Skip to content
    August 22, 2026| Top Floor Team| 11 min read

    Does Your MSP Need CMMC? External Service Provider Rules

    Your managed service provider almost certainly does not need its own CMMC certification. Under 32 CFR 170.19, an external service provider (ESP) that handles your Controlled Unclassified Information or your Security Protection Data is assessed inside your assessment, and the rule says in as many words at 170.19(c)(2)(ii) that an ESP "may voluntarily undergo a CMMC certification assessment to reduce the ESP's effort required during the OSA's assessment." Voluntarily is the operative word. The cloud does not change that answer, but it adds a different obligation, and the obligation is yours rather than the provider's: if an external cloud service provider stores, processes, or transmits CUI for you, DFARS 252.204-7012(b)(2)(ii)(D) requires you to "require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline." That is an evidence obligation you carry about your provider, not a CMMC certificate your provider has to hold.

    So the question to put to your provider is not whether they are CMMC certified. It is what evidence they will hand your assessor, and this article works through how to tell the two kinds of provider apart, what each one owes, and how to test a "CMMC compliant" claim in about ten minutes.

    Key takeaways

    • An ESP that handles your CUI or Security Protection Data is assessed within your CMMC assessment; 32 CFR 170.19(c)(2)(ii) makes the ESP's own certification voluntary, not required.
    • A cloud service provider that stores, processes, or transmits CUI is the exception, and the requirement runs through DFARS 252.204-7012, not through CMMC.
    • Your MSP's tooling (remote management agents, the SIEM, the firewall it operates) is normally a Security Protection Asset and is in your scope whether or not the MSP holds anything.
    • "CMMC compliant" is not a status the rule defines. Ask for a customer responsibility matrix and a written split of who implements what.
    • If nobody can tell you which party implements a given requirement, the gap is yours. The obligation sits with the contractor holding the contract.

    The two questions 170.19 makes you ask first

    Section 170.19 does not start by asking who your vendor is. It asks what the vendor touches. Paragraph (c)(2)(i) puts it as a pair of questions the organization seeking assessment has to answer: "The OSA must consider whether the ESP is a Cloud Service Provider (CSP) and whether the ESP processes, stores, or transmits CUI and/or Security Protection Data (SPD)."

    That is the whole taxonomy. Is this provider a cloud service provider, and does CUI or Security Protection Data land on its systems? Those two answers put every vendor you have into one of four boxes, and the boxes have genuinely different consequences. A non-cloud ESP holding your Security Protection Data is assessed inside your assessment. A cloud provider holding your CUI has an obligation defined by a different instrument entirely.

    Security Protection Data is the term people miss. It is not CUI. It is the data your security tooling generates and consumes: log data, configuration baselines, vulnerability findings, authentication records. An MSP that never sees a single CUI-marked drawing still holds a great deal of Security Protection Data about the environment where those drawings live, and 170.19 puts that squarely in the picture.

    Write the inventory before you write anything else. Every provider, what they touch, and which of the two questions gets a yes.

    What your MSP owes when it is not a cloud provider

    For the ordinary managed service provider case, the answer is uncomfortable in a specific way: the MSP owes you nothing under CMMC directly, and you owe everything.

    The rule treats the services and assets an ESP provides as part of your assessment scope. In the asset vocabulary of the CMMC Level 2 Scoping Guide and 170.19's tables, the MSP's tooling is generally a Security Protection Asset, described in the rule's tables as an asset that provides security functions or capabilities to your assessment scope. Security Protection Assets are in scope, and they are assessed against the Level 2 requirements relevant to the capabilities they provide.

    Read that carefully, because it inverts the intuition. The MSP does not get assessed. The MSP's work gets assessed, as part of you, by your assessor, against requirements you are answerable for. If the MSP's remote monitoring platform does not enforce multifactor authentication for privileged access, that is your finding, on your report, with your senior official's affirmation sitting behind it.

    This is why the ESP certification question is a distraction and the documentation question is not. What you need from a non-cloud MSP is not a certificate. It is a written, requirement-by-requirement description of what they implement, what you implement, and what neither of you has implemented yet.

    The cloud exception, and what equivalency actually means

    If a cloud service provider stores, processes, or transmits your CUI, the obligation changes shape. 170.19's tables point at the FedRAMP requirements in DFARS 252.204-7012, and 7012(b)(2)(ii)(D) requires the contractor to require and ensure that the cloud service provider meets security requirements equivalent to the FedRAMP Moderate baseline.

    There are two ways a provider satisfies that. The clean one is a FedRAMP Moderate authorization you can verify. The other is equivalency, and equivalency is where contractors get hurt, because the word sounds like a lower bar and is not. The DoD CIO's memorandum on FedRAMP equivalency set out what a provider has to produce: an assessment by a FedRAMP-recognized third-party assessment organization against the full Moderate baseline, with a body of evidence a contractor can obtain and hand over. Secureframe's explainer walks the memo's document list (they sell compliance software, so read their framing accordingly), and the practical summary is that equivalency demands a complete, closed body of evidence rather than an open plan of action.

    The obligation is on you, not on the provider. The clause says the contractor shall require and ensure. A provider that declines to give you the evidence has not created a problem for itself. It has created one for you.

    A watch item, hedged, because it is moving

    FedRAMP itself is being restructured, and the restructure touches the artifacts equivalency is built from. IntelliGRC, a compliance platform vendor writing about a program its product tracks, reports that the 2026 FedRAMP rules eliminate or substantially restructure several of the documents the DoD equivalency memo enumerates, and shift the program's terminology away from authorization and the Low, Moderate and High impact labels.

    Treat that as a watch item, not as guidance. We have not seen a DoD instrument reconciling the equivalency memo with a restructured FedRAMP, and until one exists the honest position is that the contractual requirement in 7012 stands as written while the evidence a provider can produce may change form. If a provider tells you their equivalency posture is unaffected, ask them to put the reasoning in writing and date it.

    How to test a "CMMC compliant" claim in ten minutes

    Providers market CMMC readiness aggressively, and most of the claims are not lies so much as category errors. Three questions separate the two.

    "Which of the 110 requirements do you implement on our behalf, and which do we implement?" The answer should be a document, usually called a customer responsibility matrix or a shared responsibility matrix. If the answer is a conversation, there is no matrix, and an assessor asking the same question will get the same conversation.

    "Do you hold or handle our CUI, our Security Protection Data, or both?" A provider that cannot answer this cleanly has not thought about 170.19 at all. It is the first question the rule asks and it takes one sentence.

    "What will you give my assessor, and when?" Evidence has to be produced on someone's timeline. A provider that will supply configuration exports, access review records, and log samples within a defined window is a provider you can be assessed with. A provider that treats its own controls as proprietary is a provider whose controls you cannot evidence, which for assessment purposes is the same as not having them.

    If a provider volunteers that it has voluntarily undergone a CMMC assessment of its own, that genuinely helps, and the rule says why: it reduces the ESP's effort during your assessment. It does not remove your obligation to describe the shared responsibility split.

    When you should not change providers

    Here is the part that costs us work, because provider migrations are exactly the kind of project a consultancy gets paid to run.

    Most contractors do not need a new MSP. They need their current MSP documented. The single most common finding we see in this space is not an incapable provider; it is a capable provider whose work has never been written down against a requirement list, so nobody can say who does patching, who reviews access, or who keeps the logs. That is a documentation project measured in weeks, and it is far cheaper than a migration.

    Do not switch providers because a new one says "CMMC certified" and your current one does not. The rule makes that certification voluntary, so its presence tells you the provider invested in the ecosystem, not that your obligations shrank.

    Do not build a government cloud tenant because a vendor said you need one, before you have established whether you handle CUI at all. If you are not sure, that question comes first, and we work through it in FCI vs CUI. We have watched companies migrate a whole environment on the strength of a prime's mailing list.

    Do consider switching when a provider will not produce evidence, will not describe the responsibility split, or holds CUI in a cloud service it cannot evidence against the FedRAMP Moderate baseline. Those are structural, and no amount of documentation fixes them.

    Where Top Floor fits

    The work our CMMC practice does here is unglamorous: build the provider inventory, run 170.19's two questions across it, and turn the answers into a responsibility matrix an assessor can follow requirement by requirement. That artifact is what makes the difference between an assessment where your MSP is an asset and one where it is an unexplained hole.

    Where CMMC obligations sit alongside commercial framework work, running them as one program rather than three is usually the cheaper structure, which is what compliance as a service is for.

    We do not resell managed services and we do not perform CMMC certification assessments, so we have no reason to tell you to change providers. Usually we tell people not to.

    How to decide this week

    List every external provider that touches your systems, including the ones procured by a department rather than by IT. Shadow procurement is where unaccounted CUI paths live.

    Against each one, answer 170.19's two questions in writing: is it a cloud service provider, and does it process, store, or transmit CUI or Security Protection Data.

    For every provider that gets a yes on CUI in the cloud, send one email asking for its FedRAMP authorization or its equivalency body of evidence, and put a date on the request. The answer, or the silence, is your next quarter's priority.

    For every other provider on the list, ask for the customer responsibility matrix. If none exists, that is your documentation project, and it starts before any tooling decision.

    Frequently asked questions

    Does my MSP need its own CMMC certification?

    Generally no. Under 32 CFR 170.19(c)(2)(ii) an external service provider "may voluntarily undergo a CMMC certification assessment to reduce the ESP's effort required during the OSA's assessment", which makes the ESP's own certification optional rather than required. The services and assets the provider supplies are assessed inside your assessment instead, so what you need from the provider is evidence and a documented split of responsibilities, not a certificate. A provider that has been assessed voluntarily can reduce the work during yours, but it does not transfer your obligation.

    What if my cloud provider is not FedRAMP authorized?

    Then it has to meet security requirements equivalent to the FedRAMP Moderate baseline, and you have to be able to show it. DFARS 252.204-7012(b)(2)(ii)(D) puts the duty on the contractor to "require and ensure" that a cloud service provider storing, processing, or transmitting covered defense information meets that bar. In practice equivalency means an assessment against the full Moderate baseline by a FedRAMP-recognized assessor, with a body of evidence you can obtain from the provider and produce on request. A provider that will not supply that evidence leaves the exposure with you, because the clause is written against you and not against them.

    My MSP says it is "CMMC compliant". Is that enough?

    No, because "CMMC compliant" is not a status the program rule defines for a service provider. The defined statuses attach to organizations being assessed against a level, and 32 CFR 170.19 makes an ESP's own certification voluntary. Treat the claim as a starting point and ask three concrete questions: which of the requirements do you implement on our behalf, do you handle our CUI or our Security Protection Data or both, and what evidence will you give our assessor and on what timeline. Written answers to those three are worth more than any marketing status.

    Does an MSP that never touches CUI still land in my assessment?

    Usually yes, through Security Protection Data. 32 CFR 170.19 asks whether the provider processes, stores, or transmits CUI or Security Protection Data, and an MSP that runs your firewalls, your endpoint protection, or your logging holds a great deal of the second category even if it never sees a CUI-marked file. Assets that provide security functions to your assessment scope are Security Protection Assets, they are in scope, and they are assessed against the Level 2 requirements relevant to the capabilities they provide.

    Share Share on LinkedIn

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.