Forvis Mazars earns accreditation as CMMC C3PAO

via GlobeNewswire
ⓘ This article is third-party content and does not represent the views of this site. We make no guarantees regarding its accuracy or completeness.

TYSONS, Va., Sept. 21, 2026 (GLOBE NEWSWIRE) -- Forvis Mazars LLP, one of the largest public accounting and consulting firms in the United States, has earned accreditation as a Certified Third-Party Assessment Organization (C3PAO). The firm is one of the first organizations nationwide to earn the designation, which is the premiere status for third-party assessment organizations in the Cybersecurity Maturity Model Certification (CMMC) program.

A C3PAO is an independent organization authorized to conduct CMMC assessments for companies in the U.S. defense industrial base seeking Level 2 certification.

Forvis Mazars joins a highly select group formally accredited under ISO/IEC 17020, which sets requirements for the competence, impartiality, and consistency of inspection bodies. As an accredited C3PAO, Forvis Mazars has met the final set of requirements needed to conduct CMMC Level 2 certification assessments and issue Certificates of CMMC Status, helping verify that defense contractors have implemented cybersecurity requirements designed to protect Controlled Unclassified Information (CUI).

The firm has consistently been at the forefront of this rigorous process, as it was previously one of the earliest and largest organizations to achieve authorized C3PAO status.

“Achieving C3PAO accreditation represents a significant milestone for our firm and reinforces our commitment to supporting the cybersecurity objectives of the federal government,” said Tom Tollerton, global CMMC practice leader at Forvis Mazars. “This accomplishment reflects the dedication and leadership of our entire C3PAO team and strengthens our ability to serve contractors navigating increasingly complex security and compliance requirements.”

The CMMC framework was developed by the U.S. Department of War to verify that organizations handling Federal Contract Information (FCI) and CUI maintain cybersecurity practices appropriate to the sensitivity of the information they manage.

As CMMC requirements continue to be incorporated into defense contracts, organizations throughout the defense supply chain are preparing for certification assessments that may be required for contract eligibility.

“Protecting sensitive government information is a matter of national importance,” said Paul Truitt, principal and IT Risk and Compliance national leader. “Our accreditation reflects the investment we’ve made in technical capabilities, regulatory knowledge, and quality assurance processes. We are proud to help organizations strengthen cyber resilience while supporting the security objectives of the defense ecosystem.”

Forvis Mazars has served clients across highly regulated industries for decades, providing cybersecurity, risk management, compliance, assurance, and advisory services. The firm’s CMMC capabilities build upon its broader experience helping organizations address complex security, governance, and regulatory challenges.

Organizations interested in learning more about CMMC readiness, certification requirements, or assessment services can visit forvismazars.us/it-risk-compliance.

About Forvis Mazars

Forvis Mazars, LLP is an independent member of Forvis Mazars Global, a leading global professional services network. Ranked among the largest public accounting firms in the United States, the firm’s 7,000 dedicated team members provide an Unmatched Client Experience® through the delivery of assurance, tax, and consulting services for clients in all 50 states and internationally through the global network. Visit forvismazars.us to learn more.

Contact:
Mike Brothers, PR Manager
mike.brothers@us.forvismazars.com


Primary Logo

Report this content

If you believe this article contains misleading, harmful, or spam content, please let us know.

Report this article