The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

Independent research · CPA firms, accounting services, and CMMC scope

CMMC for CPA and Accounting Firms: Does It Apply to You?

Last updated:

Last verified: against 32 CFR Part 170, DFARS, the CUI Registry, DCAA guidance, and related primary sources.

By The Defense Compliance Report Editorial Team — an independent trade publication on CMMC 2.0 and Defense Industrial Base compliance Last reviewed: August 2026 · Last verified: August 18, 2026 Editorial status: Primary-source research. Not formally reviewed by a CMMC Subject Matter Advisor.

August 2026 status alert. The Department suspended the planned transition to CMMC Phase II on July 13, 2026. The nominal Phase I window remains November 10, 2025 through November 9, 2026, but the November 10, 2026 Phase II transition is suspended. During the suspension, new procurement requirements may designate only Level 1 (Self) or Level 2 (Self), not Level 2 (C3PAO) or Level 3 (DIBCAC). DFARS 252.204-7012 safeguarding and cyber-incident duties remain in effect where that clause applies, and CMMC still uses NIST SP 800-171 Revision 2. The implementing memorandum directs amendments to active solicitations and directs removal of higher assessment requirements from existing contracts by modification before the next option period or scheduled administrative modification. Until the written instrument is amended, read the contract you actually signed. A press release does not modify it. DoD CMMC status page · Implementing Suspension of CMMC Phase II


The bottom line, up front

CMMC for CPA and accounting firms usually does not apply to ordinary accounting work — and the reason is one phrase in the rule. Under 32 CFR § 170.23(a), CMMC requirements reach prime contractors and subcontractors at all tiers that process, store, or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) on contractor information systems in the performance of the DoD contract or subcontract. An ordinary financial-statement audit, tax return, or management report prepared for a defense contractor's own corporate purposes is not automatically performance of that DoD contract.

Four facts change the answer. You hold your own DoD contract. You are a subcontractor performing on one. You provide a separate IT or cybersecurity service that meets the External Service Provider definition. Or none of those facts is present, in which case CMMC may not attach to the engagement even though contractual security duties still can.

Here's the part almost every article gets wrong, and it's the reason the questionnaire on your desk doesn't fit: the ESP route most vendor questionnaires assume is usually shut for ordinary accounting services. The definition starts with the service you provide, not merely the data you touch. But that does not erase a real subcontract, a real flow-down, or a separate technology service. We will show you where each route begins and where it stops.

Who this is for: CPA firms, government-contract accounting consultancies, outsourced accounting and CFO providers, and the contractors trying to determine whether an outside accountant affects their CMMC scope.

Who this is not for: firms that host a client's ERP, operate a client's cloud accounting environment, run security tooling, or bundle managed IT with accounting services. The ordinary-accounting answer may not fit you. Start with our CMMC External Service Provider assessment guide instead — we'd rather send you to the right page than have you read the wrong one.

Where you probably land

Your facts — Most likely path
Your factsMost likely path
Covered contract or written flow-down, and FCI or CUI lands on your firm's systems in performing that contractYour firm may need its own CMMC status for those systems
CUI stays inside the client's controlled environment and cannot reach your assetsClient-environment scoping analysis; your endpoint may be out of scope if the KVM-only conditions are actually met
You provide a separate IT or cybersecurity service and CUI or Security Protection Data reaches assets used for that serviceESP/CSP scoping analysis under §§ 170.4 and 170.19 — not an automatic standalone certification
No covered contract or flow-down, no IT/cybersecurity service, and ordinary accounting onlyGenerally outside CMMC for that engagement; contractual and professional duties still remain
Marked or otherwise identified CUI already landed in email, a portal, or a file server before anyone documented the pathStop. Preserve the facts, identify the governing contract and designation, and resolve the transfer path in writing before the next one

The honest problem with this page

Most CPA and accounting firms do not need a CMMC program for ordinary accounting work — which means this page cannot sell you one. We publish provider-category guidance for a living, and the accurate answer to the question in the title is usually "not for this engagement." We're going to say so, and then we're going to spend the rest of this page on the part that actually costs firms money.

Because the expensive mistake here runs in the opposite direction from what you'd expect. It isn't failing to buy certification. It's writing "yes, we're compliant" on a client questionnaire to protect a relationship — a statement you cannot support, in a document that outlives the engagement. Or accepting marked CUI into a standard workpaper portal because nobody wanted to look unhelpful, and discovering eighteen months later that it is also in three backups, two support tickets, and a partner's laptop.

The four routes in our decision framework are specific, and you can check all four in about ten minutes. Let's do that first.


CMMC for CPA and accounting firms: does it apply?

Not because you're a CPA firm, and not because your client does defense work. CMMC applicability turns on the contract or flow-down, the information handled in performing it, and the systems on which that information is processed, stored, or transmitted. The profession label decides nothing — 32 CFR Part 170 contains no list of covered or exempt industries, and employee count does not set the level.

The exact words that settle it

32 CFR § 170.3(c) sets program applicability. The CMMC Program applies to DoD solicitations and contracts under which a contractor will process, store, or transmit FCI or CUI on unclassified contractor information systems, above the micro-purchase threshold, excluding contracts solely for commercially available off-the-shelf items.

32 CFR § 170.23(a) extends the requirement down the supply chain, and this is the phrase to read twice: CMMC requirements apply to prime contractors and subcontractors throughout the supply chain at all tiers that will process, store, or transmit FCI or CUI on contractor information systems in the performance of the DoD contract or subcontract.

In the performance of. Not "for a company that has one." Not "related to defense." Performance.

An ordinary financial-statement audit exists because of reporting requirements, lender covenants, owners, or a board. A tax return is a filing obligation. Internal management reporting belongs to management. None of those facts alone makes the engagement performance of a DoD contract.

An indirect cost rate proposal, incurred-cost submission, proposal-pricing engagement, or contract-required agreed-upon procedure is closer to the line because the work may be prepared for a government-contracting purpose or delivered under the contract. That is a fact question about the specific engagement, and it is exactly the kind of thing to get in writing rather than assume in either direction.

The Four Doors

There are four practical doors in our editorial decision framework. They are not four statutory labels. We built them from the rule's applicability, subcontractor, and service-provider provisions, and we verified the cited rule text on August 18, 2026.

Door — What opens it — Primary source — Likely treatment — What you actually do
DoorWhat opens itPrimary sourceLikely treatmentWhat you actually do
1. You hold your own DoD contractYour firm is the contractor — for example, an audit, agreed-upon procedure, or advisory engagement sold directly to a DoD component — and your systems will handle FCI or CUI in performance32 CFR § 170.3(c)Solicitation specifies the required level. FCI-only generally points to Level 1 (Self); CUI points to Level 2 at minimumRead the solicitation provision and contract clause. Confirm the systems, status, affirmation, and SPRS entries required before award
2. You are a subcontractor performing on a DoD contractYou process, store, or transmit FCI or CUI on your systems in performance of the DoD contract or subcontract, at any tier32 CFR § 170.23(a)FCI → Level 1 (Self). CUI → Level 2 (Self) minimum; a higher type can be required by the written instrument, subject to the current suspension directionGet the clause, required level and assessment type, prime contract number, and information flow in writing
3. You provide a separate IT or cybersecurity serviceThe client uses your people, technology, or facilities for IT and/or cybersecurity services, and CUI or Security Protection Data is processed, stored, or transmitted on assets used for that service32 CFR § 170.4; § 170.19CSP, non-cloud ESP, and Security Protection Asset treatments differ. The rule does not automatically assign every ESP its own standalone CMMC statusSeparate the technology service from the accounting service, map the assets and data, and document the responsibility split
4. None of the aboveOrdinary accounting work for the client's own corporate purposes, with no covered contract role and no separate IT/cybersecurity service§§ 170.3(c) and 170.23(a), by their termsCMMC generally does not attach to that engagementStill read the security addendum, confidentiality terms, data-flow restrictions, and professional-retention duties

Door 4 is not "you're clear"

This is where firms get comfortable too early. CMMC may not attach to your engagement, but your client's obligations can still land squarely on it:

  • NIST SP 800-171 Revision 2, requirement 3.1.3 requires the contractor to control the flow of CUI.
  • The client's System Security Plan must describe the system boundary and how applicable requirements are implemented.
  • DFARS 252.204-7012 binds a contractor where included and requires flow-down when subcontract performance involves covered defense information or operationally critical support.

The practical result is the one firms see most often: the client either refuses to send CUI, requires work inside its environment, or imposes security terms by contract regardless of whether your firm needs a CMMC status. Either way, your real answer may be architectural, not certification. You change how you receive data. You do not build a compliance program around custody you never needed.

That reframe is worth more than anything else on this page, and we'll spend two full sections on it below.

The edge case that changes everything

If your firm hosts the client's ERP or accounting environment, administers the platform, manages the client's controls, or bundles outsourced accounting with managed IT, you may actually be providing an IT service — and Door 3 opens. If an external cloud service stores, processes, or transmits covered defense information in performance of a contract containing DFARS 252.204-7012, the clause's FedRAMP Moderate-equivalent requirement becomes a live question rather than a theoretical one.

That's a different analysis with a different price tag. Read our CMMC External Service Provider assessment guide before you read another vendor quote.


→ Run the door check on one engagement

You now know the four doors. Before you buy anything, pick one client engagement and write down five facts:

  1. Who is party to the DoD prime contract or subcontract?
  2. Is this accounting work itself being performed under that contract?
  3. Which clause and CMMC level or assessment type are actually written into the solicitation, contract, or flow-down?
  4. What information will be identified as FCI or CUI, by whom, and under what authority?
  5. On whose systems will that information be processed, stored, transmitted, or protected?

If one answer is missing, that missing document — not a cybersecurity product — is your next step.

For general routing after you collect those facts, use Find My CMMC Path →. It is educational triage, not a binding applicability determination. Do not submit CUI, drawings, client names, contract files, system diagrams, credentials, or other sensitive information.

The right provider category is not the same for every contractor. A C3PAO, RPO, MSSP, GRC platform, CUI enclave, and federal-contracts attorney solve different problems. The written requirement, CUI scope, assessment type, environment, and timeline decide which category belongs first. See Who to Hire First and the CMMC Provider Categories guide before you request quotes.


Is my accounting firm an External Service Provider under CMMC?

Not for ordinary accounting services alone — and this is the single most misunderstood point in the vendor-CMMC conversation. 32 CFR § 170.4 defines an External Service Provider (ESP) as external people, technology, or facilities that an organization uses for the provision and management of IT and/or cybersecurity services, with CUI or Security Protection Data processed, stored, or transmitted on the ESP's assets. Both parts matter.

That means "client data touched our systems" is not a complete ESP analysis. The definition starts with what service you provide. Ordinary tax, audit, bookkeeping, payroll, valuation, or accounting advisory work is not an IT or cybersecurity service merely because software is involved.

But do not turn that point into a broader exemption than the rule gives you. A firm can still be a covered subcontractor under § 170.23, and a firm with a separate managed-technology practice can meet the ESP definition for that service. The service role settles the ESP question. It does not erase the contract question.

The four scoping outcomes — after the service meets the IT/cybersecurity prong

32 CFR § 170.19 resolves the data and scoping side of the analysis for a service used to provide IT or cybersecurity. Read it together with § 170.4: when the provider processes neither CUI nor Security Protection Data, § 170.19 says the provider does not meet the full CMMC definition of an ESP for that service. This is not a four-row test for every ordinary vendor.

ESP fact pattern — CMMC treatment under § 170.19 — Practical consequence for the assessed organization
ESP fact patternCMMC treatment under § 170.19Practical consequence for the assessed organization
Cloud service provider processes, stores, or transmits CUIThe cloud service must meet the requirements imposed through DFARS 252.204-7012, including the applicable FedRAMP Moderate-equivalent requirementDocument the cloud service, authorization or equivalency posture, data flow, and responsibility split
Non-cloud ESP processes, stores, or transmits CUIThe services used to process, store, or transmit CUI are included in the organization's CMMC assessment scope and assessedDocument the service in the SSP, service description, and Customer Responsibility Matrix
ESP handles Security Protection Data but not CUIThe services are included in the assessment scope and assessed as Security Protection AssetsAssess the security requirements relevant to the provided capability and document the assets and responsibilities
ESP handles neither CUI nor Security Protection DataThe provider does not meet the data condition in the ESP definition for that serviceNo ESP treatment for that service; ordinary vendor management remains

An ordinary accounting firm usually exits before that table because it does not provide the first thing the definition requires: an IT or cybersecurity service. If the same firm runs a hosted accounting platform, manages access controls, operates a GRC system, or administers a client's cloud environment, run the table on that technology service separately.

DoD's scoping guide uses a cloud-accounting example — but not as a profession-wide exemption

The DoD CMMC Level 2 Scoping Guide, Version 2.13, September 2024, includes an example of a commercial cloud accounting SaaS provider that typically does not handle CUI or Security Protection Data and does not contribute to the security of the CUI environment. In that fact pattern, the service typically would not meet the ESP definition.

That is useful because it names a familiar accounting technology. It is not a blanket statement about every CPA firm, every accounting platform, or every implementation. The guide tells the assessed organization to decide based on the service actually provided and whether CUI or Security Protection Data is present.

The load-bearing authority remains the rule: § 170.4 defines the ESP, and § 170.19 determines the scoping treatment.

When a CPA firm's service does raise the ESP or cloud question

Be honest with yourself about the full service list. These are the fact patterns that change the answer:

  • You host or administer the portal where client CUI is stored
  • You operate a cloud accounting environment that holds CUI
  • Your technology practice manages the client's controls, identity, configurations, or endpoints
  • You collect security logs, vulnerability data, or SIEM output
  • You hold privileged administrative access as part of an IT or cybersecurity service
  • You operate a GRC or evidence platform for the client's compliance program
  • You manage a third-party cloud service on the client's behalf
  • You supply technology or facilities that protect the client's CUI environment

Notice that every one of those is a technology or cybersecurity service, not merely an accounting service. If your firm has an IT practice and an accounting practice, the analysis follows the service, not the letterhead. Separate the services, systems, data flows, and responsibility matrices explicitly in your engagement documents, or someone else will separate them for you later, under less pleasant circumstances.


What do I write on a client's CMMC questionnaire?

Answer factually about what you do and do not hold, separate a NIST DoD Assessment score from a CMMC status, cite the provision that governs applicability, and ask the client for the documents that actually resolve the question. Do not assert a level, a score, a CMMC UID, or "compliance" you cannot support.

Most vendor security questionnaires are built from an IT-vendor template. They routinely ask accounting firms for attributes the rule never assigns to them, and they often use "SPRS score" and "CMMC certification" as if those were the same thing. They are not.

First: separate the two SPRS records people keep conflating

  • A NIST SP 800-171 DoD Assessment summary score is the score associated with the DFARS assessment framework in 252.204-7019 and 252.204-7020, or with the applicable Part 240 class-deviation clause in a solicitation that uses the Revolutionary FAR Overhaul text.
  • A CMMC status, annual affirmation, and CMMC UID are the records used by DFARS 252.204-7021 and the preaward provision at 252.204-7025.

Both can appear in SPRS. One is not a synonym for the other.

The decoder

What the questionnaire asks — What it is actually trying to establish — Accurate response for typical accounting-only work — What to reference — What not to say
What the questionnaire asksWhat it is actually trying to establishAccurate response for typical accounting-only workWhat to referenceWhat not to say
"What is your CMMC level?"Whether your firm has a current CMMC status for the systems and engagement at issue"Our firm does not claim a CMMC status for this engagement. Please identify the clause, required level and assessment type, and the contract or subcontract you believe applies."32 CFR §§ 170.3, 170.23; DFARS 252.204-7021/-7025Never claim a level you do not hold. Do not write "CMMC compliant" as a substitute
"Are you an External Service Provider?"Whether the service meets § 170.4 and, if so, how § 170.19 scopes it"For this engagement we provide accounting services, not IT or cybersecurity services. On those facts, the ESP definition is not met. Please identify any technology service you believe changes that conclusion."32 CFR §§ 170.4 and 170.19Do not answer yes solely because client files touch software
"Provide your SPRS score."Often ambiguous: a NIST DoD Assessment score, a CMMC assessment score/status, or both"Please specify whether you are requesting a NIST SP 800-171 DoD Assessment summary score or a CMMC status/UID, and identify the clause requiring it."DFARS 252.204-7019/-7020 versus 252.204-7021/-7025Never invent, estimate, borrow, or reuse another system's score
"Do you handle CUI?"Whether information designated or otherwise identified as CUI reaches your systemsAnswer only from observed facts, then request the designating agency, category or subcategory, governing authority, marking, approved transfer path, and contract reference32 CFR §§ 2002.4 and 2002.20; DFARS 252.204-7012Do not decide from the filename or the client's anxiety
"Will you sign our security addendum?"Whether you will accept independent contractual dutiesRoute it to counsel and the engagement owner. CMMC applicability does not answer whether you should accept the addendumThe proposed contract itselfDo not sign a flow-down or incident-reporting obligation nobody at your firm has read
"Does your SOC 2 report cover this?"Whether an existing attestation satisfies the client's security requirement"A SOC 2 examination is not a CMMC assessment and does not establish implementation of all 110 CMMC Level 2 requirements."NIST SP 800-171 Rev. 2; 32 CFR Part 170Do not imply equivalence

The reply, in full

Use this only after confirming that the factual statements are true for the engagement. Put it on firm letterhead, have counsel review it once, and keep the final version in the engagement file.

Thank you for the security questionnaire. We want to answer against the engagement and contract that actually apply. Under 32 CFR § 170.23(a), CMMC requirements apply to contractors and subcontractors that process, store, or transmit Federal Contract Information or Controlled Unclassified Information on contractor information systems in the performance of a DoD contract or subcontract.

For this engagement, our firm provides accounting services and does not provide IT or cybersecurity services. We do not claim a CMMC status, CMMC UID, or NIST SP 800-171 DoD Assessment score for this engagement. If you believe the engagement is being performed under your DoD contract or subcontract, or that a CMMC or DFARS clause flows down to it, please identify the specific clause, required CMMC level and assessment type, prime contract number, and the information you expect to be designated or otherwise identified as FCI or CUI.

We are also prepared to discuss performing the work inside your controlled environment rather than receiving protected data into ours. In many accounting engagements, resolving the transfer architecture is faster and more defensible than asking an outside accountant to claim a status the contract does not require.

The five questions to send back

Ask these in writing every time. They cost you nothing and they move the determination toward the documents that control it.

  1. Do you consider our engagement to be performance of your DoD contract or subcontract? If yes, identify the prime contract and the work statement.
  2. Which clause are you flowing down, and what CMMC level and assessment type does the written instrument require?
  3. What information will be designated or otherwise identified as CUI, by which agency or authorized holder, under which CUI category and authority?
  4. Can we perform the work inside your environment instead of receiving the data into ours?
  5. Who at your organization owns the CUI-flow and System Security Plan decision for this engagement?

That fourth question is the one that ends most of these conversations. We'll show you why in a moment.


→ Put the answer in the workpaper file

Copy the final response, the client's written answers, the governing clause, and a dated data-flow decision into the engagement file. That record is more useful than a verbal "we should be fine" six months later.

For broader environment preparation, use the 32-point CMMC Readiness Checklist. It is a general readiness resource, not a CPA-specific legal determination.

Educational template, not legal advice. Have counsel review it before you send it under a signed engagement.


Is accounting data FCI or CUI? Are invoices? Are labor rates?

Not automatically — and the distinction is sharper than most firms assume. Simple transactional information necessary to process payments is excluded from the definition of Federal Contract Information. The NARA CUI Registry also contains a General Procurement and Acquisition category whose description expressly includes cost or pricing data, contract information, indirect costs, and direct labor rates. That does not make every invoice, rate, or cost report CUI. The governing authority and a valid designation still matter.

First, the payment exclusion — the good news nobody tells you

The FCI definition incorporated into CMMC excludes simple transactional information, such as that necessary to process payments. The same exclusion appears in the FCI definition used by DFARS 252.204-7021.

Read plainly: a remittance amount, bank routing instruction, or invoice total can be payment-processing information rather than FCI on its own.

The catch is that invoices are rarely just invoices. A single invoice can carry a contract number, task-order reference, program name, labor categories, a direct labor-rate schedule, a deliverable description, and a technical attachment. One benign field does not neutralize protected material in the same document or transmission. The exclusion covers the simple payment facts, not everything that traveled in the same envelope.

Practical rule for your AP and billing workflow: separate the payment facts from contract-performance material. Different attachments, different transfer paths, different access, and different retention where the engagement permits it.

Then the finding: the CUI Registry names the data accountants actually see

We read the current NARA CUI Registry category pages on August 18, 2026.

General Procurement and Acquisition — category marking PROCURE, with CUI//SP-PROCURE under its Specified authorities. The Registry describes the category as material and information relating to acquisition and procurement, including cost or pricing data, contract information, indirect costs, and direct labor rates.

Read that list again. Cost or pricing data. Contract information. Indirect costs. Direct labor rates.

Those are the exact data types a government-contract accounting practice may encounter. The important word is may. A Registry category describes information that can be CUI when an applicable law, regulation, or government-wide policy and a valid designation bring the specific information into the category. The category description is not a switch an accounting firm flips by itself.

Source Selection covers nonpublic information prepared for an agency's evaluation of a bid or proposal. Its Specified authorities use CUI//SP-SSEL; its Basic authorities use CUI, with CUI//SSEL listed as an alternative Basic banner. If your firm performs proposal support or handles agency source-selection material, this is a separate category analysis.

The grouping question can affect the minimum assessment type — but the contract still controls

The January 15, 2025 CMMC Level Determination Guide used NARA Organizational Index Groupings to set minimum assessment types: CUI outside the Defense grouping pointed to Level 2 (Self), while CUI in the Defense grouping pointed to Level 2 (C3PAO). The guide also allowed the requiring activity to select a higher level when security needs dictated.

That guide predates the July 13, 2026 suspension. The current suspension memorandum prohibits new Level 2 (C3PAO) and Level 3 designations during the review. So the guide remains useful historical context for why categories mattered, but it is not a substitute for the current solicitation, contract, flow-down, or suspension instructions.

CUI category — Typical Registry marking — NARA grouping — January 15, 2025 guide's stated minimum before the suspension — August 2026 procurement posture
CUI categoryTypical Registry markingNARA groupingJanuary 15, 2025 guide's stated minimum before the suspensionAugust 2026 procurement posture
General Procurement and AcquisitionCUI//SP-PROCURE under Specified authorities; CUI under its Basic authorityProcurement and AcquisitionLevel 2 (Self), subject to a higher requirement selected for riskNew procurement designations are limited to Level 2 (Self) during the suspension
Source SelectionCUI//SP-SSEL under Specified authorities; CUI or CUI//SSEL under Basic authoritiesProcurement and AcquisitionLevel 2 (Self), subject to a higher requirement selected for riskNew procurement designations are limited to Level 2 (Self) during the suspension
Controlled Technical InformationCUI//SP-CTIDefenseLevel 2 (C3PAO) minimum under the dated guideNew Level 2 (C3PAO) designations are suspended; verify the written instrument and amendment status

Controlled Technical Information is not the only category in the Defense grouping. The Registry also places categories such as DoD Critical Infrastructure Security Information, Naval Nuclear Propulsion Information, Privileged Safety Information, and Unclassified Controlled Nuclear Information—Defense within that grouping. Do not turn "we do not handle drawings" into "we cannot touch Defense-grouping CUI."

The financially useful conclusion is narrower and stronger than the original shortcut: an accounting engagement that genuinely involves only Procurement and Acquisition-grouping CUI may point toward Level 2 (Self) under the dated determination guide, but the program office and written contract still decide the requirement, and the current suspension limits new designations to self-assessment paths.

Two guardrails, because we'd rather be useful than dramatic:

On 41 U.S.C. 2105. The NARA category page lists sanctions associated with certain Procurement Integrity Act authorities. We are reporting the Registry's authority and sanctions columns as published. We are not telling you that an outside auditor automatically faces those penalties. Applicability is a legal question for counsel.

On tax and proprietary business data. Federal taxpayer information and proprietary business information are separate CUI categories with their own authorities. Tax information also brings IRC § 6103 and, in relevant government-handling contexts, IRS Publication 1075 into the picture. We did not re-verify the exact current banner marking for those categories in this review, so we are not publishing one. Confirm the category, authority, and marking in the CUI Registry before relying on it.

Never invent the designation yourself

This bears saying plainly because firms do it: do not create a CUI designation from a category page and do not remove a marking because you disagree with it. Under 32 CFR § 2002.4, an authorized holder designates a specific item as CUI consistent with the rule and Registry, and the designating agency is the executive branch agency that designates or approves the designation. Section 2002.20 controls the marking structure.

Your client may be the channel through which the information reaches you, but it is not automatically the designating agency. Ask for:

  • The designating agency and point of contact
  • The category or subcategory and governing authority
  • The required banner and portion markings
  • Any limited-dissemination controls
  • Whether derivative work product remains CUI
  • The approved transfer method
  • Retention, decontrol, return, and destruction instructions

If those answers do not exist, that is information too. It usually means the data should not be moving again until someone with authority resolves the designation and path.


Which accounting systems come into the CMMC boundary?

No software product carries a transferable CMMC status, and no vendor can sell you one. QuickBooks, an ERP, a payroll platform, a workpaper portal, an email tenant, and a backup system enter the analysis when the configured environment processes, stores, transmits, or protects covered information in performing a covered contract. The right question is never "is this product CMMC compliant?" It is "what protected information reaches this implementation, what role does the service play, and what requirement is written into the contract?"

Is QuickBooks CMMC compliant?

Direct answer, because people search this exact phrase: no product has a CMMC status of its own. CMMC evaluates the contractor information systems within a defined assessment scope, the implemented requirements, the evidence, and the contractual status required. A QuickBooks environment holding no FCI or CUI may sit outside the boundary. A configured environment holding covered information needs a system-specific analysis.

Anyone selling "CMMC-compliant accounting software" as a status you inherit is describing something that does not exist. A product can support a compliant architecture. It cannot transfer a CMMC status to your firm.

The system-by-system read

System — When it is commonly outside — What pulls it into the analysis — First question to ask
SystemWhen it is commonly outsideWhat pulls it into the analysisFirst question to ask
QuickBooks / general ledgerOrdinary commercial accounting data onlyContract-performance fields, protected attachments, exports into analytics, or a covered flow-downWhat FCI or CUI actually resides here?
ERP / job-cost systemNo covered contract informationContract numbers, work-breakdown structures, labor categories, direct labor rates, indirect pools, program names, technical attachmentsWhich modules, integrations, and exports touch it?
PayrollOrdinary payroll and simple payment dataLabor distributions tied to protected programs, designated rate data, free-text fields, protected attachmentsHas any contract-specific field been identified as CUI?
Tax and audit workpaper portalNo CUI or Security Protection Data presentMarked or otherwise identified CUI uploads, protected permanent-file attachments, automated backups, external support accessIs this an approved transfer and retention path in writing?
Email tenantCovered information cannot arriveAttachments, forwarding rules, retention, mobile access, journaling, discovery archivesCan covered information arrive here, and where can it persist?
Backup and archiveSource systems hold nothing coveredReplication of any system above, snapshots, e-discovery archives, support logsWhere do copies go, how long do they remain, and who can read them?
E-signature platformOrdinary engagement documents onlyProtected exhibits and attachments retained by the serviceDoes the platform retain a copy or metadata containing covered information?
Identity, firewall, SIEM, or managed endpoint platformProvides no security function to a CUI environmentProtects CUI assets or contains Security Protection DataIs it a Security Protection Asset or part of an ESP service?

The secondary-copy problem

This is where firms with a clean primary environment still lose the boundary. A well-designed path gets undone by email forwarding, local downloads, browser cache, print-to-PDF, desktop sync, backup replication, e-discovery archives, support tickets, screenshots, mobile access, and exports to an analytics tool nobody included in the diagram.

Secondary copies count when they process, store, or transmit the covered information. Map the copies, not just the intended path. The intended portal is rarely where the surprise lives.

If a cloud service holds CUI

When an external cloud service provider stores, processes, or transmits covered defense information in performance of a contract containing DFARS 252.204-7012, paragraph (b)(2)(ii)(D) requires the contractor to ensure that the provider meets security requirements equivalent to the FedRAMP Moderate baseline and complies with specified incident-reporting and forensic-support duties.

Do not shortcut that to "buy GCC High." Architecture, service role, contract text, data flow, equivalency evidence, and the responsibility split still have to be documented. A marketing badge is not the contract analysis.

That is a real project with a real budget, which is the single best argument for the section that follows.


Can we work inside the client's environment and stay out of scope?

Often — if the configuration actually prevents CUI from reaching your assets. 32 CFR § 170.19 and the DoD Level 2 Scoping Guide recognize that an endpoint used only to access a virtual desktop can be treated as an Out-of-Scope Asset when it does not process, store, or transmit CUI beyond keyboard, video, and mouse interaction with the in-scope environment.

Accounting work is unusually compatible with that architecture because much of it can be performed by viewing, analyzing, and entering information inside the client's system. That does not make the carve-out automatic. It makes it available.

The KVM-only condition, and what actually defeats it

The carve-out is real, and it is narrow. "We use VDI" is not the finding. The configuration is the finding.

Test every path that could allow CUI to be processed, stored, or transmitted outside the client's environment:

  • File transfer between the session and endpoint
  • Clipboard redirection in either direction
  • Local drive mapping
  • Local printer mapping and print-to-PDF
  • Screen capture and screen recording
  • Browser downloads, browser cache, and temporary files
  • USB and peripheral redirection
  • Mobile and tablet access
  • Offline mode
  • Session logs, crash dumps, and support-tool access
  • Credential and session-token storage on the endpoint
  • Accessibility or collaboration tools that copy session content

An enabled feature does not defeat the carve-out merely because its name appears on this list. It defeats the carve-out when the feature allows CUI to be processed, stored, or transmitted on the endpoint or another out-of-scope asset. Test the actual configuration, document the result, and re-test after material changes and at planned review intervals. "VDI" is a product label. KVM-only is a verified operating condition.

The staff-augmentation condition — narrower than it looks

The Level 2 Scoping Guide also addresses an ESP used as staff augmentation. It says the staff-augmentation ESP does not need CMMC assessment when the assessed organization provides all processes, technology, and facilities used by the external personnel.

That word all is doing enormous work. The guide does not say "uses the client's login" or "connects remotely." It says the assessed organization provides all three. When your firm supplies its own portal, workpaper system, storage, process, technology, or facility, do not assume that sentence covers the arrangement. Analyze the added assets and services instead of stretching a staff-augmentation example past its facts.

Five architectures, ranked by how much exposure they leave you

Architecture — How it works — Who retains custody of the CUI — Effect on your exposure — Tradeoff — Engagement-letter language to consider
ArchitectureHow it worksWho retains custody of the CUIEffect on your exposureTradeoffEngagement-letter language to consider
Work inside the client's environmentStaff access the client's enclave or KVM-only VDI session; CUI cannot reach firm systemsClientStrongest position available when the configuration is verifiedSlower fieldwork; client provisions accounts; some tools unavailable"Firm will access covered information only within Client's approved environment and will not download or retain copies."
Client-hosted web portal with download blockedClient retains the authoritative files, but firm endpoints display and therefore process the CUI in an ordinary browserClient retains the source; firm endpoints process it during useReduces persistent copies, but it is not the KVM-only out-of-scope condition. If a covered door is open, the endpoints may remain in scopeBrowser cache, printing, screenshots, accessibility tools, support data, and exports can create additional copiesState the permitted actions and retention controls, and do not call the endpoint out of scope without a supportable scoping analysis
Agency-authorized decontrolled or properly sanitized deliverablesAn authorized holder provides only information the client is authorized to release outside the controlled environmentClient for the controlled sourceCan reduce or remove CUI from the material transferredRequires a real authorization and defensible sanitization, not deletion of a banner"Client will not remove or alter CUI markings without authority and will identify the basis for any decontrol or sanitization."
Firm receives and holds client CUIFiles land in firm email, a file server, workpaper system, cloud drive, or applicationFirmHighest exposure. If a covered door is open, these assets can enter the assessment scopeReal money, real time, ongoing evidence and incident dutiesRequires a documented boundary, approved services, responsibility matrix, retention rules, and contract review
On-site and paper-only workTraditional fieldwork with no electronic transfer to firm systemsClient or controlled physical custody, depending on the factsLow electronic exposure, but physical CUI safeguards and custody still matterImpractical at scale; transport, copying, and storage remain risksState custody, access, reproduction, transport, return, and destruction terms

Our editorial conclusion, and we'll own it as a conclusion rather than a rule: for most accounting engagements, the correct move is to stop taking custody rather than to build a compliance program around custody you did not need. That's the sentence a compliance vendor will not write, and it is the one that saves firms the most money.

The honest limitation: it does not work everywhere. Rate work with heavy source-document review, investigations, proposal support, and tax or attest engagements with professional-retention requirements can force custody or create a different contractual need. If that's your situation, you're in the group that needs a real environment decision — keep reading.


We already received client CUI. Are we in trouble?

Receiving marked or otherwise identified CUI does not, by itself, establish that your accounting firm is subject to CMMC. Applicability still turns on the contract, subcontract, service role, and performance facts. What the transfer can create is exposure under the engagement agreement, a flowed-down clause, the client's CUI-flow controls, confidentiality duties, professional obligations, and possibly incident-reporting or preservation duties if a clause such as DFARS 252.204-7012 actually applies.

The correct response is a documented look-back and a forward-looking architecture decision. It is not a retroactive claim that you were certified, and it is not permission to delete evidence.

The four-step look-back

  1. Where did it land? Email, portal, file server, tax software, ERP import, laptop, personal device, print file, backup, archive, or support system.
  2. Who touched it? Named staff, contractors, offshore resources, support vendors, and anyone with administrative or recovery access.
  3. Is it still there? Retention policies, sync tools, journaling, backups, and legal holds often make the answer yes in more places than expected.
  4. What does the executed engagement and contract chain say? Read the final engagement letter, security addendum, flow-down, prime-contract reference, incident clause, permitted systems, subcontractor terms, and retention language — not the template.

Document the answers with a date. Preserve relevant evidence. If there is any indication of unauthorized access, compromise, or a contractually reportable event, escalate immediately to counsel, the engagement owner, and the person responsible for contract cyber reporting. Do not let a blog post decide a 72-hour reporting question.

Your client may have an undocumented flow even if CMMC does not attach to you

If CUI moved to a destination not reflected in the client's System Security Plan or data-flow documentation, the client may need to correct its records and architecture. Expect a request to change how you receive data.

That request is reasonable, and the architecture section above is your answer to it. Firms that arrive at the conversation with a documented map and a proposed controlled workflow instead of a defensive posture are easier to keep.

The retention collision — we're not going to pretend this is solved

Your professional records-retention obligations and a client's request to purge CUI can point in opposite directions. Your state board, applicable auditing or tax standards, your firm's quality-management policy, peer-review obligations, litigation-hold duties, and the engagement letter may all have something to say. CMMC does not resolve those independent duties for you.

We're not resolving that collision in an editorial article. Put it in front of qualified counsel and your firm's independence, records, or quality leadership before you delete anything, decontrol anything, or promise a destruction date.


If a door is open: what level, what assessment type, what cost?

FCI-only work generally maps to Level 1 and CUI work starts at Level 2 under 32 CFR § 170.23 — but the written solicitation, contract clause, or flow-down sets the required CMMC status for the systems used in performance. Level 1 contains 15 safeguarding requirements. Level 2 uses all 110 security requirements of NIST SP 800-171 Revision 2 across 14 families. Level 3 adds the 24 enhanced requirements selected from the February 2021 edition of NIST SP 800-172 that 32 CFR Part 170 incorporates on top of Level 2.

Under the current July 2026 suspension direction, new procurement requirements may designate only Level 1 (Self) or Level 2 (Self). Level 2 (C3PAO) and Level 3 remain defined in the rule, but new designations for those assessment types are suspended during the review.

For a complete side-by-side comparison, see CMMC Level 1 vs Level 2 vs Level 3.

Level 1 versus Level 2, for someone who has never read either

Level 1 protects FCI and maps to 15 basic safeguarding requirements derived from FAR 52.204-21. It requires a self-assessment and affirmation every year. All 15 requirements must be met; 32 CFR § 170.21 does not permit a Level 1 Plan of Action and Milestones.

Level 2 protects CUI and maps to the 110 requirements of NIST SP 800-171 Revision 2 across 14 families. A Level 2 self-assessment is conducted every three years, with an annual affirmation. A Conditional Level 2 status can use a POA&M only within the rule's limits: at least an 80-percent score, only permitted requirements, and successful closeout within 180 days. A POA&M is not a parking lot for anything not yet implemented.

Level 3 adds 24 requirements selected from the February 2021 edition of NIST SP 800-172, which addresses enhanced protection for CUI associated with critical programs or high-value assets. NIST withdrew that publication in May 2026 and superseded it with SP 800-172 Revision 3, but 32 CFR Part 170 still incorporates the February 2021 edition and its selected 24 requirements. It is not a realistic destination for an ordinary accounting engagement, and new Level 3 procurement designations are currently suspended.

The same rule-versus-catalog distinction applies at Level 2. NIST withdrew SP 800-171 Revision 2 from its active catalog after publishing SP 800-171 Revision 3 in May 2024, but the CMMC rule expressly incorporates Revision 2. Revision 3 is not the CMMC-controlling version unless DoD changes the rule, the incorporated standard, or the applicable contract requirement.

What you would actually be signing

CMMC self-assessment results and affirmations are submitted in the Supplier Performance Risk System. An Affirming Official is a senior representative responsible for affirming continuing compliance for the information systems in the assessment scope. The affirmation is not a marketing checkbox. It is a named person's attestation to the status being maintained.

Keep the records straight:

Record in or associated with SPRS — What it means — Primary DFARS reference
Record in or associated with SPRSWhat it meansPrimary DFARS reference
NIST SP 800-171 DoD Assessment summary scoreThe score under the DoD Assessment Methodology for a covered contractor information system252.204-7019 and 252.204-7020, or an applicable class-deviation replacement
CMMC assessment result and statusLevel 1 (Self), Level 2 (Self), Level 2 (C3PAO), or Level 3 status for a defined assessment scope252.204-7021
Annual affirmationAffirmation of continuous compliance required to keep the CMMC status current252.204-7021 and 32 CFR § 170.22
CMMC UIDIdentifier supplied for each relevant contractor information system in a proposal when 252.204-7025 applies252.204-7025

Cost drivers, without fake numbers

We publish cost ranges elsewhere and we're not going to duplicate them here with softer data. What we will tell you is where accounting firms specifically spend more than they expect:

  • Boundary definition in a firm where partners work from multiple locations and everyone has accumulated administrative access
  • Email and file-sharing architecture because the current environment was designed for convenience and retention, not a narrow CUI boundary
  • Identity, multi-factor authentication, and access control across a partner-heavy organization with informal delegation
  • Evidence retention — proving controls operated, not merely that a policy exists
  • Seasonal staff and turnover that make provisioning, training, and deprovisioning recurring operations
  • Professional-retention conflicts that prevent simple deletion as a scope strategy
  • Cloud-service evidence and responsibility matrices where the firm relies on inherited controls

For actual ranges and assumptions, see CMMC Level 2 Cost.

Where the program stands right now — and why it matters to your decision

The nominal Phase I period runs November 10, 2025 through November 9, 2026. The Department suspended the planned Phase II transition on July 13, 2026. During the suspension:

  • New procurement requirements may designate only Level 1 (Self) or Level 2 (Self)
  • Program managers and requiring activities may not designate new Level 2 (C3PAO) or Level 3 requirements
  • Active solicitations containing those higher assessment requirements are to be amended
  • Existing contracts containing them are directed to be modified before the next option period or scheduled administrative modification
  • DFARS 252.204-7012 safeguarding and reporting duties remain in effect where the clause applies
  • CMMC Level 2 continues to use NIST SP 800-171 Revision 2
  • Select government-led assessments can still occur

Also worth knowing: the codified FAR and DFARS pages still publish FAR 52.204-21 and DFARS 252.204-7019/-7020. Separately, DoD's Revolutionary FAR Overhaul class deviations can direct contracting officers to use replacement Part 240 text, including FAR 52.240-93 and DFARS 252.240-7997, in covered solicitations and contracts. That is not the same thing as saying the codified clauses vanished universally.

You will see old, codified, and deviation numbering in live documents. Read the actual clause text and deviation identifier in the instrument in front of you. The current official DFARS Revolutionary FAR Overhaul class-deviation page is the source to check, not a vendor's shorthand.

What this means practically: do not buy a third-party certification engagement because a 2025 article told you every CUI holder would need one in November 2026. And do not stop safeguarding work either — the underlying 800-171 and DFARS duties did not disappear. Verify the written requirement on the date you act, confirm whether an amendment or modification is pending, and get changes in writing. That's the urgency on this page that is real.


Is a DCAA accounting-system review the same as a CMMC assessment?

No — different criteria, different purpose, different evidence, and neither substitutes for the other. A Defense Contract Audit Agency preaward accounting-system survey uses the accounting-system criteria associated with Standard Form 1408 to support an acquisition or contract-administration decision. CMMC assesses cybersecurity requirements for applicable contractor information systems under 32 CFR Part 170.

An accounting-system survey can tell the Government whether a prospective contractor's system is designed to accumulate and report contract costs in an acceptable manner. It does not establish a CMMC status, a NIST SP 800-171 implementation score, or an approved CUI boundary.

We're including this because it is the single most common conflation accounting professionals make, and it makes sense why: both involve DoD, both involve reviews of systems, and both can produce uncomfortable findings. They still answer different questions.

Dimension — DCAA preaward accounting-system survey — CMMC assessment
DimensionDCAA preaward accounting-system surveyCMMC assessment
Who performs itDCAA or another survey activity, depending on the acquisitionThe contractor for self-assessment; a CMMC Third-Party Assessment Organization for Level 2 certification; DCMA DIBCAC for Level 3
Against whatAccounting-system design criteria reflected in SF 1408 and the applicable contract-cost framework15 Level 1 requirements or 110 NIST SP 800-171 Rev. 2 requirements at Level 2; Level 3 adds 24 requirements selected from the February 2021 SP 800-172 incorporated by the rule
Question answeredIs the accounting system designed to support the contemplated contract and cost-accounting needs?Are the required cybersecurity requirements implemented within the defined assessment scope?
ResultSurvey findings and a recommendation or report used by the acquisition/contracting functionA CMMC assessment result and status, with required SPRS records and affirmation
Does it satisfy the other?NoNo

If a client tells you "DCAA approved our system," that may describe a real and valuable accounting-system result. Say so kindly, then ask for the separate CMMC and CUI evidence.


Can a CPA firm sell CMMC services or become a C3PAO?

Some do — but two independence regimes can apply at once, and neither disappears because the firm uses a separate engagement letter. The CMMC rule directly prohibits a CMMC ecosystem member from participating in the Level 2 certification process for an organization it helped prepare for any CMMC assessment during the preceding three years. The Cyber AB Code of Professional Conduct implements and explains that rule. Separately, the AICPA independence framework applies to attest clients and nonattest services on its own terms.

"C3PAO" means CMMC Third-Party Assessment Organization. It does not mean "Certified Third-Party Assessment Organization."

If you're reading this page because your firm is considering a CMMC practice rather than because a client sent you a questionnaire, this section is for you — and you should know up front that most firms underestimate the arithmetic.

The two rulebooks, side by side

Question — CMMC ecosystem rule — CPA independence rule
QuestionCMMC ecosystem ruleCPA independence rule
Can we prepare a client and then perform its Level 2 certification assessment?No within the three-year lookback. 32 CFR § 170.8(b)(17)(ii)(G) prohibits participation in the Level 2 certification process after preparatory consulting for any CMMC assessment. The Cyber AB Code of Professional Conduct v2.0 applies the restriction to the C3PAO as an organization and to Assessment Team membersNonattest services can create self-review and management-participation threats. The attest client must accept responsibility, designate a person with suitable skill, knowledge, and experience, evaluate the service, and not shift management responsibility to the CPA. See the AICPA Professional Standards library
Does a small prior engagement matter?It can. The Cyber AB Code's example treats prior consulting on a Level 1 self-assessment as disqualifying for the later Level 2 certification engagement within three yearsThe cumulative effect of multiple nonattest services matters; a small label does not end the independence analysis
What governs the formal assessment procedure?The CMMC Assessment Process (CAP) v2.0 is the Cyber AB procedural guide for Level 2 certification assessments only. It is not a readiness, consulting, or self-assessment guide and does not supersede 32 CFR Part 170The applicable AICPA, state-board, SEC, PCAOB, contractual, and firm quality-management rules continue independently
What does standing up the assessment side require?Under 32 CFR § 170.9, a C3PAO must achieve ISO/IEC 17020:2012(E) accreditation within 27 months of authorization. Company personnel participating in the Level 2 certification process, including the Assessment Team and quality-assurance individual, must complete a Tier 3 background investigation resulting in a national-security eligibility determination. The investigation is initiated using SF-86, and the positions are designated non-critical sensitive/Moderate RiskFirm licensure, independence, engagement acceptance, quality management, and professional standards apply separately
Who carries the conflict duty?The organization and covered CMMC ecosystem individuals, including Certified CMMC Assessors and Certified CMMC Professionals under their applicable rule provisionsThe firm and covered practitioners under the applicable professional standards

The CAP point matters because firms use the word "assessment" loosely. A gap analysis, readiness review, mock assessment, Level 1 self-assessment, Level 2 self-assessment, and Level 2 certification assessment are not interchangeable services. Only the last one is governed by the CAP as a formal C3PAO certification process.

The public-company layer, if you have issuer audit clients

For issuer audit clients, the analysis gets stricter. The SEC's auditor-independence rules identify financial-information-systems design and implementation as a prohibited non-audit service for an audit client, subject to the precise rule text and exceptions, and permissible non-audit services generally require audit-committee preapproval. PCAOB independence and communication rules apply alongside the SEC framework.

Do not reason from a private-company engagement to an issuer engagement. They're different rulebooks with different consequences.

The two-entity structure some firms use

A separate legal entity can help divide attest and advisory operations. It does not erase common-control, personnel, brand, financial, referral, information-sharing, or CMMC conflict facts. The conclusion remains engagement-specific.

What we verified as company-stated examples — not endorsements:

Organization — Publicly stated structure or service model — What we verified — What we did not verify
OrganizationPublicly stated structure or service modelWhat we verifiedWhat we did not verify
A-LIGNIts website identifies Price and Associates CPAs, LLC dba A-LIGN ASSURANCE as a licensed CPA firm registered with the PCAOB, and A-LIGN Compliance and Security, Inc. dba A-LIGN as a cybersecurity and compliance professional-services firmThe two-entity disclosure was present on a-lign.com on August 18, 2026Current Cyber AB Marketplace status, service quality, engagement outcomes, or an independence conclusion for any client
IS Partners LLCIts own CMMC services content describes separate certification and readiness paths and states that it cannot provide both to the same client because of conflict rulesThe company-stated two-pathway description was present on ispartnersllc.com on August 18, 2026Current Cyber AB Marketplace status, service quality, engagement outcomes, or whether every service description is current

We include those examples to show the structural problem firms are trying to solve, not to recommend either company and not to make a current Marketplace status assertion. Before hiring any assessment organization, verify its live status in the Cyber AB Marketplace.

The part we'd tell you over coffee

Run the numbers before you run the practice. The three-year consulting prohibition removes readiness clients from your certification-assessment pipeline for three years. ISO/IEC 17020 accreditation is a 27-month clock with real cost attached. Personnel participating in the Level 2 certification process, including quality assurance, must complete the required Tier 3 investigation or the rule's approved equivalent path. The CAP imposes a formal process that is not the same business as advisory work.

For many small and mid-size CPA firms, doing both lanes does not pencil out. Pick a lane. Readiness and advisory work can be a natural adjacency to a government-contract accounting practice. Formal C3PAO assessment is a separate business with a separate cost structure and conflict profile.

And remember the current procurement posture: new Level 2 (C3PAO) designations are suspended while the program is under review. That does not repeal the C3PAO rules or settle the value of every existing engagement, but it does change the near-term demand assumption you should use in a business plan.


Which provider category fits, if you need one?

The right category depends on what has already been established, and a C3PAO is almost never the first call. A firm with unresolved applicability needs qualified federal-contracts counsel, often supported by an RPO, RP, or experienced readiness advisor. A firm with an architecture problem needs an MSP, MSSP, cloud specialist, or enclave provider. A firm with a documented assessment requirement needs independent assessment last.

We're not naming providers in this section, and here's the reason: on a determination page, naming a vendor before you've established that you have a problem is how firms buy things they do not need. Get the category right first.

What you have established — Best-fit category — What that category should deliver — What not to ask it to do
What you have establishedBest-fit categoryWhat that category should deliverWhat not to ask it to do
Contract, flow-down, or engagement role is ambiguousQualified federal-contracts attorney, with technical support from an experienced CMMC advisor where neededWritten applicability and contract interpretationInvent the client's CUI designation or promise a procurement outcome
Scope and data flow are ambiguousRPO/RP or experienced readiness/scoping consultantWritten boundary, asset inventory, data map, service-provider analysis, and open-issue listPerform the later certification assessment for the same client inside the three-year conflict window
Technical remediation is neededCMMC-focused MSP or MSSPArchitecture, configuration, operating procedures, monitoring, and evidenceSet the contractual level or give legal advice
Firm must hold client CUICUI enclave or secure-collaboration provider, supported by a responsible advisorA bounded environment, inherited-control evidence, and a clear responsibility matrixPromise that the platform itself is "CMMC certified"
Cloud path holds covered defense informationCloud/FedRAMP implementation specialistService-role analysis, authorization or equivalency evidence, responsibility split, and contract alignmentTreat a marketing badge as proof
SSP, POA&M, and evidence workflow need managementGRC platform plus accountable human ownershipWorkflow, evidence ownership, change control, and assessment recordsSubstitute software for implementation or an Affirming Official
Level 1 or Level 2 self-assessment support is neededRPO/RP or readiness providerObjective assessment support, evidence preparation, remediation plan, and SPRS process supportSubmit an affirmation the provider is not authorized to make for you
A live written Level 2 certification requirement remains after amendment reviewAuthorized C3PAO, after readiness and conflict checksIndependent assessment under the CAPRemediate the organization and then assess it inside the prohibited window
CPA independence is uncertainYour firm's independence leadership and qualified counselEngagement-specific conclusion under all applicable regimesRely on CMMC conflict rules alone

Editorial judgment, stated as such: under the current suspension, we deliberately do not route an accounting firm toward a third-party assessment merely because it handles accounting data for a defense contractor. The order that protects your money is applicability first, then designation and data flow, then architecture, then implementation and evidence, then formal assessment only when a live written requirement survives the contract review.

For a deeper category comparison, read CMMC Provider Categories and Who to Hire First.


→ If a door is genuinely open, get the category right before you get quotes

Find My CMMC Path → maps a general situation to the provider category that belongs first. When you are ready to compare actual providers, use Request a Quote →.

If your determination is Door 4, you may not need either. Go back to the architecture table, change how you receive client data, put the decision in writing, and save your money. We'd rather you leave this page with a cheaper answer than a bigger invoice.

Do not submit CUI, drawings, client names, contract files, system diagrams, credentials, or other sensitive information. Provider matching may generate referral compensation; any relationship is disclosed at the point of recommendation and under our Editorial & Advertising Policy.


What we actually verified for this guide

The regulatory and technical claims retained in this page were checked against the issuing authority's published text on August 18, 2026. Company examples are labeled company-stated. Editorial conclusions are labeled as conclusions. Where the source did not support a stronger statement, we narrowed the statement instead of laundering an inference into a rule.

Verified item — Primary source or controlling publication — Version or status checked
Verified itemPrimary source or controlling publicationVersion or status checked
CMMC applicability, unclassified-system scope, threshold, and COTS-only exclusion32 CFR § 170.3eCFR current through August 14, 2026
Supply-chain application and "in the performance of" language32 CFR § 170.23eCFR current through August 14, 2026
ESP definition and CSP/non-cloud ESP/SPD scoping outcomes32 CFR § 170.4 and § 170.19eCFR current through August 14, 2026
KVM-only VDI, staff augmentation, and cloud-accounting SaaS examplesDoD CMMC Level 2 Scoping GuideVersion 2.13, September 2024
Phase II suspension and current permitted procurement designationsDoD CMMC page and Implementing Suspension memorandumJuly 13, 2026 direction, read August 18, 2026
Level 1, Level 2, Level 3, affirmation, and POA&M requirements32 CFR §§ 170.14–170.22eCFR current through August 14, 2026
Rev. 2 remains the CMMC-incorporated Level 2 standard; Rev. 3 is newer in NIST's catalogNIST SP 800-171 Rev. 2, Rev. 3, and 32 CFR § 170.14NIST publication pages and current rule
Level 3 uses 24 requirements selected from the February 2021 SP 800-172 incorporated by the rule; NIST has since published SP 800-172 Rev. 332 CFR § 170.14, NIST SP 800-172, and SP 800-172 Rev. 3CMMC rule text plus NIST's May 2026 superseding publication
DFARS 252.204-7012 safeguarding, cloud, incident, and flow-down dutiesAcquisition.gov clause textCodified DFARS Change 5/7/2026
NIST DoD Assessment score versus CMMC status/UID recordsDFARS 252.204-7019, 252.204-7020, 252.204-7021, and 252.204-7025Codified DFARS Change 5/7/2026
RFO deviation numbering can coexist with codified clause numberingOfficial DFARS class-deviation indexPart 240 Revision 2 listed July 16, 2026
General Procurement and Acquisition, Source Selection, CTI, and organizational groupingsNARA CUI Registry and category pagesRegistry pages read August 18, 2026
CUI designation and marking authority32 CFR §§ 2002.4 and 2002.20Current eCFR text
C3PAO conflict rule, 27-month accreditation window, and personnel investigations32 CFR §§ 170.8–170.13Current eCFR text
Cyber AB conflict explanation and formal Level 2 assessment procedureCode of Professional Conduct v2.0 and CAP v2.0December 2024, marked effective and in force
DCAA preaward accounting-system survey and SF 1408 distinctionDCAA Preaward Accounting System Adequacy Checklist and SF 1408Official DCAA/GSA materials
A-LIGN and IS Partners examplesEach company's own public websiteCompany-stated pages read August 18, 2026

What we could not establish, and therefore did not present as fact:

  • That the January 15, 2025 CMMC Level Determination Guide remains operative in unchanged form after the July 13, 2026 suspension. We identify it by date and use it only as dated context.
  • A current Cyber AB Marketplace status for A-LIGN or IS Partners through an accessible official organization record. We make no current status assertion.
  • That the sanctions listed on the NARA General Procurement and Acquisition page automatically apply to an outside auditor.
  • The exact current CUI banner marking for federal taxpayer information or proprietary business information.
  • A universal CMMC cost or implementation timeline for a CPA firm.
  • A CPA-specific CMMC enforcement case suitable to present as representative. We did not find one, so we did not invent one.
  • That any article can give a binding applicability opinion without the actual solicitation, contract, subcontract, data, and system facts.

How this page was produced: researched and written by The Defense Compliance Report Editorial Team from the sources above. Editorial research — not formally reviewed by a CMMC Subject Matter Advisor. See our Methodology, Editorial Standards, and Corrections Policy.

Confirm engagement-specific scope, contract interpretation, CUI designation, and professional obligations with the qualified people responsible for those decisions. A Registered Practitioner or experienced CMMC advisor can help with technical scope. Qualified federal-contracts counsel should handle contract interpretation. Your CPA independence and records leadership should handle professional obligations. No single provider replaces all three.


Frequently asked questions

Does CMMC apply to accounting firms?

Usually not for ordinary accounting work by itself. CMMC reaches prime contractors and subcontractors that process, store, or transmit FCI or CUI on contractor information systems in the performance of a DoD contract or subcontract. A CPA firm's industry label does not create or remove applicability.

Is my CPA firm an External Service Provider under CMMC?

Not for ordinary accounting services alone. The ESP definition in 32 CFR § 170.4 starts with the provision and management of IT and/or cybersecurity services and also requires CUI or Security Protection Data on the assets used for that service. A separate hosted, managed-IT, security, GRC, or cloud-administration service can change the answer.

Is cost or pricing data CUI?

It can be. The NARA General Procurement and Acquisition category expressly lists cost or pricing data, contract information, indirect costs, and direct labor rates. But the category description does not automatically turn every cost record into CUI. The governing authority and valid designation of the specific information still matter.

Are invoices FCI?

Simple transactional information necessary to process payments is excluded from FCI. But an invoice can contain contract numbers, task orders, program names, labor categories, rate schedules, deliverable descriptions, or protected attachments. The payment exclusion does not sanitize everything in the document.

Does an indirect cost rate proposal automatically make the CPA firm a covered subcontractor?

No. It is closer to the line than an ordinary tax return or corporate financial-statement audit because it may be prepared for a government-contracting purpose. The answer depends on whether the engagement is being performed under the DoD contract or subcontract, what information is handled, what clause is flowed down, and whose systems hold it. Get those facts in writing.

Does firm size or employee count determine whether CMMC applies?

No. CMMC applicability and level are not set by employee count. The contract role, information type, required status, assessment type, and systems used in performance control the analysis. Headcount affects cost and complexity, not legal applicability.

Is a SPRS score the same thing as a CMMC status?

No. A NIST SP 800-171 DoD Assessment summary score under the DFARS assessment framework is different from a CMMC status, annual affirmation, and CMMC UID under DFARS 252.204-7021 and 252.204-7025. Both can involve SPRS, which is why questionnaires conflate them.

Do accounting firms need a SPRS score or CMMC UID?

Only when a governing solicitation, contract, subcontract, or flow-down requires the relevant record for the systems used in performance. Do not create a score or claim a UID because a client questionnaire asks for one. Ask which clause and which record the client means.

What CMMC level would an accounting firm need?

If a covered door is open, FCI-only work generally maps to Level 1 and CUI work starts at Level 2. Level 1 has 15 requirements and annual self-assessment. Level 2 has 110 NIST SP 800-171 Revision 2 requirements across 14 families, a three-year assessment cadence, and annual affirmation. The written instrument specifies the required assessment type.

Does a client's CMMC requirement automatically flow down to its accountant?

No. Flow-down applies through a subcontract or similar contractual instrument when the subcontractor will handle the relevant information in performing the DoD contract. A professional-services engagement for the client's independent corporate purposes is not automatically that subcontract. Ask for the flowed-down clause, prime contract number, required level, assessment type, and information flow.

Can we refuse to accept CUI from a client?

You can decline custody, negotiate a different architecture, or require work inside the client's controlled environment, subject to the engagement and professional duties. That is often the cheapest correct answer. Do not remove markings, promise destruction, or assume a no-download workflow works until the client and firm document the actual controls.

What if the material is sensitive but not marked CUI?

Lack of a banner does not prove the information is outside CUI or covered-defense-information rules. DFARS 252.204-7012 also addresses information marked or otherwise identified in the contract and information developed or handled in support of performance. Treat the status as unresolved, ask for the designating agency, category and authority, and use an approved path while the client resolves it. Do not self-designate from a blog or filename.

Does our SOC 2 report satisfy a client's CMMC questionnaire?

No. A SOC 2 examination is not a CMMC assessment and does not establish implementation of the 110 NIST SP 800-171 Revision 2 requirements. You can provide it as evidence of a broader security program when appropriate, but do not imply equivalence.

Is QuickBooks CMMC compliant?

No accounting product carries a transferable CMMC status. A configured environment can support a compliant boundary, and a specific contractor information system can receive a CMMC status after the applicable assessment and affirmation. The product name itself is not certified.

Can accountants use a client's virtual desktop without bringing firm endpoints into scope?

Potentially. An endpoint can be treated as out of scope when the configuration limits interaction to keyboard, video, and mouse and prevents CUI from being processed, stored, or transmitted on the endpoint. Downloads, clipboard transfer, local printing, cache, sync, support tools, or other enabled paths can change that result. Test the configuration; do not rely on the word "VDI."

Does a DCAA accounting-system review satisfy CMMC?

No. A DCAA preaward accounting-system survey addresses accounting-system design and contract-cost needs. CMMC addresses cybersecurity requirements within a defined information-system scope. Neither substitutes for the other.

Is tax data CUI under CMMC?

Federal taxpayer information has its own CUI category and legal authorities, and tax handling also implicates IRC § 6103 and other tax-specific rules. It is not accurate to assume all tax data is CUI under CMMC or that CMMC is the only regime. We did not re-verify the exact banner marking for this guide; confirm the current Registry entry and the actual authority before relying on one.

Can a CPA firm become a C3PAO?

Yes, but the firm must satisfy the C3PAO requirements, including the accreditation timeline and personnel investigation rules, and it must obey the three-year prohibition on assessing an organization it helped prepare. CPA independence, state-board, issuer, and quality-management rules apply separately. "C3PAO" means CMMC Third-Party Assessment Organization.

Is CMMC still being enforced after the Phase II suspension?

Yes, in part. Phase I self-assessment requirements remain, DFARS 252.204-7012 remains in effect where included, and new procurement designations may use Level 1 (Self) or Level 2 (Self). The planned November 10, 2026 Phase II transition and new Level 2 (C3PAO) and Level 3 designations are suspended during the review. Active solicitations and existing contracts with higher requirements are subject to the amendment and modification instructions described above.


The bottom line

Three sentences, and then you can go answer that email.

One: find your door. CMMC does not reach an accounting firm because it is an accounting firm. It reaches through a covered contract or subcontract, or a qualifying IT/cybersecurity service, when the information and systems meet the rule.

Two: Door 4 is not a free pass. Your client still has to control where CUI goes, and your engagement can still carry security, confidentiality, transfer, incident, and retention terms even when your firm does not need a CMMC status.

Three: change the architecture before you change the firm. For most accounting engagements, a verified KVM-only client environment — or another architecture that genuinely prevents CUI from reaching firm assets — costs less than building a compliance program around data you never needed to hold.

Then put the determination, source documents, and data-flow decision in writing, with a date, in the engagement file. That memo is worth more than a certificate you do not need.


Need help deciding which CMMC provider category belongs first? Use the general router after you have the contract, information, and system facts.

Find My CMMC Path →

Do not submit CUI, drawings, client names, contract files, system diagrams, credentials, or other sensitive information.


Disclosure

The Defense Compliance Report is an independent trade publication on CMMC 2.0 and Defense Industrial Base compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or status-verification standards.

We are not affiliated with, endorsed by, or sponsored by the Cyber AB, the Department of Defense, DCMA DIBCAC, NIST, or any U.S. government agency. This article is educational research — not legal, contractual, tax, cybersecurity, accounting, attest, procurement, or compliance advice. Confirm engagement-specific decisions with qualified federal-contracts counsel, responsible CMMC professionals, and your firm's independence and records leadership.

Methodology · Editorial Standards · Editorial & Advertising Policy · Corrections Policy