Preparing for the New Cybersecurity Expectations in Single Audits

By Mark Perez, on July 21st, 2026

The recent revisions to the Uniform Guidance introduce a significant shift in how organizations receiving federal funds will be evaluated during the Single Audit.  Historically, these audits focused primarily on financial controls and compliance with grant requirements. However, the updated guidance now incorporates certain expectations for IT security and cybersecurity practices.  This includes areas such as:

  • User access management
  • Multi‑factor authentication
  • Cybersecurity controls over protection of data involved in federal awards
  • System logging
  • Data protection
  • Incident response procedures
  • Oversight of cloud or third‑party service providers

What Recent Revisions to the Uniform Guidance Means for Federal Funding Recipients

In practical terms, this means that IT security is no longer treated as a background operational concern but as a formal compliance obligation tied directly to federal funding. During the Single Audit, the process may involve reviewing written policies, assessing the design and effectiveness of security controls, and requesting evidence that these controls are functioning as intended.  If gaps are identified—such as missing security policies, inadequate monitoring, or weak data security—these issues may be reported as audit findings, potentially leading to corrective action plans or questioned costs.

Cybersecurity Steps Organizations Should Take Now

For organizations, the implication is clear: cybersecurity readiness is now an essential component of federal grant compliance. Preparing for these changes involves reviewing existing IT practices, identifying weaknesses, and ensuring that documentation and evidence are in place before the new requirements take effect. This marks a meaningful elevation of cybersecurity expectations, affecting nonprofits, governments, and educational institutions alike.

Support for Your Compliance Journey

If you have questions about how these requirements apply to your organization, or if you would like assistance assessing your current IT control environment, please feel free to contact us directly.

Our FoxPointe Solutions team has extensive experience helping organizations strengthen cybersecurity programs and implement practical solutions that align with both regulatory expectations and business objectives. We would welcome the opportunity to discuss your specific needs and help you develop an effective path forward.

This material has been prepared for general, informational purposes only and is not intended to provide, and should not be relied on for, tax, legal or accounting advice. Should you require any such advice, please contact us directly. The information contained herein does not create, and your review or use of the information does not constitute, an accountant-client relationship.

Share on LinkedIn
Share on Facebook
Share on X

Written By

Mark Perez June 24
Mark Perez
Principal

Related Services