The C3PAO vs consultant distinction matters more now than it did before July 2026, not less, and for a reason most defense contractors have not worked through yet. The Department of War suspended CMMC Phase 2 on July 13, 2026, removing third-party certification as a condition of award. On September 3, 2026, a class deviation converted that policy pause into binding acquisition instruction. The verification step is gone for now. The obligation underneath it is not. That leaves contractors attesting to their own compliance with no independent assessor between their signature and the False Claims Act, which changes what a consultant is for and what a C3PAO can still do.
This guide explains the current state of both roles, the regulatory mechanism that keeps them separate, and how to sequence preparation work while the program is under review.
What the Phase 2 Suspension Changed
The July 13 Memoranda
On July 13, 2026 the Department of War announced the immediate suspension of CMMC Phase 2, which had been scheduled to begin on November 10, 2026. Phase 2 would have made a Level 2 certification assessment by an accredited C3PAO a condition of contract award for most contractors handling Controlled Unclassified Information. Phases 3 and 4 were frozen alongside it.
The implementing instruction is specific. For the duration of the review, program managers and requiring activities may designate only CMMC Level 1 (Self) or Level 2 (Self). Level 2 (C3PAO) and Level 3 (DIBCAC) designations are not permitted, and no waivers are being granted. Existing third-party assessment requirements come out of active solicitations, and out of awarded contracts at the next option exercise or scheduled administrative modification.
That last point produces the most common operational error. Until a contract is actually modified, the clause on it remains the clause on it. Contractors should confirm removal in the contract file in writing rather than assume a requirement was read out by press release. Elevate covered the immediate implications in its breakdown of what the CMMC Level 2 Phase 2 suspension means.
A CMMC Reform Task Force was established at the same time, reporting to the Department of War Chief Information Officer, with a 60-day window to conduct a top-to-bottom review informed by a public request for information that closed on August 14, 2026. Recommendations reached the CIO in mid-September 2026. The public report is expected between late September and early October 2026.
The September 3 Class Deviation
The July action was a policy memorandum. A memorandum governs how the Department exercises its own discretion and can be reversed as quickly as it was issued. That changed on September 3, 2026, when Revision 3 of class deviation 2026-O0025 directed contracting officers to remove third-party CMMC assessment requirements from solicitations and contracts and to use the FAR Overhaul Part 240 clause set instead.
The distinction is worth holding onto. The suspension is now embedded in acquisition regulation rather than in policy guidance, which makes reversal a more involved process than rescinding a memo. It also means the CMMC program rule itself, codified at 32 CFR Part 170, remains in force. Nothing was repealed. The mechanism that would deliver certification simply cannot be invoked right now.
What Did Not Change
The suspension paused one verification mechanism and touched nothing else.
| Requirement | Status |
|---|---|
| DFARS 252.204-7012 safeguarding obligations | Unchanged, in force |
| NIST SP 800-171 Revision 2, all 110 requirements | Unchanged, in force |
| Level 1 (Self) and Level 2 (Self) assessments | In force, the only designations currently permitted |
| SPRS score posting and annual senior official affirmation | Unchanged, condition of eligibility |
| False Claims Act exposure on a false affirmation | Unchanged, and now more concentrated |
| 32 CFR Part 170 CMMC program rule | Codified, not repealed |
| Level 2 (C3PAO) and Level 3 (DIBCAC) designations | Suspended, no waivers |
The table makes the actual risk shift visible. Every security obligation survived. What disappeared was the independent party who would have verified the claim before a contracting officer relied on it. Under Secretary of War for Acquisition and Sustainment Michael Duffey framed the intent publicly: the Department is removing the bureaucracy of third-party assessment, not relaxing the standards NIST set.
Enforcement has continued through the review window. The Department of Justice announced cybersecurity False Claims Act settlements in June and September 2026. A contractor that overstates a Level 2 self-assessment score in SPRS carries that exposure alone, without an assessor’s findings to show the claim was independently tested. Elevate examines this specific risk in its analysis of False Claims Act liability in CMMC compliance.
C3PAO Role and Authority Under 32 CFR Part 170
A CMMC Third-Party Assessment Organization is an independent entity authorized or accredited by the Accreditation Body to conduct Level 2 certification assessments and issue Certificates of CMMC Status. The authority is exclusive and it is narrow.
What C3PAOs Are Authorized to Do
C3PAOs conduct formal assessments against the 110 security requirements in NIST SP 800-171 Revision 2, using the assessment procedures in NIST SP 800-171A and the CMMC Assessment Process, and score them under the methodology at 32 CFR 170.24. A passing assessment produces a Certificate of CMMC Status.
Level 3 follows a separate path. It requires a Final Level 2 certification from a C3PAO first, then a further assessment conducted by the Defense Contract Management Agency’s Defense Industrial Base Cybersecurity Assessment Center covering additional requirements drawn from NIST SP 800-172. DIBCAC is the only authorized Level 3 assessor.
Both designations are currently unavailable. A C3PAO can still perform work, and a Final Level 2 (C3PAO) status still posts to SPRS and still satisfies any requiring activity that elects to specify a certified level. What a C3PAO cannot do is satisfy a condition of award that no longer exists in the contract.
Authorization Requirements
The barrier to becoming a C3PAO is deliberately high, and the requirements sit in 32 CFR 170.9.
An applicant must obtain authorization or accreditation from the Accreditation Body. It must receive a non-disqualifying eligibility determination resulting from a Foreign Ownership, Control or Influence risk assessment, submitting an SF 328 to the Defense Counterintelligence and Security Agency and reporting any change to that submission within 15 business days. It must then undergo a Level 2 certification assessment conducted by DCMA DIBCAC, which evaluates the C3PAO’s own environment against the same standard it will apply to others.
All C3PAO personnel participating in a Level 2 certification assessment must complete a Tier 3 background investigation resulting in a determination of national security eligibility. This is not a security clearance and is not executed for government employment purposes. The organization must also comply with Accreditation Body policies on conflict of interest, professional conduct and ethics, and must achieve and maintain conformity with ISO/IEC 17020:2012 within 27 months of authorization.
Supply has not kept pace with demand at any point in the program’s life. As of December 2025 the Accreditation Body had authorized 93 C3PAOs, and 559 organizations had achieved final Level 2 certification, against a contractor population in the tens of thousands. The assessor shortage was one of the stated drivers behind the Phase 2 review.
The Three Assessment Methods
Assessors use three methods, and the distinction matters for how a contractor prepares evidence.
The examine method reviews and analyzes specifications, mechanisms and activities to establish understanding and obtain evidence. The interview method holds discussions with individuals or groups to confirm personnel understand and can describe their security responsibilities. The test method exercises assessment objects under specified conditions and compares actual behavior against expected outcomes.
A contractor that prepares only for examine will fail interview. Documentation that describes a control accurately does not help when an administrator cannot explain how the control operates in the environment they run. Preparation that ignores the test method produces the same gap in the other direction: a policy and a trained team, with a control that does not actually behave as documented.
What CMMC Consultants Do
Consultants prepare organizations to meet the standard. Their work sits before any formal evaluation and, under current conditions, before a self-assessment and affirmation rather than before a C3PAO visit.
Preparation Work
A consultant translates the 110 requirements into steps specific to an environment. The core sequence runs through a gap assessment comparing existing controls against NIST SP 800-171 Revision 2, findings that specify risk and effect and remediation, System Security Plan drafting or refinement, policy development that matches actual practice rather than aspiration, coordination with IT teams to deploy technical controls such as multi-factor authentication and centralized logging, evidence artifact organization, and mock interviews that confirm staff can explain control operation.
The value of that last step changed with the suspension. Mock interviews used to rehearse for an assessor. They now serve as the only external test of whether a claimed control is real before an officer of the company signs an affirmation. Elevate’s guidance on choosing a CMMC consultant covers what to evaluate in that engagement.
Scoping and CUI Discovery
Consultants identify where CUI and Federal Contract Information live within an environment, define the assessment boundary, and document data flows. Accurate scoping is the single largest cost lever in the entire program. Scope sprawl inflates both remediation spend and assessment complexity, and boundaries drawn too narrowly to defend produce findings rather than savings.
The practical target is the smallest boundary an organization can actually defend, not the smallest boundary it can draw. Elevate’s CMMC compliance checklist for scoping CUI walks the boundary decision in detail.
Registered and Non-Registered Providers
Registered Provider Organizations hold a designation from the Accreditation Body to provide pre-assessment consulting. The designation requires employing at least one Registered Practitioner, passing organizational background checks, paying registration and annual renewal fees, and signing the Code of Professional Conduct.
Registration governs use of the ecosystem’s marks and standing, not competence. Non-registered consultants deliver CMMC advisory work and cannot represent themselves as holding official ecosystem standing or use the Accreditation Body’s logos. Elevate is a CMMC advisor and is not a registered RPO. The distinction to evaluate is whether a provider employs assessors who have actually sat on the other side of the table, because the standard a contractor is preparing against is applied by people, not by a registry.
Implementation Support and Recommendations
Some advisors deliver findings and stop. Others deploy alongside IT teams and then prepare the evidence showing controls operate as designed. The difference shows up at exactly one moment: when someone asks for the artifact.
A recommendation to implement centralized logging is worth something. A configured logging pipeline, with a documented retention period, a named owner, and ninety days of records demonstrating it ran, is worth considerably more, and it is the second one that survives contact with an assessor or a DOJ inquiry.
Why the Two Roles Cannot Overlap
The separation is often described as a DoD policy preference. It is more concrete than that, and the mechanism is worth knowing because it explains exactly where the line falls.
The ISO/IEC 17020 Type A Requirement
C3PAO accreditation is built on ISO/IEC 17020:2012, and the CMMC scheme requires C3PAOs to meet the Type A requirements in Annex A, Clause A.1, which define a third-party inspection body. Under the CMMC interpretation of that clause, the terms covering design, supply, installation, use or maintenance of inspection items extend to ancillary products or services provided in support of information security or cybersecurity.
The consequence follows directly: a C3PAO that also offers consulting or managed services cannot qualify as a Type A inspection body. Type B bodies, which would inspect their own organization’s systems, are not permitted in the CMMC scheme at all. Any organization that does not meet the Type A interpretation, including one offering supporting ancillary services, falls outside what the scheme allows.
This is not a rule about a single engagement. It is a structural constraint on what a C3PAO’s business can contain.
Conflict of Interest
The practical rule inside a given relationship is narrower and equally firm. A C3PAO cannot provide CMMC advisory or preparation services to an organization it assesses. If it does, that involvement disqualifies it from conducting the assessment.
The reasoning is not procedural formality. A C3PAO cannot impartially evaluate a security posture it helped design, and the certification’s value in the defense supply chain rests entirely on the assessment being independent. Records requirements under 32 CFR Part 170 reflect this: C3PAOs must retain materials relating to organizations for whom consulting services were provided, precisely so the boundary can be audited.
Why This Still Matters During the Suspension
With Level 2 (C3PAO) designations unavailable, some contractors have concluded the separation question is moot. It is not, for two reasons.
A provider that structured itself as a C3PAO is still constrained by the ISO/IEC 17020 Type A requirement, so it still cannot offer the preparation services a contractor needs right now without jeopardizing its own accreditation. And if a reformed requirement returns, a contractor that accepted preparation work from its intended assessor during the pause will find that assessor disqualified at the moment it matters. The Reform Task Force report is advice, not regulation, but the program was paused for review once before in 2021 and returned as a narrowed version of the same idea rather than disappearing.
Cost and Timeline Under Current Conditions
Cost figures in the CMMC market vary widely and most published ranges carry no citable source. The regulatory estimates published in the CMMC Program rule’s regulatory impact analysis are the defensible baseline, and they now point somewhere different than they did before July.
| Assessment path | Three-year estimated cost, small entity | Three-year estimated cost, large entity |
|---|---|---|
| Level 2 self-assessment | $37,196 | $48,827 |
| Level 2 C3PAO certification | $104,670 | $117,768 |
| Level 1 self-assessment, annual | $5,977 | $4,042 |
These are regulatory estimates from the rulemaking record, not market quotes, and the C3PAO line is historical for as long as the suspension holds. The self-assessment figures are the live-relevant ones. Note the counterintuitive Level 1 result, where the small entity estimate exceeds the large entity estimate, which reflects assumptions in the underlying model rather than a pricing anomaly in the market.
Vendor pricing for consulting and readiness work spans a wide band and depends on CUI environment size, number of locations, existing documentation maturity and whether the engagement includes implementation or only assessment. Any provider quoting a fixed price before scoping the CUI boundary is quoting on an environment they have not seen.
Timeline expectations have loosened in one specific way. C3PAO scheduling pressure, which was the binding constraint through the first half of 2026, has released for the duration of the suspension. Preparation timelines have not changed, because they are driven by remediation and evidence accumulation rather than by assessor availability. Evidence takes calendar time to accumulate regardless of what any deadline says, which is the argument against pausing control implementation work now. Elevate’s CMMC certification timeline covers the sequencing in detail.
Red Flags
Some warning signs apply to any provider in this market, and a few are specific to the current moment.
No organization can promise a CMMC certification outcome, and any guarantee of certification is disqualifying on its own. Pricing far below market usually indicates a scoping assumption that has not been tested. A provider telling a contractor that the suspension means compliance work can stop has confused the verification mechanism with the obligation, and that advice creates False Claims Act exposure rather than avoiding cost.
The subtler failure is internal. Organizations that ran CMMC preparation and NIST SP 800-171 remediation as one project under one budget line will halt both when they pause the first. Separate the budget lines before pausing either.
How to Sequence the Work Now
The practical sequence under current conditions inverts the old order in one respect. The self-assessment is no longer a rehearsal for the real assessment. It is the assessment of record, and the affirmation attached to it carries the legal weight.
Start with scope. Establish where CUI and FCI live, define a boundary that can be defended, and document data flows. Everything downstream inherits the accuracy of this step.
Run a gap assessment against the 110 requirements in NIST SP 800-171 Revision 2, with findings that state risk, effect and remediation path rather than a pass or fail list. Build the System Security Plan and the Plan of Action and Milestones from those findings.
Implement and then let evidence accumulate. A control configured last week and a control configured nine months ago produce the same screenshot and very different defensibility.
Keep the SPRS score current and defensible. Verify that the affirming senior official understands what they are attesting to and can point to the artifact behind each claim. Elevate’s guide to the SPRS score and CMMC Level 2 explains how the weighting works.
Confirm contract status in writing. Third-party requirements come out of awarded contracts at the next option exercise or administrative modification, not automatically, so the clause may still bind.
Organizations that want an independent read on where their environment stands against the current requirement can book a readiness call with an Elevate advisor.
Conclusion
The C3PAO vs consultant distinction was never about which partner is better. It is about which function each one performs and why the regulatory scheme forbids one organization from performing both. That structure survived the Phase 2 suspension intact, because it is built into the ISO/IEC 17020 accreditation the scheme rests on rather than into the phased rollout the Department paused.
What changed is the risk allocation. For as long as third-party certification is unavailable as a condition of award, the contractor’s own affirmation is the only assertion in the file, and the False Claims Act is the only thing testing it. That makes preparation work more consequential than it was when an assessor stood between a claim and a contract, not less.
Contractors should treat the current period as a scheduling question rather than a scope question. The standard did not move. The Reform Task Force may recommend a narrower or cheaper verification path, and the Department may adopt it, but nothing in any of the announced outcomes reduces the underlying requirement to implement 110 controls and produce evidence that they operate. Organizations weighing how to use the pause can book a readiness call to establish where their evidence actually stands.
Key Takeaways
The suspension changed who verifies compliance, not what compliance requires.
- Phase 2 is suspended and the suspension is now regulation. The July 13, 2026 memoranda paused the November 10, 2026 transition to C3PAO certification. Revision 3 of class deviation 2026-O0025, signed September 3, 2026, directs contracting officers to strip third-party assessment requirements from solicitations and contracts.
- Only self-assessment designations are currently permitted. Program managers may designate CMMC Level 1 (Self) or Level 2 (Self). Level 2 (C3PAO) and Level 3 (DIBCAC) are unavailable and no waivers are being granted.
- Contracts do not update themselves. Third-party requirements come out of awarded contracts at the next option exercise or scheduled administrative modification. Until that modification is signed, the clause still binds.
- The separation rule is an accreditation constraint, not a policy preference. C3PAO accreditation requires meeting the ISO/IEC 17020:2012 Type A requirements for a third-party inspection body, and a C3PAO offering consulting or managed services cannot qualify as Type A.
- The self-assessment is now the assessment of record. With no independent assessor, the affirming senior official’s signature carries the full False Claims Act exposure, which raises rather than lowers the value of independent preparation work.
- Regulatory cost estimates now point at self-assessment. The rulemaking record estimates three-year Level 2 self-assessment cost at $37,196 for a small entity and $48,827 for a large entity. The C3PAO figures are historical for the duration of the suspension.
FAQs
What is the difference between a C3PAO and a CMMC consultant? A C3PAO is an organization authorized or accredited by the Accreditation Body to conduct CMMC Level 2 certification assessments under 32 CFR Part 170 and issue Certificates of CMMC Status. A consultant prepares an organization to meet the standard: gap assessment against the 110 NIST SP 800-171 Revision 2 requirements, System Security Plan development, control implementation, evidence organization and staff readiness. Consultants cannot issue certifications regardless of their expertise, and as of September 2026 C3PAOs cannot issue them either, because Level 2 (C3PAO) designations are suspended.
Can one organization be both my CMMC consultant and my C3PAO? No. C3PAO accreditation is built on ISO/IEC 17020:2012, and the CMMC scheme requires C3PAOs to meet the Type A requirements for a third-party inspection body. Under the scheme’s interpretation, offering consulting or managed services in support of information security disqualifies an organization from Type A status. Separately, a C3PAO that provides advisory services to a specific organization is disqualified from assessing that organization. Both constraints remain in force during the suspension.
Is CMMC cancelled? No. CMMC Phase 2 is suspended, not repealed. The program rule remains codified at 32 CFR Part 170, DFARS 252.204-7012 is unchanged, and NIST SP 800-171 Revision 2 still applies. A CMMC Reform Task Force delivered recommendations to the Department of War CIO in mid-September 2026, with a public report expected between late September and early October. A task force report is advice: contractual obligations change only through a class deviation, a DFARS rule, or an amendment to 32 CFR Part 170.
Should defense contractors stop CMMC preparation during the suspension? Pausing C3PAO scheduling and certification-specific spend is defensible where no customer requires it. Pausing control implementation is not, because those controls are NIST SP 800-171 requirements that DFARS 252.204-7012 still mandates independently of CMMC. The common failure is an organization that runs both under one project name and halts both at once. Separate the budget lines first. Evidence also accumulates on calendar time, so a pause in collection cannot be recovered later.
Who carries the legal risk without a third-party assessor? The contractor. A current NIST SP 800-171 self-assessment posted in SPRS with an annual senior official affirmation remains a condition of eligibility. A false or overstated affirmation carries False Claims Act exposure, along with potential contract termination, suspension or debarment. The Department of Justice announced cybersecurity False Claims Act settlements during the review window, so enforcement did not pause with the program.