Looking for the latest information security and privacy insights from EXTEND? Follow us on LinkedIn.
Group of business people looking at a computer monitor while sitting at a desk

10 Red Flags to Consider When Vetting a CMMC Consultant

The main objective of the Cybersecurity Maturity Model Certification (CMMC) program is to create a framework for auditing and certifying organizations within the Defense Industrial Base (DIB) to safeguard sensitive data that could compromise national security. Introduced in 2020, CMMC was updated in November 2021 to CMMC 2.0, streamlining the number of cybersecurity compliance levels from five to three. The CMMC Final Rule was published in October 2024 and becomes effective on December 16, 2024.

Under the CMMC 2.0 framework, companies risk losing their ability to renew, bid on, or even maintain existing contracts if they fail to achieve self-attestation for level 1 or certification for level 2 and level 3. Our team at EXTEND regularly receives inquiries from organizations looking to understand CMMC requirements, work with our consultants to improve and verify compliance with the framework, and schedule a certification assessment with a CMMC Third-Party Assessor Organization (C3PAO).

Particularly, there are four main challenges that highlight why companies often need a CMMC consultant:

Pain Point #1 – Dealing with Complex and Time-Consuming Documentation

Sorting through the mountain of paperwork needed for CMMC compliance can feel never-ending. Between the many pages in NIST 800-171, CMMC  documentation, and audit guides, it can take several months to fully understand everything and document your program. A consultant helps cut through the clutter and can also assist with drafting policies, processes, procedures and a solid System Security Plan (SSP), a comprehensive document that outlines your entire security program, which is required to pass a CMMC audit.

Pain Point #2 – Implementing NIST 800-171 Requirements

Companies in the DIB have been required to comply with NIST 800-171, the cybersecurity framework referenced in DoD contracts and regulations, since 2017. CMMC is the DoD’s method for validating compliance with the NIST framework. If an organization has not previously put NIST 800-171 processes and controls into practice, it will have a significant amount of information security program development work to complete before considering CMMC certification.

Pain Point #3 – Managing Organizational Change

Compliance with CMMC often means making some big changes within your organization—creating information enclaves, securing data, updating processes, training, and getting everyone on the same page. Knowing how to manage all these moving parts can be tricky. Fortunately, a consultant brings the know-how to engage team members with effective communication and keep everything organized and running smoothly during the transition.

Pain Point #4 – Re-evaluating Security Tools

The CMMC framework might require you to rethink some of your existing security tools and, in some cases, ditch them altogether. This could mean relying more on manual processes, which no one wants. A consultant can help you overcome these challenges by helping your organization adopt CMMC-compliant tools like PreVeil and Azure Government Cloud, and other platforms like OnTrack® that are easy to integrate into your existing technology stack.

Have you read?

How to Prepare for a CMMC Assessment with a C3PAO

Creating a CMMC Enclave: Does It Make Sense for Your Organization?

CMMC Compliance: Be ready to achieve DoD cybersecurity certification

 

Top 10 Red Flags to Avoid When Hiring a CMMC Consultant

When identifying potential vendors to assist with preparing your organization for an audit, you should look for an experienced resource who can help you develop a compliance plan, document your practices, and provide ongoing support — both through the initial assessment process and to help you maintain compliance for future assessments. However, there is a lot of conflicting information available about how to evaluate a consultant, so here are ten red flags to watch out for when choosing one:

1. If the implementor or CMMC consultant is not accredited by The CyberAB, strike them from your candidate list.

If the consultant or implementation partner isn’t listed on The Cyber AB’s official marketplace directory, that’s a major red flag. When you visit the marketplace and begin to identify potential providers, be sure to ask if they have certified CMMC consultants, discuss their process and pricing for implementation, and, most importantly, ask for references. Doing so will help you select a qualified implementor.

We strongly recommend finding a CMMC consultant who, at a minimum, holds the CMMC Registered Practitioner (RP) designation. Ideally, you should find either a Certified CMMC Professional (CCP) or a Certified CMMC Assessor (CCA) who is not part of the C3PAO you plan to engage for the audit to ensure impartiality and prevent conflicts of interest in the certification process.

Below is a high-level visual reference outlining the different types of individual CMMC practitioners that organizations can engage. CMMC preparation and assessment tasks may be performed by a variety of roles depending on accreditation and a practitioner’s involvement in a client’s CMMC assessment. For detailed information about training, accreditation, responsibilities, and limitations, read more about The Cyber AB CMMC Ecosystem Roles.

A chart highlighting four types of CMMC Practitioners

Important note: CCAs are individual professionals certified to conduct CMMC assessments. Rather, C3PAOs are organizations accredited to manage and oversee CMMC assessments, providing the structure and oversight under which CCAs operate.

2. If anyone promises you will get certified quickly, that’s a red flag.

No one should guarantee certification because it depends on your organization’s ability to effectively implement and demonstrate compliance with the required security practices. Ultimately, the final decision is up to the auditors, who evaluate whether your processes and controls meet CMMC standards. Additionally, achieving CMMC compliance is not an overnight process. For Level 1 organizations, it may take a few months to verify all controls, while Level 2 organizations could require 15-18 months to prepare for an audit, especially when starting the compliance process from scratch. Rushing this process could lead to missed requirements, failing the certification, and wasting money on C3PAOs since they will have to audit your organization again if you don’t pass.

 

Matrix Graphic: CMMC 2.0 Certification Levels

 

3. If a CMMC consultant sends you a certification quote that seems outrageous—whether that’s a couple of thousand dollars or millions of dollars—seek other options.

Misconceptions are unfortunately common when it comes to the pricing of CMMC services. While quotes can vary depending on an organization’s cybersecurity maturity, size, required CMMC level, and scope of work, official sources provide useful guidelines for understanding the real costs involved with CMMC certification. For example, the updated cost estimates, published in the Federal Register as part of the CMMC 2.0 Final Rule, outline the financial impact of implementing cybersecurity standards.

Remember: If your organization was not already compliant with the NIST 800-171 information security requirements as required by the Department of Defense (DoD) before CMMC was introduced, you may face additional security program development costs in addition to certification costs. 

4. If your potential vendor doesn’t know what documentation to use, run away.

The DoD requires extensive documentation during the CMMC compliance process, and it’s crucial for the CMMC consultant to ensure that all relevant materials are properly prepared and utilized. Key documents include the System Security Plan (SSP), CMMC assessment guides, and NIST 800-171 controls and objectives.

Additionally, all policies for governance and activities, such as access control and employee security training records, also need to be well-documented. A well-prepared implementor will likely leverage pre-built templates to help create customized versions of the SSP, policies, and procedures to speed up the documentation process.

5. If the implementor tells you that no one needs to approve documents, walk away.

Policies, regardless of the level of certification to be achieved, must be signed by a senior official of the company such as the C-suite. The documentation approval process is critical because executives can be held accountable for false claims, and whistleblowers who expose these violations may receive significant financial rewards under various federal programs, such as the False Claims Act (FCA). The FCA encourages whistleblowers to report fraud related to government contracts, and penalties for false certifications can be severe, including hefty fines and potential legal consequences.

6. If the CMMC consultant asks you for access to any CUI data, clarify the request.

If a consultant asks for access or to view your Controlled Unclassified Information (CUI) other than for auditing purposes, that’s a huge red flag. A consultant might require limited access to FCI or CUI for auditing purposes; however, they should not take copies of that data. It is good practice to always keep your CUI locked down using FIPS 140-2 encrypted storage and tools like Multi-Factor Authentication (MFA).

7. If the provider doesn’t have a technical background, it is time to look for someone else.

Specifically, the provider you end up working with should be comfortable handling security-focused technology implementations, ideally having done this work under NIST 800-171 r2. The implementor should also know how to work with artifacts such as network diagrams, data flow models, asset inventories, and more. A good sign that a consultant can assist your organization is if they have experience setting up systems in government clouds. For instance, using Microsoft’s Azure Government Cloud (GCC) High or Medium is a popular way to support meeting CMMC requirements.

8. If anyone tells you that you can achieve certification without meeting a CMMC objective, they are not a wise resource choice.

Level 1 requires meeting 17 security controls and associated objectives with no flexibility, while Level 2 involves fulfilling 110 security controls with 320 objectives which must be passed at the objective level. Level 2 allows for the use of a Plan of Action and Milestones (POA&Ms) — some controls can be partially implemented if a clear plan is in place to address the gaps within 180 days. Ultimately all controls must be fully met at the objective level in order to achieve Level 2 certification.

Side note: The implementor should know that CMMC audit is based on NIST 171–800A controls, which provides assessment procedures for evaluating whether an organization has effectively implemented the controls and associated objectives outlined in NIST SP 800-171.

9. If the person you’re evaluating doesn’t know what an “enclave” is, move to the next candidate.

Did you know that even if an employee overhears a conversation in an adjacent cubicle next to someone discussing CUI, that person will also be in scope for CMMC compliance? Depending on the defined scope of the services your organization provides to the DoD, an effective solution might point to isolating employees in separate buildings, storing sensitive documents in separate locations, and even using specific hardware only accessible by certain individuals.

Hence, a CUI enclave is a dedicated, air-gapped section of a company’s network and facilities designed to protect systems and data that must be in compliance with NIST SP 800-171. It applies security controls only to the systems and personnel handling Controlled Unclassified Information (CUI) or Federal Contract Information (FCI), using strict access controls and dedicated infrastructure to limit the scope of compliance. This setup should be considered as an option by companies that also provide services to non-government agencies, allowing them to focus compliance efforts on specific teams or systems while keeping the rest of the business outside the CMMC scope — without having to overhaul their entire infrastructure.

10. Ask the CMMC consultant to explain NFO controls. If they don’t know, look for a resource who does.

Non-Federal Organization or NFO controls are assumed to be in place because they are controls that cover basic cyber hygiene that any organization is expected to have. These controls are considered so fundamental that they aren’t always explicitly stated in certain frameworks because they should already be in place. If an implementer doesn’t know what NFO controls are, it’s a red flag because it means they may lack an understanding of essential cybersecurity practices needed for CMMC compliance.

Now that you know the most important warning signs to look out for, you should also know that CMMC is not a one-and-done deal — it’s an ongoing process that requires regular upkeep. For Level 1, annual self-assessments with an affirmation of compliance by a senior company official are required, while Level 2 involves annual self-assessments and a third-party certification every three years.

After all, complying with CMMC requires you to take a structured, ongoing approach to properly understand your sensitive data, follow NIST SP 800-171 guidelines at the objective level, and properly document each security procedure. With EXTEND Resources, compliance for CMMC Level 1 and Level 2 requirements becomes a streamlined, achievable journey. We offer comprehensive services, led by a CMMC Registered Practitioner, tailored to your unique needs.

If your organization is looking for a CMMC consultant or needs guidance throughout the compliance journey, reach out to our team of CMMC experts today.

Scroll to Top
Skip to content