13 Jul 2026CMMC Phase II suspended: no C3PAO assessments can be designated. DFARS 7012 and Rev 2 still apply.What changed, and what did not

Free · no sign-in · 13 questions, each with its rule

Is your MSP actually CMMC-ready? Grade them.

What a result proves: whether the provider you are paying can be evidenced inside your scope, or is a gap with a monthly invoice. Not sure what a full answer looks like? MacTech publishes its own responsibility matrix for all 110 requirements.

What does this provider touch?

An ESP handling CUI, at least partly as a cloud service

  1. 1Deal-breaker

    Have they given you a written service description and a Customer Responsibility Matrix that says, for each of the 110 requirements, whether they do it, you do it, or it is shared?

    The rule requires the relationship and the services to be documented in your SSP and described in the provider's service description and CRM; without one you cannot say what you inherit. 32 CFR 170.19(c)(2)(ii)

  2. 2Deal-breaker

    For any cloud service of theirs that stores, processes or transmits your CUI (including mail and files), is it FedRAMP Moderate authorized on the FedRAMP Marketplace, or documented as FedRAMP Moderate equivalent under DoD policy?

    Table 4 says a CSP handling CUI "shall meet the FedRAMP requirements in 48 CFR 252.204-7012"; equivalency needs the documentation DoD policy specifies, not a promise. 32 CFR 170.19(c)(2)(i), Table 4; DFARS 252.204-7012(b)(2)(ii)(D)

  3. 3Deal-breaker

    If they handle your CUI outside a cloud service, have they accepted in writing that those services are inside your CMMC assessment scope and will be assessed as part of your assessment (or do they hold their own CMMC Level 2 certification for them)?

    Table 4 puts a non-CSP's CUI services inside your scope; a provider that will not be assessed leaves you unable to close the requirement. 32 CFR 170.19(c)(2)(i), Table 4; 170.19(c)(2)(ii)

  4. 4Important

    If they hold your security protection data (logs, configurations, vulnerability data, credentials) without CUI, have they accepted that those services are assessed as Security Protection Assets?

    Table 4 treats SPD-only services as Security Protection Assets inside your scope; the provider that "only does monitoring" is still assessed. 32 CFR 170.19(c)(2)(i), Table 4; 32 CFR 170.4 (SPD)

  5. 5Deal-breaker

    Can they produce the CMVP certificate numbers for the cryptography protecting your CUI at rest and in transit on their systems?

    Without validated modules 3.13.11 scores −3 at best and −5 with no encryption; the certificate number is the evidence, not the vendor's brochure. NIST SP 800-171 3.13.11; DoD Assessment Methodology sliding scale

  6. 6Deal-breaker

    Will they meet the DFARS 7012 incident duties for an incident on their side: tell you fast enough for the 72-hour DIBNet report, preserve images and monitoring data for 90 days, and submit malware to DC3?

    The clock runs from discovery, and a provider who reports in a week has already cost you the deadline. DFARS 252.204-7012(c), (d), (e)

  7. 7Important

    Is DFARS 252.204-7012, or its substance, written into your agreement with them?

    The clause flows down without alteration whenever performance involves covered defense information; a handshake is not a flow-down. DFARS 252.204-7012(m)

  8. 8Important

    Do they enforce multifactor authentication for their own staff's access to your environment, including remote maintenance sessions?

    Their admin session is your privileged access; 3.5.3 and 3.7.5 do not stop at your payroll. NIST SP 800-171 3.5.3, 3.7.5

  9. 9Important

    Are the people who can touch your CUI screened, and will they tell you who they are?

    3.9.1 requires screening before access; an unnamed rotating support pool cannot be screened. NIST SP 800-171 3.9.1

  10. 10Important

    Can they give you audit logs and evidence on request, in a form you can hand to an assessor, within a defined time?

    An assessor asks you, not them; evidence you cannot obtain is evidence you do not have. NIST SP 800-171 3.3.1, 3.3.5, 3.12.3

  11. 11Important

    Have they documented where your CUI goes inside their operation: sub-processors, backup locations, support tooling, and who else can see it?

    Control of CUI flow (3.1.3) and protection of backups (3.8.9) both fail the moment a sub-processor appears that nobody wrote down. NIST SP 800-171 3.1.3, 3.8.9

  12. 12Good practice

    Do they hold standing administrative access to your environment with no approval trail on your side?

    Least privilege and separation of duties are yours to demonstrate; a provider with unreviewed standing admin defeats both. NIST SP 800-171 3.1.4, 3.1.5, 3.1.7

  13. 13Good practice

    Do they run their own NIST 800-171 program, with a current SSP and, if they hold DoD contracts, a score in SPRS?

    A provider that has never assessed itself will struggle to be assessed inside your scope. DFARS 252.204-7019, 7020 (where the provider is itself a DoD contractor)

The rules behind the questions

What is an External Service Provider under CMMC?
32 CFR 170.4 defines an ESP as external people, technology or facilities an organization uses for the provision and management of IT or cybersecurity services on its behalf, and adds that CUI or security protection data must be processed, stored or transmitted on the ESP's assets for it to count. A provider that touches neither is not an ESP, whatever it is called on the invoice.
Does my MSP need its own CMMC certification?
Not by rule. Table 4 to 32 CFR 170.19(c)(2)(i) puts a non-cloud provider's CUI services inside your assessment scope, to be assessed as part of your assessment; 170.19(c)(2)(ii) says the ESP may voluntarily undergo a CMMC certification to reduce its effort during yours. A cloud service holding your CUI is different: it must meet the FedRAMP requirements of DFARS 252.204-7012.
What is a Customer Responsibility Matrix and why does the grader treat it as a deal-breaker?
The document that says, for each requirement, whether the provider does it, you do it, or it is shared. 32 CFR 170.19(c)(2)(ii) requires the ESP relationship and services to be documented in your SSP and described in the provider's service description and CRM. Without it you cannot claim a single inherited control, so the grade cannot pass without one.
Is this an assessment of my provider?
No. It is a reading of your answers against the rules, and a letter that puts each open question to the provider with its citation. Their answers, and the evidence behind them, are what an assessor will look at.

From MacZine

Working notes on providers and flow-down

The full run →