Internal controls advisory services
When compliance demands grow, internal controls need to do more than check a box. Wipfli helps you identify risks, enhance control effectiveness and support better performance outcomes.
How we help you
Wipfli’s internal controls services help you protect assets, strengthen compliance and increase efficiency.
Develop a tailored internal audit plan.
Gain new insight into your daily operational risks.
Improve your organization’s risk culture.
Maintain effective controls for your systems and IT environment.
Elevate value and trust with strong internal controls
Our multidisciplinary team brings the skills and experience needed to both protect and drive value in your organization.
Explore our internal controls services
Streamline SOX requirements with Wipfli. We create a seamless process by identifying your key business processes related to controls over financial reporting, determining the controls and systems supporting the business processes and then testing the effectiveness of the controls. We then turn SOX program data into internal control knowledge and help provide the resources you need to fill technical and capacity resource gaps.
Wipfli’s internal audit team is ready to help your organization identify your true risk and develop an internal audit plan tailored to your unique goals and challenges. We combine extensive industry experience and practical guidance to help your organization choose the solutions and approaches that best suit your needs. We also provide quality assurance reviews and support for your internal audit team.
Help ensure your IT controls are operating effectively and securely with Wipfli. Our IT controls review helps you identify risks and provides your organization with best practices and actionable feedback so that you can be confident that your controls are effective.
Insights and Resources
- Learn More
EVENT | January 19, 2027
January 2027 Uniform Guidance regulation training
Join us for a practical and engaging virtual training of the Office of Management and Budget’s (OMB) Uniform Guidance (2 CFR Part 200) — the cornerstone of federal grant compliance. This training is designed to help nonprofit and government professionals understand federal grant regulations and how to apply them effectively and avoid common pitfalls in managing federal awards. Led by experienced trainers with years of auditing and consulting expertise, this session blends regulatory review with real-world examples and actionable insights. Whether you’re new to federal
Learn MoreARTICLE
From compliance to confidence: Mastering the new CMMC 2.0 requirements
The Cybersecurity Maturity Model Certification (CMMC) 2.0 is the newest iteration of the Department of Defense’s (DoD) cybersecurity rules for contractors. This framework aims to ensure that all defense contractors implement necessary cybersecurity safeguards to protect controlled unclassified information (CUI) and federal contract information (FCI). CMMC 2.0 compliance requirements were originally scheduled to take effect in four phases from November 2025 through 2028. However, in July 2026, the DoD paused Phase II indefinitely , although most other CMMC requirements remain active. Keep reading to learn what’s changing and how your business may need to adapt. What is CMMC 2.0? The Cybersecurity Maturity Model Certification (CMMC) 2.0 is a cybersecurity compliance framework for defense contractors and other vendors who work with the Department of Defense (informally referred to as the Department of War). CMMC 2.0 is the latest version of the CMMC framework and now appears in all DoD contracts with the goal of raising cybersecurity standards for the defense industrial base (DIB). Is CMMC compliance mandatory? DoD contractors who wish to continue bidding on federal defense contracts must meet CMMC 2.0 compliance requirements . However, the Phase II pause means you no longer have to complete a third-party assessment in order to demonstrate compliance. Who does CMMC 2.0 apply to? CMMC 2.0 applies to all contractors, vendors and other third-party organizations that do business with the Department of Defense. Especially in light of the Phase II pause, expect that CMMC will continue to evolve in the coming years. What is the CMMC 2.0 Phase II pause? On July 13, 2026, the DoD announced it was pausing Phase II of the CMMC 2.0 rollout indefinitely. Phase II, which was supposed to begin on November 10, 2026, originally required organizations handling higher levels of sensitive information to complete third-party CMMC compliance assessments. However, due to the pause, organizations no longer have to complete third-party assessments to demonstrate CMMC 2.0 compliance. Most other requirements remain in effect, and DoD is continuing to include CMMC in new contracts. It is likely that DoD will announce significant revisions to the rest of the CMMC rollout at some point in the future. Before the pause, CMMC 2.0 had originally established a three-year phased implementation period CMMC 2.0 was originally scheduled to roll out in four phases from 2025 through 2028. While the Phase II pause means the entire rollout schedule will likely be revamped, here is that original schedule as it was first established: Phase I: The first phase began on November 10, 2025. During this phase, the DoD can begin to include CMMC 2.0 requirements in new contracts. Contractors will need to meet Level 1 or Level 2 self-assessment requirements as a condition of contract award. Phase II: Before the pause, the second phase was originally scheduled to start one year after Phase I, on November 10, 2026. In this phase, contractors handling CUI would have been required to undergo a third-party assessment by a certified assessor organization as a condition of award. Phase III: The third phase was scheduled to begin on November 10, 2027. This phase would have involved the DoD itself conducting Level 3 CMMC assessments for contracts involving the most sensitive CUI, but will also likely be revamped in light of the Phase II pause. Phase IV: The final phase was supposed to start three years on November 10, 2028. This phase would have marked the full implementation of the CMMC requirements across all applicable solicitations and contracts. This phased approach was intended to address ramp-up issues, provide runway to train the necessary number of assessors and allow companies the time needed to understand and implement CMMC requirements . Key clarifications around CMMC 2.0 compliance requirements As the newest version of DoD cybersecurity rules, CMMC 2.0 provides several key clarifications that are crucial for CISOs and compliance officers at defense contractors to understand. These include: The operational plan of action allows contractors to identify temporary vulnerabilities and deficiencies, as opposed to documenting in a plan of action and milestones (POA&M). This allows for management to remediate vulnerabilities or deficiencies identified through the normal operation of detective controls without causing you to go out of compliance. Contractors must retain artifacts used in evidence for an assessment for at least six years after the date of their certification assessment. This retention obligation extends to the annual self-certifications that contractors must perform. External service providers are not required to have CMMC certification, but are “in-scope” if they store, transmit or process CUI. An endpoint hosting a virtual desktop infrastructure (VDI) client configured to disallow processing, storage or transmission of CUI beyond keyboard/video/mouse sent to the VDI client is considered an out-of-scope asset. How should you implement the CMMC 2.0 cybersecurity framework? Even with the Phase II pause, most CMMC 2.0 requirements remain in effect. Defense contractors must take several steps to become compliant and properly flow down the compliance requirements to their subcontractors, including: 1. Understand the three CMMC 2.0 levels Based on the type of sensitive information or CUI your organization handles, you should determine the appropriate CMMC level for your organization. This will guide your compliance efforts and help you identify the specific requirements you need to meet. The three levels are: Level 1: Basic protection of FCI, requiring an annual self-assessment. Level 2: General protection of CUI, which can now be achieved through a self-assessment in light of the Phase II pause. Level 3: Enhanced protection against advanced persistent threats. This would have required an assessment led by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), starting with Phase III in November 2027, but may now be revamped. 2. Conduct proper scoping of your environment. Proper scoping of your environment for CMMC 2.0 is crucial because it clearly defines the boundaries where CUI is stored, processed and transmitted within your organization. This allows you to focus security efforts only on the relevant systems and data, minimizing the scope of your assessment and ultimately reducing the cost and complexity of achieving compliance while ensuring the most critical assets are adequately protected. If not done correctly, your entire network could be considered “in-scope” for assessment, leading to unnecessary overhead and potential noncompliance issues. 3. Perform a gap analysis. Assess your current cybersecurity posture against the CMMC 2.0 standards. Conduct a thorough gap analysis to identify deficiencies in your existing cybersecurity controls. This will help you develop a POA&M to address these gaps and achieve compliance. 4. Implement required controls. Based on the results of your gap analysis, implement the necessary cybersecurity controls to meet the CMMC requirements. This may involve updating your policies, procedures and technical controls, or implementing new technology. 5. Prepare for assessment. You’ll need to complete a self-assessment to demonstrate CMMC 2.0 compliance. Before you begin, ensure that you have all the required documentation and evidence in place. This includes maintaining control evidence for six years and being prepared for potential audits by the DoD. 6. Flow down requirements to subcontractors. Ensure that your subcontractors are also compliant with the CMMC requirements. Flow down the relevant requirements to all subcontractors at every tier and verify their compliance. By following these steps, defense contractors can help ensure that they are fully compliant with the CMMC 2.0 requirements and are well-prepared to protect sensitive information from evolving cyberthreats. A third-party advisor can help you navigate this process and implement solutions to bring you up to speed. Read more Cybersecurity is a financial issue The right cybersecurity framework boosts a business’s value 5 common CMMC 2.0 pitfalls
Learn MoreARTICLE
Cybersecurity in construction: How CIOs can better protect their firms
Construction firms face a rising level of cybersecurity risk. But too many firms still don’t have a proper cybersecurity strategy in place, which is likely why Wipfli’s survey of 308 construction executives found that 80% reported experiencing at least one data breach within the past year. However, there are proven steps and processes you can implement to strengthen your defenses. Done thoughtfully, a cyber strategy will not only protect your business, data and infrastructure but also give you an opportunity to modernize your systems to meet the changing demands of the industry . Let’s explore further. Why does cybersecurity matter for construction firms? For construction firms, investing in modern cybersecurity and IT infrastructure, whether as an internal capacity or through outsourcing, carries clear business benefits. Beyond mitigating the risk of a cyberattack , stronger cybersecurity also creates business opportunities and even makes it easier to recruit top talent. Key benefits include: Reduced risk of attack: This is obviously a big one. With better defenses and more modern systems in place, you’ll be less likely to experience a major (and majorly expensive) cybersecurity incident or suffer significant ripple effects if an attack does get through. DoD contracts: If you meet CMMC requirements, you’ll be able to bid on DoD and other government contracts. Data center bids: Strong cybersecurity is also often necessary to compete for complex private sector projects like data centers. Competitive advantage: If you get ahead of competitors in upgrading your systems, you’ll be able to move faster, with a lower risk of being slowed by an attack. Recruiting: You’ll have an easier time recruiting talented employees who want to work for innovative companies. Top cybersecurity challenges faced by construction firms Every industry is vulnerable to cyberattacks, but construction may be especially so. The construction business tends to be fairly traditional, with an emphasis on following proven processes rather than chasing new ideas — a tendency which has left firms more exposed than their counterparts in other industries. Here are some of the top reasons that construction firms are vulnerable to cybersecurity incidents: Underinvestment: Construction companies have historically underinvested in IT and cybersecurity. Manufacturers, for example, spend 3% to 5% of revenue on IT, while construction typically spends closer to 1% to 2%. Large financial transactions: Construction firms buy large amounts of materials and expensive equipment. They also receive large draw payments from their clients. This makes them lucrative targets for cybersecurity attacks due to their historically poor security investments. Rising insurance premiums: Insurance providers are now charging construction companies higher cybersecurity insurance premiums because of the higher risk those firms face. Cyber requirements in contracts: The Department of Defense and other federal agencies now require construction firms to meet cybersecurity maturity model certification (CMMC) requirements in order to bid for contracts. Private data center contracts will often have similar rules. National Institute of Standards and Technology (NIST) security requirements are also appearing in many contracts. Disconnected systems: As many construction firms still rely heavily on older software and technology, they frequently don’t have integrated, cloud-based systems in place. This usually leads to fragmented, siloed data and a larger footprint for an attack. Slowed productivity: Companies using outdated tech systems are often less productive than their peers. From a cyber-specific perspective, consider the impact an attack could have on your ability to conduct day-to-day operations. Limited IT talent: Construction firms using legacy tech solutions may struggle to hire skilled IT employees, as talented candidates typically prefer to work for businesses that use the latest tech. All of these elements either increase the risk of a cyberattack, prevent your business from bidding on certain contracts or otherwise limit opportunities. Fortunately, there is a relatively straightforward solution to this problem. Cybersecurity best practices for construction companies Implementing a practical, up-to-date cybersecurity strategy will help mitigate your company’s cyber risks and reduce the likelihood of suffering a costly cyberattack. Think holistically In many cases, you’re often better off upgrading your cybersecurity and IT infrastructure over one defined upgrade period rather than doing it piecemeal over several years. This holistic approach allows you to modernize your entire tech stack to not only strengthen your cyber defenses but also transition to cloud-based, integrated systems that will help you remain competitive with your peers. Do a cybersecurity assessment An effective cybersecurity risk management strategy should be tailored to your specific threats and vulnerabilities. Start by working with a cybersecurity advisor to do an IT health and cybersecurity assessment , which will often be based on the NIST Cybersecurity Framework (NIST CSF) assessment. This will help you identify high-priority weak spots that need to be addressed, as well as which vulnerabilities may be lower-priority. Create a roadmap Based on the results of your assessment, create a roadmap for strengthening your cybersecurity and IT capabilities. When developing your roadmap, also consider tech trends within the construction industry , the age of your own systems, and any critical control gaps you’ve identified. Establish a budget Once you know what needs to be upgraded, put together a budget based on criticality. A full tech and cybersecurity upgrade might take over a year, although this can vary depending on your organizational needs, so your budget can help you plan out how to make good use of that time by deciding which systems to upgrade first. You can use the priority ranking from your assessment to good effect here. Leverage outsourcing If upgrading your cybersecurity and tech stack on your own sounds like a lot to handle, consider outsourcing and managed services support . Outsourcing is especially useful for construction firms because modern cybersecurity typically requires more resources than a single, in-house IT person can bring to bear. An outsourcing relationship can allow you to access top-tier cybersecurity talent without needing to hire your own larger internal team, and can also include strategic leadership like a vCIO or vCISO. Train your team An outsourcing partner can’t do everything for you. You’ll still need to train your own team on how to limit cybersecurity risks by avoiding phishing attempts or other common attacks. For maximum effect, this training should be ongoing, not just a one-time event. What are the key barriers to change that construction CIOs must overcome? Construction leaders who want to spearhead a cybersecurity and IT upgrade may first need to overcome several barriers to change. These include: Lack of clarity around risks: Some leaders may not realize just how vulnerable their business is. To create buy-in around an upgrade, you can ask an advisory firm to conduct penetration testing of your existing systems. Cultural resistance: Construction firms that still rely heavily on legacy systems and processes may also be culturally resistant to change. Confusion around regulatory requirements: Construction isn’t used to being a regulated industry, so many firms may be unaware or not fully under CMMC or similar requirements. Communications: Your internal IT person may struggle to articulate the business case for tech upgrades because they don’t have the knowledge and background. Transition or succession complications: An owner who is preparing to exit may see cybersecurity upgrades as something that the next owner can worry about — but should consider that implementing an effective, modern tech stack will actually boost the value of the business in a sale. Learn how 308 construction leaders are deploying technology to deliver impact Wipfli interviewed 308 construction executives to find out how firms are deploying technology today. Read the full report, “The state of technology in the construction industry” to gain fresh insights on cybersecurity, AI, data strategies and growth. Get the original research report Read more Cybersecurity is a financial issue, not just an IT problem AI in construction 101: How to keep your firm competitive How to improve performance with smarter construction technology management
Perspective changes everything.
Receive timely industry developments, regulatory changes and other news impacting your success.
Reach out to our team
Connect with our team to get proactive support for mitigating risk, strengthening controls and building resilience.


LET'S CONNECT
See how Wipfli can help you implement risk management that supports compliance, productivity and long-term success.




