If you are a defense contractor working toward CMMC, you will hear three terms again and again: RPO, C3PAO and doing it in-house. They are not interchangeable. One helps you get ready, one assesses you, and the third option means your own team carries the whole load. Picking the wrong mix wastes months and money, and in some cases the rules don't allow the combination at all.
This guide explains what each one does, why a C3PAO can't also be your consultant, how the options compare, and what the July 2026 pause on CMMC Phase 2 means for your plans.
RPO, C3PAO and in-house: what each one does
- RPO (Registered Practitioner Organization): a consulting organization registered with the Cyber AB, the CMMC accreditation body, that helps contractors prepare. RPOs advise, help implement controls and prepare documentation. They do not perform certification assessments.
- C3PAO (CMMC Third-Party Assessment Organization): an organization authorized to perform official CMMC Level 2 certification assessments using certified assessors. A C3PAO assesses; it does not prepare you.
- In-house: your own staff scope the environment, implement the NIST SP 800-171 controls, write the System Security Plan and gather evidence, sometimes with outside help for specific tasks.
Many companies also use experienced cybersecurity consultants who are not registered RPOs. Registration is a useful signal, but what matters most is demonstrated experience with CUI scoping, NIST SP 800-171 and assessment evidence.
Why a C3PAO can't also be your consultant
Independence is built into the CMMC rule. The CMMC program regulation, 32 CFR Part 170, requires the accreditation body to prohibit ecosystem members from participating in a Level 2 certification assessment for an organization they served as a consultant within the previous 3 years. In practice, the firm that helps you prepare can't be the firm that certifies you, and you should plan to use separate organizations for readiness and assessment.
What the Phase 2 pause means right now
On 13 July 2026, the Department of War suspended the CMMC Phase 2 requirements that were due on 10 November 2026, the phase that would have introduced third-party (C3PAO) Level 2 assessments into contracts. A CMMC reform task force is reviewing the program. As of September 2026, its report has not been published.
What has not changed matters more:
- Phase 1 remains in force. Level 1 and Level 2 self-assessments, SPRS scores and annual affirmations still apply.
- Contractors remain bound by DFARS 252.204-7012 to safeguard covered defense information and to implement NIST SP 800-171.
- The Department has said it will keep enforcing NIST SP 800-171 through self-assessments and government-led assessments.
- Inaccurate self-assessment scores and affirmations still carry False Claims Act risk.
The practical conclusion: the timing of C3PAO assessments is uncertain, but the underlying requirement to be genuinely compliant is not. Readiness work is still worth doing now, and it is what you'll need whenever third-party assessments resume.
Comparison: RPO vs. C3PAO vs. in-house
| Factor | RPO or experienced consultant | C3PAO | In-house |
|---|---|---|---|
| Role | Prepare and remediate | Independent certification assessment | Prepare and maintain yourself |
| When you use them | Before assessment, and for ongoing maintenance | At assessment time (Level 2 certification) | Throughout |
| Can they certify you? | No | Yes | No |
| Main cost driver | Scope, gap size, remediation support | Environment size and complexity | Staff time, tools, training |
| Time to readiness | Usually faster, because they have done it before | Not applicable | Depends on internal expertise and capacity |
| Internal effort | Moderate: your team still owns systems and evidence | Moderate during the assessment | High |
| Risk | Choosing a provider without CUI scoping experience | Being assessed before you're ready | Underestimating effort; gaps you can't see |
Going in-house: what you need
Doing it yourself works when you have security staff who understand NIST SP 800-171 in depth, time to document all 110 requirements and their assessment objectives, and tooling to generate and retain evidence. The most common failure is not technical. It is scoping: drawing the CUI boundary too wide makes the project unaffordable, and drawing it too narrow creates gaps an assessor will find.
Using an RPO or consultant: what a good engagement includes
- A gap assessment against NIST SP 800-171.
- CUI boundary and asset scoping.
- A System Security Plan (SSP) and a Plan of Action and Milestones (POA&M).
- Remediation support, turning controls into working configurations, not just policies.
- Evidence collection that will stand up to an assessor.
- Mock assessment and support through the real one.
Contract on the line? CMMC Level 2 readiness is a scoping and evidence problem before it's a tooling problem. VisioneerIT maps your CUI boundary, closes the gaps, and preps you for the C3PAO. Book a CMMC gap assessment →
How to decide: a 5-question self-check
- Do we know exactly where CUI lives? If not, start with scoping help.
- Do we have someone who has taken a company through a NIST SP 800-171 assessment before? If not, outside expertise will save time.
- How big is the gap? A gap assessment tells you whether you need light guidance or hands-on remediation.
- What does our SPRS score say, and can we defend it? An unsupportable score is a legal risk, not just a compliance one.
- Who will maintain compliance after assessment? CMMC status needs annual affirmation, so plan for ongoing ownership.
For the questions to ask before hiring outside help, see how to choose a CMMC consultant. For the background on requirements, read our CMMC 2.0 compliance guide.
Frequently asked questions
What is the difference between an RPO and a C3PAO?
An RPO is registered with the Cyber AB to provide CMMC advisory and preparation services. A C3PAO is authorized to perform official CMMC Level 2 certification assessments. The same organization can't consult for you and then assess you within three years.
Is CMMC still required after the Phase 2 suspension?
Yes. As of September 2026, Phase 1 self-assessment requirements, SPRS scores, annual affirmations and DFARS 252.204-7012 obligations remain in effect. Only the Phase 2 third-party assessment requirements are paused while the program is reviewed.
How long does CMMC Level 2 readiness take?
It usually takes a few months to a year, depending on how far your environment is from NIST SP 800-171 and how clearly your CUI boundary is defined.
Do we need an RPO, or can we use any cybersecurity consultant?
Registration with the Cyber AB is a useful signal, but not a legal requirement for consultants. Prioritize proven experience with CUI scoping, SSPs, POA&Ms and assessment evidence.
Key takeaways
- RPOs and consultants prepare you; C3PAOs assess and certify you; in-house means your team does the preparation.
- The CMMC rule bars assessors from certifying an organization they consulted for within three years.
- CMMC Phase 2 third-party assessments were suspended in July 2026, but Phase 1 self-assessments, SPRS and DFARS obligations remain.
- Readiness work is still worthwhile: it reduces legal risk now and prepares you for when C3PAO assessments resume.
- Choose your path based on CUI scoping clarity, in-house expertise, gap size and who will maintain compliance.
Regulatory status reviewed September 2026.

