Costpoint + CMMC-scoped AI
On-prem AI for Costpoint inside a CMMC Level 2 enclave
Short answer
A contractor running Deltek Costpoint inside a CMMC Level 2 scoped enclave, often on GCC High or an equivalent environment, has to treat any new AI tool as a potential new CUI data flow. Running the model and retrieval layer inside the same enclave, rather than calling an external AI API, is the deployment pattern that avoids adding an unassessed boundary to your SSP.
- ERP
- Deltek Costpoint
- Industries
- Government Contracting, Defense
- Written for
- CISO
If Costpoint sits inside your CMMC Level 2 scope, every system that touches CUI in or near it, including any AI tool, is fair game for your assessor to ask about. A well-meaning AI pilot that sends project or contract data to a public model API can turn into a scope expansion problem discovered during a mock assessment, not before.
The core issue is not whether AI is useful on Costpoint data, it clearly can be, for variance commentary, exception triage, and records Q&A. The issue is where the model actually runs and what data crosses the enclave boundary to get there. A SaaS AI feature, even one with an enterprise agreement, typically means data leaves your accredited boundary and lands in infrastructure your assessor has not evaluated.
The alternative most CMMC L2 contractors land on is running an open-weight model inside the same enclave, on GPU hardware that is itself in scope and covered by your existing System Security Plan (SSP), so the AI layer inherits access control, audit logging, and boundary protection instead of introducing a new one.
This page is written for the CISO or compliance lead who has to sign off on adding AI to a Costpoint environment already carrying a CMMC L2 assessment, GCC High tenancy, or an equivalent enclave: what changes in your SSP, what your assessor will likely ask, and what a defensible architecture looks like.
What usually gets in the way
The problems we hear most from ciso teams running Deltek Costpoint.
AI tools are a new, unassessed data flow by default
Most commercial AI features assume data leaves your environment to reach a model; inside a CMMC L2 boundary, that is a scope question before it is a productivity question.
GCC High does not automatically make every AI feature compliant
Being in GCC High covers the Microsoft 365 workload; a third-party AI tool integrated with Costpoint still needs its own assessment of where inference happens and what data it touches.
SSP updates lag behind tool adoption
Teams sometimes pilot an AI tool informally before updating the System Security Plan to reflect it, creating a documentation gap an assessor will flag.
Finance and program staff want AI value now
The same variance commentary, timesheet exception, and records Q&A use cases that make sense on Costpoint elsewhere are just as valuable here, but staff cannot self-serve a public AI tool without risking scope.
Assessors increasingly ask about AI explicitly
C3PAOs are starting to probe for AI tool usage during assessments; having no answer, or an informal one, is worse than having a documented, in-boundary deployment.
Where AI earns its place in Deltek Costpoint
Each use case names the ERP objects it reads or writes, so your ERP team can judge the integration effort before anyone commits budget.
In-enclave variance and exception narrative drafting
The same variance commentary and timesheet exception drafting valuable to any Costpoint finance team, run entirely inside the CMMC-scoped enclave so CUI-adjacent project and labor data never leaves the boundary.
Touches: Project Actuals, Indirect Pool, Timesheet, Labor Distribution
Outcome: delivers the same drafting time savings as an unrestricted deployment, without expanding your assessment boundary
CUI-aware document retrieval for contract and project records
Retrieval over contract and project documentation respects CUI marking and access controls already defined in Costpoint and your document management system, rather than indexing everything indiscriminately.
Touches: Contract, Project Documentation, CUI-marked records
Outcome: gives staff faster access to non-restricted answers while keeping CUI-marked content behind existing access controls
SSP-ready audit logging for AI queries
Every AI query and the records it touched is logged in a form your assessor can review alongside existing system logs, supporting your continuous monitoring and audit requirements.
Touches: System audit log, Access control record
Outcome: gives your compliance team documented evidence of AI tool behavior ready for a C3PAO assessment, not an informal claim
Access-control-consistent Q&A over Costpoint data
The AI layer respects the same role-based access already configured in Costpoint, so a user asking a question only ever sees data they would already be authorized to see in the application.
Touches: Costpoint role/permission structure, Project, Contract
Outcome: avoids the access-control gap that ad hoc AI tool adoption commonly introduces
Model and infrastructure inventory for your SSP
The deployment produces a clear inventory of the model, hosting environment, and data flows involved, formatted to slot into your existing System Security Plan documentation.
Touches: System boundary documentation, Data flow diagram
Outcome: reduces the effort of updating SSP documentation when AI capability is added, since the architecture is designed with SSP inclusion in mind
Insider-risk-aware query monitoring
Query logs can be reviewed for unusual access patterns (a user asking about contracts or projects outside their normal scope), supporting insider threat monitoring requirements.
Touches: Audit log, User access pattern
Outcome: adds a monitoring signal that complements existing insider risk controls without a separate tool
Controlled expansion beyond finance to program management
Once the finance use cases are validated inside the enclave, the same architecture extends to program status Q&A and contract deliverable tracking for program managers, under the same boundary controls.
Touches: Project, Contract Deliverable, Program status
Outcome: lets the organisation expand AI use case by use case without renegotiating the compliance boundary each time
Reference architecture
Every component, model, retrieval index, and connector, runs inside the same CMMC-scoped enclave as Costpoint, so the AI layer is covered by existing boundary, access control, and audit documentation rather than requiring a new assessment scope.
- 1
In-enclave connector layer
Reads Costpoint project, labor, and contract data through its documented API from inside the enclave boundary, using an account subject to the same access controls as any other in-scope system.
- 2
Data and semantic layer
Maps Costpoint entities to a semantic layer while respecting CUI markings and access restrictions already defined for project and contract records.
- 3
Model serving layer
Runs an open-weight model on vLLM or Ollama on GPU hardware physically or virtually inside the CMMC-scoped boundary, with no outbound call to any external AI API.
- 4
Retrieval and agent layer
Constrains retrieval to data the requesting user is already authorized to see, and treats any drafted output (variance commentary, exception follow-up) as requiring human review before use outside the system.
- 5
Governance and audit layer
Produces audit logs formatted to integrate with existing continuous monitoring tooling and SSP documentation, supporting assessment readiness rather than adding a parallel, unreviewed log.
Integration notes for your ERP team
- Document the AI layer's data flow explicitly for your SSP before go-live, not after; assessors respond far better to a documented, in-scope system than to a discovered, undocumented one.
- Confirm with your C3PAO or CMMC consultant whether the AI layer's GPU hardware needs to be added as a formal asset in your asset inventory, which it typically does if it processes CUI.
- Use the same identity provider and access control mechanism already governing Costpoint access for the AI layer's service accounts, rather than a separate authentication scheme.
- If any part of the stack (model weights, orchestration software) is sourced from an external vendor, get clarity on export control and supply chain provenance, particularly for model weights from non-US labs.
- Route all AI query logs into your existing SIEM or log aggregation tooling so continuous monitoring covers the AI layer without a separate review process.
- Treat any drafted output that could become a deliverable to the government (an ICS schedule, a contract report) as requiring the same human review and approval chain it would without AI involvement.
- Plan for periodic re-validation of the AI layer's boundary and data flow alongside your existing CMMC assessment or self-assessment cadence.
Deployment options
Air-gapped on-prem within the enclave
Contractors whose CMMC L2 boundary is an on-prem or co-located data center environment.
Model and retrieval layer run on GPU hardware physically located within the assessed boundary, with no network path outside the enclave required for inference.
Private cloud within the assessed boundary
Contractors whose CMMC L2 scope includes a GCC High or equivalent cloud tenancy already covering Costpoint or adjacent systems.
The model runs in a virtual environment inside the same cloud tenancy and network boundary, inheriting the tenancy's existing access control and monitoring configuration.
Hybrid with staged scope expansion
Contractors wanting to validate the architecture on a narrower, already-in-scope data set before expanding coverage.
AI capability is enabled first for a subset of already-in-boundary data (e.g. one program's finance data), with scope expanded to additional programs or data types after assessor-facing documentation is validated.
Compliance and data control
How the architecture supports your obligations. Certification and accountability stay with your organisation; the design keeps the evidence straightforward.
CMMC 2.0 Level 2
Keeping the model, retrieval index, and connector inside the existing assessment boundary avoids introducing a new external system that would need to be added to scope, and the deployment's audit logging is designed to support your assessment evidence.
NIST SP 800-171 (access control, audit, media protection families)
The AI layer inherits the same access control and audit logging controls already implemented for Costpoint and the surrounding enclave, rather than requiring a parallel control set to be designed and assessed.
DFARS 252.204-7012
Because inference never leaves the covered contractor information system boundary, the deployment avoids creating a new covered defense information transmission path that would need to be separately justified.
GCC High tenancy alignment
Where Costpoint or adjacent systems already run in a GCC High or equivalent tenancy, deploying the AI layer inside that same tenancy keeps the architecture consistent with the environment your assessor has already reviewed.
How an engagement runs
Phase 1 . 2-3 weeks
Discovery
- -Review of current CMMC L2 boundary, SSP, and Costpoint hosting environment
- -Data flow mapping for proposed AI use cases against CUI marking and access control requirements
- -Alignment with your compliance lead or C3PAO consultant on scope implications
Phase 2 . 6-8 weeks
Pilot
- -In-enclave model and connector deployment for one or two priority use cases
- -Draft SSP language and asset inventory update for the AI layer
- -Access control and audit log validation against existing NIST 800-171 controls
Phase 3 . Ongoing after pilot sign-off
Production
- -Rollout to the full finance or program team within the assessed boundary
- -Finalised SSP documentation and asset inventory entries
- -Continuous monitoring integration confirmed with your security operations
Phase 4 . Following assessment cadence
Scale
- -Extension to additional in-scope use cases (program management, contracts)
- -Re-validation of boundary and data flow ahead of assessment or self-assessment cycles
- -Documentation handoff to support future C3PAO assessments
Questions to ask any vendor, including us
A short list that separates real Deltek Costpoint AI work from a chatbot demo.
- Can you show, concretely, that CUI never leaves our assessed CMMC boundary at any point in the AI workflow?
- Will this deployment require an update to our SSP and asset inventory, and can you help draft that language?
- Does the AI layer's service account inherit our existing access control, or does it need a new identity and permission model?
- What is the export control and supply chain provenance of the model weights being used?
- How does the audit logging integrate with our existing SIEM and continuous monitoring process?
- Has this architecture been reviewed by, or built with input from, a CMMC-experienced compliance advisor?
- What GPU hardware is required, and does it need to be formally added as an in-scope asset?
- How do we handle re-assessment when the AI layer or model changes after go-live?
Frequently asked questions
Does adding AI to Costpoint automatically expand my CMMC assessment scope?
It depends entirely on where the AI runs. A public AI API almost always expands scope because CUI leaves your boundary to reach it. Running the model and retrieval layer inside your existing assessed enclave, using the same access controls and audit logging already in place, is designed specifically to avoid that scope expansion.
Is GCC High enough to make any AI tool CMMC-compliant?
No. GCC High covers the Microsoft 365 workloads it hosts, but a third-party AI tool integrated with Costpoint still needs its own review of where inference happens and what data it touches. If it calls an external model API, being in GCC High does not change that data flow.
What does our SSP need to say about an AI layer like this?
At minimum, a data flow description showing the AI layer stays within the existing system boundary, an asset inventory entry for the hosting infrastructure, and a description of how it inherits existing access control and audit logging. Your CMMC consultant or C3PAO should review the specific language before an assessment.
Can we pilot AI on Costpoint before finalising our CMMC documentation?
It is safer to document the data flow before go-live, even for a pilot, since assessors respond far better to a documented in-scope system than to something discovered informally. A short discovery phase to map the data flow before piloting is worth the time.
Does this replace the need for a CMMC consultant or C3PAO relationship?
No. This describes an architecture pattern for keeping AI inside your existing boundary; your CMMC consultant or C3PAO still needs to review the specific implementation and any resulting SSP or asset inventory changes.
What use cases make sense to start with inside a CMMC L2 enclave?
Variance commentary drafting and timesheet exception triage are reasonable starting points: they touch data already inside your assessed boundary, do not require new external access, and give the compliance team a small, well-defined scope to validate the architecture against.
How long does it take to get an AI pilot running inside an existing CMMC boundary?
A focused pilot typically takes six to eight weeks after a two to three week discovery phase, though the timeline depends on how quickly your compliance team and C3PAO consultant can review the proposed data flow and SSP language.
Related guides
AI for Deltek Costpoint in government contract accounting
AI on Deltek Costpoint for timesheets, indirect rates, and incurred cost, grounded on real data and deployed on-prem to keep DCAA-relevant data in house.
CMMC 2.0 + on-prem AICMMC Level 2 AI for ERP Without Blowing Up Your Scope
How to deploy AI inside your CMMC 2.0 Level 2 assessment boundary without expanding CUI scope. Enclave architecture a CISO can defend to a C3PAO.
ITAR + on-prem AIITAR-Compliant AI for ERP Technical Data
How to add generative AI to your ERP without creating a deemed export under ITAR. On-prem architecture patterns an Empowered Official can sign off on.
DFARS 7012 + NIST 800-171Mapping DFARS 7012 and NIST 800-171 Controls to AI on Your ERP
Map DFARS 252.204-7012 and NIST SP 800-171 control families to an AI system layered on your ERP, with evidence a Compliance Manager can defend.
Buyer guide: cloud AI vs private AIFedRAMP / GCC High AI vs On-Prem AI for Your ERP: An Honest Comparison
An honest CISO comparison of FedRAMP High or GCC High AI copilots versus on-prem private LLMs for ERP data: what each authorization actually covers, and when each fits.
Defense contractor AIAI for ERP Across the US Defense Supply Chain
A CIO's guide to adding AI on top of the ERP defense primes and tier 2-3 suppliers already run, without adding a compliance risk the program cannot absorb.
Plan it with numbers
CMMC 2.0 Level 2 Readiness Assessment
Answer 10 questions mapped to NIST SP 800-171 control families and get an instant CMMC Level 2 readiness score with prioritized next steps.
Free ToolDFARS 252.204-7012 Compliance Self-Assessment
A 10-question self-assessment covering the full DFARS 7012 clause: NIST 800-171 implementation, SPRS, incident reporting, cloud requirements, and flowdown.
Free ToolITAR AI Workload Compliance Assessment
Score your AI deployments across eight dimensions of ITAR exposure, from technical data classification and US persons access control to technology control plan coverage.
GuideCMMC-Compliant AI Deployment: What Level 2 Contractors Must Know
CMMC-compliant AI deployment explained: how Level 2 defense contractors can run AI on CUI without expanding assessment scope. Controls, enclaves, and costs.
GuideITAR and CMMC Handling of AI Workloads
How ITAR and CMMC apply to AI workloads: technical data boundaries, CUI handling, assessed environments, and where on-prem AI is the only option.
GuideOn-Prem AI for Defense Contractors: The Complete Guide
On-prem AI for defense contractors: deploy LLMs and AI agents inside your CMMC and ITAR boundary. Architecture, hardware costs, timelines, and vendor options.
Talk it through with an engineer who knows Deltek Costpoint
Bring one real question your team cannot answer from the ERP today. We will map the data path, the model, and where it runs, and tell you honestly if AI is the wrong tool for it.