by Scott Jack
Content Contributor, E-N Computers
Over 10 years of experience in healthcare IT and tech support.
Updated August 26, 2024
CMMC Registered Practitioners (RPs) and Registered Practitioner Organizations (RPOs) are extremely valuable pre-audit resources that can help you get ready for CMMC certification. The Cyber AB, the CMMC accreditation body, says that “utilizing a third-party for CMMC certification is highly valuable and recommended.”
While using this type of CMMC consultant will be an up-front expense, their expertise can ultimately save you time and money in your quest for certification.
If you are a contractor or subcontractor that 1) works with the Department of Defense and 2) handles Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), you need to become CMMC-compliant.
Although CMMC compliance is not yet a requirement in defense contracts, it will be in the near future. The Department of Defense submitted the CMMC 2.0 rule to the Office of Management and Budget Office of Information and Regulatory Affairs, and the final rule should be published in the Federal Register no later than October 2024.
We expect that defense contracts will likely have CMMC requirements in Q1 2025. Since it can take a year or more to reach compliance, start as soon as possible to avoid being disqualified from contract opportunities.
E-N Computers is a Registered Practitioner Organization, and we have three Registered Practitioners, including 0ur founder and president Ian Macrae and our director of technology Thomas Kinsinger. We offer CMMC consulting services tailored to smaller businesses.
QUICK ANSWER:
What are CMMC Registered Practitioners and do I need one?
CMMC Registered Practitioners are individuals recognized by The Cyber AB, the DoD’s exclusive CMMC implementation partner, as being qualified to help organizations prepare for CMMC certification. If you rely on DoD contracts and plan to become CMMC certified, it is highly recommended to work with one because preparing for and passing the audit is complex and costly.
The CMMC ecosystem
Cyber AB
The Cyber AB (formerly the CMMC Accreditation Body) is the independent, exclusive implementation partner of the Department of Defense. It oversees the training, and certification of assessors and organizations seeking certification. Its website provides an overview of roles in the CMMC ecosystem. Here are a few key roles.
Registered Practitioner
CMMC Registered Practitioners are individuals with in-depth knowledge and experience in cybersecurity. A Registered Practitioner can assist your organization to prepare for and achieve CMMC certification according to its needs, capabilities, and budget. There are two levels of Registered Practitioner — regular and advanced. As The Cyber AB states, “Individuals holding any level of an RP designation can provide CMMC implementation consulting services”.
There are several steps to become a Registered Practitioner:
- Pay a $600 application fee
- Pass a commercial background check and be a citizen of the USA, Australia, South Korea, or NATO countries
- Complete basic online training and online course exams
- Sign a Cyber AB Code of Professional Conduct and RP Agreement
- Pay a $500 annual renewal fee
After achieving the RP designation, an individual can complete additional steps to gain the Registered Practitioner Advanced (RPA) designation:
- Pay a $1000 application fee
- Implement, at minimum, 50 cybersecurity controls from NIST 800-171 which forms the basis of CMMC 2.0 Level 2
- Complete a more thorough online training
- Take and pass the Cyber AB RPA exam
- Sign an updated Code of Professional Conduct
- Pay a $750 annual renewal fee
Registered Practitioners can work independently or for a Registered Practitioner Organization. At E-N Computers, we have three Registered Practitioners, Ian MacRae, Thomas Kinsinger and Jonathan Lambert.
Registered Practitioner Organization
A Registered Practitioner Organization is a business that has one or more Registered Practitioners on staff. These organizations are well-versed in cybersecurity standards and can offer full-scale support to companies seeking to comply with CMMC requirements. Working with a Registered Practitioner Organization ensures a streamlined and professional approach to reaching the desired certification level. E-N Computers became a Registered Practitioner Organization in October 2023.
Certified Third-Party Assessor Organizations (C3PAOs)
C3PAOs are authorized to conduct official CMMC assessments. There are requirements and guidelines that these organizations must meet, and their assessors (Certified Assessors) have different levels of certification based on the CMMC levels they are authorized to assess. They employ Certified CMMC Assessors (CCA) and Certified CMMC Professionals (CCP).
Working with a Registered Practitioner
How much does it cost to work with a Registered Practitioner?
At E-N Computers, CMMC consulting with a Registered Practitioner costs about $1000/month. It also costs you some time: we expect you to set aside at least one hour every one to two weeks to work through all the details. True CMMC compliance will affect your business workflows, and this collaborative approach produces much better results and less disruption than having us make all the decisions for you.
While the investment in a Registered Practitioner might seem substantial, the value it provides often outweighs the expense. Not only can it speed up your certification process, it can help you improve how you run your business.
Why use a Registered Practitioner
The value that Registered Practitioners provide to organizations seeking certification is enormous, including:
- Expert Guidance: Tailored support to navigate the complexities of the CMMC framework.
- Cost-Efficiency: Utilizing proven methods to achieve compliance without unnecessary expenses.
- Trust and Credibility: Enhancing reputation with governmental bodies, partners, and clients.
- Risk Mitigation: Implementing security measures to protect vital information and business continuity.
Can a Registered Practitioner or organization help maintain compliance?
Yes, we are happy to help you maintain compliance. CMMC compliance efforts are ongoing due to factors like:
- adjustments to cybersecurity best practices like NIST 800-171,
- changes in contract requirements, and
- changes in your business.
Am I required to work with a Registered Practitioner?
No, you don’t have to work with a Registered Practitioner. But if you do, you’ll be working with a consultant validated by The Cyber AB for the needed knowledge, skills, and experience to guide you to compliance.
The CMMC framework is complex, and implementing the required controls takes time. Don’t fail your third-party audit because you missed a detail. Investing in a Registered Practitioner can ultimately save you time and and money by avoiding mistakes.
Can an individual be my Registered Practitioner and my assessor?
No. An individual can hold multiple designations, but they cannot assess your company if they previously assisted you with an implementation consultation.
How to prepare for a CMMC audit
To prepare for a CMMC audit, you need to set realistic expectations about:
- what CMMC level you need,
- how long it takes,
- your role in the process, and
- how expensive it is.
Which CMMC level do I need to reach?
The CMMC framework is aligned with NIST 800-171 and consists of three certification levels.
- Level 1 (17 controls): Sufficient for businesses handling Federal Contract Information (FCI). The audit for this level is not expected to be as documentation heavy.
- Level 2 (110 controls): Required for handling Controlled Unclassified Information (CUI). Because each control can have multiple objectives, there are over 300 objectives to meet. A third-party audit is likely to be required for all organizations seeking level 2 certification.
- Level 3: Suitable for organizations at high risk. This level is usually reserved for prime contractors.
A Registered Practitioner can help you determine which level you realistically need. Together, we’ll examine 1) what kind of information you handle and 2) what systems process and store sensitive information. We’ll also look at what systems you have in place to simplify administrative tasks like user account control (e.g. single sign-on).
How long does it take to become CMMC compliant?
Becoming CMMC compliant can easily take 12 to 18 months, depending on your starting point and the level you need to reach. During this period, you need to:
- assess your current security posture,
- perform a gap analysis to determine what you are missing to reach your desired CMMC level,
- implement all necessary controls and processes,
- complete an audit by a C3PAO, and
- receive certification by successfully passing an audit.
How involved will I be?
We mentioned this in the section on cost, but it bears repeating: you will be regularly and actively involved throughout the process of working toward CMMC compliance. Full collaboration is absolutely critical to a successful implementation and audit. Consider a few reasons.
CMMC implementation will affect the way you do business. A Registered Practitioner knows cybersecurity and CMMC, but you know your business and team. The combination of your areas of expertise will produce the best result — one that you understand, support, and that works for you day-to-day.
There will be a LOT of documentation. As you can expect when working with the government, especially the Department of Defense, paperwork is the name of the game. There will be a lot of documentation to produce and review in preparation for the audit. You have information that will be integrated into that documentation. But you will also be expected to understand how all the pieces fit together.
This is an opportunity to streamline your technology and strengthen your competitive advantage. Too often, poorly designed and implemented tech inhibits business functions. The deep dive that you will do while preparing for certification will reveal inefficiencies and weaknesses in your tools and processes. You can ignore them and do the bare minimum to reach compliance, or you can take advantage of the situation and optimize with the guidance of an expert consultant.
Frequently Asked Questions
How much will a CMMC audit cost?
A rough estimate is that the audit will cost $20,000 to $40,000 for organizations seeking Level 2 certification.
In general, what should I expect during the audit?
The assessor will examine and validate your documentation. They may interview your staff to verify the technical and procedural safeguards you have in place.
What happens if we do not pass the audit the first time?
You will receive a list of deficiencies and be given 180 days to correct them. Once you correct the deficiencies, the assessor will return to re-assess. As long as the re-assessment happens in the allotted time, it should not cost extra.
What happens if we do not maintain CMMC compliance?
Failure to comply with CMMC requirements can lead to serious consequences, including losing existing DoD contracts, becoming ineligible for future contracts, legal penalties, and reputational damage. Non-compliance can also be considered a breach of contract.
How much does it cost to become CMMC compliant?
The costs in the table below are geared to CMMC 2.0 Level 2 and are ballpark figures only. Your costs will depend on the maturity of your IT environment. (Get more details in our article Is CMMC worth the cost?)
Consultation: This is the preparatory work you do, ideally with a Registered Practitioner. This is a relatively long-term engagement.
Implementation: This includes implementing controls, tools and software, and training. Implementation costs are the least predictable because they are heavily dependent on what you’ve already done. Many contractors use Google Workspace or Microsoft 365 but will need to move to the government cloud version of these products to become compliant. This migration alone can cost tens of thousands of dollars.
Audit: As mentioned above, recent estimates place an audit by a C3PAO in the $20,000 to $40,000 range.
Category | Cost |
---|---|
Consultation | $15,000 |
Implementation | $50,000 |
Audit | $30,000 |
Rough total | $90,000 |
Ongoing costs such as software subscriptions, monitoring, and training are not included here. Our Pricing Calculator can give you an idea of the monthly costs we charge for an organization with CMMC compliance requirements. Set the slider to the number of users you have and select the box “I need help with security and compliance”.
Where can I find a list of Registered Practitioners?
Visit The Cyber AB Marketplace for an updated list of Registered Practitioners (RP/RPA), Registered Practitioner Organizations (RPO), Certified Third Party Assessor Organizations (C3PAO), and more.
We also encourage you to ask for references, case studies, and detailed explanations of the RP’s approach to ensure their experience aligns with your specific needs and expectations.
Learn more about CMMC
The Cybersecurity Maturity Model Certification is a unifying standard for cybersecurity implementation across the Defense Industrial Base (DIB). It encompasses three maturity levels that range from basic to advanced cybersecurity practices. By adhering to the CMMC, organizations know they are implementing the cybersecurity best practices that meet federal requirements, protecting sensitive data, and mitigating risks. You can learn more about CMMC in the following articles:
- The Ultimate Guide to CMMC
- The Ultimate Guide to DFARS and NIST 800-171 (in plain English)
- What is FCI and should I worry about it?
- What is CUI and should I worry about it?
If you’re looking for CMMC tools and training:
- We found the best GRC tool for CMMC
- What is Microsoft GCC High and do I need it?
- Best CMMC training resources
- CMMC Level 1 guide as audio book
- CMMC Level 2 guide as audio book
If you’re looking for a CMMC consultant or Registered Practitioner Organization:
- Best CMMC consultants
- Best CMMC RPOs near Washington, DC
- Best Virginia Registered Practitioner Organizations
If you’re looking for a CMMC assessor:
If you’re looking for information about CMMC that is targeted toward smaller businesses:
Complimentary review with a veteran engineer
Are you ready for CMMC?
Get a free strategic consultation to start your journey toward CMMC compliance.
Industries
Locations
Waynesboro, VA
Corporate HQ
215 Fifth St.
Waynesboro, VA 22980
Sales: 540-217-6261
Service: 540-885-3129
Accounting: 540-217-6260
Fax: 703-935-2665
Washington D.C.
1126 11th ST. NW
Suite 603
Washington, DC 20001-4366
Sales: 202-888-2770
Service: 866-692-9082
VA DCJS # 11-6604
Locations
Harrisonburg, VA
45 Newman Ave.
Harrisonburg, VA 22801
Sales: 540-569-3465
Service: 866-692-9082
Richmond, VA
3026A W. Cary St.
Richmond, VA 23221
Sales: 804-729-8835
Service: 866-692-9082