In a significant development for the defense contracting industry, the Department of War announced in July 2026 the suspension of Phase II of its Cybersecurity Maturity Model Certification (CMMC) program. This program, originally slated to require over 100,000 defense contractors to undergo costly third-party cybersecurity assessments beginning in November of the same year, has been indefinitely postponed. The decision, attributed to the program’s own logistical and financial burdens, including projected compliance costs nearing $600,000 per organization and a critical scarcity of qualified assessors, serves as a potent reminder for other sectors, particularly accounting firms, about the persistent nature of cybersecurity risks.
While accounting and tax firms are not directly subject to the CMMC mandate, the underlying principles and the implications of this delay warrant close examination by any professional advising clients on compliance and risk management. The suspension of a federal deadline can create a tempting, albeit potentially hazardous, perception of leniency. However, for firms entrusted with sensitive client financial and tax records, this instinct to delay related security initiatives is one that should be actively resisted. Regulatory obligations under frameworks such as the FTC Safeguards Rule and the Gramm-Leach-Bliley Act (GLBA) remain in full effect, irrespective of shifts in unrelated program timelines. Moreover, the high-value nature of client financial data as a target for cybercriminals has not diminished in the slightest, regardless of developments within the defense sector.
The Deeper Implications of Program Suspension
The suspension of the CMMC program’s Phase II is not an isolated incident in the realm of federal compliance. Government-led regulatory initiatives are subject to revision, delay, or outright cancellation with a degree of regularity. However, the underlying risks that these programs are designed to mitigate rarely experience a similar ebb in intensity. For accounting and finance professionals who manage client data encompassing confidential tax records, intricate banking details, and sensitive payroll information, a robust, documented, and consistently enforced cybersecurity policy transcends being a mere regulatory checkbox. It has evolved into a baseline expectation that clients increasingly assume is already firmly in place.

Firms that approach cybersecurity policy as an integrated, ongoing practice, rather than a reactive measure to an impending compliance deadline, are far better positioned to proactively identify vulnerabilities before they manifest as critical security incidents. This proactive stance becomes particularly crucial during peak periods, such as tax filing season, when the volume of client data processed is at its highest, and any disruption or downtime carries the most significant financial and reputational costs.
Navigating the Cybersecurity Landscape: A Proactive Approach for Firms
The CMMC situation underscores a broader trend: regulatory landscapes shift, but the fundamental threat landscape remains dynamic and often escalates. For accounting firms, this necessitates a strategic and forward-thinking approach to cybersecurity.
Key Considerations for Firms:
- Risk Assessment and Mitigation: Regularly conduct comprehensive risk assessments to identify potential vulnerabilities in systems, processes, and third-party vendor relationships. This includes evaluating the security of cloud services, remote access solutions, and any software used to manage client data.
- Data Encryption and Access Controls: Implement strong encryption for data both in transit and at rest. Enforce granular access controls, ensuring that employees only have access to the information necessary for their job functions. This principle of least privilege is fundamental to minimizing the impact of a potential breach.
- Employee Training and Awareness: Human error remains a leading cause of data breaches. Regular, comprehensive cybersecurity awareness training for all staff is paramount. This training should cover phishing detection, secure password practices, social engineering tactics, and the proper handling of sensitive client information.
- Incident Response Planning: Develop and regularly test a formal incident response plan. This plan should clearly outline the steps to be taken in the event of a security breach, including identification, containment, eradication, recovery, and post-incident analysis. Prompt and effective response can significantly mitigate damage.
- Vendor Management: Thoroughly vet all third-party vendors who have access to client data or systems. Ensure they have robust security practices in place and that contractual agreements clearly define security responsibilities and data protection measures.
Addressing Common Concerns: A Q&A for Accounting Professionals
The CMMC suspension has naturally prompted questions within the accounting community. Understanding these concerns and their implications is vital for maintaining client trust and regulatory adherence.

Why does a defense-sector suspension matter to accounting firms?
The CMMC program’s delay offers a valuable case study. It illustrates how regulatory timelines can shift while the underlying cybersecurity risks to sensitive data remain constant. For accounting firms, this is a stark reminder that their obligations under regulations like GLBA and the FTC Safeguards Rule, which are designed to protect consumer financial information, are not contingent on the timelines of unrelated programs. These rules are active and enforceable, regardless of what happens in the defense industry.
We’re a small or mid-sized firm. Are we really a target?
Absolutely. Attackers often view smaller and mid-sized firms as particularly attractive targets precisely because they may operate under the assumption that such entities have fewer resources dedicated to cybersecurity, and therefore, potentially weaker defenses. The resale value of compromised client financial data on the dark web is substantial, regardless of the size of the firm from which it was obtained. Therefore, firm size is not a shield against cyber threats.

Do we need a formal Written Information Security Program (WISP) if no client has asked for one yet?
Yes, it is highly advisable to have a formal WISP in place. This is not merely a matter of client accommodation but a fundamental regulatory expectation under rules like the FTC Safeguards Rule. Having a WISP proactively demonstrates a commitment to data security and compliance. It avoids the chaotic scramble to produce documentation under pressure, which often occurs when a client, insurer, or regulator requests it unexpectedly. A well-defined WISP provides a structured framework for your firm’s security practices.
What’s the realistic cost of getting this wrong?
The repercussions of a cybersecurity failure extend far beyond potential regulatory fines. A data breach can severely disrupt a firm’s operations, especially during its busiest periods, leading to lost revenue and client dissatisfaction. Perhaps more critically, such incidents can cause irreparable damage to the trust clients place in a firm to safeguard their most sensitive financial information. Rebuilding that trust can be an arduous and sometimes impossible task. The reputational damage alone can have long-term, detrimental effects on a firm’s viability.

The Enduring Imperative: Security as a Continuous Practice
The suspension of Phase II of the CMMC program highlights a critical distinction: federal mandates may pause, but the inherent risks to client financial data and the regulatory expectations for protecting that data do not. Firms that proactively invest in and maintain a documented, robust security policy, prior to any demand from a client, insurer, or examiner, are demonstrably better positioned to uphold the reliability and trustworthiness that their clients depend on.
The landscape of cybersecurity is constantly evolving, with threat actors employing increasingly sophisticated tactics. For accounting firms, this means that cybersecurity cannot be a static set of procedures but rather a dynamic, continuously improving practice. It requires ongoing vigilance, adaptation, and a commitment to staying ahead of emerging threats.
Scott Carr, owner of Farmhouse Networking, a firm specializing in IT services for businesses including accounting and finance, emphasizes this point. With over 30 years of experience in Network & Computer Systems Architecture, Carr notes, "The core lesson from events like the CMMC suspension is that underlying risks don’t disappear just because a specific regulation’s timeline shifts. Client data is a prime target, and firms have a fiduciary duty to protect it. Proactive, managed IT security isn’t a luxury; it’s a fundamental necessity for maintaining client confidence and operational resilience."
Firms that treat cybersecurity as an integral component of their business operations, rather than an ancillary compliance burden, are not only mitigating risk but also building a stronger, more resilient foundation for future growth and client relationships. The digital world demands constant adaptation, and for firms handling financial data, that adaptation must prioritize security above all else. The lessons from the CMMC postponement are clear: prepare for the risk, not just the regulation.








