loading min read

CohnReznick earns reauthorization of CMMC Third-Party Assessment Organization (C3PAO) designation

Discover how CohnReznick’s renewed C3PAO status empowers DoD contractors to meet CMMC compliance under the new rule effective December 2024.

The Department of Defense (DoD) has officially published the CMMC final rule, effective Dec. 16, 2024. Read what this could mean for your organization (Opens a new window) and next steps to take.

New York, NY — June 27, 2025 — CohnReznick, LLP, one of the leading professional services firms in the United States, announced that on May, 2025, it was reauthorized by the Cybersecurity Maturity Model Certification (CMMC) accreditation body (Cyber AB) as a CMMC Third-Party Assessment Organization (C3PAO). The designation allows CohnReznick to assess Department of Defense (DoD) contractors seeking CMMC compliance under the joint surveillance voluntary assessment program or as soon as the CMMC rule is finalized.

New Image

“CohnReznick is excited to continue playing a critical role within the CMMC ecosystem in protecting our nation against cybersecurity threats from adversaries. We look forward to working with the Defense Industrial Base companies to conduct assessments and helping them become CMMC compliant,” said Bhavesh Vadhani, Global Leader of CohnReznick’s Cybersecurity, Technology Risk, and Privacy Practice and a Lead CCA. “

CohnReznick is also a certified CMMC Registered Provider Organization (RPO), which acknowledges that CohnReznick is familiar with the basic constructs of the CMMC Standard and delivers non-certified CMMC consulting services. As an RPO, CohnReznick can guide and prepare organizations for CMMC compliance.

“CohnReznick has a 40-year history of serving the government contracting community,” said Kristen Soles, CohnReznick Government Contracting Practice Leader. “This prestigious designation places CohnReznick among only 71 available C3PAO providers in the nation authorized to conduct CMMC assessments of government contractors seeking to provide services to the Department of Defense (DoD). We are pleased to further commit to serving defense contractors by adding CMMC compliance to our suite of advisory services for government contractors.”

It's important to note that the Cybersecurity Maturity Model Certification (CMMC) is required for any organizations that are part of the Defense Industrial Base. CMMC will apply to organizations of all sizes in the supply chain and manufacturing. Information technology, engineering, consulting, and universities.

About The Cyber AB

The CMMC Accreditation Body, Inc., is a private, independent, Maryland-based, nonprofit, 501(c)(3) tax-exempt organization that serves as the sole official partner of the Department of Defense, via contract, for the implementation, accreditation, and oversight of the CMMC Ecosystem and its support to the Defense Industrial Base.

Related services

Our solutions are tailored to each client’s strategic business drivers, technologies, corporate structure, and culture.

Receive CohnReznick insights and event invitations on topics relevant to your business and role.
Subscribe

"CohnReznick" is the brand name under which CohnReznick LLP and CohnReznick Advisory LLC and their respective subsidiaries provide professional services. CohnReznick LLP and CohnReznick Advisory LLC (and their respective subsidiaries) practice in an alternative practice structure in accordance with the AICPA Code of Professional Conduct and applicable law, regulations, and professional standards. CohnReznick LLP is a licensed CPA firm that provides attest services to its clients. CohnReznick Advisory LLC provides tax and business consulting services to its clients. CohnReznick Advisory LLC and its subsidiaries are not licensed CPA firms.

member of nexia

CohnReznick is a member of Nexia, a leading, global network of independent accounting and consulting firms. Please see the “Member firm disclaimer (Opens a new window)” for further details.

© 2026 CohnReznick Advisory LLC, All Rights Reserved.