Schedule a call

Compliance

How to choose a CMMC partner

Cloud Kings

The questions that actually separate providers — and the ones that don’t.

Most guides to choosing a CMMC provider are checklists of things every provider will say yes to. “Do you have CMMC experience?” Yes. “Do you know NIST 800-171?” Yes. “Can you help with GCC High?” Yes.

Questions everyone passes tell you nothing. Here are the ones that actually produce different answers from different providers, and what the answers mean.

First, the honest framing

Providers in this market broadly split into two shapes, and neither is better.

National-scale providers serve hundreds or thousands of contractors. They have the deepest benches, the longest published track records, separate managed IT, security-operations and GRC practices, and usually a 24/7 SOC. If you are a mid-size or large contractor with a complex estate, or your board wants the largest documented assessment history available, this shape fits you and you should be talking to them.

Boutique providers serve a focused book. Fewer accounts, senior people directly on them, more flexibility in scope and contract shape. If you are a smaller contractor, the relevant risk at a large provider is not competence — it is being a modest line item among hundreds.

The mistake is picking on brand recognition rather than on which shape matches how you actually buy and how much attention you need. Work out which you are first. The questions below work for either.

The questions that discriminate

1. “Which of the 320 assessment objectives do you take responsibility for, and which stay mine?”

The single most useful question you can ask, and the one that produces the widest variation in answers.

Every provider covers some subset. Almost none cover all of it, because much of CMMC is organisational — training, policy adherence, personnel screening — and cannot be outsourced to a technology partner. A provider who answers “we handle all of it” either misunderstands the framework or is telling you what you want to hear.

Ask for the shared responsibility matrix in writing, objective by objective. A provider who has one will send it. A provider who doesn’t will send a brochure. That distinction alone will thin your shortlist.

Ours is published here, at family level, with a CSV you can send to every provider you are considering — including us.

2. “Are you yourself CMMC certified, at what level, and can I see the status?”

Your provider will handle your CUI. That makes them part of your scope.

Some providers hold their own CMMC certification. Some hold certification for the company but not for the specific managed service you would be buying — those are different assertions and it is fair to ask which you are being offered. Ask for the specifics rather than the logo.

3. “Who specifically will be on my account, and what else are they on?”

Every provider sells senior expertise. Fewer will name the individual and tell you their other commitments.

There is no correct answer — a named engineer with eight accounts may serve you better than a rotating pool of thirty. But you want to know which you are getting before you find out at 6pm during an incident.

4. “Do you do remediation and assessment preparation and run the environment?”

Often yes, and often fine — but understand the shape. A provider who builds your environment, remediates it, and then prepares you for assessment on it is marking their own homework at every stage.

The follow-up matters more: “Who independently checks your work?” A provider comfortable with that question will have an answer. Note that a C3PAO cannot assess an environment it helped build, so if your provider has a close C3PAO relationship, ask directly how that separation is maintained.

5. “What happens to my environment if I leave?”

Ask before you sign, not when you want to go.

Specifically: does the tenant belong to you or to them? Are the licences under your agreement or theirs? Will you get your documentation, policies and evidence in a usable form? Is there a defined offboarding process, and what does it cost?

A provider confident in their retention answers this without discomfort.

6. “What’s your read on the Phase II suspension?”

A current-events question that works as a competence test.

CMMC Phase II was suspended on 13 July 2026. A provider who tells you the requirement has gone away is wrong and not paying attention. Phase I, DFARS 252.204-7012 and NIST SP 800-171 all remain in force, a current CMMC status still gates contract award, and only Level 1 (Self) and Level 2 (Self) may be designated during the suspension.

The answer you want describes what changed, what didn’t, and what they are advising clients to do differently — if anything. Here is ours.

7. “Can I speak to a client roughly my size?”

Not a reference — a size-matched reference.

A provider with a thousand clients will have excellent references. Whether any of them look like a thirty-person shop is the actual question. If every reference offered is several times your size, that tells you where their operating model is tuned, which is useful and not damning.

8. “How long until work actually starts — and how many hands does it pass through?”

Ask for two dates, not one: when the contract is signed, and when a named person is actually in your tenant doing work. Providers talk about project duration. The gap before the project begins is where they differ most and disclose least.

Then ask how many teams the work passes through. At a larger provider a typical engagement moves from a sales engineer to a scoping team to a delivery team to a support team. Each of those handoffs is a place where days accumulate, and none of them show up in a quoted project timeline.

Neither model is wrong — a queue exists because demand is high, and specialised teams exist because they are good at their piece. But if getting to a defensible posture quickly matters to you, ask the question and compare the answers. It is one of the few places where a smaller provider has a structural rather than a rhetorical advantage.

Be sceptical of anyone quoting you a firm completion date before they have seen your tenant. Real turnaround depends on the state of your environment, how fast your own side can make decisions, and whether licensing is already in place. A confident number offered before a scoping conversation is a guess.

9. “What is not included?”

Ask it exactly that way and stay quiet.

Every scope has edges — endpoint hardware, physical security, personnel screening, training delivery, incident response retainers, the assessment fee itself. You want the edges named up front rather than discovered as a change order.

Questions that sound good but don’t discriminate

  • “Do you have CMMC experience?” Everyone says yes.
  • “Do you know GCC High?” Everyone selling into this market says yes.
  • “Are you a Microsoft partner?” Nearly universal. Ask about specific specializations if you want signal.
  • “How many clients do you have?” Tells you their size, not your fit.
  • “What’s your pass rate?” Almost nobody publishes a denominator, and clients who never reached assessment usually aren’t in it.

Red flags

  • A guaranteed certification outcome. Nobody can promise this. The assessment is not theirs to decide.
  • “You’ll be fully compliant in six weeks” — or any timeframe offered without having seen your environment.
  • A quote before a scoping conversation. Either they are guessing or the scope will change later.
  • Any suggestion the suspension means you can stop. See question 6.
  • Reluctance to put the shared responsibility matrix in writing.

Where the suspension changes the calculus

The Phase II suspension makes provider choice more consequential, not less.

With third-party certification paused, the artefact carrying the weight is your own self-assessment and the annual affirmation a named senior person in your organisation signs in SPRS. There is no external assessor scheduled to catch a provider who has quietly let your posture drift.

So the question shifts from “can this provider get me through an assessment” to “will this provider keep me genuinely compliant when nobody external is checking.” Questions 1, 4 and 5 above are the ones that get at it.

Where Cloud Kings fits

We are a boutique provider by choice. We deploy and manage CMMC Level 2-ready GCC High and Azure Government environments for defense contractors, and we work with a focused book so that the people who build your environment are the people who answer when you call.

The practical consequence is turnaround. Your project does not enter a queue and does not pass between a scoping team, a delivery team and a support team before anyone touches your tenant. The person who scopes your environment is the person who builds it, and decisions about your environment do not travel up a chain before they get made. That is not a claim about effort — it is a description of how a smaller firm is structured, and you can verify it in the first conversation.

We begin work within five business days of signature. That is a commitment rather than an estimate. If a particular engagement cannot start inside that window, we will tell you before you sign rather than after.

What we will not do is quote you a completion date before seeing your environment. How long the whole thing takes genuinely depends on the state of your tenant, how quickly your side can make decisions, and whether your licensing is already in place. Anyone giving you a firm end date before they have looked is guessing. Ask us question 8 and you will get real dates for the start; you get the finish date once we have seen what we are starting on.

We are not the right fit for everyone. If you are a large contractor who needs the deepest bench in the market and a 24/7 SOC under the same contract, a national-scale provider will serve you better, and we would rather say so now.

Put the nine questions above to us and to whoever else you are considering. If our answers aren’t the best ones you get, you should go elsewhere — and you will have chosen well either way.

We offer a free CMMC gap assessment for qualifying contractors — where you actually stand against the 110 controls, and which of them are yours rather than ours. Schedule a call if you would like to start with question 1.


Reflects the regulatory position as of 4 August 2026 and will change when the CMMC Reform Task Force reports. Last reviewed 4 August 2026. Not legal advice.

Continue reading

Keep in the loop