02
Readiness consulting vs. an official CMMC assessment: what's the difference?
The short answer: they are two different jobs, and by design they cannot be performed by the same firm for the same client.
What a readiness partner does
A readiness consultant, whether a Registered Provider Organization, a managed service provider, or your own internal team, helps you become compliant. That work typically includes:
- Assessing where you stand against the 110 requirements
- Writing or rebuilding your System Security Plan
- Implementing technical controls and configuring your environment
- Organizing evidence and documentation
- Training your staff on what they will be asked to demonstrate
This is hands-on, advisory work. A good readiness partner is invested in getting you to a passing outcome, which is exactly what you want from them.
What an assessor does
An authorized third-party assessment organization conducts the official assessment and issues the certification decision. The work is evaluative, not advisory. We examine your environment against the assessment objectives, interview your people, validate evidence, and record what we find.
We do not fix things during an assessment. We do not tell you how to implement a control while we are evaluating whether you implemented it. That restraint is not unhelpfulness, it is the entire point.
Why the same firm cannot do both
An assessor who also sold you the readiness work has an interest in what they find. If they identify a gap, they are identifying their own failure. That is a conflict, and the program treats it as one.
An authorized assessment organization cannot assess a client to whom it has provided CMMC advisory services, with a lookback period of three years. The rule exists so that a certification means something to the government relying on it.
For you as a buyer, that has a practical consequence: you will likely need both kinds of firm, and they need to be different firms. It also means every advisory engagement you enter with an assessor removes them as your assessor for three years, which is worth knowing before you sign anything.
A question worth asking any assessor
Ask whether they also sell CMMC advisory work. If the answer is yes, ask how they keep the two apart, and whether taking advisory help from them today disqualifies them from assessing you later. The answer will tell you a great deal.
ManageIT Security does not sell advisory or readiness services to anyone. That means we can assess any organization that calls us, and it means we are not competing with the partner who got you ready.
How to sequence it
Readiness first, assessment second. Bring in a readiness partner or use your internal team to close your gaps, get your documentation aligned with reality, organize your evidence, and then engage an assessor. Organizations that reverse the order tend to pay for an assessment that tells them what a readiness review would have told them for less.
If you are working with a readiness partner and want to know what an assessment will look like, book an intro call.