# Who Should a Small Defense Subcontractor Hire to Get Ready for CMMC Level 2? — Eagle Ridge Advisory Insights # Who Should a Small Defense Subcontractor Hire to Get Ready for CMMC Level 2? By Eagle Ridge Advisory · September 10, 2026 · 6 min read A small defense subcontractor needs someone to get it ready before it signs with a C3PAO assessor. If you have the bandwidth in house, do it yourself. If not, hire a readiness partner first and a C3PAO second. The readiness partner gets you to a passing posture. The C3PAO confirms it. By rule, one firm cannot do both for the same client. This article explains who the players are, why the split exists, and how to pick the right one for a company with 10 to 100 people and no security department. ## Who are the four kinds of CMMC help? Four kinds of firm will offer to help you with CMMC Level 2. They do different jobs. | Who | What they do | What they cannot do | | --- | --- | --- | | Readiness partner (RPO / Registered Provider) | Finds your gaps against the 110 NIST 800-171 controls, helps close them, writes the System Security Plan (SSP), packages evidence, calculates your SPRS score | Cannot certify you | | C3PAO (assessor) | Runs the official Level 2 assessment and issues the certification result | Cannot prepare the same client it assesses | | MSP / IT provider | Runs your network, laptops, email, and cloud. Applies the technical fixes. | Usually does not own the documentation, scoping, or evidence work | | Compliance platform (software) | Tracks controls, stores policies, collects some evidence automatically | Does not decide what is in scope, write your narratives, or fix your systems | Most small contractors end up with two or three of these at once. A typical mix is a readiness partner plus your existing MSP, followed by a C3PAO at the end. See the [glossary](/glossary) for the acronyms. ## Why can't the assessor also get me ready? The CMMC program keeps the grader and the coach separate. A C3PAO that helped you build your program cannot then assess that program. The result would not be independent, and the certification would not mean much. This is the same logic your accountant follows. The firm that keeps your books does not audit them. The practical effect for you: plan two relationships, in order. First the readiness work. Then the assessment. We wrote more on why the order matters in [Why Readiness Comes Before the Assessment](/insights/readiness-before-the-assessment). ## Do I need a readiness partner if I already have an MSP? Usually yes, and the two work well together. Your MSP is good at the technical fixes: multi-factor authentication, logging, encryption, patching. Those fixes move your SPRS score. But CMMC Level 2 also requires a scoped system boundary, an SSP with 110 control narratives, signed policies, and an evidence inventory an assessor can follow. Documentation is most of the work, and it is the part an MSP rarely owns. An assessor treats "not documented" as "not met." A readiness partner writes that documentation and hands your MSP a prioritized list of technical fixes. Ask your MSP directly: "Will you write the SSP and the policies?" If the answer is no, you need a readiness partner too. ## Is a compliance platform enough on its own? No. A platform tracks work. It does not do the work. It will not decide whether your CUI lives on three laptops or your whole network, or which gaps to fix first, or write narratives that match how your company operates. Software helps most after the program exists, when the job is keeping evidence current. Before that, a tool-only offer leaves a founder with a dashboard full of red and no plan. ## What should I ask on the first call? Ask these questions to any firm, and listen for specific answers. 1. Are you a C3PAO, or a readiness provider? If both, which one will you be for us? 2. Who scopes our CUI boundary, and how do you decide what to leave out? 3. What does the gap assessment produce? (You want a score against all 110 controls and a prioritized list.) 4. Who writes the SSP narratives and the policies? Is that in the price? 5. What is my team's part, in hours, and what is yours? 6. What happens after the assessment? Who keeps the SSP current? Good answers name a person and a deliverable. Vague answers ("we handle everything") are a signal to keep looking. ## What are the red flags? * **Template SSPs.** An SSP written from a template describes a company that does not exist. Assessors read for that. Generic policy templates make things worse when they do not match what you actually do. * **"Guaranteed certification."** No readiness provider controls the assessment. The C3PAO does. A guarantee either means the firm is also the assessor (not allowed) or the guarantee is empty. * **Tool-only offers.** A login and a checklist is not readiness. Ask who does the scoping, writing, and evidence work. * **No score.** If the first deliverable does not include an honest SPRS score, you cannot see how far you have to go. Read [The Path to 88](/path-to-88) to see what a real score trajectory looks like. * **Your hours look like their hours.** A plan that lists 100 hours of work without saying who does them leaves a 10-person shop holding the homework. ## How Eagle Ridge fits Eagle Ridge does readiness only. We scope the boundary, assess all 110 controls, prioritize the fixes with your IT support, write the SSP and policies, package the evidence, and review it the way an assessor will. A Registered Provider reviews every deliverable. Then you hire a C3PAO for the assessment, and we do not compete with them. If you want to gauge where you stand before a call, start with the [CMMC readiness checklist](/cmmc-readiness-checklist). When you are ready, [book a readiness call](/contact). ## FAQ **Can a C3PAO give me advice before my assessment?** A C3PAO can answer general questions. It cannot build your program, write your SSP, or fix your gaps and then assess the result. If you want one firm to do the preparation, it must be a different firm from your assessor. **Does my readiness partner need to be an RPO?** The Cyber AB registers readiness firms as Registered Provider Organizations. Registration signals the firm knows the program rules. Ask for it, then judge the firm on its deliverables and its answers to the questions above. **Can my MSP be my readiness partner?** Some MSPs offer it. Check whether they will own the scoping, the SSP, the policies, and the evidence inventory, not only the technical controls. If they only do the technical side, pair them with a readiness partner. **When do I need this?** The Department of War suspended CMMC Phase 2 (the third-party certification requirement that was due in November 2026) on July 13, 2026, pending a reform review. Level 2 self-assessments, SPRS scores, annual affirmations, and DFARS 252.204-7012 remain in force, and primes still flow requirements down. Readiness for a small contractor typically takes months, so the sensible move is to keep your SPRS score honest and your documentation current while the rules settle.