News release

The Cyber AB Names RSM an Authorized Cybersecurity Maturity Model Certification (CMMC) Third-Party Assessment Organization (C3PAO)

RSM is Now the Largest C3PAO in the CMMC Ecosystem

November 09, 2022

Kimberly Bartok, Enterprise Public Relations Leader, kim.bartok@rsmus.com, 212.372.1239
Andreia DeVries, Enterprise Public Relations Manager, andreia.devries@rsmus.com, 919.645.6821
for media use only 

The Cyber AB Names RSM an Authorized Cybersecurity Maturity Model Certification (CMMC) Third-Party Assessment Organization (C3PAO)

RSM is Now the Largest C3PAO in the CMMC Ecosystem

CHICAGO – (November 9, 2022) – RSM US LLP (“RSM”) – the nation’s leading provider of audit, tax and consulting services focused on the middle market – was recently authorized as a Cybersecurity Maturity Model Certification (CMMC) Third-Party Assessment Organization (C3PAO) by The Cyber AB. The Cyber AB is the official accreditation body of the CMMC Ecosystem and the sole authorized non-governmental partner of the U.S. Department of Defense (DOD) in implementing and overseeing the CMMC conformance regime. With this authorization, RSM is the largest C3PAO in the CMMC Ecosystem.

The C3PAO designation authorizes RSM to provide consulting and examination services to contractors within the Defense Industrial Base (DIB). A C3PAO is an organization that has passed a rigorous series of requirements to become acknowledged by The Cyber AB, on behalf of the DOD, as being objective and competent to perform assessments, consulting and remediation of Organizations Seeking Certifications (OSC). The designation also certifies that RSM has built a secure environment to maintain its clients’ Controlled Unclassified Information (CUI) in accordance with the DOD’s and The Cyber AB’s expectations.

As an authorized C3PAO, RSM is one of a few firms currently approved to provide surveillance examinations of OSCs in collaboration with the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) during the interim rulemaking process.  

“I am immensely proud of our government contracting cybersecurity & privacy team for achieving this authorization,” said Dara Castle, Washington DC metro area managing partner and national government contracting leader with RSM US LLP. “As a C3PAO we are able to help our defense industrial base clients safeguard sensitive national security information while they execute their critical mission objectives. This designation also enables us to help other clients, key groups and organizations, and aligns with our commitment to serving the Federal government contracting and grant recipient community.”

“This designation underscores how we’ve developed a practice specially-trained to provide the depth and breadth of federal cyber risk services to help protect our nation’s sensitive unclassified data and critical infrastructure,” said Charles Barley Jr., principal and national government contracting security and privacy risk leader with RSM US LLP.

For more information about RSM’s cybersecurity services, visit our website.


About RSM US LLP

RSM empowers middle market companies worldwide to take charge of change. The clients we serve are the engine of global commerce and economic growth. Our unique middle market perspective makes RSM the natural choice for growth-oriented, internationally active organizations seeking relevant insights and tailored, innovative solutions for a complex and changing world. With a global reach spanning more than 120 countries, we instill confidence in a world of change by bringing the full power of RSM to make a lasting impact on our clients, colleagues and communities. For more information, visit rsmus.com, like us on Facebook, follow us on X and/or connect with us on LinkedIn.

"