Registered Practitioner Home

CMMC Registered Practitioner is abbreviated “CMMC RP”


The CMMC RP is a person who pays $500 a year to the Cyber-AB to be advertised as someone who can help companies prepare for the CMMC.


Here are the benefits of working with a CMMC Registered Practitioner

  • The RP gets a handful hours of general training as described here: https://www.cmmcaudit.org/review-of-cmmc-registered-practitioner-training/
  • The RP has to pass a simple background screen.
  • The RP has to sign an ethics agreement.
  • And the CMMC-AB holds the right to yank their badge if they get a complaint about unethical practices. *I have never heard of this happening yet*

That is it. Notice I didn’t say anything about cybersecurity ability or resume review or any other level of competency.

Many “Registered Practitioners” have almost no knowledge of CMMC and are simply milking the title to make money.

Who is the typical Registered Practitioner?

In the early days of CMMC, only the Registered Practitioner program was available. It wasn’t possible to take certified assessor training. So many people (including myself) signed up as an RP.

Now that respectable certification programs are available: Certified CMMC Professional, Certified CMMC Assessor; there is very little reason for anyone to be a Registered Practitioner except for the fact that there is almost no vetting, so you don’t need to be competent in order to get a CMMC title.

Certified Assessors have to take two mandatory instructor-lead trainings and pass two exams to be certified. A Registered Practitioner just needs to click through a few hours of out-of-date CBTs. Which person do you want helping your company prepare for CMMC? Which title do you think an incompetent person will choose to get?

The Registered Practitioner program is the #1 revenue maker for the Cyber-AB, worth probably 70% or more of the revenue that the Cyber-AB is taking in yearly. So they promote this program heavily. They depend on it. Even though the program is at odds with the Cyber-AB’s need to get ISO certified as an Accreditation Body.

What can you expect as a Registered Practitioner?

You can advertise yourself using the Cyber-AB Marketplace, in exchange for paying a fee.

You get some web training about CMMC

Will you start getting tons of calls from clients?

The CMMC-AB Marketplace will probably not boost your career very much by itself. At least I haven’t heard of anyone being contacted just because they were listed as an RP. Maybe it will occur as the CMMC gets more popular.


What have you heard? How is your experience as an RP going?

Recommended articles

Policy templates and tools for CMMC and 800-171

CMMC Scope – are you ready for an assessment?

How to read and start preparing for the CMMC

Leave a Reply

Your email address will not be published. Required fields are marked *