Forvis Mazars Earned C3PAO Accreditation

The firm is now authorized to issue CMMC Level 2 certification assessments for U.S. defense contractors.

Updated on Sept. 21, 2026 in Cybersecurity

Bold flat-color editorial illustration of a heavy industrial steel hinge, representing institutional security and compliance standards.
Forvis Mazars has been accredited as a Certified Third-Party Assessment Organization, authorizing the firm to conduct official CMMC Level 2 audits for U.S. defense contractors. AI Illustration. Upload story photo >

Live Poll

Should defense contractors be required to meet strict third-party cybersecurity standards?

Forvis Mazars LLP has secured accreditation as a Certified Third-Party Assessment Organization (C3PAO). This status empowers the firm to conduct official CMMC Level 2 assessments for the U.S. defense industrial base.

Why it matters

This accreditation enables the firm to provide mandatory cybersecurity validation for defense contractors, supporting federal compliance objectives. It helps organizations navigate the stringent requirements necessary to secure Department of Defense contracts.

The firm successfully completed the ISO/IEC 17020 accreditation process, a standard for the competence of bodies performing inspection. This allows Forvis Mazars to officially issue Certificates of CMMC Status to entities within the defense industrial base.

The players

Forvis Mazars LLP

A professional services firm providing accounting, tax, and IT risk compliance services to businesses.

The details

As a C3PAO, Forvis Mazars performs independent audits against the Cybersecurity Maturity Model Certification (CMMC) Level 2 framework, which dictates how defense contractors handle sensitive federal information. The ISO/IEC 17020 standard ensures that the assessment body maintains technical competence and operational impartiality during the certification process.

Timeline

  1. September 21, 2026: Forvis Mazars earned C3PAO accreditation.

The Tech Race

This accreditation aligns with the federal government's broader mandate to secure the defense supply chain through standardized cybersecurity oversight. It positions the firm within the competitive tier of authorized assessors required to clear the national defense industrial base for secure contract operations.

Defense contractors requiring CMMC Level 2 certification can now engage Forvis Mazars to conduct their mandatory compliance assessments. Organizations should use these services to ensure they meet the security prerequisites required for federal contract eligibility.

The takeaway

This certification allows Forvis Mazars to serve as a gatekeeper for federal defense compliance. Contractors should review their current cybersecurity posture to determine if they require a CMMC assessment before their next contract renewal cycle.

Further reading

For additional context on the regulatory landscape, visit the Cybersecurity section.

More information

Learn more about these audit offerings on the CMMC readiness and certification services portal.

Source note: This article includes information reported by CPA Practice Advisor.

Live Poll

Should defense contractors be required to meet strict third-party cybersecurity standards?