The codified CMMC rule runs to roughly 25,800 words across 41 pages in the 2025 edition of 32 CFR Part 170. In all of it, the word “consultant” appears exactly once, and not to define one. It appears in a rule barring them:
Prohibit CMMC Ecosystem members from participating in the Level 2 certification assessment process for an assessment in which they previously served as a consultant to prepare the organization for any CMMC assessment within 3 years.
That single sentence tells you most of what you need before hiring a CMMC consultant. The people who prepare you are structurally separate from the people who judge you, and the rule enforces the separation with a three-year bar. Everything else about the consulting half of this market is unregulated, including the title itself.
What follows is what 32 CFR Part 170 actually creates, where a consultant sits relative to it, and the question about the spend that almost nobody raises until the money is gone.
What the Rule Actually Creates
The program lives at 32 CFR Part 170, effective 16 December 2024. The contract clause that actually puts it in your agreement, DFARS 252.204-7021, took effect on 10 November 2025. Those are two different instruments, and the second is the one that binds you.
Three assessment paths exist, and which one applies to you is decided by the contract, not by you or your adviser. A DoD program office selects the CMMC Status a given procurement requires.
| CMMC Status | Who performs the assessment | How often |
|---|---|---|
| Level 1 (Self) | You. The rule calls it an activity performed by an Organization Seeking Assessment to evaluate its own information system. | Annually, with an affirmation |
| Level 2 (Self) | You again, on the same basis, with results submitted to SPRS. | Every three years |
| Level 2 (C3PAO) | A CMMC Third-Party Assessment Organization, defined as an organization authorized or accredited by the Accreditation Body to conduct Level 2 certification assessments. | Every three years |
| Level 3 (DIBCAC) | The Defense Contract Management Agency’s DIBCAC. Not a private firm at all. | Per the rule’s Level 3 process |
Two things follow that contractors regularly get wrong. A consultant never awards a CMMC Status, because only a C3PAO or DIBCAC performs a certification assessment. And at Level 1 and Level 2 (Self) there is no third party in the process at all, which means the entire quality of your position rests on work nobody external ever reviews.
Where a CMMC Consultant Sits, and Why the Title Is Unregulated
One qualification, because it cuts against the point if you find it later. The rule does create an advisory credential. A CMMC Certified Professional under 32 CFR 170.13 is trained to provide advice, consulting and recommendations to client organizations, and is certified by the CAICO. What the rule never does is require you to hire one, or restrict who calls themselves a CMMC consultant. An optional credential is not a licensing regime, and the distinction is the whole subject of this article.
Part 170 defines the Accreditation Body, C3PAOs and DIBCAC. It does not define, license or set competence requirements for a consultant. The phrases “Registered Provider Organization” and “RPO” do not appear in the rule anywhere, which is worth saying plainly because those labels are marketed as though the regulation issued them. Those designations come from the Accreditation Body, not from Part 170.
So the CMMC consultant market has a regulated half and an unregulated half. Assessment is regulated: who does it, how often, and what happens to the result. Preparation is not. Anyone is free to use the title, and the rule’s only interest in them is keeping whoever prepared you away from the decision on whether you passed.
Treat that as structure rather than scandal. Every audit regime draws the same separation, for the same reason: nobody independently examines their own work. What it does mean is that the burden of judging competence sits entirely with you.
The Three-Year Bar Changes How You Should Sequence the Work
Read the prohibition again and notice the direction it runs. A firm that prepares you is excluded from your Level 2 certification assessment for three years afterwards. Contractors who hire a single provider expecting to be walked from readiness through certification discover the handoff late, usually after the preparation invoice is settled.
The practical consequence is a sequencing decision rather than a vendor decision. Decide up front whether you want your preparation firm to be a candidate assessor later. If you do, hire someone who is not a C3PAO for the preparation. If you would rather have the C3PAO relationship early, use them for scoping conversations and take the readiness work elsewhere.
The cheapest question in the process. Ask a prospective CMMC consultant which of your contracts actually carries a CMMC requirement today, and at what level. The rule phases in through Phases 1, 2 and 3, and the requirement arrives through your solicitations rather than on a fixed industry-wide date. A candidate who answers by asking to see your contract vehicles is doing the work. A candidate who answers with a level before reading anything is selling a package.
The Question Nobody Asks Until the Money Is Gone
Here is the part that sits outside the cybersecurity conversation entirely, and it is the reason an accounting firm has anything to say about CMMC at all.
CMMC work costs real money, and on a federal contract the cost of a thing and the recoverability of that cost are two different questions. Whether your CMMC spend is allowable, how it is classified, and which contracts it gets allocated to are decided by federal cost principles and by how your accounting system is set up. A security consultant has no reason to think about any of that, and generally does not.
The failure mode is quiet. A contractor spends heavily on remediation, books all of it to a single indirect pool without considering whether the treatment is defensible, and finds out at the incurred cost audit which portion survives. By then the spend is historic and the classification is in the records. We have written the detail up separately: what FAR Part 31 lets you recover, and what the assessment itself costs by level.
The sequencing point is worth stating on its own. The accounting treatment is cheap to get right before the spending starts and expensive to argue about afterwards.
Program Status: Phase 2 Is Suspended
This section carries a date, because the answer moved recently and most CMMC sales material has not caught up.
On 13 July 2026 the Department of War suspended CMMC Phase 2 and stood up a CMMC Reform Task Force to review the program over 60 days. Third-party certification assessments had been scheduled to start on 10 November 2026. That start is on hold.
What did not move: Phase 1 self-assessment requirements remain in effect, and DFARS 252.204-7012, the older safeguarding clause, is untouched. An industry request for information closed on 14 August 2026, and the task force report to the DoW Chief Information Officer is expected around mid-September 2026.
Read the suspension correctly. A paused phase is not a canceled requirement, and the obligation to protect covered defense information did not go anywhere. What the pause buys you is scheduling room, not an exemption. Any consultant using the November 2026 date as a closing argument is working from a timetable that no longer holds, which is itself a useful thing to learn about them.
Timing the Spend Against the Phase-In
Because the requirement reaches you through solicitations rather than on a single date, and because the phase schedule itself is now under review, contractors face a genuine timing decision and usually do not recognize it as one. Spend early and you carry cost before any contract obliges you to. Wait and you risk a solicitation arriving with a status requirement you cannot meet inside the bid window.
The resolution is not a guess about dates. It is a reading of your own pipeline. If the work you intend to bid over the next two years handles the kind of information that drives a Level 2 requirement, you are going to need the posture regardless, and the only open question is whether you build it under commercial pressure or on your own schedule. If your pipeline is genuinely outside that scope, the honest answer is that you are being sold urgency.
Note also that the three-year cadence makes this an operating cost rather than a project. The rule is specific: a Level 2 certification assessment must be completed within three years of the CMMC Status Date (32 CFR 170.17(a)(1)), and affirmation is required at the time of each assessment and annually thereafter (32 CFR 170.17(a)(2)). A contractor who budgets for CMMC once, treats it as a capital event and moves on will meet the same bill again on a predictable cycle, along with the annual affirmation obligations in between.
Three Ways Contractors Overpay
The expensive mistakes here are scoping and sequencing errors, made before any consultant writes a line of policy.
- Scoping the boundary too wide. The cost of a CMMC program scales with how much of your environment falls inside the assessment boundary. Contractors who never do the work of establishing where the covered information actually lives end up securing the whole company because it is easier than drawing the line. That decision, made by default, is usually the single largest driver of the bill.
- Buying a package before knowing the level. Level 1 and Level 2 sit far apart in effort, and the level is set by the contract. Any engagement priced before somebody has read your contract vehicles is priced on an assumption, and the assumption is rarely in your favor.
- Leaving the cost treatment to the end. Remediation spend gets classified when it is booked. A contractor who runs a full program and only afterwards asks how much of it is recoverable has removed their own room to structure the answer.
How to Test a CMMC Consultant
Since the title carries no guarantee, the interview does the work. Four questions separate people who have operated inside the regime from people who have read about it.
- Which of my contracts carries the requirement, and at what level? The requirement arrives through solicitations during the phase-in, so the answer starts with your contract vehicles. Anyone who names a level before reading them is guessing.
- What goes into SPRS, and who is accountable for what is submitted? Results go into the government’s system of record and carry an affirmation. A candidate who treats submission as an administrative afterthought has not sat with the consequences of one.
- What happens to my POA&M items if they are still open at 180 days? The rule gives deficiencies under a POA&M a 180-day closeout window. A fluent answer covers what is eligible to go on a POA&M in the first place, which is where the real constraint lives.
- Will you be barred from assessing us afterwards? If the candidate has not raised the three-year separation before you do, they have not read the part of the rule that governs their own role.
Where We Fit, Stated Plainly
Amerifusion Bookkeeping is not a C3PAO. We do not perform certification assessments and we do not issue a CMMC Status, because under the rule no consulting firm does. If what you need is a Level 2 certification assessment, you need an authorized C3PAO, and we will say so.
What we do sits on the seam the security firms leave alone. The practice is led by a CPA and CISSP who audited financial statements at KPMG, ran a third-party risk practice at BDO across SOC 1, SOC 2, HITRUST and HIPAA engagements, and led the IT audit function at Stryker. That background covers both halves of the problem a CMMC program creates for a federal contractor: the control environment, and the cost treatment that decides how much of the spend you keep.
Frequently Asked Questions
Is a CMMC consultant required?
No. Nothing in the rule requires one. Level 1 and Level 2 (Self) are self-assessments by design, and a contractor with the internal capability performs them without outside help. What the rule requires is the assessment and the affirmation, not advice on the way there.
Is a CMMC consultant the same as a C3PAO?
No, and the rule keeps them apart on purpose. A C3PAO is authorized or accredited by the Accreditation Body to conduct Level 2 certification assessments. A consultant prepares you for one. A firm that prepared you is prohibited from participating in your Level 2 certification assessment for three years.
How often does the assessment have to be repeated?
Level 2 certification assessments are performed within three years of the CMMC Status Date (32 CFR 170.17(a)(1)), and the Level 2 self-assessment runs on the same three-year cadence with results submitted to SPRS. Affirmation is separate and more frequent: it is required at each assessment and annually thereafter (32 CFR 170.17(a)(2)). Level 1 operates on an annual self-assessment and affirmation. Treat CMMC as a recurring obligation with a recurring cost rather than a one-time project.
Are CMMC consulting fees recoverable on a federal contract?
That is a cost-principles question rather than a cybersecurity one, and the answer turns on how the cost is classified and allocated in your accounting system. Get the treatment decided before the spending starts. Our separate piece on what FAR Part 31 lets you recover works through it.
When does CMMC apply to my contracts?
Through a phased rollout, with the requirement reaching you in solicitations rather than on a single industry-wide date. As of August 2026 the position is split: Phase 1 self-assessment requirements are live, and Phase 2, which would have introduced third-party certification assessments from 10 November 2026, was suspended on 13 July 2026 pending a Department of War review. That is why the first question to any adviser is about your contract vehicles rather than about levels.
The Short Version
Assessment is regulated and preparation is not, so the title on the invoice proves little and the interview does all the work. Ask what the rule requires of your specific contracts, and settle the cost treatment before the spending starts rather than after.
And check the date on whatever timetable you are being sold. Phase 2 has been suspended since 13 July 2026, with a task force report expected around mid-September 2026. The requirement is still coming. The schedule is not what it was.
See our DCAA-compliant bookkeeping services, or book a 30-minute readiness call to talk through the cost side before you commit to a CMMC program.



