CMMC Compliance Services for Professional Services Firms
Consulting, engineering, accounting, and advisory firms often touch defense-related work without operating like a typical defense contractor. A subcontract for financial modeling, engineering support, or program management can still carry a DFARS 252.204-7012 clause, and once it does, the same NIST SP 800-171 requirements bind your firm as they would any manufacturer or systems integrator in the defense industrial base. We help professional services firms figure out exactly what that clause requires of them and build a compliance program that fits how consulting and advisory work operates.
The Certification Timeline Moved. Your Contract Obligations Didn't.
The Department of War suspended CMMC Phase 2 on July 13, 2026, while a Reform Task Force reconsiders how the program should work. Third-party certification is on hold as a result. What hasn't changed is Phase 1: self-assessment obligations remain active, and any professional services contract that references DFARS 252.204-7012 or NIST SP 800-171 Rev 2 still binds you to those standards today.
Professional services firms often discover their exposure later than other contractors because the work doesn't look like defense work on its face. A cybersecurity assessment, a supply chain analysis, or an engineering study your firm delivers to a defense client can still involve CUI, and the compliance clock doesn't wait for a firm to notice.
Compliance Across How Your Firm Works
Turning a Contract Requirement Into an Operating Standard
Recognizing When It's Time to Act
The signal to start usually isn't a calendar date. It's a new engagement letter with unfamiliar clauses, a client mentioning CMMC in a proposal request, or a prime contractor asking about your security posture before extending a subcontract. Any of these should trigger a review, regardless of where Phase 2 stands federally.
If your firm has active or pending work referencing DFARS 252.204-7012, or if you're uncertain whether a past or current engagement already put you in scope, that uncertainty itself is worth resolving now rather than during a client audit.
What Professional Services Firms Ask About CMMC
Our firm doesn't think of itself as a defense contractor. Could we still be in scope?
Yes, and this is one of the most common blind spots. If a contract or subcontract you've signed includes DFARS 252.204-7012, you're in scope regardless of your firm's industry classification or self-perception.
With Phase 2 suspended, is there any urgency to deal with this now?
Yes. Phase 1 self-assessment requirements are currently active, and they don't depend on Phase 2's status. Your contractual obligation exists independently of the certification timeline.
How do we figure out if a past engagement already exposed us?
Start by reviewing the contract language on any defense-related work your firm has performed. If DFARS 252.204-7012 or NIST SP 800-171 appears anywhere in that agreement, that engagement likely brought you into scope.
What counts as CUI in a professional services context?
It depends on the engagement, but it can include technical data, program information, or sensitive analysis your firm prepares for a defense client, even if your firm never touches a classified system directly.
Is self-assessment enough right now, or do we need third-party certification?
Self-assessment is the current active requirement under Phase 1. Phase 2 was scheduled to make third-party certification through a C3PAO mandatory, and that requirement is on hold.
We use cloud-based project management tools across all our clients. Does that complicate things?
It can, since those platforms often hold data from multiple clients and engagements. We assess whether and how CUI moves through your shared tools and whether segmentation or access controls need adjustment.
How long does it take to determine our scope and close any gaps?
It depends on how many engagements and systems the review covers and how clearly your existing contracts document their requirements. We provide a timeline once we've reviewed your specific situation.
Do subcontracted consultants or contract staff we bring in affect our compliance?
Yes. Anyone with access to CUI through your firm, whether a full-time employee or a subcontracted specialist, falls within the scope of your assessment.
What happens if a gap turns up during a self-assessment?
It goes into a Plan of Action and Milestones with a defined remediation timeline. Whether you have a hard deadline to close it depends on what your specific contract requires.
Can we still bid on defense-related work while Phase 2 is paused?
In many cases, yes, since Phase 1 requirements are what currently apply to new solicitations. Check the specific solicitation language, since requirements vary by contract.
What should we pull together before a compliance review?
Copies of any contracts or subcontracts with defense-related language, a list of engagements that might involve CUI, and a point of contact who understands both your client relationships and your IT setup.
How do you keep our compliance approach current as the program changes?
We track Reform Task Force recommendations and DoW guidance as they're released and adjust your plan accordingly, so you're never working from an outdated assumption about what's required.