The CMMC consultant you choose has a direct effect on whether you pass your assessment, how much you spend getting there, and whether your SPRS score and annual affirmations hold up to scrutiny. The market is crowded, and many providers sound the same. The right questions quickly separate firms that have taken contractors through real NIST SP 800-171 assessments from those selling tools or templates.
Here are the 10 questions to ask, the red flags to watch for, and what a good engagement looks like.
Why the consultant choice matters, even with Phase 2 paused
In July 2026 the Department of War suspended CMMC Phase 2, which would have added third-party (C3PAO) Level 2 assessments to contracts from November 2026, while a reform task force reviews the program. Phase 1 still applies: self-assessments, SPRS scores, annual affirmations and the DFARS 252.204-7012 obligation to implement NIST SP 800-171. An inaccurate score or affirmation carries False Claims Act risk. A good consultant helps you reach a score you can defend today and prepares you for third-party assessment whenever it resumes.
The 10 questions to ask a CMMC consultant
- How many organizations have you prepared for a NIST SP 800-171 or CMMC Level 2 assessment, and how did they do? Ask for examples in your sector and of your size.
- Are you a Registered Practitioner Organization (RPO) with the Cyber AB, and who on your team holds CMMC credentials? Registration isn't mandatory, but credentials and direct experience matter.
- How do you scope the CUI boundary? The answer should cover data flows, enclaves, cloud services, external service providers and how to keep scope, and cost, under control.
- What exactly will we have at the end? Expect a gap assessment, System Security Plan (SSP), Plan of Action and Milestones (POA&M), remediated controls and organized evidence.
- Do you implement, or only advise? Find out whether they configure systems and build controls, or hand your team a list.
- How do you validate our SPRS score? They should test the implementation of each requirement against its assessment objectives, not just review policies.
- How do you handle cloud services and external service providers? Ask about FedRAMP equivalency and the shared responsibility for CUI in cloud platforms.
- What will our team have to do? A realistic consultant tells you how much internal time is needed and when.
- How do you prepare us for the assessment itself? Look for mock assessments, evidence walkthroughs and support during the real one.
- How do we stay compliant afterwards? CMMC status requires annual affirmation, so ask how evidence and controls are maintained.
Red flags
- Guaranteed certification. No consultant controls the assessment outcome, and the assessor must be independent.
- Offering to assess you as well. The CMMC rule bars organizations from assessing a company they consulted for within the previous three years.
- Tool-first pitches. A product doesn't make you compliant; scoping, implementation and evidence do.
- Policy templates without implementation. Assessors test whether controls work, not whether documents exist.
- No questions about your CUI. A consultant who doesn't ask where CUI lives can't scope your project.
- Vague pricing with no defined deliverables or phases.
If you're still deciding between hiring help and doing it yourself, see CMMC RPO vs. C3PAO vs. in-house.
Contract on the line? CMMC Level 2 readiness is a scoping and evidence problem before it's a tooling problem. VisioneerIT maps your CUI boundary, closes the gaps, and preps you for the C3PAO. Book a CMMC gap assessment →
What a VisioneerIT CMMC engagement looks like
VisioneerIT treats CMMC readiness as engineering, not paperwork. Controls become configurations, pipelines and dashboards, with evidence produced as a by-product of running them. An engagement follows five phases:
- Posture thesis: confirm the CMMC level you need, the contracts involved and where CUI lives.
- Architect controls: design the CUI boundary and control architecture, including a gap assessment against NIST SP 800-171.
- Implement: build and configure the controls, with automated evidence collection, and produce the SSP and POA&M.
- Maintain: train your team to operate and maintain the controls.
- Assess and sustain: support you through the C3PAO assessment when required, and keep compliance current for annual affirmations and renewal.
The official certification assessment is always performed by an accredited third party. VisioneerIT's role is to get you ready and support you through it. Readiness typically takes a few months to a year, depending on how large the gap is.
Frequently asked questions
How much does a CMMC consultant cost?
It depends on the size of your CUI environment, the gap to NIST SP 800-171 and how much hands-on implementation you need. Ask for a gap assessment first; it gives you a fixed scope to price remediation against.
How long does CMMC Level 2 readiness take?
Usually a few months to a year. Organizations with a clearly defined CUI boundary and mature IT practices move faster.
Can our CMMC consultant also perform our assessment?
No. The CMMC rule prohibits ecosystem members from participating in the Level 2 certification assessment of an organization they consulted for within the previous three years.
Do we still need a CMMC consultant after the Phase 2 suspension?
If you handle CUI, yes. Phase 1 self-assessments, SPRS scores, annual affirmations and DFARS 252.204-7012 obligations still apply, and third-party assessments are paused for review, not cancelled.
Key takeaways
- Choose a consultant based on proven NIST SP 800-171 assessment experience, CUI scoping skill and concrete deliverables.
- Ask the 10 questions above, and watch for guarantees, tool-first pitches and template-only offers.
- Your consultant can't also be your assessor within three years.
- CMMC Phase 2 is paused, but Phase 1 obligations and False Claims Act risk remain.
- A good engagement leaves you with an SSP, POA&M, working controls, organized evidence and a plan to stay compliant.
Regulatory status reviewed September 2026.

