaffected by the pause in the CMMC Phase 2 transition, which changed when third-party assessment requirements appear in new solicitations, not what contractors owe.

Scoped to the work an RPO actually does, nothing has changed:

  • DFARS 252.204-7012 requirements, including implementation of NIST SP 800-171, are still in every covered contract and have been since 2017\.
  • CMMC Level 1 and Level 2 self-assessments can still be designated in solicitations and still have to be performed correctly.
  • SPRS scores and annual affirmations still have to be submitted, and an affirming official still signs them.
  • Prime contractor flowdown requirements run on the primes' schedule, not the government's rollout schedule. Primes have continued issuing supplier requirements based on supply chain risk management, not the phase timeline.
  • Readiness carries forward. Verification requirements for self-assessments will remain in place and third-party assessment verification may return in the same or a revised form. Implementation work done now is not wasted under either verification regime.

Gap analysis, control implementation, SSP and POA\&M development, evidence collection: all of it is work you still owe. The RPO relationship is a readiness relationship, and readiness is the part of CMMC the pause left fully intact.

Recommended reading

CMMC Phase 2 Pause: What Changed and What Did Not

What is changing in the CMMC RPO program?

The Cyber AB's Cyber Engagement Forum (Cyber EF) subsidiary is rebuilding the RP, RPA, and RPO programs on a roadmap that runs into 2027, covering revised training, a rebuilt marketplace, practitioner councils, and a validation system for RPO services. Existing credentials are expected to carry forward through a transition process rather than a recertification.

The Cyber EF is a wholly owned nonprofit subsidiary of the Cyber AB, created to handle practitioner training, outreach, and market facilitation for the CMMC and Secure Controls Framework ecosystems. The practitioner overhaul has been promised since late 2025\. It now has a stated sequence.

PeriodWhat the Cyber EF says is planned
Q3 2026Surveys to RPOs on the tools, frameworks, and implementation work they actually perform, used to shape the revised program. Practitioner webinars on implementation and on how the new councils and committees will function
Q4 2026Cyber EF website launch, an updated learning management system with the new RP course released module by module for pilot feedback, and expanded RPO resources delivered through third-party partnerships
Q1 2027A validation system for RPO services and products, intended to confirm that an organization actually delivers the services it advertises
Q2 2027Steady state, meaning the new program, marketplace, and resources run without further build-out

Three changes are worth knowing:

  1. The RP and RPA split is likely to consolidate. The original design separated the two designations by framework, with RP mapped to NIST SP 800-171 and RPA mapped to NIST SP 800-172. The Cyber EF has signaled it will most likely replace that split with a single practitioner designation carrying framework-specific training underneath it.
  2. New practitioner training is being written to NIST SP 800-171 Rev 3\. Delta training is being held in reserve for contracts that still cite Rev 2\.
  3. Practitioners will be staffed under their RPO in the rebuilt marketplace. An RPO will manage its RPs and RPAs, their training records, and role-based permissions inside one organizational account rather than through individual affiliations.

None of this suspends the current program, and none of it changes what you owe under an existing contract. The requirements below describe the program as it operates today.

Recommended reading

The Cyber EF Just Put a Calendar on the RPO Overhaul

What are the CMMC RPO requirements?

RPO status is not self-declared. The Cyber AB sets a defined bar an organization has to clear to earn it and keep it, which is a meaningful part of what separates an RPO from a general cybersecurity consultant selling CMMC services.

To become an RPO today, an organization must meet specific eligibility and ethical requirements defined by the Cyber AB, including:

  • Register with and receive authorization from the Cyber AB
  • Employ at least one CMMC Registered Practitioner (RP) or Registered Practitioner Advanced (RPA) in good standing
  • Sign a Cyber AB Code of Professional Conduct and RPO agreement
  • Pass identity verification and background checks
  • Pay a $6,000 registration fee and $5,000 annual renewal fee

These requirements ensure that RPOs remain accountable, knowledgeable, and committed to supporting the goals of the CMMC ecosystem.

The table below shows how the current requirements for RPs, RPAs, and RPOs overlap and differ.

RequirementsRPRPARPO
Cyber AB registration and authorizationRequiredRequiredRequired
RP status and additional experienceN/AMust have achieved RP status and implemented at least 50+ cybersecurity framework controls that align with CMMC Level 2Must employ at least one Registered Practitioner (RP)
Training completionComplete Cyber AB-provided RP trainingComplete Cyber AB-provided RPA trainingN/A
ExamMust pass RP course examMust pass RPA course examN/A
Background checkRequired to pass commercial background checkAssumed under RP statusAssumed under RP status. Required to pass organizational background check
Signed documentsCyber AB Code of Professional Conduct and RP AgreementUpdated Code of Professional Conduct (CoPC), if requiredMust agree to and uphold the Cyber AB Code of Professional Conduct

How do you become a CMMC RPO?

Here is the step-by-step process an organization goes through to become a CMMC Registered Practitioner Organization under the current program. If you are vetting an RPO rather than becoming one, this is what the firm you are considering has already been through.

Step 1: Hire a Registered Practitioner

The first requirement for becoming a CMMC RPO is to employ at least one CMMC Registered Practitioner (RP).

An RP is an individual who has completed Cyber AB-approved training and passed the required exam and background check. They must also agree to abide by the CMMC Code of Professional Conduct. Your RP will be your organization's credentialed expert, helping you meet and maintain your RPO requirements and status.

Hiring an RP does not necessarily require onboarding a new employee. Many organizations sponsor training for existing team members. However, the RP must be active and listed in the Cyber AB system for your organization to be eligible for RPO status.

Step 2: Register with the Cyber AB

Next, your organization will need to formally register as an RPO through the Cyber AB's online portal. This process involves:

  • completing the RPO application
  • submitting organization details
  • providing proof of your RP's status
  • paying a $6,000 registration fee, which covers listing in the Cyber AB Marketplace and access to official branding

The registration process is designed to verify your organization's legitimacy and ensure you are prepared to ethically and effectively support OSAs on their CMMC journey.

Step 3: Sign the Code of Professional Conduct

All RPOs must agree to uphold the Cyber AB's Code of Professional Conduct. This code outlines your responsibilities as a consulting organization and establishes standards around confidentiality, ethical behavior, conflicts of interest, and professionalism.

Your RP or RPs and your organization as a whole must adhere to this code. Violations can result in disciplinary action, removal from the Marketplace, or revocation of RPO status, so it is crucial to understand and comply with these obligations.

Step 4: Complete identity and background checks

The Cyber AB requires identity verification and background checks for all RPs and your organization as a whole. These checks help maintain trust and integrity across the CMMC ecosystem by ensuring only vetted individuals and organizations support defense contractors and subcontractors.

Once complete, your RPO profile is activated in the Cyber AB system and visible in the Cyber AB Marketplace, allowing organizations seeking assessment to find and engage your services.

Step 5: Maintain active status

Becoming an RPO is not a one-time event. To stay listed in good standing, you will need to pay $5,000 to renew your registration annually and keep your RP or RPs current on training and other obligations.

Maintaining active status ensures you are consistently providing accurate and compliant guidance to clients working toward CMMC certification.

How do you choose an RPO for your organization?

Choosing the right RPO can provide a streamlined path to cybersecurity compliance, saving you months of confusion and rework.

The registration process described above is the floor, not the ceiling. Here are the key factors to consider when evaluating and selecting the right RPO for you.

Verify their CMMC experience

Not all RPOs offer the same level of experience. Ask how many clients they have helped prepare for CMMC Level 1 or Level 2 assessments and whether they have worked with organizations similar to yours in size, industry, or technical environment. Ask if they have helped customers get through a C3PAO certification assessment if you’re considering that path.

This will help you assess their familiarity with real-world implementation challenges that your organization may face, which is often just as important as their knowledge of the CMMC framework.

Experienced RPOs should be able to walk you through the readiness process, provide sample documentation, and explain what to expect during an SPRS self-assessment or C3PAO assessment.

Treat a Marketplace listing as registration, not vetting

Verify that the RPO is officially listed in the Cyber AB Marketplace and employs at least one RP. Then keep going. A listing confirms that an organization completed the registration process, paid its fees, and passed a background check. It does not confirm the quality of the services it sells.

The Cyber EF has acknowledged this gap directly and has a validation system for RPO services planned for 2027 to close it. Until that exists, references, sample deliverables, and self-assessment and C3PAO experience are your real diligence.

Check their knowledge of CMMC

Assess an RPO's knowledge of the underlying DoW requirements, including the DFARS 70 series and FAR 52.204-21. Note that a February 2026 class deviation renumbered several of these clauses, and both old and new numbers still circulate in active solicitations, so a current RPO should be able to speak to both.

If you are working toward Level 2, CMMC Level 2 maps to the 110 security requirements in NIST SP 800-171, so any credible RPO should have deep knowledge of them. Rev 2 remains the baseline cited in current contracts, although rulemaking to align CMMC to Rev 3 is supposed to be in progress, so ask which revision the firm is building to. If your RPO does not understand these requirements or how to meet them in a real operational environment, it may lead to incomplete documentation or unaddressed gaps.

Additionally, some RPOs have more knowledgeable and experienced staff than others. The best RPOs have more than one RP on staff and RPAs ready to support their customers.

Recommended reading

NIST 800-171 Rev 2 vs Rev 3: What Changed and What It Means for CMMC

Ask whether they are participating in the program rebuild

RPOs taking part in the Cyber EF's surveys, councils, and training pilots will see revised requirements earlier than those that are not. It is a reasonable proxy for how closely a firm tracks the program it operates in.

Understand their service offerings

Based on their experience and expertise, RPOs offer different services. Make sure you select an RPO that can meet your specific needs.

If you are starting from scratch, ask whether the RPO helps with gap assessments, SSP development, and POA\&M tracking. These services are all essential to a defensible Level 2 posture. If you have made some progress but are frustrated with your speed or the technical complexity, you may want an RPO who can manage SSP and POA\&M updates and monitor progress toward remediation milestones.

Also ask what happens after your score is submitted. Annual affirmations require an operational record built through the year, not a document assembled the week it is due.

Ask for references and case studies

Do not hesitate to ask for success stories or referrals. A reputable RPO should be able to share case studies or connect you with satisfied customers who can speak to the effectiveness of their support and the self- or C3PAO assessments those customers have been through.

Direct feedback from peers offers valuable insight into what it is really like to work with a particular RPO, especially in terms of responsiveness, technical depth, and overall value.

CMMC Level 2 compliance checklist

Walk through all 110 NIST 800-171 requirements and 320 assessment objectives behind CMMC Level 2 to start organizing your cybersecurity efforts, identifying gaps, and implementing controls.

How an RPO like Secureframe can help you navigate CMMC

CMMC compliance is complex, but you do not have to navigate it alone. Partnering with the right RPO can help you understand and meet technical requirements, reduce the risk of assessment delays, and accelerate your path to certification.

Secureframe is a CMMC Registered Practitioner Organization with CMMC Registered Practitioners on staff. Our experts bring deep knowledge of CMMC, NIST 800-171, and other federal frameworks. Combined with Secureframe Defense, we can help you implement and maintain your requirements at speed and scale, including a Managed CUI Enclave, automated cloud provisioning, automated SSP and POA\&M generation, and real-time SPRS scoring.

Whether you are just starting your compliance journey or maintaining a posture you have already built, Secureframe has the people, tools, and experience to help you succeed.

Get certified. Stay compliant.

Request a demo

FAQs

What does RPO stand for?

RPO stands for Registered Practitioner Organization. It refers to organizations approved by the Cyber AB to provide CMMC consulting and readiness support services. To be approved, RPOs must employ at least one Registered Practitioner and meet other requirements involving Cyber AB registration, code of conduct, and fees.

Is an RPO required for CMMC certification?

No. Working with an RPO is optional. Contractors can implement requirements and self-assess on their own, or work with an MSP or independent consultant. What an RPO adds is a Cyber AB-registered organization with credentialed practitioners, a signed code of conduct, and organizational accountability behind the advice, rather than an individual with a designation.

Does the CMMC Phase 2 pause mean I can stop working with an RPO?

No. The pause affects when third-party assessment requirements appear in new contracts. DFARS 252.204-7012 and the NIST SP 800-171 requirements it flows down remain in effect, self-assessment and annual affirmation obligations remain in effect, and prime contractors continue to flow requirements down on their own timelines. The implementation work an RPO performs is unchanged.

How much does it cost to work with an RPO?

RPO engagement pricing is not published or standardized, and it varies widely with your scope, your starting maturity, and whether the engagement is advisory only or includes implementation. Consulting rates in the CMMC market commonly run in the range of $250 to $400 per hour, and scoped readiness engagements are typically quoted as fixed-fee projects. See our CMMC certification cost breakdown for how RPO fees fit alongside remediation, tooling, and assessment costs.

What is the difference between a C3PAO and an RPO?

A C3PAO (Certified Third-Party Assessment Organization) performs official CMMC assessments and grants certifications. An RPO (Registered Practitioner Organization) provides readiness support and consulting but cannot conduct assessments. An individual who helped implement CMMC for a company as an RP or RPA cannot then assess that same company.

How do I get CMMC RP certified?

To become a CMMC Registered Practitioner (RP), individuals must complete Cyber AB-approved training, pass a background check, and agree to the CMMC Code of Professional Conduct. Once approved, they are listed in the Cyber AB Marketplace and can work for an RPO to provide CMMC guidance. Note that revised RP training is in development through the Cyber EF and is being released in modules rather than as a single course, and the designation structure itself may consolidate.

What is the difference between an RP and an RPA?

Both RPs and Registered Practitioner Advanced (RPAs) are authorized by the Cyber AB to help organizations prepare for CMMC certification, but they differ in experience and expertise. RPs offer foundational guidance, while RPAs have demonstrated hands-on experience implementing CMMC-aligned controls.

  • RP: Provides CMMC readiness support after completing Cyber AB training and exams and meeting other requirements.
  • RPA: Builds on RP status with proof of implementing 50+ CMMC Level 2 controls and passing advanced training and an exam.

The Cyber EF has signaled that this two-tier structure will most likely be replaced by a single practitioner designation with framework-specific training underneath it.

Anna Fitzgerald

Senior Content Marketing Manager

Anna Fitzgerald is a digital and product marketing professional with nearly a decade of experience delivering high-quality content across highly regulated and technical industries, including healthcare, web development, and cybersecurity compliance. At Secureframe, she specializes in translating complex regulatory frameworks—such as CMMC, FedRAMP, NIST, and SOC 2—into practical resources that help organizations of all sizes and maturity levels meet evolving compliance requirements and improve their overall risk management strategy.

Rob Gutierrez

Senior Cybersecurity and Compliance Manager, CISA, CCSK, CMMC RP

Rob Gutierrez is an information security leader with nearly a decade of experience in GRC, IT audit, cybersecurity, FedRAMP, cloud, and supply chain assessments. As a former auditor and security consultant, Rob performed and managed CMMC, FedRAMP, FISMA, and other security and regulatory audits. At Secureframe, he’s helped hundreds of customers achieve compliance with federal and commercial frameworks, including NIST 800-171, NIST 800-53, FedRAMP, CMMC, SOC 2, and ISO 27001.