How to Vet a CMMC Level 2 Consulting Company Before Your Audit
Before choosing a CMMC Level 2 consulting company, it’s critical to ask the right questions and understand the full financial and operational impact.
This is the internal vetting process we use at Allen CIO — along with a pricing spreadsheet you can request by emailing [email protected].
⚠️ Warning: Be cautious of companies making “too good to be true” promises.
Step 1: Non-Investment Questions
These are the foundational questions to ask any potential consulting partner:
-
What are the internal expectations of time required from your team?
-
How long will the entire CMMC readiness process take?
-
Who will guide you through the process?
-
Meet them directly.
-
Get references to verify their expertise.
-
Confirm they’ll be your primary point of contact per the contract.
-
-
Can they provide three references from similar industries?
-
What policies and plans will they deliver, and do they explicitly map to CMMC controls?
-
Will they help you minimize CUI exposure by defining the smallest possible number of users who need access?
Step 2: First-Year Investment
(Assume using Azure Gov & GCC High environments with X number of users.)
Licensing & Cloud Costs
-
GCC High Licensing
-
Azure Virtual Desktop licensing for GPU engineering workstations
-
Cloud server costs for storing CUI
-
Engineering app licenses (e.g., SolidWorks, Mastercam) hosted in the cloud
Governance, Risk, and Compliance (GRC) Tools
-
What GRC platform will they provide to track NIST 800-171 compliance?
-
What’s the cost of setup and ongoing use?
Enclave & Security Costs
-
Cost to set up the CMMC enclave
-
Additional Microsoft stack software costs, including:
-
AvePoint (Required backups)
-
CrowdStrike (Required endpoint protection)
-
KnowBe4 or similar training tools (DoD-mandated annual training)
-
Application patching solutions (Required)
-
Airlock for app whitelisting (Required)
-
Zscaler for secure remote access
-
Ticketing systems (Required for evidence tracking)
-
Managed Service Providers
-
MSP Costs: Ongoing IT support for your environment
-
MSSP Costs: Security monitoring, incident response, and SIEM integration
Audit Readiness & Experience
-
What’s the cost to prepare for the C3PAO audit?
-
How many audits have they supported successfully?
-
Which C3PAO auditors have they worked with?
-
What were the total audit costs (C3PAO + consulting fees)?
Step 3: Years 2 & 3 Investment
After year one, what are the expected recurring costs for:
-
Licensing renewals
-
Managed services
-
Security tool subscriptions
-
Ongoing compliance reporting
Step 4: Audit Years (Years 4, 7, 10, etc.)
In audit years, clarify:
-
The additional costs beyond normal years
-
Whether C3PAO audit fees decrease after successful certification in Year 1




