By The Defense Compliance Report Editorial Team — an independent trade publication on CMMC 2.0 and Defense Industrial Base compliance Last reviewed: August 2026 · Last verified: August 18, 2026 Editorial status: Primary-source research. Not formally reviewed by a CMMC Subject Matter Advisor.
August 2026 status alert. The Department suspended the planned transition to CMMC Phase II on July 13, 2026. The nominal Phase I window remains November 10, 2025 through November 9, 2026, but the November 10, 2026 Phase II transition is suspended. During the suspension, new procurement requirements may designate only Level 1 (Self) or Level 2 (Self), not Level 2 (C3PAO) or Level 3 (DIBCAC). DFARS 252.204-7012 safeguarding and cyber-incident duties remain in effect where that clause applies, and CMMC still uses NIST SP 800-171 Revision 2. The implementing memorandum directs amendments to active solicitations and directs removal of higher assessment requirements from existing contracts by modification before the next option period or scheduled administrative modification. Until the written instrument is amended, read the contract you actually signed. A press release does not modify it. DoD CMMC status page · Implementing Suspension of CMMC Phase II
The bottom line, up front
CMMC for CPA and accounting firms usually does not apply to ordinary accounting work — and the reason is one phrase in the rule. Under 32 CFR § 170.23(a), CMMC requirements reach prime contractors and subcontractors at all tiers that process, store, or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) on contractor information systems in the performance of the DoD contract or subcontract. An ordinary financial-statement audit, tax return, or management report prepared for a defense contractor's own corporate purposes is not automatically performance of that DoD contract.
Four facts change the answer. You hold your own DoD contract. You are a subcontractor performing on one. You provide a separate IT or cybersecurity service that meets the External Service Provider definition. Or none of those facts is present, in which case CMMC may not attach to the engagement even though contractual security duties still can.
Here's the part almost every article gets wrong, and it's the reason the questionnaire on your desk doesn't fit: the ESP route most vendor questionnaires assume is usually shut for ordinary accounting services. The definition starts with the service you provide, not merely the data you touch. But that does not erase a real subcontract, a real flow-down, or a separate technology service. We will show you where each route begins and where it stops.
Who this is for: CPA firms, government-contract accounting consultancies, outsourced accounting and CFO providers, and the contractors trying to determine whether an outside accountant affects their CMMC scope.
Who this is not for: firms that host a client's ERP, operate a client's cloud accounting environment, run security tooling, or bundle managed IT with accounting services. The ordinary-accounting answer may not fit you. Start with our CMMC External Service Provider assessment guide instead — we'd rather send you to the right page than have you read the wrong one.
Where you probably land
| Your facts | Most likely path |
|---|---|
| Covered contract or written flow-down, and FCI or CUI lands on your firm's systems in performing that contract | Your firm may need its own CMMC status for those systems |
| CUI stays inside the client's controlled environment and cannot reach your assets | Client-environment scoping analysis; your endpoint may be out of scope if the KVM-only conditions are actually met |
| You provide a separate IT or cybersecurity service and CUI or Security Protection Data reaches assets used for that service | ESP/CSP scoping analysis under §§ 170.4 and 170.19 — not an automatic standalone certification |
| No covered contract or flow-down, no IT/cybersecurity service, and ordinary accounting only | Generally outside CMMC for that engagement; contractual and professional duties still remain |
| Marked or otherwise identified CUI already landed in email, a portal, or a file server before anyone documented the path | Stop. Preserve the facts, identify the governing contract and designation, and resolve the transfer path in writing before the next one |
The honest problem with this page
Most CPA and accounting firms do not need a CMMC program for ordinary accounting work — which means this page cannot sell you one. We publish provider-category guidance for a living, and the accurate answer to the question in the title is usually "not for this engagement." We're going to say so, and then we're going to spend the rest of this page on the part that actually costs firms money.
Because the expensive mistake here runs in the opposite direction from what you'd expect. It isn't failing to buy certification. It's writing "yes, we're compliant" on a client questionnaire to protect a relationship — a statement you cannot support, in a document that outlives the engagement. Or accepting marked CUI into a standard workpaper portal because nobody wanted to look unhelpful, and discovering eighteen months later that it is also in three backups, two support tickets, and a partner's laptop.
The four routes in our decision framework are specific, and you can check all four in about ten minutes. Let's do that first.
CMMC for CPA and accounting firms: does it apply?
Not because you're a CPA firm, and not because your client does defense work. CMMC applicability turns on the contract or flow-down, the information handled in performing it, and the systems on which that information is processed, stored, or transmitted. The profession label decides nothing — 32 CFR Part 170 contains no list of covered or exempt industries, and employee count does not set the level.
The exact words that settle it
32 CFR § 170.3(c) sets program applicability. The CMMC Program applies to DoD solicitations and contracts under which a contractor will process, store, or transmit FCI or CUI on unclassified contractor information systems, above the micro-purchase threshold, excluding contracts solely for commercially available off-the-shelf items.
32 CFR § 170.23(a) extends the requirement down the supply chain, and this is the phrase to read twice: CMMC requirements apply to prime contractors and subcontractors throughout the supply chain at all tiers that will process, store, or transmit FCI or CUI on contractor information systems in the performance of the DoD contract or subcontract.
In the performance of. Not "for a company that has one." Not "related to defense." Performance.
An ordinary financial-statement audit exists because of reporting requirements, lender covenants, owners, or a board. A tax return is a filing obligation. Internal management reporting belongs to management. None of those facts alone makes the engagement performance of a DoD contract.
An indirect cost rate proposal, incurred-cost submission, proposal-pricing engagement, or contract-required agreed-upon procedure is closer to the line because the work may be prepared for a government-contracting purpose or delivered under the contract. That is a fact question about the specific engagement, and it is exactly the kind of thing to get in writing rather than assume in either direction.
The Four Doors
There are four practical doors in our editorial decision framework. They are not four statutory labels. We built them from the rule's applicability, subcontractor, and service-provider provisions, and we verified the cited rule text on August 18, 2026.
| Door | What opens it | Primary source | Likely treatment | What you actually do |
|---|---|---|---|---|
| 1. You hold your own DoD contract | Your firm is the contractor — for example, an audit, agreed-upon procedure, or advisory engagement sold directly to a DoD component — and your systems will handle FCI or CUI in performance | 32 CFR § 170.3(c) | Solicitation specifies the required level. FCI-only generally points to Level 1 (Self); CUI points to Level 2 at minimum | Read the solicitation provision and contract clause. Confirm the systems, status, affirmation, and SPRS entries required before award |
| 2. You are a subcontractor performing on a DoD contract | You process, store, or transmit FCI or CUI on your systems in performance of the DoD contract or subcontract, at any tier | 32 CFR § 170.23(a) | FCI → Level 1 (Self). CUI → Level 2 (Self) minimum; a higher type can be required by the written instrument, subject to the current suspension direction | Get the clause, required level and assessment type, prime contract number, and information flow in writing |
| 3. You provide a separate IT or cybersecurity service | The client uses your people, technology, or facilities for IT and/or cybersecurity services, and CUI or Security Protection Data is processed, stored, or transmitted on assets used for that service | 32 CFR § 170.4; § 170.19 | CSP, non-cloud ESP, and Security Protection Asset treatments differ. The rule does not automatically assign every ESP its own standalone CMMC status | Separate the technology service from the accounting service, map the assets and data, and document the responsibility split |
| 4. None of the above | Ordinary accounting work for the client's own corporate purposes, with no covered contract role and no separate IT/cybersecurity service | §§ 170.3(c) and 170.23(a), by their terms | CMMC generally does not attach to that engagement | Still read the security addendum, confidentiality terms, data-flow restrictions, and professional-retention duties |
Door 4 is not "you're clear"
This is where firms get comfortable too early. CMMC may not attach to your engagement, but your client's obligations can still land squarely on it:
- NIST SP 800-171 Revision 2, requirement 3.1.3 requires the contractor to control the flow of CUI.
- The client's System Security Plan must describe the system boundary and how applicable requirements are implemented.
- DFARS 252.204-7012 binds a contractor where included and requires flow-down when subcontract performance involves covered defense information or operationally critical support.
The practical result is the one firms see most often: the client either refuses to send CUI, requires work inside its environment, or imposes security terms by contract regardless of whether your firm needs a CMMC status. Either way, your real answer may be architectural, not certification. You change how you receive data. You do not build a compliance program around custody you never needed.
That reframe is worth more than anything else on this page, and we'll spend two full sections on it below.
The edge case that changes everything
If your firm hosts the client's ERP or accounting environment, administers the platform, manages the client's controls, or bundles outsourced accounting with managed IT, you may actually be providing an IT service — and Door 3 opens. If an external cloud service stores, processes, or transmits covered defense information in performance of a contract containing DFARS 252.204-7012, the clause's FedRAMP Moderate-equivalent requirement becomes a live question rather than a theoretical one.
That's a different analysis with a different price tag. Read our CMMC External Service Provider assessment guide before you read another vendor quote.
→ Run the door check on one engagement
You now know the four doors. Before you buy anything, pick one client engagement and write down five facts:
- Who is party to the DoD prime contract or subcontract?
- Is this accounting work itself being performed under that contract?
- Which clause and CMMC level or assessment type are actually written into the solicitation, contract, or flow-down?
- What information will be identified as FCI or CUI, by whom, and under what authority?
- On whose systems will that information be processed, stored, transmitted, or protected?
If one answer is missing, that missing document — not a cybersecurity product — is your next step.
For general routing after you collect those facts, use Find My CMMC Path →. It is educational triage, not a binding applicability determination. Do not submit CUI, drawings, client names, contract files, system diagrams, credentials, or other sensitive information.
The right provider category is not the same for every contractor. A C3PAO, RPO, MSSP, GRC platform, CUI enclave, and federal-contracts attorney solve different problems. The written requirement, CUI scope, assessment type, environment, and timeline decide which category belongs first. See Who to Hire First and the CMMC Provider Categories guide before you request quotes.
Is my accounting firm an External Service Provider under CMMC?
Not for ordinary accounting services alone — and this is the single most misunderstood point in the vendor-CMMC conversation. 32 CFR § 170.4 defines an External Service Provider (ESP) as external people, technology, or facilities that an organization uses for the provision and management of IT and/or cybersecurity services, with CUI or Security Protection Data processed, stored, or transmitted on the ESP's assets. Both parts matter.
That means "client data touched our systems" is not a complete ESP analysis. The definition starts with what service you provide. Ordinary tax, audit, bookkeeping, payroll, valuation, or accounting advisory work is not an IT or cybersecurity service merely because software is involved.
But do not turn that point into a broader exemption than the rule gives you. A firm can still be a covered subcontractor under § 170.23, and a firm with a separate managed-technology practice can meet the ESP definition for that service. The service role settles the ESP question. It does not erase the contract question.
The four scoping outcomes — after the service meets the IT/cybersecurity prong
32 CFR § 170.19 resolves the data and scoping side of the analysis for a service used to provide IT or cybersecurity. Read it together with § 170.4: when the provider processes neither CUI nor Security Protection Data, § 170.19 says the provider does not meet the full CMMC definition of an ESP for that service. This is not a four-row test for every ordinary vendor.
| ESP fact pattern | CMMC treatment under § 170.19 | Practical consequence for the assessed organization |
|---|---|---|
| Cloud service provider processes, stores, or transmits CUI | The cloud service must meet the requirements imposed through DFARS 252.204-7012, including the applicable FedRAMP Moderate-equivalent requirement | Document the cloud service, authorization or equivalency posture, data flow, and responsibility split |
| Non-cloud ESP processes, stores, or transmits CUI | The services used to process, store, or transmit CUI are included in the organization's CMMC assessment scope and assessed | Document the service in the SSP, service description, and Customer Responsibility Matrix |
| ESP handles Security Protection Data but not CUI | The services are included in the assessment scope and assessed as Security Protection Assets | Assess the security requirements relevant to the provided capability and document the assets and responsibilities |
| ESP handles neither CUI nor Security Protection Data | The provider does not meet the data condition in the ESP definition for that service | No ESP treatment for that service; ordinary vendor management remains |
An ordinary accounting firm usually exits before that table because it does not provide the first thing the definition requires: an IT or cybersecurity service. If the same firm runs a hosted accounting platform, manages access controls, operates a GRC system, or administers a client's cloud environment, run the table on that technology service separately.
DoD's scoping guide uses a cloud-accounting example — but not as a profession-wide exemption
The DoD CMMC Level 2 Scoping Guide, Version 2.13, September 2024, includes an example of a commercial cloud accounting SaaS provider that typically does not handle CUI or Security Protection Data and does not contribute to the security of the CUI environment. In that fact pattern, the service typically would not meet the ESP definition.
That is useful because it names a familiar accounting technology. It is not a blanket statement about every CPA firm, every accounting platform, or every implementation. The guide tells the assessed organization to decide based on the service actually provided and whether CUI or Security Protection Data is present.
The load-bearing authority remains the rule: § 170.4 defines the ESP, and § 170.19 determines the scoping treatment.
When a CPA firm's service does raise the ESP or cloud question
Be honest with yourself about the full service list. These are the fact patterns that change the answer:
- You host or administer the portal where client CUI is stored
- You operate a cloud accounting environment that holds CUI
- Your technology practice manages the client's controls, identity, configurations, or endpoints
- You collect security logs, vulnerability data, or SIEM output
- You hold privileged administrative access as part of an IT or cybersecurity service
- You operate a GRC or evidence platform for the client's compliance program
- You manage a third-party cloud service on the client's behalf
- You supply technology or facilities that protect the client's CUI environment
Notice that every one of those is a technology or cybersecurity service, not merely an accounting service. If your firm has an IT practice and an accounting practice, the analysis follows the service, not the letterhead. Separate the services, systems, data flows, and responsibility matrices explicitly in your engagement documents, or someone else will separate them for you later, under less pleasant circumstances.
What do I write on a client's CMMC questionnaire?
Answer factually about what you do and do not hold, separate a NIST DoD Assessment score from a CMMC status, cite the provision that governs applicability, and ask the client for the documents that actually resolve the question. Do not assert a level, a score, a CMMC UID, or "compliance" you cannot support.
Most vendor security questionnaires are built from an IT-vendor template. They routinely ask accounting firms for attributes the rule never assigns to them, and they often use "SPRS score" and "CMMC certification" as if those were the same thing. They are not.
First: separate the two SPRS records people keep conflating
- A NIST SP 800-171 DoD Assessment summary score is the score associated with the DFARS assessment framework in 252.204-7019 and 252.204-7020, or with the applicable Part 240 class-deviation clause in a solicitation that uses the Revolutionary FAR Overhaul text.
- A CMMC status, annual affirmation, and CMMC UID are the records used by DFARS 252.204-7021 and the preaward provision at 252.204-7025.
Both can appear in SPRS. One is not a synonym for the other.
The decoder
| What the questionnaire asks | What it is actually trying to establish | Accurate response for typical accounting-only work | What to reference | What not to say |
|---|---|---|---|---|
| "What is your CMMC level?" | Whether your firm has a current CMMC status for the systems and engagement at issue | "Our firm does not claim a CMMC status for this engagement. Please identify the clause, required level and assessment type, and the contract or subcontract you believe applies." | 32 CFR §§ 170.3, 170.23; DFARS 252.204-7021/-7025 | Never claim a level you do not hold. Do not write "CMMC compliant" as a substitute |
| "Are you an External Service Provider?" | Whether the service meets § 170.4 and, if so, how § 170.19 scopes it | "For this engagement we provide accounting services, not IT or cybersecurity services. On those facts, the ESP definition is not met. Please identify any technology service you believe changes that conclusion." | 32 CFR §§ 170.4 and 170.19 | Do not answer yes solely because client files touch software |
| "Provide your SPRS score." | Often ambiguous: a NIST DoD Assessment score, a CMMC assessment score/status, or both | "Please specify whether you are requesting a NIST SP 800-171 DoD Assessment summary score or a CMMC status/UID, and identify the clause requiring it." | DFARS 252.204-7019/-7020 versus 252.204-7021/-7025 | Never invent, estimate, borrow, or reuse another system's score |
| "Do you handle CUI?" | Whether information designated or otherwise identified as CUI reaches your systems | Answer only from observed facts, then request the designating agency, category or subcategory, governing authority, marking, approved transfer path, and contract reference | 32 CFR §§ 2002.4 and 2002.20; DFARS 252.204-7012 | Do not decide from the filename or the client's anxiety |
| "Will you sign our security addendum?" | Whether you will accept independent contractual duties | Route it to counsel and the engagement owner. CMMC applicability does not answer whether you should accept the addendum | The proposed contract itself | Do not sign a flow-down or incident-reporting obligation nobody at your firm has read |
| "Does your SOC 2 report cover this?" | Whether an existing attestation satisfies the client's security requirement | "A SOC 2 examination is not a CMMC assessment and does not establish implementation of all 110 CMMC Level 2 requirements." | NIST SP 800-171 Rev. 2; 32 CFR Part 170 | Do not imply equivalence |
The reply, in full
Use this only after confirming that the factual statements are true for the engagement. Put it on firm letterhead, have counsel review it once, and keep the final version in the engagement file.
Thank you for the security questionnaire. We want to answer against the engagement and contract that actually apply. Under 32 CFR § 170.23(a), CMMC requirements apply to contractors and subcontractors that process, store, or transmit Federal Contract Information or Controlled Unclassified Information on contractor information systems in the performance of a DoD contract or subcontract.
For this engagement, our firm provides accounting services and does not provide IT or cybersecurity services. We do not claim a CMMC status, CMMC UID, or NIST SP 800-171 DoD Assessment score for this engagement. If you believe the engagement is being performed under your DoD contract or subcontract, or that a CMMC or DFARS clause flows down to it, please identify the specific clause, required CMMC level and assessment type, prime contract number, and the information you expect to be designated or otherwise identified as FCI or CUI.
We are also prepared to discuss performing the work inside your controlled environment rather than receiving protected data into ours. In many accounting engagements, resolving the transfer architecture is faster and more defensible than asking an outside accountant to claim a status the contract does not require.
The five questions to send back
Ask these in writing every time. They cost you nothing and they move the determination toward the documents that control it.
- Do you consider our engagement to be performance of your DoD contract or subcontract? If yes, identify the prime contract and the work statement.
- Which clause are you flowing down, and what CMMC level and assessment type does the written instrument require?
- What information will be designated or otherwise identified as CUI, by which agency or authorized holder, under which CUI category and authority?
- Can we perform the work inside your environment instead of receiving the data into ours?
- Who at your organization owns the CUI-flow and System Security Plan decision for this engagement?
That fourth question is the one that ends most of these conversations. We'll show you why in a moment.
→ Put the answer in the workpaper file
Copy the final response, the client's written answers, the governing clause, and a dated data-flow decision into the engagement file. That record is more useful than a verbal "we should be fine" six months later.
For broader environment preparation, use the 32-point CMMC Readiness Checklist. It is a general readiness resource, not a CPA-specific legal determination.
Educational template, not legal advice. Have counsel review it before you send it under a signed engagement.
Is accounting data FCI or CUI? Are invoices? Are labor rates?
Not automatically — and the distinction is sharper than most firms assume. Simple transactional information necessary to process payments is excluded from the definition of Federal Contract Information. The NARA CUI Registry also contains a General Procurement and Acquisition category whose description expressly includes cost or pricing data, contract information, indirect costs, and direct labor rates. That does not make every invoice, rate, or cost report CUI. The governing authority and a valid designation still matter.
First, the payment exclusion — the good news nobody tells you
The FCI definition incorporated into CMMC excludes simple transactional information, such as that necessary to process payments. The same exclusion appears in the FCI definition used by DFARS 252.204-7021.
Read plainly: a remittance amount, bank routing instruction, or invoice total can be payment-processing information rather than FCI on its own.
The catch is that invoices are rarely just invoices. A single invoice can carry a contract number, task-order reference, program name, labor categories, a direct labor-rate schedule, a deliverable description, and a technical attachment. One benign field does not neutralize protected material in the same document or transmission. The exclusion covers the simple payment facts, not everything that traveled in the same envelope.
Practical rule for your AP and billing workflow: separate the payment facts from contract-performance material. Different attachments, different transfer paths, different access, and different retention where the engagement permits it.
Then the finding: the CUI Registry names the data accountants actually see
We read the current NARA CUI Registry category pages on August 18, 2026.
General Procurement and Acquisition — category marking PROCURE, with CUI//SP-PROCURE under its Specified authorities. The Registry describes the category as material and information relating to acquisition and procurement, including cost or pricing data, contract information, indirect costs, and direct labor rates.
Read that list again. Cost or pricing data. Contract information. Indirect costs. Direct labor rates.
Those are the exact data types a government-contract accounting practice may encounter. The important word is may. A Registry category describes information that can be CUI when an applicable law, regulation, or government-wide policy and a valid designation bring the specific information into the category. The category description is not a switch an accounting firm flips by itself.
Source Selection covers nonpublic information prepared for an agency's evaluation of a bid or proposal. Its Specified authorities use CUI//SP-SSEL; its Basic authorities use CUI, with CUI//SSEL listed as an alternative Basic banner. If your firm performs proposal support or handles agency source-selection material, this is a separate category analysis.
The grouping question can affect the minimum assessment type — but the contract still controls
The January 15, 2025 CMMC Level Determination Guide used NARA Organizational Index Groupings to set minimum assessment types: CUI outside the Defense grouping pointed to Level 2 (Self), while CUI in the Defense grouping pointed to Level 2 (C3PAO). The guide also allowed the requiring activity to select a higher level when security needs dictated.
That guide predates the July 13, 2026 suspension. The current suspension memorandum prohibits new Level 2 (C3PAO) and Level 3 designations during the review. So the guide remains useful historical context for why categories mattered, but it is not a substitute for the current solicitation, contract, flow-down, or suspension instructions.
| CUI category | Typical Registry marking | NARA grouping | January 15, 2025 guide's stated minimum before the suspension | August 2026 procurement posture |
|---|---|---|---|---|
| General Procurement and Acquisition | CUI//SP-PROCURE under Specified authorities; CUI under its Basic authority | Procurement and Acquisition | Level 2 (Self), subject to a higher requirement selected for risk | New procurement designations are limited to Level 2 (Self) during the suspension |
| Source Selection | CUI//SP-SSEL under Specified authorities; CUI or CUI//SSEL under Basic authorities | Procurement and Acquisition | Level 2 (Self), subject to a higher requirement selected for risk | New procurement designations are limited to Level 2 (Self) during the suspension |
| Controlled Technical Information | CUI//SP-CTI | Defense | Level 2 (C3PAO) minimum under the dated guide | New Level 2 (C3PAO) designations are suspended; verify the written instrument and amendment status |
Controlled Technical Information is not the only category in the Defense grouping. The Registry also places categories such as DoD Critical Infrastructure Security Information, Naval Nuclear Propulsion Information, Privileged Safety Information, and Unclassified Controlled Nuclear Information—Defense within that grouping. Do not turn "we do not handle drawings" into "we cannot touch Defense-grouping CUI."
The financially useful conclusion is narrower and stronger than the original shortcut: an accounting engagement that genuinely involves only Procurement and Acquisition-grouping CUI may point toward Level 2 (Self) under the dated determination guide, but the program office and written contract still decide the requirement, and the current suspension limits new designations to self-assessment paths.
Two guardrails, because we'd rather be useful than dramatic:
On 41 U.S.C. 2105. The NARA category page lists sanctions associated with certain Procurement Integrity Act authorities. We are reporting the Registry's authority and sanctions columns as published. We are not telling you that an outside auditor automatically faces those penalties. Applicability is a legal question for counsel.
On tax and proprietary business data. Federal taxpayer information and proprietary business information are separate CUI categories with their own authorities. Tax information also brings IRC § 6103 and, in relevant government-handling contexts, IRS Publication 1075 into the picture. We did not re-verify the exact current banner marking for those categories in this review, so we are not publishing one. Confirm the category, authority, and marking in the CUI Registry before relying on it.
Never invent the designation yourself
This bears saying plainly because firms do it: do not create a CUI designation from a category page and do not remove a marking because you disagree with it. Under 32 CFR § 2002.4, an authorized holder designates a specific item as CUI consistent with the rule and Registry, and the designating agency is the executive branch agency that designates or approves the designation. Section 2002.20 controls the marking structure.
Your client may be the channel through which the information reaches you, but it is not automatically the designating agency. Ask for:
- The designating agency and point of contact
- The category or subcategory and governing authority
- The required banner and portion markings
- Any limited-dissemination controls
- Whether derivative work product remains CUI
- The approved transfer method
- Retention, decontrol, return, and destruction instructions
If those answers do not exist, that is information too. It usually means the data should not be moving again until someone with authority resolves the designation and path.
Which accounting systems come into the CMMC boundary?
No software product carries a transferable CMMC status, and no vendor can sell you one. QuickBooks, an ERP, a payroll platform, a workpaper portal, an email tenant, and a backup system enter the analysis when the configured environment processes, stores, transmits, or protects covered information in performing a covered contract. The right question is never "is this product CMMC compliant?" It is "what protected information reaches this implementation, what role does the service play, and what requirement is written into the contract?"
Is QuickBooks CMMC compliant?
Direct answer, because people search this exact phrase: no product has a CMMC status of its own. CMMC evaluates the contractor information systems within a defined assessment scope, the implemented requirements, the evidence, and the contractual status required. A QuickBooks environment holding no FCI or CUI may sit outside the boundary. A configured environment holding covered information needs a system-specific analysis.
Anyone selling "CMMC-compliant accounting software" as a status you inherit is describing something that does not exist. A product can support a compliant architecture. It cannot transfer a CMMC status to your firm.
The system-by-system read
| System | When it is commonly outside | What pulls it into the analysis | First question to ask |
|---|---|---|---|
| QuickBooks / general ledger | Ordinary commercial accounting data only | Contract-performance fields, protected attachments, exports into analytics, or a covered flow-down | What FCI or CUI actually resides here? |
| ERP / job-cost system | No covered contract information | Contract numbers, work-breakdown structures, labor categories, direct labor rates, indirect pools, program names, technical attachments | Which modules, integrations, and exports touch it? |
| Payroll | Ordinary payroll and simple payment data | Labor distributions tied to protected programs, designated rate data, free-text fields, protected attachments | Has any contract-specific field been identified as CUI? |
| Tax and audit workpaper portal | No CUI or Security Protection Data present | Marked or otherwise identified CUI uploads, protected permanent-file attachments, automated backups, external support access | Is this an approved transfer and retention path in writing? |
| Email tenant | Covered information cannot arrive | Attachments, forwarding rules, retention, mobile access, journaling, discovery archives | Can covered information arrive here, and where can it persist? |
| Backup and archive | Source systems hold nothing covered | Replication of any system above, snapshots, e-discovery archives, support logs | Where do copies go, how long do they remain, and who can read them? |
| E-signature platform | Ordinary engagement documents only | Protected exhibits and attachments retained by the service | Does the platform retain a copy or metadata containing covered information? |
| Identity, firewall, SIEM, or managed endpoint platform | Provides no security function to a CUI environment | Protects CUI assets or contains Security Protection Data | Is it a Security Protection Asset or part of an ESP service? |
The secondary-copy problem
This is where firms with a clean primary environment still lose the boundary. A well-designed path gets undone by email forwarding, local downloads, browser cache, print-to-PDF, desktop sync, backup replication, e-discovery archives, support tickets, screenshots, mobile access, and exports to an analytics tool nobody included in the diagram.
Secondary copies count when they process, store, or transmit the covered information. Map the copies, not just the intended path. The intended portal is rarely where the surprise lives.
If a cloud service holds CUI
When an external cloud service provider stores, processes, or transmits covered defense information in performance of a contract containing DFARS 252.204-7012, paragraph (b)(2)(ii)(D) requires the contractor to ensure that the provider meets security requirements equivalent to the FedRAMP Moderate baseline and complies with specified incident-reporting and forensic-support duties.
Do not shortcut that to "buy GCC High." Architecture, service role, contract text, data flow, equivalency evidence, and the responsibility split still have to be documented. A marketing badge is not the contract analysis.
That is a real project with a real budget, which is the single best argument for the section that follows.
Can we work inside the client's environment and stay out of scope?
Often — if the configuration actually prevents CUI from reaching your assets. 32 CFR § 170.19 and the DoD Level 2 Scoping Guide recognize that an endpoint used only to access a virtual desktop can be treated as an Out-of-Scope Asset when it does not process, store, or transmit CUI beyond keyboard, video, and mouse interaction with the in-scope environment.
Accounting work is unusually compatible with that architecture because much of it can be performed by viewing, analyzing, and entering information inside the client's system. That does not make the carve-out automatic. It makes it available.
The KVM-only condition, and what actually defeats it
The carve-out is real, and it is narrow. "We use VDI" is not the finding. The configuration is the finding.
Test every path that could allow CUI to be processed, stored, or transmitted outside the client's environment:
- File transfer between the session and endpoint
- Clipboard redirection in either direction
- Local drive mapping
- Local printer mapping and print-to-PDF
- Screen capture and screen recording
- Browser downloads, browser cache, and temporary files
- USB and peripheral redirection
- Mobile and tablet access
- Offline mode
- Session logs, crash dumps, and support-tool access
- Credential and session-token storage on the endpoint
- Accessibility or collaboration tools that copy session content
An enabled feature does not defeat the carve-out merely because its name appears on this list. It defeats the carve-out when the feature allows CUI to be processed, stored, or transmitted on the endpoint or another out-of-scope asset. Test the actual configuration, document the result, and re-test after material changes and at planned review intervals. "VDI" is a product label. KVM-only is a verified operating condition.
The staff-augmentation condition — narrower than it looks
The Level 2 Scoping Guide also addresses an ESP used as staff augmentation. It says the staff-augmentation ESP does not need CMMC assessment when the assessed organization provides all processes, technology, and facilities used by the external personnel.
That word all is doing enormous work. The guide does not say "uses the client's login" or "connects remotely." It says the assessed organization provides all three. When your firm supplies its own portal, workpaper system, storage, process, technology, or facility, do not assume that sentence covers the arrangement. Analyze the added assets and services instead of stretching a staff-augmentation example past its facts.
Five architectures, ranked by how much exposure they leave you
| Architecture | How it works | Who retains custody of the CUI | Effect on your exposure | Tradeoff | Engagement-letter language to consider |
|---|---|---|---|---|---|
| Work inside the client's environment | Staff access the client's enclave or KVM-only VDI session; CUI cannot reach firm systems | Client | Strongest position available when the configuration is verified | Slower fieldwork; client provisions accounts; some tools unavailable | "Firm will access covered information only within Client's approved environment and will not download or retain copies." |
| Client-hosted web portal with download blocked | Client retains the authoritative files, but firm endpoints display and therefore process the CUI in an ordinary browser | Client retains the source; firm endpoints process it during use | Reduces persistent copies, but it is not the KVM-only out-of-scope condition. If a covered door is open, the endpoints may remain in scope | Browser cache, printing, screenshots, accessibility tools, support data, and exports can create additional copies | State the permitted actions and retention controls, and do not call the endpoint out of scope without a supportable scoping analysis |
| Agency-authorized decontrolled or properly sanitized deliverables | An authorized holder provides only information the client is authorized to release outside the controlled environment | Client for the controlled source | Can reduce or remove CUI from the material transferred | Requires a real authorization and defensible sanitization, not deletion of a banner | "Client will not remove or alter CUI markings without authority and will identify the basis for any decontrol or sanitization." |
| Firm receives and holds client CUI | Files land in firm email, a file server, workpaper system, cloud drive, or application | Firm | Highest exposure. If a covered door is open, these assets can enter the assessment scope | Real money, real time, ongoing evidence and incident duties | Requires a documented boundary, approved services, responsibility matrix, retention rules, and contract review |
| On-site and paper-only work | Traditional fieldwork with no electronic transfer to firm systems | Client or controlled physical custody, depending on the facts | Low electronic exposure, but physical CUI safeguards and custody still matter | Impractical at scale; transport, copying, and storage remain risks | State custody, access, reproduction, transport, return, and destruction terms |
Our editorial conclusion, and we'll own it as a conclusion rather than a rule: for most accounting engagements, the correct move is to stop taking custody rather than to build a compliance program around custody you did not need. That's the sentence a compliance vendor will not write, and it is the one that saves firms the most money.
The honest limitation: it does not work everywhere. Rate work with heavy source-document review, investigations, proposal support, and tax or attest engagements with professional-retention requirements can force custody or create a different contractual need. If that's your situation, you're in the group that needs a real environment decision — keep reading.
We already received client CUI. Are we in trouble?
Receiving marked or otherwise identified CUI does not, by itself, establish that your accounting firm is subject to CMMC. Applicability still turns on the contract, subcontract, service role, and performance facts. What the transfer can create is exposure under the engagement agreement, a flowed-down clause, the client's CUI-flow controls, confidentiality duties, professional obligations, and possibly incident-reporting or preservation duties if a clause such as DFARS 252.204-7012 actually applies.
The correct response is a documented look-back and a forward-looking architecture decision. It is not a retroactive claim that you were certified, and it is not permission to delete evidence.
The four-step look-back
- Where did it land? Email, portal, file server, tax software, ERP import, laptop, personal device, print file, backup, archive, or support system.
- Who touched it? Named staff, contractors, offshore resources, support vendors, and anyone with administrative or recovery access.
- Is it still there? Retention policies, sync tools, journaling, backups, and legal holds often make the answer yes in more places than expected.
- What does the executed engagement and contract chain say? Read the final engagement letter, security addendum, flow-down, prime-contract reference, incident clause, permitted systems, subcontractor terms, and retention language — not the template.
Document the answers with a date. Preserve relevant evidence. If there is any indication of unauthorized access, compromise, or a contractually reportable event, escalate immediately to counsel, the engagement owner, and the person responsible for contract cyber reporting. Do not let a blog post decide a 72-hour reporting question.
Your client may have an undocumented flow even if CMMC does not attach to you
If CUI moved to a destination not reflected in the client's System Security Plan or data-flow documentation, the client may need to correct its records and architecture. Expect a request to change how you receive data.
That request is reasonable, and the architecture section above is your answer to it. Firms that arrive at the conversation with a documented map and a proposed controlled workflow instead of a defensive posture are easier to keep.
The retention collision — we're not going to pretend this is solved
Your professional records-retention obligations and a client's request to purge CUI can point in opposite directions. Your state board, applicable auditing or tax standards, your firm's quality-management policy, peer-review obligations, litigation-hold duties, and the engagement letter may all have something to say. CMMC does not resolve those independent duties for you.
We're not resolving that collision in an editorial article. Put it in front of qualified counsel and your firm's independence, records, or quality leadership before you delete anything, decontrol anything, or promise a destruction date.
If a door is open: what level, what assessment type, what cost?
FCI-only work generally maps to Level 1 and CUI work starts at Level 2 under 32 CFR § 170.23 — but the written solicitation, contract clause, or flow-down sets the required CMMC status for the systems used in performance. Level 1 contains 15 safeguarding requirements. Level 2 uses all 110 security requirements of NIST SP 800-171 Revision 2 across 14 families. Level 3 adds the 24 enhanced requirements selected from the February 2021 edition of NIST SP 800-172 that 32 CFR Part 170 incorporates on top of Level 2.
Under the current July 2026 suspension direction, new procurement requirements may designate only Level 1 (Self) or Level 2 (Self). Level 2 (C3PAO) and Level 3 remain defined in the rule, but new designations for those assessment types are suspended during the review.
For a complete side-by-side comparison, see CMMC Level 1 vs Level 2 vs Level 3.
Level 1 versus Level 2, for someone who has never read either
Level 1 protects FCI and maps to 15 basic safeguarding requirements derived from FAR 52.204-21. It requires a self-assessment and affirmation every year. All 15 requirements must be met; 32 CFR § 170.21 does not permit a Level 1 Plan of Action and Milestones.
Level 2 protects CUI and maps to the 110 requirements of NIST SP 800-171 Revision 2 across 14 families. A Level 2 self-assessment is conducted every three years, with an annual affirmation. A Conditional Level 2 status can use a POA&M only within the rule's limits: at least an 80-percent score, only permitted requirements, and successful closeout within 180 days. A POA&M is not a parking lot for anything not yet implemented.
Level 3 adds 24 requirements selected from the February 2021 edition of NIST SP 800-172, which addresses enhanced protection for CUI associated with critical programs or high-value assets. NIST withdrew that publication in May 2026 and superseded it with SP 800-172 Revision 3, but 32 CFR Part 170 still incorporates the February 2021 edition and its selected 24 requirements. It is not a realistic destination for an ordinary accounting engagement, and new Level 3 procurement designations are currently suspended.
The same rule-versus-catalog distinction applies at Level 2. NIST withdrew SP 800-171 Revision 2 from its active catalog after publishing SP 800-171 Revision 3 in May 2024, but the CMMC rule expressly incorporates Revision 2. Revision 3 is not the CMMC-controlling version unless DoD changes the rule, the incorporated standard, or the applicable contract requirement.
What you would actually be signing
CMMC self-assessment results and affirmations are submitted in the Supplier Performance Risk System. An Affirming Official is a senior representative responsible for affirming continuing compliance for the information systems in the assessment scope. The affirmation is not a marketing checkbox. It is a named person's attestation to the status being maintained.
Keep the records straight:
| Record in or associated with SPRS | What it means | Primary DFARS reference |
|---|---|---|
| NIST SP 800-171 DoD Assessment summary score | The score under the DoD Assessment Methodology for a covered contractor information system | 252.204-7019 and 252.204-7020, or an applicable class-deviation replacement |
| CMMC assessment result and status | Level 1 (Self), Level 2 (Self), Level 2 (C3PAO), or Level 3 status for a defined assessment scope | 252.204-7021 |
| Annual affirmation | Affirmation of continuous compliance required to keep the CMMC status current | 252.204-7021 and 32 CFR § 170.22 |
| CMMC UID | Identifier supplied for each relevant contractor information system in a proposal when 252.204-7025 applies | 252.204-7025 |
Cost drivers, without fake numbers
We publish cost ranges elsewhere and we're not going to duplicate them here with softer data. What we will tell you is where accounting firms specifically spend more than they expect:
- Boundary definition in a firm where partners work from multiple locations and everyone has accumulated administrative access
- Email and file-sharing architecture because the current environment was designed for convenience and retention, not a narrow CUI boundary
- Identity, multi-factor authentication, and access control across a partner-heavy organization with informal delegation
- Evidence retention — proving controls operated, not merely that a policy exists
- Seasonal staff and turnover that make provisioning, training, and deprovisioning recurring operations
- Professional-retention conflicts that prevent simple deletion as a scope strategy
- Cloud-service evidence and responsibility matrices where the firm relies on inherited controls
For actual ranges and assumptions, see CMMC Level 2 Cost.
Where the program stands right now — and why it matters to your decision
The nominal Phase I period runs November 10, 2025 through November 9, 2026. The Department suspended the planned Phase II transition on July 13, 2026. During the suspension:
- New procurement requirements may designate only Level 1 (Self) or Level 2 (Self)
- Program managers and requiring activities may not designate new Level 2 (C3PAO) or Level 3 requirements
- Active solicitations containing those higher assessment requirements are to be amended
- Existing contracts containing them are directed to be modified before the next option period or scheduled administrative modification
- DFARS 252.204-7012 safeguarding and reporting duties remain in effect where the clause applies
- CMMC Level 2 continues to use NIST SP 800-171 Revision 2
- Select government-led assessments can still occur
Also worth knowing: the codified FAR and DFARS pages still publish FAR 52.204-21 and DFARS 252.204-7019/-7020. Separately, DoD's Revolutionary FAR Overhaul class deviations can direct contracting officers to use replacement Part 240 text, including FAR 52.240-93 and DFARS 252.240-7997, in covered solicitations and contracts. That is not the same thing as saying the codified clauses vanished universally.
You will see old, codified, and deviation numbering in live documents. Read the actual clause text and deviation identifier in the instrument in front of you. The current official DFARS Revolutionary FAR Overhaul class-deviation page is the source to check, not a vendor's shorthand.
What this means practically: do not buy a third-party certification engagement because a 2025 article told you every CUI holder would need one in November 2026. And do not stop safeguarding work either — the underlying 800-171 and DFARS duties did not disappear. Verify the written requirement on the date you act, confirm whether an amendment or modification is pending, and get changes in writing. That's the urgency on this page that is real.
Is a DCAA accounting-system review the same as a CMMC assessment?
No — different criteria, different purpose, different evidence, and neither substitutes for the other. A Defense Contract Audit Agency preaward accounting-system survey uses the accounting-system criteria associated with Standard Form 1408 to support an acquisition or contract-administration decision. CMMC assesses cybersecurity requirements for applicable contractor information systems under 32 CFR Part 170.
An accounting-system survey can tell the Government whether a prospective contractor's system is designed to accumulate and report contract costs in an acceptable manner. It does not establish a CMMC status, a NIST SP 800-171 implementation score, or an approved CUI boundary.
We're including this because it is the single most common conflation accounting professionals make, and it makes sense why: both involve DoD, both involve reviews of systems, and both can produce uncomfortable findings. They still answer different questions.
| Dimension | DCAA preaward accounting-system survey | CMMC assessment |
|---|---|---|
| Who performs it | DCAA or another survey activity, depending on the acquisition | The contractor for self-assessment; a CMMC Third-Party Assessment Organization for Level 2 certification; DCMA DIBCAC for Level 3 |
| Against what | Accounting-system design criteria reflected in SF 1408 and the applicable contract-cost framework | 15 Level 1 requirements or 110 NIST SP 800-171 Rev. 2 requirements at Level 2; Level 3 adds 24 requirements selected from the February 2021 SP 800-172 incorporated by the rule |
| Question answered | Is the accounting system designed to support the contemplated contract and cost-accounting needs? | Are the required cybersecurity requirements implemented within the defined assessment scope? |
| Result | Survey findings and a recommendation or report used by the acquisition/contracting function | A CMMC assessment result and status, with required SPRS records and affirmation |
| Does it satisfy the other? | No | No |
If a client tells you "DCAA approved our system," that may describe a real and valuable accounting-system result. Say so kindly, then ask for the separate CMMC and CUI evidence.
Can a CPA firm sell CMMC services or become a C3PAO?
Some do — but two independence regimes can apply at once, and neither disappears because the firm uses a separate engagement letter. The CMMC rule directly prohibits a CMMC ecosystem member from participating in the Level 2 certification process for an organization it helped prepare for any CMMC assessment during the preceding three years. The Cyber AB Code of Professional Conduct implements and explains that rule. Separately, the AICPA independence framework applies to attest clients and nonattest services on its own terms.
"C3PAO" means CMMC Third-Party Assessment Organization. It does not mean "Certified Third-Party Assessment Organization."
If you're reading this page because your firm is considering a CMMC practice rather than because a client sent you a questionnaire, this section is for you — and you should know up front that most firms underestimate the arithmetic.
The two rulebooks, side by side
| Question | CMMC ecosystem rule | CPA independence rule |
|---|---|---|
| Can we prepare a client and then perform its Level 2 certification assessment? | No within the three-year lookback. 32 CFR § 170.8(b)(17)(ii)(G) prohibits participation in the Level 2 certification process after preparatory consulting for any CMMC assessment. The Cyber AB Code of Professional Conduct v2.0 applies the restriction to the C3PAO as an organization and to Assessment Team members | Nonattest services can create self-review and management-participation threats. The attest client must accept responsibility, designate a person with suitable skill, knowledge, and experience, evaluate the service, and not shift management responsibility to the CPA. See the AICPA Professional Standards library |
| Does a small prior engagement matter? | It can. The Cyber AB Code's example treats prior consulting on a Level 1 self-assessment as disqualifying for the later Level 2 certification engagement within three years | The cumulative effect of multiple nonattest services matters; a small label does not end the independence analysis |
| What governs the formal assessment procedure? | The CMMC Assessment Process (CAP) v2.0 is the Cyber AB procedural guide for Level 2 certification assessments only. It is not a readiness, consulting, or self-assessment guide and does not supersede 32 CFR Part 170 | The applicable AICPA, state-board, SEC, PCAOB, contractual, and firm quality-management rules continue independently |
| What does standing up the assessment side require? | Under 32 CFR § 170.9, a C3PAO must achieve ISO/IEC 17020:2012(E) accreditation within 27 months of authorization. Company personnel participating in the Level 2 certification process, including the Assessment Team and quality-assurance individual, must complete a Tier 3 background investigation resulting in a national-security eligibility determination. The investigation is initiated using SF-86, and the positions are designated non-critical sensitive/Moderate Risk | Firm licensure, independence, engagement acceptance, quality management, and professional standards apply separately |
| Who carries the conflict duty? | The organization and covered CMMC ecosystem individuals, including Certified CMMC Assessors and Certified CMMC Professionals under their applicable rule provisions | The firm and covered practitioners under the applicable professional standards |
The CAP point matters because firms use the word "assessment" loosely. A gap analysis, readiness review, mock assessment, Level 1 self-assessment, Level 2 self-assessment, and Level 2 certification assessment are not interchangeable services. Only the last one is governed by the CAP as a formal C3PAO certification process.
The public-company layer, if you have issuer audit clients
For issuer audit clients, the analysis gets stricter. The SEC's auditor-independence rules identify financial-information-systems design and implementation as a prohibited non-audit service for an audit client, subject to the precise rule text and exceptions, and permissible non-audit services generally require audit-committee preapproval. PCAOB independence and communication rules apply alongside the SEC framework.
Do not reason from a private-company engagement to an issuer engagement. They're different rulebooks with different consequences.
The two-entity structure some firms use
A separate legal entity can help divide attest and advisory operations. It does not erase common-control, personnel, brand, financial, referral, information-sharing, or CMMC conflict facts. The conclusion remains engagement-specific.
What we verified as company-stated examples — not endorsements:
| Organization | Publicly stated structure or service model | What we verified | What we did not verify |
|---|---|---|---|
| A-LIGN | Its website identifies Price and Associates CPAs, LLC dba A-LIGN ASSURANCE as a licensed CPA firm registered with the PCAOB, and A-LIGN Compliance and Security, Inc. dba A-LIGN as a cybersecurity and compliance professional-services firm | The two-entity disclosure was present on a-lign.com on August 18, 2026 | Current Cyber AB Marketplace status, service quality, engagement outcomes, or an independence conclusion for any client |
| IS Partners LLC | Its own CMMC services content describes separate certification and readiness paths and states that it cannot provide both to the same client because of conflict rules | The company-stated two-pathway description was present on ispartnersllc.com on August 18, 2026 | Current Cyber AB Marketplace status, service quality, engagement outcomes, or whether every service description is current |
We include those examples to show the structural problem firms are trying to solve, not to recommend either company and not to make a current Marketplace status assertion. Before hiring any assessment organization, verify its live status in the Cyber AB Marketplace.
The part we'd tell you over coffee
Run the numbers before you run the practice. The three-year consulting prohibition removes readiness clients from your certification-assessment pipeline for three years. ISO/IEC 17020 accreditation is a 27-month clock with real cost attached. Personnel participating in the Level 2 certification process, including quality assurance, must complete the required Tier 3 investigation or the rule's approved equivalent path. The CAP imposes a formal process that is not the same business as advisory work.
For many small and mid-size CPA firms, doing both lanes does not pencil out. Pick a lane. Readiness and advisory work can be a natural adjacency to a government-contract accounting practice. Formal C3PAO assessment is a separate business with a separate cost structure and conflict profile.
And remember the current procurement posture: new Level 2 (C3PAO) designations are suspended while the program is under review. That does not repeal the C3PAO rules or settle the value of every existing engagement, but it does change the near-term demand assumption you should use in a business plan.
Which provider category fits, if you need one?
The right category depends on what has already been established, and a C3PAO is almost never the first call. A firm with unresolved applicability needs qualified federal-contracts counsel, often supported by an RPO, RP, or experienced readiness advisor. A firm with an architecture problem needs an MSP, MSSP, cloud specialist, or enclave provider. A firm with a documented assessment requirement needs independent assessment last.
We're not naming providers in this section, and here's the reason: on a determination page, naming a vendor before you've established that you have a problem is how firms buy things they do not need. Get the category right first.
| What you have established | Best-fit category | What that category should deliver | What not to ask it to do |
|---|---|---|---|
| Contract, flow-down, or engagement role is ambiguous | Qualified federal-contracts attorney, with technical support from an experienced CMMC advisor where needed | Written applicability and contract interpretation | Invent the client's CUI designation or promise a procurement outcome |
| Scope and data flow are ambiguous | RPO/RP or experienced readiness/scoping consultant | Written boundary, asset inventory, data map, service-provider analysis, and open-issue list | Perform the later certification assessment for the same client inside the three-year conflict window |
| Technical remediation is needed | CMMC-focused MSP or MSSP | Architecture, configuration, operating procedures, monitoring, and evidence | Set the contractual level or give legal advice |
| Firm must hold client CUI | CUI enclave or secure-collaboration provider, supported by a responsible advisor | A bounded environment, inherited-control evidence, and a clear responsibility matrix | Promise that the platform itself is "CMMC certified" |
| Cloud path holds covered defense information | Cloud/FedRAMP implementation specialist | Service-role analysis, authorization or equivalency evidence, responsibility split, and contract alignment | Treat a marketing badge as proof |
| SSP, POA&M, and evidence workflow need management | GRC platform plus accountable human ownership | Workflow, evidence ownership, change control, and assessment records | Substitute software for implementation or an Affirming Official |
| Level 1 or Level 2 self-assessment support is needed | RPO/RP or readiness provider | Objective assessment support, evidence preparation, remediation plan, and SPRS process support | Submit an affirmation the provider is not authorized to make for you |
| A live written Level 2 certification requirement remains after amendment review | Authorized C3PAO, after readiness and conflict checks | Independent assessment under the CAP | Remediate the organization and then assess it inside the prohibited window |
| CPA independence is uncertain | Your firm's independence leadership and qualified counsel | Engagement-specific conclusion under all applicable regimes | Rely on CMMC conflict rules alone |
Editorial judgment, stated as such: under the current suspension, we deliberately do not route an accounting firm toward a third-party assessment merely because it handles accounting data for a defense contractor. The order that protects your money is applicability first, then designation and data flow, then architecture, then implementation and evidence, then formal assessment only when a live written requirement survives the contract review.
For a deeper category comparison, read CMMC Provider Categories and Who to Hire First.
→ If a door is genuinely open, get the category right before you get quotes
Find My CMMC Path → maps a general situation to the provider category that belongs first. When you are ready to compare actual providers, use Request a Quote →.
If your determination is Door 4, you may not need either. Go back to the architecture table, change how you receive client data, put the decision in writing, and save your money. We'd rather you leave this page with a cheaper answer than a bigger invoice.
Do not submit CUI, drawings, client names, contract files, system diagrams, credentials, or other sensitive information. Provider matching may generate referral compensation; any relationship is disclosed at the point of recommendation and under our Editorial & Advertising Policy.
What we actually verified for this guide
The regulatory and technical claims retained in this page were checked against the issuing authority's published text on August 18, 2026. Company examples are labeled company-stated. Editorial conclusions are labeled as conclusions. Where the source did not support a stronger statement, we narrowed the statement instead of laundering an inference into a rule.
| Verified item | Primary source or controlling publication | Version or status checked |
|---|---|---|
| CMMC applicability, unclassified-system scope, threshold, and COTS-only exclusion | 32 CFR § 170.3 | eCFR current through August 14, 2026 |
| Supply-chain application and "in the performance of" language | 32 CFR § 170.23 | eCFR current through August 14, 2026 |
| ESP definition and CSP/non-cloud ESP/SPD scoping outcomes | 32 CFR § 170.4 and § 170.19 | eCFR current through August 14, 2026 |
| KVM-only VDI, staff augmentation, and cloud-accounting SaaS examples | DoD CMMC Level 2 Scoping Guide | Version 2.13, September 2024 |
| Phase II suspension and current permitted procurement designations | DoD CMMC page and Implementing Suspension memorandum | July 13, 2026 direction, read August 18, 2026 |
| Level 1, Level 2, Level 3, affirmation, and POA&M requirements | 32 CFR §§ 170.14–170.22 | eCFR current through August 14, 2026 |
| Rev. 2 remains the CMMC-incorporated Level 2 standard; Rev. 3 is newer in NIST's catalog | NIST SP 800-171 Rev. 2, Rev. 3, and 32 CFR § 170.14 | NIST publication pages and current rule |
| Level 3 uses 24 requirements selected from the February 2021 SP 800-172 incorporated by the rule; NIST has since published SP 800-172 Rev. 3 | 32 CFR § 170.14, NIST SP 800-172, and SP 800-172 Rev. 3 | CMMC rule text plus NIST's May 2026 superseding publication |
| DFARS 252.204-7012 safeguarding, cloud, incident, and flow-down duties | Acquisition.gov clause text | Codified DFARS Change 5/7/2026 |
| NIST DoD Assessment score versus CMMC status/UID records | DFARS 252.204-7019, 252.204-7020, 252.204-7021, and 252.204-7025 | Codified DFARS Change 5/7/2026 |
| RFO deviation numbering can coexist with codified clause numbering | Official DFARS class-deviation index | Part 240 Revision 2 listed July 16, 2026 |
| General Procurement and Acquisition, Source Selection, CTI, and organizational groupings | NARA CUI Registry and category pages | Registry pages read August 18, 2026 |
| CUI designation and marking authority | 32 CFR §§ 2002.4 and 2002.20 | Current eCFR text |
| C3PAO conflict rule, 27-month accreditation window, and personnel investigations | 32 CFR §§ 170.8–170.13 | Current eCFR text |
| Cyber AB conflict explanation and formal Level 2 assessment procedure | Code of Professional Conduct v2.0 and CAP v2.0 | December 2024, marked effective and in force |
| DCAA preaward accounting-system survey and SF 1408 distinction | DCAA Preaward Accounting System Adequacy Checklist and SF 1408 | Official DCAA/GSA materials |
| A-LIGN and IS Partners examples | Each company's own public website | Company-stated pages read August 18, 2026 |
What we could not establish, and therefore did not present as fact:
- That the January 15, 2025 CMMC Level Determination Guide remains operative in unchanged form after the July 13, 2026 suspension. We identify it by date and use it only as dated context.
- A current Cyber AB Marketplace status for A-LIGN or IS Partners through an accessible official organization record. We make no current status assertion.
- That the sanctions listed on the NARA General Procurement and Acquisition page automatically apply to an outside auditor.
- The exact current CUI banner marking for federal taxpayer information or proprietary business information.
- A universal CMMC cost or implementation timeline for a CPA firm.
- A CPA-specific CMMC enforcement case suitable to present as representative. We did not find one, so we did not invent one.
- That any article can give a binding applicability opinion without the actual solicitation, contract, subcontract, data, and system facts.
How this page was produced: researched and written by The Defense Compliance Report Editorial Team from the sources above. Editorial research — not formally reviewed by a CMMC Subject Matter Advisor. See our Methodology, Editorial Standards, and Corrections Policy.
Confirm engagement-specific scope, contract interpretation, CUI designation, and professional obligations with the qualified people responsible for those decisions. A Registered Practitioner or experienced CMMC advisor can help with technical scope. Qualified federal-contracts counsel should handle contract interpretation. Your CPA independence and records leadership should handle professional obligations. No single provider replaces all three.
Frequently asked questions
Does CMMC apply to accounting firms?
Usually not for ordinary accounting work by itself. CMMC reaches prime contractors and subcontractors that process, store, or transmit FCI or CUI on contractor information systems in the performance of a DoD contract or subcontract. A CPA firm's industry label does not create or remove applicability.
Is my CPA firm an External Service Provider under CMMC?
Not for ordinary accounting services alone. The ESP definition in 32 CFR § 170.4 starts with the provision and management of IT and/or cybersecurity services and also requires CUI or Security Protection Data on the assets used for that service. A separate hosted, managed-IT, security, GRC, or cloud-administration service can change the answer.
Is cost or pricing data CUI?
It can be. The NARA General Procurement and Acquisition category expressly lists cost or pricing data, contract information, indirect costs, and direct labor rates. But the category description does not automatically turn every cost record into CUI. The governing authority and valid designation of the specific information still matter.
Are invoices FCI?
Simple transactional information necessary to process payments is excluded from FCI. But an invoice can contain contract numbers, task orders, program names, labor categories, rate schedules, deliverable descriptions, or protected attachments. The payment exclusion does not sanitize everything in the document.
Does an indirect cost rate proposal automatically make the CPA firm a covered subcontractor?
No. It is closer to the line than an ordinary tax return or corporate financial-statement audit because it may be prepared for a government-contracting purpose. The answer depends on whether the engagement is being performed under the DoD contract or subcontract, what information is handled, what clause is flowed down, and whose systems hold it. Get those facts in writing.
Does firm size or employee count determine whether CMMC applies?
No. CMMC applicability and level are not set by employee count. The contract role, information type, required status, assessment type, and systems used in performance control the analysis. Headcount affects cost and complexity, not legal applicability.
Is a SPRS score the same thing as a CMMC status?
No. A NIST SP 800-171 DoD Assessment summary score under the DFARS assessment framework is different from a CMMC status, annual affirmation, and CMMC UID under DFARS 252.204-7021 and 252.204-7025. Both can involve SPRS, which is why questionnaires conflate them.
Do accounting firms need a SPRS score or CMMC UID?
Only when a governing solicitation, contract, subcontract, or flow-down requires the relevant record for the systems used in performance. Do not create a score or claim a UID because a client questionnaire asks for one. Ask which clause and which record the client means.
What CMMC level would an accounting firm need?
If a covered door is open, FCI-only work generally maps to Level 1 and CUI work starts at Level 2. Level 1 has 15 requirements and annual self-assessment. Level 2 has 110 NIST SP 800-171 Revision 2 requirements across 14 families, a three-year assessment cadence, and annual affirmation. The written instrument specifies the required assessment type.
Does a client's CMMC requirement automatically flow down to its accountant?
No. Flow-down applies through a subcontract or similar contractual instrument when the subcontractor will handle the relevant information in performing the DoD contract. A professional-services engagement for the client's independent corporate purposes is not automatically that subcontract. Ask for the flowed-down clause, prime contract number, required level, assessment type, and information flow.
Can we refuse to accept CUI from a client?
You can decline custody, negotiate a different architecture, or require work inside the client's controlled environment, subject to the engagement and professional duties. That is often the cheapest correct answer. Do not remove markings, promise destruction, or assume a no-download workflow works until the client and firm document the actual controls.
What if the material is sensitive but not marked CUI?
Lack of a banner does not prove the information is outside CUI or covered-defense-information rules. DFARS 252.204-7012 also addresses information marked or otherwise identified in the contract and information developed or handled in support of performance. Treat the status as unresolved, ask for the designating agency, category and authority, and use an approved path while the client resolves it. Do not self-designate from a blog or filename.
Does our SOC 2 report satisfy a client's CMMC questionnaire?
No. A SOC 2 examination is not a CMMC assessment and does not establish implementation of the 110 NIST SP 800-171 Revision 2 requirements. You can provide it as evidence of a broader security program when appropriate, but do not imply equivalence.
Is QuickBooks CMMC compliant?
No accounting product carries a transferable CMMC status. A configured environment can support a compliant boundary, and a specific contractor information system can receive a CMMC status after the applicable assessment and affirmation. The product name itself is not certified.
Can accountants use a client's virtual desktop without bringing firm endpoints into scope?
Potentially. An endpoint can be treated as out of scope when the configuration limits interaction to keyboard, video, and mouse and prevents CUI from being processed, stored, or transmitted on the endpoint. Downloads, clipboard transfer, local printing, cache, sync, support tools, or other enabled paths can change that result. Test the configuration; do not rely on the word "VDI."
Does a DCAA accounting-system review satisfy CMMC?
No. A DCAA preaward accounting-system survey addresses accounting-system design and contract-cost needs. CMMC addresses cybersecurity requirements within a defined information-system scope. Neither substitutes for the other.
Is tax data CUI under CMMC?
Federal taxpayer information has its own CUI category and legal authorities, and tax handling also implicates IRC § 6103 and other tax-specific rules. It is not accurate to assume all tax data is CUI under CMMC or that CMMC is the only regime. We did not re-verify the exact banner marking for this guide; confirm the current Registry entry and the actual authority before relying on one.
Can a CPA firm become a C3PAO?
Yes, but the firm must satisfy the C3PAO requirements, including the accreditation timeline and personnel investigation rules, and it must obey the three-year prohibition on assessing an organization it helped prepare. CPA independence, state-board, issuer, and quality-management rules apply separately. "C3PAO" means CMMC Third-Party Assessment Organization.
Is CMMC still being enforced after the Phase II suspension?
Yes, in part. Phase I self-assessment requirements remain, DFARS 252.204-7012 remains in effect where included, and new procurement designations may use Level 1 (Self) or Level 2 (Self). The planned November 10, 2026 Phase II transition and new Level 2 (C3PAO) and Level 3 designations are suspended during the review. Active solicitations and existing contracts with higher requirements are subject to the amendment and modification instructions described above.
The bottom line
Three sentences, and then you can go answer that email.
One: find your door. CMMC does not reach an accounting firm because it is an accounting firm. It reaches through a covered contract or subcontract, or a qualifying IT/cybersecurity service, when the information and systems meet the rule.
Two: Door 4 is not a free pass. Your client still has to control where CUI goes, and your engagement can still carry security, confidentiality, transfer, incident, and retention terms even when your firm does not need a CMMC status.
Three: change the architecture before you change the firm. For most accounting engagements, a verified KVM-only client environment — or another architecture that genuinely prevents CUI from reaching firm assets — costs less than building a compliance program around data you never needed to hold.
Then put the determination, source documents, and data-flow decision in writing, with a date, in the engagement file. That memo is worth more than a certificate you do not need.
Need help deciding which CMMC provider category belongs first? Use the general router after you have the contract, information, and system facts.
Do not submit CUI, drawings, client names, contract files, system diagrams, credentials, or other sensitive information.
Disclosure
The Defense Compliance Report is an independent trade publication on CMMC 2.0 and Defense Industrial Base compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or status-verification standards.
We are not affiliated with, endorsed by, or sponsored by the Cyber AB, the Department of Defense, DCMA DIBCAC, NIST, or any U.S. government agency. This article is educational research — not legal, contractual, tax, cybersecurity, accounting, attest, procurement, or compliance advice. Confirm engagement-specific decisions with qualified federal-contracts counsel, responsible CMMC professionals, and your firm's independence and records leadership.
Methodology · Editorial Standards · Editorial & Advertising Policy · Corrections Policy