No — CMMC does not require your consultant to be US-based. As long as the consultant never accesses Controlled Unclassified Information (CUI), advisory work — gap analysis, SSP writing, enclave design, SPRS scoring — can be delivered from anywhere. Only the certification assessment must come from a C3PAO.
Where the myth comes from
People conflate two different things: handling CUI (which carries ITAR/EAR and NARA marking obligations, and often US-person requirements) and advising on the control environment around it. The DoD’s CMMC rules regulate who assesses you and how CUI is protected — they do not nationality-test your consultant.
The one real boundary
If a consultant would touch CUI itself — log into the enclave, open contract documents, handle technical data — then export-control rules absolutely apply, and for ITAR data that generally means US persons only. The fix is architectural: a well-run engagement keeps the consultant outside the CUI boundary entirely. Screenshots of configurations, sanitized exports and screen-share sessions driven by your staff cover 100% of advisory needs.
What this means for your budget
International consultants typically price 30–50% below US market rates for identical NIST SP 800-171 expertise. On a Level 2 programme that difference funds your entire enclave build — see our Virginia enclave case study, where re-architecture cut a $20,000 quote to about $5,000.
Checklist before you hire any CMMC consultant
- They commit in writing to a no-CUI-access engagement model.
- They can show assessor-style SPRS scoring, not just policy templates.
- They separate readiness (them) from assessment (a C3PAO) — anyone offering both should worry you.
Related: CMMC for non-US companies · Free SPRS calculator · CMMC cost planner