Forvis Mazars Earned C3PAO Accreditation

The firm is now authorized to conduct official CMMC Level 2 cybersecurity assessments for defense contractors.

Updated on Sept. 21, 2026 in Cybersecurity

Bold flat-color editorial illustration of a monolithic angular gateway in deep red and cream, representing institutional cybersecurity compliance standards.
Forvis Mazars has earned its C3PAO accreditation, authorizing the firm to conduct official CMMC Level 2 cybersecurity assessments for United States defense contractors. AI Illustration. Upload story photo >

Live Poll

Should defense contractors be required to meet strict third-party cybersecurity standards?

Forvis Mazars LLP has officially earned its accreditation as a Certified Third-Party Assessment Organization (C3PAO). This status authorizes the firm to perform CMMC Level 2 assessments for entities within the United States defense industrial base.

Why it matters

This accreditation enables the firm to help defense contractors navigate complex federal security and compliance requirements. It supports broader government objectives to strengthen cybersecurity standards across the industrial base.

The firm is authorized to conduct CMMC Level 2 assessments and issue Certificates of CMMC Status. This follows the firm completing the rigorous ISO/IEC 17020 accreditation process.

The players

Forvis Mazars LLP

This is a professional services firm that provides audit, tax, and consulting services to a variety of industries.

The details

By meeting these professional standards, Forvis Mazars can now issue formal certification to contractors seeking to comply with Department of Defense security regulations. The firm previously held authorized C3PAO status, allowing it to continue serving the defense sector.

Timeline

  1. September 21, 2026: Forvis Mazars earned C3PAO accreditation.

The Tech Race

This accreditation follows the requirements established by the Cybersecurity Maturity Model Certification framework to ensure third-party verification of security standards. It marks a shift toward standardized, expert-led compliance vetting for sensitive defense supply chain partners.

Defense contractors can now engage Forvis Mazars to obtain the necessary CMMC Level 2 certifications required to maintain their federal eligibility. This provides companies with a verified pathway to meet stringent government cybersecurity mandates.

The takeaway

Entities seeking defense contracts must ensure their cybersecurity posture meets the evolving CMMC standards to remain competitive. Partnering with accredited assessors is a critical step for organizations to avoid potential disruptions in their government business.

Further reading

Learn more about the latest updates in Cybersecurity regarding federal compliance standards.

More information

Review the full scope of CMMC readiness and certification services on the firm website.

Source note: This article includes information reported by CPA Practice Advisor.

Live Poll

Should defense contractors be required to meet strict third-party cybersecurity standards?