The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

Readiness provider review · primary-sourced · last reviewed August 2026

Sikich CMMC Review: RPO Status, STARS, Cost, and What to Verify Before You Sign

Last updated:

Last verified: against CMMC rules, DFARS and FAR clauses, NIST publications, Cyber AB records, Microsoft and Exostar materials, and Sikich public company, service, and program pages.

Sikich CMMC review illustration showing a legal-entity map, a readiness evidence workspace, an Exostar-style platform boundary, and a separate independent assessment checkpoint

By The Defense Compliance Report Editorial Team Last reviewed: August 2026 · Last verified: August 28, 2026 · Next scheduled review: mid-September 2026

Evaluation depth: Public-source profile. We read Sikich's live CMMC pages, checked every regulation and clause they cite against the rules as they actually stand today, reviewed the Cyber AB Marketplace record, and read the July 2026 Department of War memoranda. We did not hire Sikich, test a service, interview their team, or audit customer outcomes.

Compensation status: None. The Defense Compliance Report has no paid, referral, sponsorship, or partner relationship with Sikich as of August 28, 2026. No link on this page is a referral link.

Affiliation: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We are not affiliated with Sikich, the Cyber AB, the Department of War or Department of Defense, DCMA DIBCAC, NIST, or any U.S. government agency.


The bottom line, up front

If you're searching for a Sikich CMMC review, here's the short version. Sikich is a readiness firm, not an assessor. Our research locates Sikich LLC in the Cyber AB Marketplace as a Registered Provider Organization — the consulting role — under the identifier RPO-60910. We found no current C3PAO (CMMC Third-Party Assessment Organization) listing, which means Sikich cannot perform your formal Level 2 certification assessment. Their CMMC offering is called STARS.

That's the answer. Here's the part nobody else has checked.

Sikich's own CMMC pages never mention that RPO listing. Not once. They also list a program deliverable — a "basic self-assessment" — whose underlying DFARS provision was deleted on February 1, 2026. Their page was last updated on April 6, 2026, two months after the deletion.

We'll show you exactly how we found that, why it's more complicated than a simple error, and the eleven questions it should put in your statement of work. Because the point of this page isn't to talk you out of Sikich. It's to make sure that if you hire them, you hire the right entity, for the right scope, with the right words in the contract.


First-screen verdict

Decision point Where we landed —
Decision point Where we landed
Provider categoryRegistered Provider Organization (RPO) — readiness, scoping, documentation, remediation planning, ongoing advisory
Cyber AB MarketplaceResearch locates Sikich LLC as RPO-60910. Open the live listing yourself before you sign.
Formal Level 2 assessment authorityNot found. No current C3PAO listing located. Plan a separate assessor.
Named programSTARS — Scope, Train, Assess, Remediate, Support
Published CMMC pricingNone. Not on any Sikich page we reviewed.
Best forMid-sized DIB contractors who need structured scoping, an SSP, a POA&M, and a program they can sustain
Not best forAnyone who needs a certificate, a fixed public price, or someone to run their IT day to day
Biggest thing to verifyWhich of the four Sikich legal entities signs your SOW
Last verifiedAugust 28, 2026

⚠️ Timing correction most vendor pages haven't caught up to

On July 13, 2026, the Department of War suspended CMMC Phase II, which had been scheduled to begin November 10, 2026. Phase II would have made third-party C3PAO certification a condition of award for applicable Level 2 contracts. All pending and future implementation milestones — including Phase 3 — are suspended pending a review.

Phase I did not go anywhere. Level 1 and Level 2 self-assessments, DFARS 252.204-7012 safeguarding duties, SPRS score postings, and annual affirmations all remain in force.

Practical translation: do not let any provider — Sikich or anyone else — sell you urgency built on a November 10, 2026 deadline that no longer exists. Your urgency comes from your actual contract clause, your prime's flow-down, your SPRS obligation, and your real security gaps. Those are plenty.


The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source citation on every claim and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they spend six figures.


Is Sikich a C3PAO or an RPO?

Sikich LLC appears in the Cyber AB Marketplace as a Registered Provider Organization (RPO) — the CMMC consulting and implementation role — under identifier RPO-60910. We did not locate a current C3PAO listing for any Sikich entity. Under 32 CFR § 170.9, only an authorized or accredited C3PAO conducts a Level 2 certification assessment. An RPO advises and implements; it does not certify.

Let's define the terms, because buyers collapse them constantly and it costs real money.

A C3PAO (CMMC Third-Party Assessment Organization) is authorized by the Cyber AB to conduct formal Level 2 certification assessments. Per a March 2025 Department of Defense Inspector General report (DODIG-2025-056), a candidate C3PAO must complete twelve requirements before authorization — including passing its own high-confidence assessment. There are roughly 103 of them. That's the whole population.

An RPO (Registered Provider Organization) is registered with the Cyber AB to provide CMMC consulting. Registration involves a signed agreement, an organizational background check, and agreement to the Code of Professional Conduct. There are roughly 387. It is a role registration and a conduct commitment. It is not a competence guarantee, and it is not assessment authority.

Here's the thing worth pausing on. Sikich holds an RPO registration — and never mentions it on any of its CMMC pages.

We read all three: the main CMMC service page, the Exostar/STARS landing page, and the STARS explainer article. The words "RPO," "Registered Provider Organization," "Registered Practitioner," "Cyber AB," and "C3PAO" appear on none of them.

We're not sure what to make of that, and we'll say so plainly rather than invent a motive. It may be a marketing oversight. It may be deliberate caution about implying authority they don't have. What it definitely creates is a buyer problem: the single most useful credential fact about this firm is invisible on the pages where a prospect will look for it. If you'd only read Sikich's website, you would have no idea whether they hold any CMMC role at all.

What this means for your decision:

If you need… The role that does it Is Sikich verified for it? — —
If you need… The role that does it Is Sikich verified for it?
CUI scoping, gap analysis, SSP, POA&M, remediation planningRPO / readiness consultantYes — RPO listing located; confirm live
Day-to-day operation of security controlsMSSP / External Service ProviderAdjacent capability marketed; CMMC operating scope must be confirmed in the SOW
Formal Level 2 certification assessmentAuthorized C3PAONo. No C3PAO listing located.
Level 3 assessmentDCMA DIBCAC (government)No private firm substitutes for this

One caution on our own finding. The Cyber AB Catalog is a JavaScript application that search engines do not index, so we could not render and screenshot the listing directly for this profile. Treat RPO-60910 as a pointer that tells you exactly where to look — not as our certification of current status. Marketplace records change. Open the live Catalog at cyberab.org, search Sikich LLC, confirm the status field is active, and save a dated screenshot for your file before you sign anything.

Not sure whether you need a readiness firm, a platform, or an assessor?

Hiring the wrong role is the most expensive mistake in CMMC procurement, and it's the easiest one to avoid. Map your required level, FCI/CUI scope, assessment type, environment, and contract timeline first.

Map my CMMC provider category with Find My CMMC Path

Do not submit CUI, drawings, export-controlled data, credentials, or sensitive contract details.


Which Sikich actually signs your contract?

Sikich operates in an alternative practice structure, an arrangement the AICPA permits so that a licensed CPA firm can sit alongside a separately owned advisory business. At least four legal entities carry the Sikich name. By Sikich's own published disclosure, those entities are independently owned and are not liable for each other's services. Your System Security Plan names a legal entity, not a brand.

This is the finding we'd want most if we were the one signing. It is not on a single competing page.

Every page on sikich.com carries a footer disclosure. Read carefully, it describes four distinct legal entities:

Entity What it is What it does Why it matters to you — — —
Entity What it is What it does Why it matters to you
Sikich LLC (and subsidiaries)Explicitly not a licensed CPA firmTax and business advisory. Copyright holder on sikich.com. The Cyber AB RPO listing we located is under this name.Almost certainly where STARS lives. Confirm on the SOW.
Sikich CPA LLCLicensed CPA firmAudit and attest, including third-party attestation and SOC reportingIf you ever want a SOC 2 report on Sikich's own services, that's a different entity than the one doing your CMMC work
Sikich Corporate Finance LLCFINRA/SIPC memberSecuritiesOut of scope — listed so the map is complete
Sikich FinancialSEC Registered Investment AdvisorInvestment advisoryOut of scope

And then this sentence, which appears in that same footer on every page:

The entities under the Sikich brand "are independently owned and are not liable for the services provided by any other entity."

Read that again with a compliance hat on.

Your SSP names an External Service Provider by legal entity. Your contract runs to a legal entity. Your indemnification, your insurance certificate, your data-handling obligations, your breach-notification clause — all of them attach to a legal entity. "Sikich" is a brand covering at least four of them, and by their own published terms, they do not backstop each other.

This is not a scandal. Alternative practice structures are common, legal, and increasingly standard as private capital moves into accounting. Sikich took a $250 million minority growth investment from Bain Capital, announced May 9, 2024, while retaining majority control under CEO Christopher Geier. Outside capital cannot own an attest firm, which is precisely why the structure exists.

There is even a DIB-relevant upside buried in their acquisition history: Sikich acquired CliftonLarsonAllen's federal government practice in Washington, D.C. That is the most defense-relevant thing in their corporate record, and it isn't mentioned on their CMMC pages either.

One more detail we noticed, offered as an observation and not an accusation. The wording of this disclosure changed between May 2024 and December 2024. The May 2024 investment announcement described Sikich LLC providing personnel to Sikich CPA LLC. The current version reverses that framing and adds the non-liability sentence. Both versions are public, both are dated, and you can pull them yourself. If your legal team cares about which entity carries what — and it should — that evolution is worth ten minutes of their time.

The question to put in writing: Which legal entity will execute this SOW, and is it the same entity listed in the Cyber AB Marketplace?

Turn this into a document you can actually send

Get the contracting-entity check plus a printable, dated statement-of-work letter you can hand to any provider — not just Sikich. Free, no email required, and it never asks for CUI.

Build my Sikich due-diligence brief

[Sticky mobile CTA activates here: Find My CMMC Path]


The right CMMC provider isn't the same for every contractor — the category you need (a C3PAO, an RPO, an MSSP, a GRC platform, or a CUI enclave) depends on your required CMMC level, whether you handle FCI or CUI, your assessment type, your cloud and IT environment, and your contract timeline. The contract clause sets your level, not a checklist. Because a general answer can't resolve those for you, use The Defense Compliance Report's Find My CMMC Path tool to map your situation to the right provider category before you request quotes — and do not submit CUI, drawings, or sensitive contract details.


What we verified about Sikich — and what we couldn't

The strongest public facts about Sikich's CMMC practice are the RPO listing and the published STARS service descriptions. The largest gaps are pricing, methodology behind their timeline claim, and named CMMC customer outcomes. Those gaps are not disqualifying. They are the questions your discovery call needs to answer.

Here is the whole thing in one table. Every row is labeled by how it must be verified.

Buyer question What Sikich says or signals What we can support Evidence status Your action before signing — — — —
Buyer question What Sikich says or signals What we can support Evidence status Your action before signing
Is Sikich in the Cyber AB Marketplace?Not mentioned on any Sikich CMMC pageResearch locates Sikich LLC as RPO-60910Current-verification; recheck liveOpen the Catalog, confirm active status and entity, screenshot with date
Is Sikich a current C3PAO?No claim madeNo current C3PAO listing locatedNot verified — do not read absence as permanentSearch both Sikich LLC and Sikich CPA LLC on contract date; plan a separate assessor
What is STARS?Scope, Train, Assess, Remediate, SupportFramework exists and is described publiclyProvider-stated; outcomes not independently validatedRequest a sample project plan, deliverable list, RACI, and acceptance criteria per phase
Does "Assess" mean certification assessment?Public pages describe scoping, self-assessment scoring, gap analysisReadiness and internal assessment — not C3PAO authorityEditorial judgment from verified roleRequire the SOW to state whether each assessment is gap, mock, self, or formal
CUI scoping?Stated: define CUI scope, scope the CMMC enclaveProvider-stated current serviceProvider-statedDemand a boundary narrative, asset inventory by category, data-flow diagrams, ESP list, exclusions
SSP and POA&M?Stated: documents the SSP, develops POA&M remediation plansProvider-stated current serviceProvider-statedPut document ownership, editable formats, control-level evidence mapping, and handoff rights in the contract
Technical implementation?Pages reference remediation, penetration testing, policy development, Azure Government, managed ITBroader than documentation-only, but the CMMC-engagement boundary is not publicPartially supportedRequire a control-by-control RACI: what Sikich configures, what your MSP operates, what you own
Ongoing support?Stated: playbook, quarterly compliance reports, quarterly executive updates, annual IR training and testing, annual awareness training, optional subcontractor compliance reportsProvider-statedProvider-statedAsk for the recurring calendar, SLAs, evidence-refresh cadence, and annual affirmation support
Public CMMC pricing?None found on reviewed pagesNo Sikich-specific CMMC price locatedResearch boundary as of Aug 28, 2026Request an itemized quote; see the cost stack below
"Over three months faster"?Stated on the Exostar pageClaim located; no methodology foundProvider-stated onlyAsk for sample size, baseline, starting maturity, and what the clock stops on
Named CMMC case studies?None foundNo attributable Sikich CMMC case study with methodology locatedNot publicly substantiatedRequest two references matching your size, industry, and environment
Are the public pages current?Three CMMC assets, three different vintagesDocumented staleness — see the clause audit belowIndependently verifiedRequire the SOW to name the controlling rule and version
Which entity signs?Four entities under one brandFooter distinguishes them; RPO listing is Sikich LLCCurrent-verificationConfirm the exact contracting entity, insurance, and data obligations
Can a readiness firm also assess you?Buyers assume yes32 CFR prohibits it within three years — see belowPrimary-source verifiedPut the separate-C3PAO model in writing

What we found when we checked Sikich's regulatory references

We took every clause, rule, and regulatory statement on Sikich's three public CMMC assets and checked each one against the DFARS and FAR as they actually operate on August 28, 2026. Most hold up. Two do not. One of those matters enough to change your statement of work.

This is the part of the review that took the longest and the part no summarizer will get right, because it requires three separate checks that most people don't know to run.

The finding

Sikich's live CMMC service page lists, among the STARS deliverables:

"Perform DoW basic self-assessment"

That page's own metadata shows it was last modified April 6, 2026.

The standalone "Basic" self-assessment requirement was eliminated on February 1, 2026.

Why that happened, and why it's more complicated than an error

On February 1, 2026, thirty-eight DFARS class deviations took effect as part of the Revolutionary FAR Overhaul. Three of them matter to every DIB contractor:

  • DFARS 252.204-7019 — the provision that told you to perform a Basic NIST SP 800-171 self-assessment and have a current score on file before award — was eliminated.
  • DFARS 252.204-7020 was renumbered to DFARS 252.240-7997 under the new DFARS Part 240. All references to "Basic" assessments were stripped out. The revised clause now defines only Medium and High assessments, both performed by the government.
  • FAR 52.204-21 was renumbered to FAR 52.240-93, keeping the same title and the same fifteen basic safeguarding requirements.

DFARS 252.204-7012 and the CMMC clause, DFARS 252.204-7021, were untouched.

Now here's the wrinkle. None of this went through formal rulemaking. It happened by class deviation. Which means the codified regulation still shows the old numbers.

We checked. We loaded the DFARS clause index that Sikich links to from their own CMMC page. It is dated "Revised November 10, 2025," and it still lists 252.204-7019 and 252.204-7020 as live clauses with full text. Contracting officers are applying the deviations. The published regulation still shows the originals. Contractors are carrying two numbers for one requirement, and will until rulemaking catches up.

So Sikich is not sloppy against the Code of Federal Regulations. They are stale against what contracting officers are actually applying — and the source they cite would tell you they're right.

Does the work disappear? No, and this is important. You still assess yourself against NIST SP 800-171 Rev. 2. You still post a score in SPRS. What changed is that the obligation now lives inside CMMC under DFARS 252.204-7021, with a CMMC unique identifier and an annual affirmation from your affirming official, rather than as a parallel standalone requirement. The work survived. The label on the deliverable did not.

Ask Sikich to restate that deliverable in current clause terms. A firm that can do it in one sentence on a discovery call is a firm that's paying attention.

The full audit

What Sikich publishes Status as of August 28, 2026 Why it matters — —
What Sikich publishes Status as of August 28, 2026 Why it matters
"Perform DoW basic self-assessment" as a STARS deliverableSuperseded. DFARS 252.204-7019 eliminated; 252.204-7020 renumbered 252.240-7997, Feb 1, 2026The work still matters as a CMMC Level 1 or Level 2 self-assessment under 32 CFR §§ 170.15–170.16. The clause label no longer maps.
Link to DFARS 252.204-7012 at the acq.osd.mil DPAP mirrorLive and working — we loaded it — but dated "Revised November 10, 2025," pre-deviationCredit where due: a working primary-source link is more than most vendor pages offer. It's also the exact trap described above.
"Any prime or subcontractor that provides goods or services… will need to comply with the CMMC"Over-broad. 32 CFR § 170.3(c) applies CMMC where a contractor will process, store, or transmit FCI or CUI, above the micro-purchase threshold, and excludes contracts exclusively for COTS items. § 170.3(b) excludes federal information systems operated on the government's behalf.A commercially-available-off-the-shelf-only supplier reading that sentence could buy a program they don't need
"CMMC contrasts DFARS 252.204-7012 by forcing the requirement before award"Half-current. True for Level 1 (Self) and Level 2 (Self). The C3PAO-certification-before-award mechanism the sentence implies is exactly what July 13 suspended.The pre-award reality changed three months after this page was last touched
No mention of DFARS 252.204-7021 or 252.204-7025 anywhereBoth current, both NOV 2025 versionsThese are the two clauses that create the obligation being sold against. 7021 is the contract clause; 7025 is the solicitation provision requiring your CMMC unique identifiers in the proposal.
No mention of 32 CFR Part 170Controlling program rule since December 16, 2024Same point
"320 determination statements and 110 controls" in NIST SP 800-171 and 800-171AAccurateSay it plainly: this is a correct, specific, non-obvious technical detail. Someone competent wrote the original.
Global "DoD" → "DoW" rename applied across the pageReflects the Department of War secondary designationCredit them. Most vendor pages hadn't caught up in April. The find-and-replace also produced "DoW basic self-assessment," which is not a term of art in any rule — a tell that the page was renamed but not re-read against the regulation.

Run this test on every vendor you're considering

We're publishing the method because it's more valuable than the finding:

  1. Pull every clause number and rule citation off the vendor's page.
  2. Check each against acquisition.gov and the eCFR.
  3. Check whether a class deviation has moved or killed it — deviations don't show up in the CFR.
  4. Compare against the page's own last-modified date. In most content management systems it's in the page source as article:modified_time.

Ten minutes per vendor. It tells you more about whether a firm tracks the regulation than any capability deck will.

The version-drift trap you'll hit next

While you're at it, watch the Level 1 number. You will see vendor content — a lot of it, including material published in 2026 — describing CMMC Level 1 as 17 practices. Under the Final Rule at 32 CFR § 170.14, Level 1 consists of 15 security requirements, drawn from FAR 52.204-21 (now also numbered FAR 52.240-93).

Both numbers have a real history. The legacy CMMC model translated the 15 FAR safeguarding requirements into 17 CMMC practices, and a Department-hosted training deck says exactly that. But the legacy model is not the rule. 15 is what governs. If a vendor's collateral still says 17, it was written against the old model, and you should ask what else was.

Same discipline applies to the NIST revision. CMMC Level 2 maps to NIST SP 800-171 Revision 2 — 110 security requirements across 14 control families. DoD issued a class deviation to DFARS 252.204-7012 to hold Rev. 2 as the assessment standard until Rev. 3 is incorporated through future rulemaking. Any provider quoting you against Rev. 3 for CMMC purposes is ahead of the regulation, not ahead of the curve.

Run the same check on any vendor you're evaluating

Our CMMC Readiness Checklist maps all 110 requirements across the 14 control families, with the current clause numbers and the evidence an assessor actually asks for. Ungated. No email wall.

Download the CMMC Readiness Checklist


What's actually in the STARS program?

STARS is Sikich's five-phase CMMC readiness program: Scope, Train, Assess, Remediate, Support. Published deliverables include a CUI scoping document, training on the 110 requirements and 320 assessment objectives, a gap assessment, a POA&M, an SSP, and ongoing compliance support. Sikich states you can enter at a later phase if your program is already partly mature.

That entry-point flexibility is genuinely buyer-friendly and most firms don't offer it. If you've already done scoping and have a draft SSP, you shouldn't pay to redo it. Credit where it's earned.

Here's each phase, what Sikich publishes, and what you should convert it into before signing.

Scope

They publish: identify CUI, review data types and how data enters your systems, map people, technologies, and shared resources with business partners, then deliver a CMMC scoping document.

Turn it into: a written boundary narrative, an asset inventory sorted by CMMC asset category, CUI data-flow diagrams, a list of every External Service Provider and cloud service provider in scope, stated assumptions, multi-site treatment, and a defined scope-change procedure.

Scoping is where CMMC budgets are won or lost. An over-broad boundary can double your cost. An under-broad one fails you at assessment. This deliverable deserves more contract language than any other.

Train

They publish: remote training covering the 320 determination statements and 110 controls in NIST SP 800-171 and 800-171A, CUI classification, labeling and handling practices, and security awareness.

Turn it into: a syllabus, a role matrix, an attendance-evidence method, a stated frequency, and a named owner for the annual refresh.

Assess

They publish: review of NIST SP 800-171 controls through interviews, documentation review, and controls validation; testing to identify gaps; a remediation plan delivered inside Exostar's Certification Assistant rather than as a static PDF; and an executive presentation for the board and C-suite.

Turn it into: an explicit statement of the assessment type. Is it a gap analysis, a mock assessment, a self-assessment, or something else? Require mapping to all applicable assessment objectives, not just a summary score. And require the word "certification" to appear nowhere near it, because this is not that.

Remediate

They publish: a Plan of Action and Milestones, detailed gap-remediation recommendations, and system security and incident response plans. Their own description of the SSP is specific — scope, assessment outcome including score, status of the 110 controls, and steps to compliance — and correctly notes it's a living document.

Turn it into: a control-by-control work breakdown that names who implements each item. This is the single biggest gap between what a readiness proposal implies and what it delivers. "Recommendations" and "implementation" are different products at very different prices.

Support

They publish: a compliance and controls playbook, risk-remediation advisory, quarterly compliance reports, quarterly executive updates, annual incident-response training and testing, annual security awareness training, and optional subcontractor compliance reports.

Turn it into: a recurring-service calendar with SLAs, defined evidence-refresh cadence, incident obligations, and explicit support for the annual affirmation.

That subcontractor compliance reporting line deserves attention if you're a mid-tier prime. Under DFARS 252.204-7021(f), you must ensure subcontractors have the appropriate CMMC status before subcontract award, with flow-down governed by 32 CFR § 170.23. Note the carve-out: the flow-down excludes subcontracts exclusively for commercially available off-the-shelf items. If you're managing a supplier base, ask what that reporting actually contains and whether it's built for your tier count.


Who holds your evidence? The Exostar question

Sikich describes itself as a preferred Exostar partner and states that STARS remediation plans are delivered through Exostar's Certification Assistant — the platform that calculates your SPRS score and generates your System Security Plan and POA&M. That means the artifacts an assessor will eventually examine live in a third party's system, under a license somebody has to own.

We think this is underrated as a buying consideration, and we haven't seen anyone else raise it.

The chain runs: Sikich advises → Exostar's platform holds the artifacts → your SSP, POA&M, and SPRS score come out of it → your affirming official signs for all of it.

That last step never moves. Under DFARS 252.204-7021(d)(3), the annual affirmation of continuous compliance is made by your affirming official in SPRS. Under DFARS 252.204-7012(c), the 72-hour cyber incident report goes from you to dibnet.dod.mil. No consultant, no platform, and no managed service provider takes either of those off your desk.

Five questions to settle in the SOW:

Question Why it matters —
Question Why it matters
Who holds the Exostar license — you or Sikich?Determines whether you keep your evidence when the engagement ends
Can you export the SSP and POA&M in editable, usable formats?Evidence portability is the most-skipped clause in a readiness contract
Does anything in the platform process, store, or transmit CUI?If yes, 32 CFR § 170.19 scoping applies and it belongs in your SSP with a Customer Responsibility Matrix
Who signs the annual affirmation?Always you
Who files a 72-hour incident report?Always you

The same ESP question applies to Sikich itself. Sikich markets managed IT and security services with a 24/7 security operations center. That's not on their CMMC pages, but it's in their service catalog. If Sikich runs any part of your environment, they become an External Service Provider in your CMMC scope. That's a different conversation, a different set of contract terms, and a Customer Responsibility Matrix you'll need before an assessor asks for it.

One genuinely positive signal, and it's attributable: Sikich's governance, risk and compliance lead, Ken Squires, has appeared on Exostar's public CMMC webinars alongside an authorized C3PAO. Public practice engagement isn't a credential, but it's real, checkable, and more than most firms show.


Does any of this still matter after the July 2026 suspension?

Yes — and arguably more than before. The Department of War suspended Phase II on July 13, 2026, freezing the move to mandatory third-party certification. Phase I self-assessments, DFARS 252.204-7012, NIST SP 800-171 Rev. 2, SPRS postings, and annual affirmations all remain in force. The suspension paused the verification mechanism, not the security obligation.

Now the honest part.

What we have to tell you

Every public Sikich CMMC asset predates the suspension. Their main CMMC page was last modified April 6, 2026. The Exostar page, January 21, 2026. The STARS explainer article still carries language written for a 2023 interim rule that never arrived in that form. As of August 28, 2026, we searched and found nothing from Sikich addressing what changed on July 13.

Sikich CMMC asset Last modified Days before July 13, 2026 — —
Sikich CMMC asset Last modified Days before July 13, 2026
Exostar / STARS landing pageJanuary 21, 2026173
Main CMMC service pageApril 6, 202698
STARS explainer articleFebruary 19, 2025509

We'd rather you heard that from us than found it yourself after signing.

And here's why it shouldn't scare you off

Two reasons.

First, this is a market-wide problem, not a Sikich problem. We run this same check on every provider we profile, and almost nobody's marketing pages have caught up to a program that moved twice in seven months — once on February 1 with the clause renumbering, once on July 13 with the suspension. Sikich actually moved faster than most. They pushed the Department of War rename through in April while much of the field was still writing "DoD." Stale marketing copy is a signal about a marketing department. It is not a verdict on delivery quality.

Second — and this is the part that should change how you're thinking about your budget — the suspension made readiness work more important, not less.

Think about what got frozen. The C3PAO certification lane. What's left standing is the self-assessment lane, which is now the entire enforcement mechanism. And a self-assessment is not a lighter obligation. It's a heavier one, because the signature on it is yours.

The Department of Justice's Civil Cyber-Fraud Initiative did not pause. Defense contractors have continued to settle False Claims Act allegations over misrepresented cybersecurity compliance. An inflated SPRS score or an unsupported annual affirmation is legal exposure with or without a third-party assessor in the room.

So the work that matters right now is exactly the work a readiness firm does: honest scoping, a defensible SSP, a real POA&M, and evidence you could actually show someone. That is the whole ballgame during a suspension.

A firm shaped like Sikich is more relevant after July 13. They just haven't said so in public.

What's suspended and what isn't

Still in force Suspended —
Still in force Suspended
Phase I Level 1 (Self) and Level 2 (Self) requirementsThe November 10, 2026 Phase II transition
DFARS 252.204-7012 safeguarding and 72-hour reportingNew Level 2 (C3PAO) designations in solicitations
NIST SP 800-171 Rev. 2 — 110 requirements, 14 familiesNew Level 3 (DIBCAC) designations
SPRS score posting and annual affirmationsPhase 3 and Phase 4 milestones
Prime contractor flow-down obligations
DOJ False Claims Act exposure

During the suspension, program managers and requiring activities may designate only Level 1 (Self) or Level 2 (Self). For contracts that already carry Phase II requirements, contracting officers are directed to remove them by modification before the next option period or at the next scheduled administrative modification.

A CMMC Reform Task Force reporting to the Department of War CIO was given 60 days to deliver recommendations. The public request for information closed August 14, 2026. As of August 28, 2026, no report has been published. Expect it around mid-September.

If Sikich isn't your category, don't force it

Be honest with yourself about what you're actually buying. If you're a shop of 40 people with no internal IT and you need someone to hold the keys and run the environment, a national advisory firm is not your first hire — you need a CMMC-focused managed service provider. That's a different category with different economics.

Compare CMMC provider categories side by side See the small-business path


How much does Sikich CMMC consulting cost?

Sikich publishes no pricing for its CMMC or STARS services, and we found no credible third-party figure we're willing to repeat. That's normal for scoped professional services and it is not a red flag. It does mean any number you see attributed to Sikich online should be treated as unsourced until Sikich itself quotes you.

Let's kill one specific mistake before it costs you.

A directory minimum is not a CMMC price. Business-services directories list Sikich with a minimum project size in the low five figures. That number reflects Sikich's entire book of business — managed IT, ERP implementations, accounting work. It has nothing to do with a CMMC readiness engagement, and general star ratings across those services tell you nothing about CMMC delivery. Do not carry either into your budget or your board deck.

What we can give you instead is the structure that makes any two quotes comparable.

Normalize every quote into the same cost stack

Cost layer What it may include What to ask — —
Cost layer What it may include What to ask
Discovery and scopingInterviews, CUI boundary, asset inventory, data flowsFixed fee or hourly? Which sites and users are assumed?
Readiness assessmentObjective-level review, evidence examination, scoring, gap reportMapped to all assessment objectives or just requirements? Who owns the report?
DocumentationSSP, policies, procedures, POA&M, diagrams, RACICustom or template? Editable files? How many revision cycles?
Technical remediationIdentity, endpoint, logging, backup, network, encryption, FIPS-validated cryptographyWho configures? Which hours are included? What are the acceptance tests?
Cloud or enclave workMicrosoft 365 GCC High, Azure Government, or another architectureMigration, licensing, inherited controls, ongoing administration, shared responsibility matrix
Platform licensingExostar Certification Assistant or equivalentWho holds the license? Included or passed through? What happens at termination?
Ongoing supportProgram management, evidence refresh, training, incident supportCadence, SLA, minimum term, exit rights
Formal assessmentA separate C3PAO fee, when your contract requires itEntirely separate engagement and separate firm
Travel and onsiteFacility walkthroughs, manufacturing floor, multi-site discoveryRates, caps, approval process
Change ordersScope expansion, new systems, delayed client tasksWhat triggers one? At what rate? Written approval required?

One line worth flagging on Sikich's page specifically

Their published capability list includes "Azure Gov Cloud implementation." Azure Government is not Microsoft 365 GCC High. They are different environments with different CMMC and export-control implications, and for most DIB contractors handling CUI in email and files, GCC High or a CUI enclave is the relevant question.

GCC High is not named anywhere in Sikich's CMMC collateral that we reviewed. We are not saying they don't do it — we're saying we didn't find it, and if your CUI environment is the hard part of your problem, that's a direct question for the first call.

Ten quote red flags

  1. A fixed price with no defined scope
  2. "Certification guaranteed," in any wording
  3. Readiness and formal assessment bundled into one engagement
  4. Platform licensing buried inside a labor line
  5. Deliverables described only as "support compliance" or "prepare for CMMC"
  6. No named implementer for technical remediation
  7. No stated controlling rule version
  8. Urgency built on the suspended November 10, 2026 deadline
  9. No change-order trigger defined
  10. No evidence-export or exit-assistance terms

For context on the market as a whole: in announcing the suspension, the Department of War CIO cited Small Business Administration data suggesting future CMMC phases could cost small and mid-sized businesses more than $7 billion annually, with individual compliance bills approaching $600,000 — against a population of more than 100,000 companies needing assessments and roughly 100 authorized assessment organizations. Treat those as the Department's stated rationale for the pause, not as a per-company estimate for you.

Compare scoped work, not headline prices

A cheap readiness quote that excludes implementation, evidence, and sustainment costs more than an expensive one that names the work. Use the same scope brief with every provider you talk to.

Get matched with source-checked provider options for your level, scope, and timeline

Do not submit CUI or sensitive contract information.


Does the "over three months faster" claim hold up?

Sikich states on its Exostar page that its services shrink compliance timelines by over three months. We located the claim. We found no published methodology — no sample size, baseline, starting maturity, or definition of what the clock stops on. Treat it as a provider claim to investigate, not an expected result.

We want to be fair here, because the claim is not implausible. A structured five-phase program with a shared platform genuinely can remove coordination waste from a project that otherwise sprawls across a dozen email threads. The problem isn't that it couldn't be true. The problem is that you can't budget or schedule around a number you can't inspect.

Six questions make the claim evaluable:

  1. How many organizations were measured?
  2. What sizes and environments were in the sample?
  3. What was the starting maturity and initial SPRS score?
  4. What's the baseline — do-it-yourself, another consultant, or Sikich's own pre-STARS process?
  5. Where does the clock stop — readiness, assessment start, conditional status, or final certificate?
  6. What's the mean, the median, the range, and what was excluded?

Ask for those. Then, whatever the answer, put any promised milestone in the SOW with your own dependencies named — because the fastest way to blow a compliance timeline is a client team that can't produce evidence on schedule, and no consultant can fix that from the outside.

And do not pair this claim with a deadline that no longer exists. If a proposal ties three months of acceleration to the November 10, 2026 Phase II date, that's manufactured urgency built on a suspended milestone. Real urgency comes from your solicitation, your prime's flow-down, your active clause, and your actual gaps.


Who is Sikich right for — and who should look somewhere else?

Sikich fits a specific buyer: a mid-sized DIB contractor that needs structured scoping, documentation, remediation planning, and ongoing advisory support, and that values continuity with a firm it may already use for accounting or technology work. It fits poorly if you need someone to operate your IT, if you need a certificate, or if a public fixed price is a precondition.

Your situation Sikich fit Why Verify first — — —
Your situation Sikich fit Why Verify first
Mid-sized DIB manufacturer or supplier, some internal IT, weak CMMC governance and documentationPlausible shortlistSTARS maps directly to scoping, training, self-assessment, SSP, POA&M, and sustainmentManufacturing-floor scope, who implements technical controls, references at your size
Already a Sikich accounting, ERP, or IT clientPlausible shortlistContinuity and financial-controls fluency are real advantagesThat the CMMC team is not the same team you know; ask for named practitioners
Under \~50 people, no internal IT or security operatorConditional at bestAdjacent managed services exist, but the CMMC pages alone don't prove operational ownership24/7 coverage, endpoint and network ownership, SLAs, ESP scope, shared responsibility
Assessment-ready, need a formal Level 2 (C3PAO) assessmentWrong categoryNo C3PAO listing locatedEngage a separate authorized C3PAO
CUI environment is the hard part — GCC High, enclave, ITAR dataConditionalEnclave scoping and Azure Government are mentioned; GCC High is notArchitecture, licensing, inherited controls, export-control handling
Drowning in evidence tracking, want softwareWeaker fitThis is a consulting-led program, not a self-service productMinimum engagement, platform dependencies, deliverable ownership
Level 1, FCI only, capable internal teamOften more than you need15 requirements and an annual self-assessment may not justify a full readiness programConfirm your level from the contract clause first
Multi-site enterprise, complex governancePlausible but evidence-dependentFirm scale may genuinely helpNamed team, multi-site methodology, CMMC-specific references

Walk away from any provider — Sikich or otherwise — that won't put in writing: the contracting legal entity, current Cyber AB role, assigned delivery team, comparable references, controlling rule versions, named deliverables, the technical implementer, evidence ownership, exclusions, change-order triggers, and the separate-assessor plan.


Can Sikich prepare you and then assess you?

No, and this is a rule rather than a preference. 32 CFR Part 170 prohibits CMMC ecosystem members from participating in a Level 2 certification assessment for an organization they provided consulting to within the preceding three years. Readiness and formal assessment must be separate engagements, and in practice separate firms.

Buyers ask for one vendor end to end constantly. It's a reasonable instinct and it is not available here.

The clean sequence looks like this:

  1. Your contract determines the required level and assessment type. Not a checklist, not a vendor's opinion — the clause. DFARS 252.204-7025 is the solicitation provision where a contracting officer specifies Level 1 (Self), Level 2 (Self), Level 2 (C3PAO), or Level 3 (DIBCAC).
  2. A readiness provider scopes, assesses gaps, supports remediation, and organizes evidence.
  3. You reach a documented readiness gate — meaning you could survive an assessment, not that you feel ready.
  4. A separate authorized C3PAO performs the formal Level 2 assessment, when and if your contract requires one. Note that during the current suspension, new solicitations are not designating Level 2 (C3PAO).
  5. You maintain continuous compliance and file annual affirmations in SPRS.

Put the boundary in the contract explicitly: the engagement is advisory and readiness; it does not guarantee certification; you select the assessor; Sikich discloses potential conflicts; evidence ownership and transfer rights are yours; and the assessor reaches independent findings.

A firm that volunteers this boundary before you ask is telling you something good about how they work.


Eleven questions to put in a Sikich SOW before you sign

These are the questions our review left open. Sikich may have strong answers to every one — we're not positioned to know, because none of them are addressed in their published material.

  1. Which legal entity signs this SOW — Sikich LLC, a Sikich LLC subsidiary, or Sikich CPA LLC — and is it the entity in the Cyber AB Marketplace?
  2. What is your current Cyber AB status and identifier, and can you provide a dated screenshot of the live listing?
  3. Which named practitioners hold RP, RPA, CCP, or CCA credentials, and will they be on our engagement?
  4. Restate every deliverable in current clause terms. No "basic self-assessment" label.
  5. Who holds the Exostar license, and what happens to our artifacts at termination?
  6. Will Sikich process, store, or transmit any FCI or CUI? If yes, provide a Customer Responsibility Matrix for our SSP.
  7. Do you implement Microsoft 365 GCC High, or only Azure Government?
  8. Where does any AI-assisted analysis run, and what is the subprocessor list? (Sikich markets AI-enhanced risk analysis and reporting.)
  9. Confirm in writing that Sikich will not perform our formal CMMC assessment.
  10. What triggers a change order, and at what rate?
  11. What is the evidence export format and the exit-assistance term?

Print these. They work on any provider, not just this one. That's rather the point.


How we evaluated Sikich

We used a claim-by-claim method rather than a numeric score, because we have no basis for a score. Every consequential statement on this page is labeled as verified against a primary source, current-verified as of a date, provider-stated, or editorial judgment derived from verified facts.

What we did:

  • Read Sikich's three public CMMC assets on August 28, 2026 and recorded the last-modified date each page publishes in its own metadata
  • Checked every clause and rule reference on those pages against 32 CFR Part 170 in the eCFR, the DFARS text at acquisition.gov and the Department's DPAP mirror, and the February 2026 class deviations
  • Read DFARS 252.204-7012, 252.204-7019, 252.204-7020, 252.204-7021, and 252.204-7025 in full
  • Read the July 13, 2026 Department of War memoranda and the accompanying release
  • Reviewed the Cyber AB Marketplace record and the ecosystem role definitions
  • Reviewed secondary business-services directory listings, and declined to use their figures as CMMC pricing

What we did not do: hire Sikich, test any Sikich service, interview anyone at Sikich, receive documents from Sikich, audit customer outcomes, or accept anything of value from Sikich.

What we could not verify: we could not render and screenshot the Cyber AB Catalog listing directly, because it's a JavaScript application search engines don't index. We could not confirm Sikich's CMMC pricing, the methodology behind the timeline claim, whether Sikich offers Microsoft 365 GCC High, which specific Sikich entity delivers CMMC work, or any named CMMC customer outcome.

Compensation status: none, as of August 28, 2026.

What would upgrade this to a deeper review: a completed provider questionnaire, an on-the-record interview, a sample SOW and deliverable review, current pricing structure, named staff verification, published methodology for the timeline claim, and two or more customer-reference interviews.

Corrections: if you find an outdated status, a changed service, or a source we missed, send us the current primary source. We log material corrections and only update the last-verified date after rechecking the affected claim.


Sikich CMMC review: quick answers

Is Sikich an RPO? Our research locates Sikich LLC in the Cyber AB Marketplace as a Registered Provider Organization under identifier RPO-60910. RPO is the CMMC consulting and implementation role. Recheck the live Catalog before contracting, because Marketplace records change.

Is Sikich a C3PAO? We did not locate a current C3PAO listing for any Sikich entity as of August 28, 2026. Only an authorized or accredited C3PAO conducts the formal Level 2 certification assessment under 32 CFR § 170.9. Plan a separate assessor.

Can Sikich certify our company for CMMC? No. No consultant of any kind issues a CMMC certificate. Level 2 certification assessments are performed by authorized C3PAOs; Level 3 assessments are performed by DCMA DIBCAC.

What is the Sikich STARS program? STARS stands for Scope, Train, Assess, Remediate, Support. It's Sikich's five-phase CMMC readiness program covering CUI scoping, training, gap assessment, SSP and POA&M documentation, remediation planning, and ongoing compliance support.

Does "Assess" in STARS mean a certification assessment? No. Sikich's public descriptions refer to readiness assessment, gap analysis, self-assessment scoring, interviews, and documentation review. Require the SOW to state the assessment type explicitly.

How much does Sikich charge for CMMC? Sikich publishes no CMMC pricing on any page we reviewed. Directory minimums reflect Sikich's whole business, not a CMMC engagement. Request an itemized quote and normalize it against the cost stack above.

Does Sikich work with Exostar? Sikich describes itself as a preferred Exostar partner and states that STARS remediation plans are delivered through Exostar's Certification Assistant. Settle license ownership and evidence export rights in the contract.

Can our accounting firm also handle our CMMC compliance? It can do readiness work. It cannot perform your formal certification assessment. Under an alternative practice structure the attest firm and the advisory firm are separate legal entities, so confirm which one signs your SOW.

Do we still need CMMC work after the July 2026 suspension? Yes. Phase II is suspended; Phase I is not. Level 1 and Level 2 self-assessments, DFARS 252.204-7012, NIST SP 800-171 Rev. 2, SPRS postings, and annual affirmations remain in force, and False Claims Act exposure for inaccurate self-assessments is unchanged.

Which Sikich entity would sign our contract? Not published. At least four legal entities carry the Sikich name, and the Cyber AB listing we located is under Sikich LLC. Confirm the contracting entity in writing before signing.

Does Sikich do GCC High? Not found in the CMMC collateral we reviewed. Their published capability list names Azure Government, which is a different environment from Microsoft 365 GCC High. Ask directly if CUI in email and files is your problem.

Who signs our annual CMMC affirmation? You do. Under DFARS 252.204-7021(d)(3), your affirming official enters the annual affirmation of continuous compliance in SPRS. No consultant, platform, or managed service provider takes that on.


Need help deciding what type of CMMC provider you need?

Tell us your level, scope, and timeline, and we'll match you with source-checked CMMC provider options.

Find My CMMC Path

⚠️ Do not submit CUI, drawings, export-controlled information, credentials, or sensitive contract details.


Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification. We have no compensation relationship with Sikich as of August 28, 2026.

Not advice. This article is educational research on CMMC and DIB compliance. It is not legal, contractual, or compliance advice. Your required CMMC level is set by your contract clause and the information you handle, not by a checklist or an article. Confirm scope and applicability with a CMMC Registered Practitioner (RP) or Registered Provider Organization (RPO), or with a qualified federal-contracts attorney.

Primary sources: 32 CFR Part 170 (eCFR) · DFARS 252.204-7012, 252.204-7021, 252.204-7025, 252.240-7997 (acquisition.gov) · FAR 52.204-21 / 52.240-93 · NIST SP 800-171 Rev. 2 and NIST SP 800-171A (NIST CSRC) · Department of War CMMC Phase II suspension memoranda and release, July 13, 2026 · DODIG-2025-056 · Cyber AB Marketplace · SPRS.