Construction risk management services

When risks aren’t managed consistently, growth stalls and profits suffer. Wipfli helps construction leaders identify vulnerabilities and implement practical solutions for long-term stability.

Explore our services

Insights and resources

  • A mature architect smiling while using a computer at his desk in a brightly lit office

    ARTICLE

    General contractors can no longer bid on DoD jobs without CMMC compliance. That’s a big opportunity.

    Contractors and other vendors who work with the Department of Defense must now meet the Cybersecurity Maturity Model Certification (CMMC) 2.0 standards to be eligible to bid on new DoD contracts. CMMC 2.0, which is a cybersecurity framework aimed at protecting controlled unclassified information (CUI), kicked off a three-year, four-phase rollout after the final rule took effect on November 10, 2025. The rule requires compliance with specific, tiered cybersecurity standards (self-assessments or third-party certifications) to be listed in the Supplier Performance Risk System (SPRS) — and meeting those standards is a complicated process. However, because many construction firms may forgo DoD bids rather than become CMMC compliant, companies that do achieve compliance will face limited competition for contracts. Keep reading to learn more about how CMMC works and how to make your compliance journey simpler and more effective. CMMC 2.0 cybersecurity compliance is mandatory for all new DoD contracts All new DoD contracts contain a clause requiring the vendor to certify compliance with CMMC 2.0 cybersecurity rules. However, because CMMC is taking effect in phases, the specific requirements you’ll need to meet will evolve over time : During the first implementation phase, which lasts through November 9, 2026, you can certify compliance by doing a self-assessment and attesting that your business meets CMMC standards. During the next three phases of the CMMC rollout, which kick in at one-year intervals beginning November 10, 2026, you will also be required to complete an external CMMC assessment conducted by a certified third-party assessor organization (C3PAO) to bid on many jobs. CMMC compliance is typically assessed at the time of contract award, not when work actually begins, which means there is real urgency here for contractors, as achieving compliance doesn’t happen overnight. You should also note that contractors are also responsible for ensuring that any subcontractors they share CUI with also meet CMMC standards. There’s also a major risk management element to consider here. At any point, you can be audited on your compliance — and if you don’t meet CMMC standards, you may be subject to substantial fines under the False Claims Act. CMMC-compliant contractors now face less competition for DoD jobs Many contractors are opting to forgo DoD bids, at least for now, rather than take the steps to become CMMC compliant. This makes DoD contracts less competitive than in years past, which means that construction firms that make the upfront investment in compliance now will have an easier time winning DoD bids. In other words, there’s actually a huge opportunity here for firms willing to adjust. And it’s likely one that will only continue to grow, as more federal agencies will likely roll out similar cybersecurity requirements in the coming years. Contractors that make the leap now will have a head start on their competitors and the potential to grow their federal contracting business while slower-moving peers are still just trying to understand this new regulatory environment. How can your construction firm achieve CMMC certification? Don’t try to tackle CMMC certification on your own. The rules are too dense and intricate for non-experts to implement — to the point that you risk failing a DoD audit because you don’t realize that your good-faith internal compliance effort doesn’t even come close to meeting standards. Instead, work with a registered provider organization (RPO) to bring your business into compliance. What is an RPO? An RPO is an advisory firm that specializes in helping companies meet CMMC compliance standards. An RPO can help you prepare to complete both a Phase 1 self-assessment and the third-party external assessment required for many jobs starting in Phase 2. What does an RPO actually do? An RPO will assess your current cybersecurity capabilities, identify gaps, and make recommendations for areas that need improvement. Advisors from your RPO will also work with your team to actually implement changes needed to bring your business into CMMC 2.0 compliance. How do you choose the right RPO? Do your due diligence when choosing an RPO. An RPO that understands CMMC compliance but doesn’t know the construction business can harm your firm by implementing compliance in a way that significantly interferes with your work. Look for an RPO with deep experience in federal regulatory compliance, cybersecurity and construction. What are the major challenges for construction firms when implementing CMMC? CMMC rules apply to all DoD vendors and supply chain companies, not just construction firms. But contractors face additional challenges when implementing CMMC, including not just change management and culture shock, but practical questions about how you can maintain compliance while sharing CUI among contractors, subcontractors and workers in the field. The right RPO can help you navigate these waters, including key challenges like: Maintaining subcontractor compliance General contractors who attest to their own compliance are also responsible for any subcontractors they use. This can quickly get complicated, as sensitive data may be shared with dozens or even hundreds of workers on a job site or involved in planning efforts. Do your due diligence and ask your subcontractors about their own compliance efforts to understand where they are in this process. You can also explore creating an enclave to protect CUI and other sensitive information, essentially allowing subcontractors to log into your systems via a portal rather than simply sharing files, which can help limit the spread of data. Avoiding workflow interference The best compliance program in the world is useless if it prevents your business from operating effectively. Equally useless is a compliance effort that interferes with your workflows to the point where your team just ignores it. In other words, it’s not enough to be compliant; you have to do it in a way that fits with the realities of the job. That’s why it’s critical to tackle compliance with an eye towards your specific processes, culture and operations and design an approach that fits within that framework. Overcoming culture shock Construction has long been one of the most lightly regulated sectors of the economy, which makes strict CMMC requirements a genuine culture shock. You’ll need to change significant aspects of how you work, including transitioning away from paper and into digital tools and incorporating new security standards into your day-to-day activities. And because compliance isn’t a one-and-done effort, you’ll need to sustain an ongoing culture of compliance. This takes time to implement and demands buy-in from leaders who may be used to doing things a certain way. Managing change Compliance is also an exercise in change management. Before you jump into a compliance effort, be honest about how much change your business is prepared to handle. You’ll need to make a lot of changes, fast, to become compliant — is your team up for that? It’s essential to have an open dialogue within your company about the compliance process. This includes your job-site workers, who will have to follow through with compliance efforts while actively doing construction in the field. CMMC may be about cybersecurity, but compliance is not just an IT issue, so the more you can involve your whole team in a collaborative effort here, the better. What are your next steps to achieving CMMC compliance? If you want to bid on new DoD contracts or prepare for future cybersecurity requirements by other federal agencies, here’s how to start your CMMC 2.0 compliance process: Find an RPO: Conduct a search for an RPO that specializes in CMMC compliance specifically for construction firms and understands the nuances of your business. Do a gaps assessment: Ask your RPO to assess your current cybersecurity practices and identify areas of improvement needed to meet CMMC standards. Create a CMMC roadmap: Based on your gaps assessment, work with your RPO to create a CMMC roadmap to outline specific steps you’ll need to take to achieve compliance, with a focus on how you can keep your efforts aligned with operational and jobsite requirements. Implement your CMMC roadmap: Make the specific changes outlined in your compliance roadmap, while maintaining ongoing communication with your team to ensure a smoother change process. Complete a self-assessment or third-party assessment: Depending on when you undertake this compliance process and the type of job you’re bidding on, you’ll complete either a compliance self-assessment or third-party assessment. At this point, you’ll be able to take on new DoD jobs. Read more CMMC 2.0 compliance requirements: What should you know? 2026 construction industry trends: Time to break bad habits Is it time for mid-sized construction firms to embrace private equity?

  • construction worker on a laptop

    ARTICLE

    Why your construction firm needs to get serious about cybersecurity

    Construction firms face a rising level of cybersecurity risk. But too many firms still don’t have a proper cybersecurity strategy in place, which makes the likelihood of a costly, damaging attack a matter of when, not if. In fact, in a survey of 308 construction executives for Wipfli’s report on the state of technology within the construction industry , 80% reported experiencing at least one data breach within the past year. Fortunately, there are proven steps and processes you can implement to strengthen your defenses. Done thoughtfully, a cyber strategy will not only protect your business, data and infrastructure but also give you an opportunity to modernize your systems to meet the changing demands of the industry . Let’s explore further. Construction firms face a web of interconnected cybersecurity challenges Cybersecurity isn’t only a challenge for the construction industry. It’s universal, with businesses across all sectors being regularly targeted by threats like ransomware, email compromise or fraud. But in some ways, construction is especially vulnerable. The construction business tends to be fairly traditional, with an emphasis on following proven processes rather than chasing new ideas — and that has left firms more exposed than their counterparts in other industries. Here are some of the major cybersecurity-related challenges construction firms face today: Underinvestment: Construction companies have historically underinvested in IT and cybersecurity. Manufacturers, for example, spend 3% to 5% of revenue on IT, while construction typically spends closer to 1% to 2%. Large financial transactions: Construction firms buy large amounts of materials and expensive equipment. They also receive large draw payments from their clients. This makes them lucrative targets for cybersecurity attacks due to their historically poor security investments. Rising insurance premiums: Insurance providers are now charging construction companies higher cybersecurity insurance premiums because of the higher risk those firms face. Cyber requirements in contracts: The Department of Defense and other federal agencies now require construction firms to meet cybersecurity maturity model certification (CMMC) requirements in order to bid for contracts. Private data center contracts will often have similar rules. National Institute of Standards and Technology (NIST) security requirements are also appearing in many contracts. Disconnected systems: As many construction firms still rely heavily on older software and technology, they frequently don’t have integrated, cloud-based systems in place. This usually leads to fragmented, siloed data and a larger footprint for an attack. Slowed productivity: Companies using outdated tech systems are often less productive than their peers. From a cyber-specific perspective, consider the impact an attack could have on your ability to conduct day-to-day operations. Limited IT talent: Construction firms using legacy tech solutions may struggle to hire skilled IT employees, as talented candidates typically prefer to work for businesses that use the latest tech. All of these elements either increase the risk of a cyberattack or prevent your business from bidding on certain contracts or otherwise finding opportunities. Fortunately, there is a relatively straightforward solution to this problem. A holistic approach toward cybersecurity can strengthen your business In many cases, you’re often better off upgrading your cybersecurity and IT infrastructure over one defined upgrade period rather than doing it piecemeal over several years. This holistic approach allows you to modernize your entire tech stack to not only strengthen your cyber defenses but also transition to cloud-based, integrated systems that will help you remain competitive with your peers. The key to making a holistic upgrade strategy work is creating a roadmap and then following it. Start by doing an IT health and cybersecurity assessment. Work with an advisor to look at tech trends within the construction industry , consider the age of your own systems, identify critical gaps and measure your cybersecurity risk profile via a NIST Cybersecurity Framework (NIST CSF) assessment. Once you know what needs to be upgraded, put together a budget based on criticality. A full tech upgrade might take over a year, although this can vary depending on your organizational needs, so your budget can help you plan out how to make good use of that time by deciding which systems to upgrade first. After you have your roadmap in place, you’re ready to implement. Outsourcing can make it simpler to upgrade your cybersecurity defenses If upgrading your whole tech stack on your own sounds like a lot to handle, consider outsourcing . The right outsourcing partner can manage most of your cybersecurity and IT needs for you. Outsourcing is especially useful for construction firms because modern cybersecurity typically requires more resources than a single, in-house IT person can bring to bear. An outsourcing relationship can allow you to access top-tier cybersecurity talent without needing to hire your own larger internal team. And while every situation is different, outsourcing is often cheaper than building up your internal capacity — and sometimes considerably so. However, an outsourcing partner can’t do everything for you. You’ll still need to train your own team on how to limit cybersecurity risks by avoiding phishing attempts or other common attacks. What are the key barriers to change? Construction leaders who want to spearhead a cybersecurity and IT upgrade may first need to overcome several barriers to change. These include: Lack of clarity around risks: Some leaders may not realize just how vulnerable their business is. To create buy-in around an upgrade, you can ask an advisory firm to conduct penetration testing of your existing systems. Cultural resistance: Construction firms that still rely heavily on legacy systems and processes may also be culturally resistant to change. Confusion around regulatory requirements: Construction isn’t used to being a regulated industry, so many firms may be unaware or not fully under CMMC or similar requirements. Communications: Your internal IT person may struggle to articulate the business case for tech upgrades because they don’t have the knowledge and background. Transition or succession complications: An owner who is preparing to exit may see cybersecurity upgrades as something that the next owner can worry about — but should consider that implementing an effective, modern tech stack will actually boost the value of the business in a sale. What are the benefits of upgrading your cybersecurity and tech? For construction firms, investing in modern cybersecurity and IT infrastructure, whether as an internal capacity or through outsourcing, carries clear business benefits. Five big areas of interest include: Reduced risk of attack: This is obviously a big one. With better defenses and more modern systems in place, you’ll be less likely to experience a major (and majorly expensive) cybersecurity incident. DoD contracts: If you meet CMMC requirements, you’ll be able to bid on DoD and other government contracts Data center bids: Strong cybersecurity is also often necessary to compete for complex private sector projects like data centers. Competitive advantage: If you get ahead of competitors in upgrading your systems, you’ll be able to move faster, with a lower risk of being slowed by an attack. Recruiting: You’ll have an easier time recruiting talented employees who want to work for innovative companies. Learn more about how construction firms are upgrading their technology Wipfli interviewed 308 construction executives to find out how firms are deploying technology today. Read the full report, “The state of technology in the construction industry” to gain fresh insights on cybersecurity, AI, data strategies and growth. Read the report Read more Cybersecurity is a financial issue, not just an IT problem AI in construction 101: How to keep your firm competitive How to improve performance with smarter construction technology management

  • CRE-TAX-Get set for new Corporate Transparency Act reporting requirements

    ARTICLE

    Get set for new Corporate Transparency Act reporting requirements

    As part of the Anti-Money Laundering Act of 2020 , the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) was authorized to collect beneficial ownership information (BOI) and establish reporting requirements for certain corporations, limited liability companies and similar entities created in or registered to do business in the U.S. Reporting requirements go into effect on January 1, 2024. Who must report Domestic entities formed under the laws of the U.S. and Indian tribes, unless an exemption applies, must report. Foreign entities that have registered to do business in any U.S. state or tribal jurisdiction by filing a document with a secretary of state or similar office of the state or tribe must report. The rules provide for 23 specific entity exemptions: Securities reporting issuers Governmental authorities Banks Credit unions Depository institution holding companies Money services businesses Brokers or dealers in securities Securities exchanges or clearing agencies Other Exchange Act registered entities Investment companies and investment advisors Venture capital fund advisors Insurance companies State-licensed insurance producers Commodity Exchange Act registered entities Accounting firms Public utilities Financial market utilities Pooled investment vehicles Tax-exempt entities Subsidiaries of certain exempt entities Large operating companies meeting six criteria who: Employ more than 20 full-time employees. Filed tax returns for the prior year demonstrating more than $5 million in gross receipts or sales (excluding sales outside the U.S.). Have an operating presence at a physical office within the U.S. Entity-assisting tax-exempt entities Inactive entities What must be reported Beneficial owner information : Individual’s full legal name, date of birth, current residential or business street address and unique identifying number from an acceptable identification document (e.g., passport) or the individual’s FinCEN identifier Company applicant Beneficial owner Includes any individual who, directly or indirectly, either (1) exercises substantial control over a reporting company or (2) owns or controls at least 25% of the ownership interests of a reporting company. In defining who has substantial control, the rule sets forth a range of activities that could constitute substantial control of a reporting company. This list captures anyone who is able to make important decisions on behalf of the entity. A person can have “substantial control” without having ownership and there is no limit on the number of persons who may be reported as having “substantial control.” The rules provide standards and mechanisms for determining whether an individual owns or controls 25% of the ownership interests of a reporting company. Company applicant The individual who directly files the document that creates the entity, or in the case of a foreign reporting company, the document that first registers the entity to do business in the U.S. The individual who is primarily responsible for directing or controlling the filing of the relevant document by another. Entities that are existing or registered at the time of the effective date of the rule are not required to identify and report on their company applicants. Due dates Newly created or registered entities: Reporting companies created or registered on or after January 1, 2024, and before January 1, 2025, have 90 calendar days to file their initial reports. Existing entities: Companies in existence as of January 1, 2024, must submit an initial report by January 1, 2025. Change in information previously reported Updated reporting is required within 30 days when there is a change in the information previously provided, the entity becomes exempt or inaccuracies in previous reporting are discovered. How to file The reports must be electronically filed with FinCEN. Penalties The willful failure to report complete or updated beneficial ownership information to FinCEN or the willful provision of or attempt to provide false or fraudulent beneficial ownership information may result in civil or criminal penalties including civil penalties of up to $500 for each day that the violation continues or criminal penalties including imprisonment for up to two years and/or a fine of up to $10,000. Senior officers of an entity that fails to file a required report may be held accountable for that failure.

Perspective changes everything.

Receive timely industry developments, regulatory changes and other news impacting your success.

Reach out to our team

See how you can move beyond compliance checklists to create practical risk management strategies that support business performance.