DeltekRole & RegulationUnited States

Costpoint + CMMC-scoped AI

On-prem AI for Costpoint inside a CMMC Level 2 enclave

Short answer

A contractor running Deltek Costpoint inside a CMMC Level 2 scoped enclave, often on GCC High or an equivalent environment, has to treat any new AI tool as a potential new CUI data flow. Running the model and retrieval layer inside the same enclave, rather than calling an external AI API, is the deployment pattern that avoids adding an unassessed boundary to your SSP.

ERP
Deltek Costpoint
Industries
Government Contracting, Defense
Written for
CISO

If Costpoint sits inside your CMMC Level 2 scope, every system that touches CUI in or near it, including any AI tool, is fair game for your assessor to ask about. A well-meaning AI pilot that sends project or contract data to a public model API can turn into a scope expansion problem discovered during a mock assessment, not before.

The core issue is not whether AI is useful on Costpoint data, it clearly can be, for variance commentary, exception triage, and records Q&A. The issue is where the model actually runs and what data crosses the enclave boundary to get there. A SaaS AI feature, even one with an enterprise agreement, typically means data leaves your accredited boundary and lands in infrastructure your assessor has not evaluated.

The alternative most CMMC L2 contractors land on is running an open-weight model inside the same enclave, on GPU hardware that is itself in scope and covered by your existing System Security Plan (SSP), so the AI layer inherits access control, audit logging, and boundary protection instead of introducing a new one.

This page is written for the CISO or compliance lead who has to sign off on adding AI to a Costpoint environment already carrying a CMMC L2 assessment, GCC High tenancy, or an equivalent enclave: what changes in your SSP, what your assessor will likely ask, and what a defensible architecture looks like.

What usually gets in the way

The problems we hear most from ciso teams running Deltek Costpoint.

AI tools are a new, unassessed data flow by default

Most commercial AI features assume data leaves your environment to reach a model; inside a CMMC L2 boundary, that is a scope question before it is a productivity question.

GCC High does not automatically make every AI feature compliant

Being in GCC High covers the Microsoft 365 workload; a third-party AI tool integrated with Costpoint still needs its own assessment of where inference happens and what data it touches.

SSP updates lag behind tool adoption

Teams sometimes pilot an AI tool informally before updating the System Security Plan to reflect it, creating a documentation gap an assessor will flag.

Finance and program staff want AI value now

The same variance commentary, timesheet exception, and records Q&A use cases that make sense on Costpoint elsewhere are just as valuable here, but staff cannot self-serve a public AI tool without risking scope.

Assessors increasingly ask about AI explicitly

C3PAOs are starting to probe for AI tool usage during assessments; having no answer, or an informal one, is worse than having a documented, in-boundary deployment.

Where AI earns its place in Deltek Costpoint

Each use case names the ERP objects it reads or writes, so your ERP team can judge the integration effort before anyone commits budget.

In-enclave variance and exception narrative drafting

The same variance commentary and timesheet exception drafting valuable to any Costpoint finance team, run entirely inside the CMMC-scoped enclave so CUI-adjacent project and labor data never leaves the boundary.

Touches: Project Actuals, Indirect Pool, Timesheet, Labor Distribution

Outcome: delivers the same drafting time savings as an unrestricted deployment, without expanding your assessment boundary

CUI-aware document retrieval for contract and project records

Retrieval over contract and project documentation respects CUI marking and access controls already defined in Costpoint and your document management system, rather than indexing everything indiscriminately.

Touches: Contract, Project Documentation, CUI-marked records

Outcome: gives staff faster access to non-restricted answers while keeping CUI-marked content behind existing access controls

SSP-ready audit logging for AI queries

Every AI query and the records it touched is logged in a form your assessor can review alongside existing system logs, supporting your continuous monitoring and audit requirements.

Touches: System audit log, Access control record

Outcome: gives your compliance team documented evidence of AI tool behavior ready for a C3PAO assessment, not an informal claim

Access-control-consistent Q&A over Costpoint data

The AI layer respects the same role-based access already configured in Costpoint, so a user asking a question only ever sees data they would already be authorized to see in the application.

Touches: Costpoint role/permission structure, Project, Contract

Outcome: avoids the access-control gap that ad hoc AI tool adoption commonly introduces

Model and infrastructure inventory for your SSP

The deployment produces a clear inventory of the model, hosting environment, and data flows involved, formatted to slot into your existing System Security Plan documentation.

Touches: System boundary documentation, Data flow diagram

Outcome: reduces the effort of updating SSP documentation when AI capability is added, since the architecture is designed with SSP inclusion in mind

Insider-risk-aware query monitoring

Query logs can be reviewed for unusual access patterns (a user asking about contracts or projects outside their normal scope), supporting insider threat monitoring requirements.

Touches: Audit log, User access pattern

Outcome: adds a monitoring signal that complements existing insider risk controls without a separate tool

Controlled expansion beyond finance to program management

Once the finance use cases are validated inside the enclave, the same architecture extends to program status Q&A and contract deliverable tracking for program managers, under the same boundary controls.

Touches: Project, Contract Deliverable, Program status

Outcome: lets the organisation expand AI use case by use case without renegotiating the compliance boundary each time

Reference architecture

Every component, model, retrieval index, and connector, runs inside the same CMMC-scoped enclave as Costpoint, so the AI layer is covered by existing boundary, access control, and audit documentation rather than requiring a new assessment scope.

  1. 1

    In-enclave connector layer

    Reads Costpoint project, labor, and contract data through its documented API from inside the enclave boundary, using an account subject to the same access controls as any other in-scope system.

  2. 2

    Data and semantic layer

    Maps Costpoint entities to a semantic layer while respecting CUI markings and access restrictions already defined for project and contract records.

  3. 3

    Model serving layer

    Runs an open-weight model on vLLM or Ollama on GPU hardware physically or virtually inside the CMMC-scoped boundary, with no outbound call to any external AI API.

  4. 4

    Retrieval and agent layer

    Constrains retrieval to data the requesting user is already authorized to see, and treats any drafted output (variance commentary, exception follow-up) as requiring human review before use outside the system.

  5. 5

    Governance and audit layer

    Produces audit logs formatted to integrate with existing continuous monitoring tooling and SSP documentation, supporting assessment readiness rather than adding a parallel, unreviewed log.

Integration notes for your ERP team

  • Document the AI layer's data flow explicitly for your SSP before go-live, not after; assessors respond far better to a documented, in-scope system than to a discovered, undocumented one.
  • Confirm with your C3PAO or CMMC consultant whether the AI layer's GPU hardware needs to be added as a formal asset in your asset inventory, which it typically does if it processes CUI.
  • Use the same identity provider and access control mechanism already governing Costpoint access for the AI layer's service accounts, rather than a separate authentication scheme.
  • If any part of the stack (model weights, orchestration software) is sourced from an external vendor, get clarity on export control and supply chain provenance, particularly for model weights from non-US labs.
  • Route all AI query logs into your existing SIEM or log aggregation tooling so continuous monitoring covers the AI layer without a separate review process.
  • Treat any drafted output that could become a deliverable to the government (an ICS schedule, a contract report) as requiring the same human review and approval chain it would without AI involvement.
  • Plan for periodic re-validation of the AI layer's boundary and data flow alongside your existing CMMC assessment or self-assessment cadence.

Deployment options

Air-gapped on-prem within the enclave

Contractors whose CMMC L2 boundary is an on-prem or co-located data center environment.

Model and retrieval layer run on GPU hardware physically located within the assessed boundary, with no network path outside the enclave required for inference.

Private cloud within the assessed boundary

Contractors whose CMMC L2 scope includes a GCC High or equivalent cloud tenancy already covering Costpoint or adjacent systems.

The model runs in a virtual environment inside the same cloud tenancy and network boundary, inheriting the tenancy's existing access control and monitoring configuration.

Hybrid with staged scope expansion

Contractors wanting to validate the architecture on a narrower, already-in-scope data set before expanding coverage.

AI capability is enabled first for a subset of already-in-boundary data (e.g. one program's finance data), with scope expanded to additional programs or data types after assessor-facing documentation is validated.

Compliance and data control

How the architecture supports your obligations. Certification and accountability stay with your organisation; the design keeps the evidence straightforward.

CMMC 2.0 Level 2

Keeping the model, retrieval index, and connector inside the existing assessment boundary avoids introducing a new external system that would need to be added to scope, and the deployment's audit logging is designed to support your assessment evidence.

NIST SP 800-171 (access control, audit, media protection families)

The AI layer inherits the same access control and audit logging controls already implemented for Costpoint and the surrounding enclave, rather than requiring a parallel control set to be designed and assessed.

DFARS 252.204-7012

Because inference never leaves the covered contractor information system boundary, the deployment avoids creating a new covered defense information transmission path that would need to be separately justified.

GCC High tenancy alignment

Where Costpoint or adjacent systems already run in a GCC High or equivalent tenancy, deploying the AI layer inside that same tenancy keeps the architecture consistent with the environment your assessor has already reviewed.

How an engagement runs

Phase 1 . 2-3 weeks

Discovery

  • -Review of current CMMC L2 boundary, SSP, and Costpoint hosting environment
  • -Data flow mapping for proposed AI use cases against CUI marking and access control requirements
  • -Alignment with your compliance lead or C3PAO consultant on scope implications

Phase 2 . 6-8 weeks

Pilot

  • -In-enclave model and connector deployment for one or two priority use cases
  • -Draft SSP language and asset inventory update for the AI layer
  • -Access control and audit log validation against existing NIST 800-171 controls

Phase 3 . Ongoing after pilot sign-off

Production

  • -Rollout to the full finance or program team within the assessed boundary
  • -Finalised SSP documentation and asset inventory entries
  • -Continuous monitoring integration confirmed with your security operations

Phase 4 . Following assessment cadence

Scale

  • -Extension to additional in-scope use cases (program management, contracts)
  • -Re-validation of boundary and data flow ahead of assessment or self-assessment cycles
  • -Documentation handoff to support future C3PAO assessments

Questions to ask any vendor, including us

A short list that separates real Deltek Costpoint AI work from a chatbot demo.

  1. Can you show, concretely, that CUI never leaves our assessed CMMC boundary at any point in the AI workflow?
  2. Will this deployment require an update to our SSP and asset inventory, and can you help draft that language?
  3. Does the AI layer's service account inherit our existing access control, or does it need a new identity and permission model?
  4. What is the export control and supply chain provenance of the model weights being used?
  5. How does the audit logging integrate with our existing SIEM and continuous monitoring process?
  6. Has this architecture been reviewed by, or built with input from, a CMMC-experienced compliance advisor?
  7. What GPU hardware is required, and does it need to be formally added as an in-scope asset?
  8. How do we handle re-assessment when the AI layer or model changes after go-live?

Frequently asked questions

Does adding AI to Costpoint automatically expand my CMMC assessment scope?

It depends entirely on where the AI runs. A public AI API almost always expands scope because CUI leaves your boundary to reach it. Running the model and retrieval layer inside your existing assessed enclave, using the same access controls and audit logging already in place, is designed specifically to avoid that scope expansion.

Is GCC High enough to make any AI tool CMMC-compliant?

No. GCC High covers the Microsoft 365 workloads it hosts, but a third-party AI tool integrated with Costpoint still needs its own review of where inference happens and what data it touches. If it calls an external model API, being in GCC High does not change that data flow.

What does our SSP need to say about an AI layer like this?

At minimum, a data flow description showing the AI layer stays within the existing system boundary, an asset inventory entry for the hosting infrastructure, and a description of how it inherits existing access control and audit logging. Your CMMC consultant or C3PAO should review the specific language before an assessment.

Can we pilot AI on Costpoint before finalising our CMMC documentation?

It is safer to document the data flow before go-live, even for a pilot, since assessors respond far better to a documented in-scope system than to something discovered informally. A short discovery phase to map the data flow before piloting is worth the time.

Does this replace the need for a CMMC consultant or C3PAO relationship?

No. This describes an architecture pattern for keeping AI inside your existing boundary; your CMMC consultant or C3PAO still needs to review the specific implementation and any resulting SSP or asset inventory changes.

What use cases make sense to start with inside a CMMC L2 enclave?

Variance commentary drafting and timesheet exception triage are reasonable starting points: they touch data already inside your assessed boundary, do not require new external access, and give the compliance team a small, well-defined scope to validate the architecture against.

How long does it take to get an AI pilot running inside an existing CMMC boundary?

A focused pilot typically takes six to eight weeks after a two to three week discovery phase, though the timeline depends on how quickly your compliance team and C3PAO consultant can review the proposed data flow and SSP language.

Talk it through with an engineer who knows Deltek Costpoint

Bring one real question your team cannot answer from the ERP today. We will map the data path, the model, and where it runs, and tell you honestly if AI is the wrong tool for it.