Cloud Compliance

We prioritize the security of your data by continuously enhancing our capabilities to keep up with the ever-evolving security landscape.

SOC reports are designed to provide assurance on internal controls over financial reporting (SOC 1), as well as system security (SOC 2 and SOC 3). These reports are created for Deltek by an independent auditor who evaluates Deltek's internal security controls with the AICPA defined control standards.


The SOC 1 Type II Report provides information on controls at a service organization, like Deltek, that are relevant to user entities' internal control over financial reporting.

Soc 1 reports are prepared in accordance with AT-C section 320 and are specifically intended to meet the needs of entities that use service organizations and the CPAs that audit the user entities’ financial statements.

SOC 2/ISAE 3000

The SOC 2 Type II Report provides information on controls at a service organization which may include one or more of the following trust services criteria: security, availability, processing integrity, confidentiality and/or privacy. Deltek conducts semi-annual SOC 2 reports for products hosted in Deltek’s Cloud.


The SOC 3 Report discusses the evaluation of the same AICPA criteria as a SOC 2 Report but does not include a description of the auditor's tests of controls and results, making this report available for general use.


National Institute of Standards and Technology (NIST) Special Publication 800-171 governs the storage, use and control of Controlled Unclassified Information (CUI) in Non-Federal Information Systems and Organizations. These standards define how to safeguard and distribute material designated by the United States Government to be sensitive but not classified.

Under federal regulations, such as DFARS clause 252.204-7012, certain companies and agencies are required to assess and document their compliance against NIST SP 800-171. This requirement includes assessing how networks are configured and how all data is protected.

Costpoint GCC & GCCM

Costpoint GCC & GCCM

Talent Management


The Cybersecurity Maturity Model Certification (CMMC) is designed to enhance the protection of controlled unclassified information (CUI) in the United States Department of Defense supply chain and leverages NIST SP 800-171 controls and requirements.

Deltek is committed to supporting CMMC readiness. Deltek’s Costpoint ERP delivered in GovCon Cloud Moderate (GCCM) has already implemented all the necessary controls to support compliance with FAR, DFARS and CMMC requirements.


Costpoint GovCon Cloud Moderate (GCCM) has officially achieved FedRAMP Moderate Ready status by the Federal Risk and Authorization Management Program (FedRAMP®). This major achievement demonstrates Deltek's continued commitment and investment in delivering industry-leading, secure solutions.

Deltek's achievement of FedRAMP Moderate Ready means that a recognized third-party assessment organization (3PAO) has thoroughly evaluated Costpoint GCCM against FedRAMP Moderate controls and has verified that Costpoint GCCM meets this high standard for data security.