Managed CUI Vault · responsibility matrix
Of 110 controls, we carry 64. 44 are shared. 2 stay yours.
Moving CUI into the Managed Vault changes your CMMC problem from 110 controls you own to a short list you share or keep. This is the exact list: every NIST SP 800-171 Rev 2 requirement, who carries it, what MacTech does as vault operator, what you still do as subscriber, and the evidence you keep.
Per control, not per assessment objective. The 320 objectives are adjudicated individually in Trust Codex; responsibility at that granularity is published only once every objective has been assigned. Rows marked azure-per-MAC-SEC-312 ride on Microsoft Azure services under the separate Microsoft/MacTech matrix.
64
MacTech carries
Implemented and evidenced by the vault operator.
44
Shared
Vault provides the mechanism; you operate part of it and keep evidence.
2
You carry
Outside the vault boundary: your people, your policy.
110 of 110 controls. Click a row for the provider and customer statements.
| Control | Title | Who carries it | Inherited from |
|---|---|---|---|
| 3.1.1 | Limit system access to authorized users, processes, devices | Shared | vault-platform |
| 3.1.2 | Limit access to types of transactions and functions | Shared | vault-platform |
| 3.1.3 | Control the flow of CUI | Shared | vault-platform |
| 3.1.4 | Separate duties of individuals | Shared | vault-platform |
| 3.1.5 | Employ least privilege | Shared | vault-platform |
| 3.1.6 | Use non-privileged accounts for non-privileged activities | Shared | vault-platform |
| 3.1.7 | Prevent non-privileged users from executing privileged functions | MacTech | vault-platform |
| 3.1.8 | Limit unsuccessful logon attempts | MacTech | vault-platform |
| 3.1.9 | Display privacy and security notices | MacTech | vault-platform |
| 3.1.10 | Use session lock after inactivity period | Shared | vault-platform |
| 3.1.11 | Terminate sessions after defined conditions | MacTech | vault-platform |
| 3.1.12 | Monitor and control remote access sessions | Shared | vault-platform |
| 3.1.13 | Use cryptographic mechanisms for remote access | MacTech | vault-platform |
| 3.1.14 | Route remote access via managed access control points | MacTech | vault-platform |
| 3.1.15 | Authorize remote execution of privileged commands via remote access | MacTech | vault-platform |
| 3.1.16 | Authorize wireless access prior to connecting | MacTech | azure-per-MAC-SEC-312 |
| 3.1.17 | Protect wireless access using authentication and encryption | MacTech | azure-per-MAC-SEC-312 |
| 3.1.18 | Control connection of mobile devices | Shared | vault-platform |
| 3.1.19 | Encrypt CUI on mobile devices and mobile computing platforms | Shared | vault-platform |
| 3.1.20 | Verify and control all external system connections | Shared | vault-platform |
| 3.1.21 | Limit use of portable storage devices | Shared | vault-platform |
| 3.1.22 | Control CUI posted or processed on publicly accessible systems | Shared | vault-platform |
| 3.2.1 | Ensure personnel are aware of security risks | Shared | vault-platform |
| 3.2.2 | Train personnel to carry out assigned security responsibilities | You | - |
| 3.2.3 | Provide security awareness training on recognizing threats | Shared | vault-platform |
| 3.3.1 | Create and retain system audit logs | MacTech | vault-platform |
| 3.3.2 | Ensure actions of individual users are traceable | Shared | vault-platform |
| 3.3.3 | Review and update logged events | MacTech | vault-platform |
| 3.3.4 | Alert in the event of an audit logging process failure | MacTech | vault-platform |
| 3.3.5 | Correlate audit record review, analysis, and reporting processes | MacTech | vault-platform |
| 3.3.6 | Provide audit record reduction and report generation | MacTech | vault-platform |
| 3.3.7 | Provide system capability that compares and synchronizes internal clocks | MacTech | vault-platform |
| 3.3.8 | Protect audit information and tools from unauthorized access | MacTech | vault-platform |
| 3.3.9 | Limit management of audit logging to subset of privileged users | MacTech | vault-platform |
| 3.4.1 | Establish and maintain baseline configurations | MacTech | vault-platform |
| 3.4.2 | Establish and enforce security configuration settings | MacTech | vault-platform |
| 3.4.3 | Track, review, approve, and log changes to systems | MacTech | vault-platform |
| 3.4.4 | Analyze security impact of changes before implementation | MacTech | vault-platform |
| 3.4.5 | Define and document access restrictions for changes | MacTech | vault-platform |
| 3.4.6 | Employ principle of least functionality | MacTech | vault-platform |
| 3.4.7 | Restrict, disable, or prevent the use of nonessential programs | MacTech | vault-platform |
| 3.4.8 | Apply deny-by-exception policy for unauthorized software | MacTech | vault-platform |
| 3.4.9 | Control and monitor user-installed software | MacTech | vault-platform |
| 3.5.1 | Identify system users, processes, and devices | Shared | vault-platform |
| 3.5.2 | Authenticate the identities of those users, processes, or devices | Shared | vault-platform |
| 3.5.3 | Use multifactor authentication for local and network access to privileged accounts | Shared | vault-platform |
| 3.5.4 | Employ replay-resistant authentication mechanisms | MacTech | vault-platform |
| 3.5.5 | Employ identifier management practices to prevent reuse | MacTech | vault-platform |
| 3.5.6 | Disable identifiers after defined inactivity period | Shared | vault-platform |
| 3.5.7 | Enforce minimum password complexity and change requirements | MacTech | vault-platform |
| 3.5.8 | Prohibit password reuse for a specified number of generations | MacTech | vault-platform |
| 3.5.9 | Allow temporary password use with immediate change requirement | MacTech | vault-platform |
| 3.5.10 | Store and transmit only cryptographically-protected passwords | MacTech | vault-platform |
| 3.5.11 | Obscure feedback of authentication information | MacTech | vault-platform |
| 3.6.1 | Establish operational incident-handling capability | Shared | vault-platform |
| 3.6.2 | Track, document, and report incidents | Shared | azure-per-MAC-SEC-312 |
| 3.6.3 | Test the organizational incident response capability | Shared | vault-platform |
| 3.7.1 | Perform maintenance on organizational systems | MacTech | azure-per-MAC-SEC-312 |
| 3.7.2 | Provide controls on the tools, techniques, mechanisms, and personnel for maintenance | MacTech | azure-per-MAC-SEC-312 |
| 3.7.3 | Ensure equipment removed for off-site maintenance is sanitized | Shared | azure-per-MAC-SEC-312 |
| 3.7.4 | Check media containing diagnostic programs for malicious code | MacTech | azure-per-MAC-SEC-312 |
| 3.7.5 | Require MFA to establish remote maintenance sessions | MacTech | vault-platform |
| 3.7.6 | Supervise maintenance activities of personnel without required access authorization | Shared | azure-per-MAC-SEC-312 |
| 3.8.1 | Protect system media containing CUI, both paper and digital | Shared | azure-per-MAC-SEC-312 |
| 3.8.2 | Limit access to CUI on system media to authorized users | Shared | vault-platform |
| 3.8.3 | Sanitize or destroy system media before disposal or reuse | Shared | azure-per-MAC-SEC-312 |
| 3.8.4 | Mark media with necessary CUI markings and distribution limitations | You | - |
| 3.8.5 | Control access to media containing CUI during transport | MacTech | azure-per-MAC-SEC-312 |
| 3.8.6 | Implement cryptographic mechanisms to protect CUI during transport | MacTech | vault-platform |
| 3.8.7 | Control the use of removable media on system components | MacTech | vault-platform |
| 3.8.8 | Prohibit the use of portable storage without identifiable owner | Shared | vault-platform |
| 3.8.9 | Protect the backup copies of CUI | Shared | azure-per-MAC-SEC-312 |
| 3.9.1 | Screen individuals prior to authorizing access to organizational systems containing CUI | Shared | vault-platform |
| 3.9.2 | Ensure CUI is protected during and after personnel actions (termination/transfer) | Shared | vault-platform |
| 3.10.1 | Limit physical access to authorized individuals | Shared | azure-per-MAC-SEC-312 |
| 3.10.2 | Protect and monitor the physical facility and support infrastructure | Shared | azure-per-MAC-SEC-312 |
| 3.10.3 | Escort visitors and monitor visitor activity | Shared | azure-per-MAC-SEC-312 |
| 3.10.4 | Maintain audit logs of physical access | Shared | azure-per-MAC-SEC-312 |
| 3.10.5 | Control and manage physical access devices | Shared | azure-per-MAC-SEC-312 |
| 3.10.6 | Enforce safeguarding measures for CUI at alternate work sites | Shared | vault-platform |
| 3.11.1 | Periodically assess risk to organizational operations and assets | Shared | vault-platform |
| 3.11.2 | Scan for vulnerabilities in organizational systems and applications | MacTech | vault-platform |
| 3.11.3 | Remediate vulnerabilities in accordance with assessments of risk | MacTech | vault-platform |
| 3.12.1 | Periodically assess the security controls in organizational systems | Shared | vault-platform |
| 3.12.2 | Develop and implement plans of action to correct deficiencies | Shared | vault-platform |
| 3.12.3 | Monitor security controls on an ongoing basis | Shared | vault-platform |
| 3.12.4 | Develop, document, and periodically update system security plans | Shared | vault-platform |
| 3.13.1 | Monitor, control, and protect communications at external boundaries | MacTech | azure-per-MAC-SEC-312 |
| 3.13.2 | Employ architectural designs to separate CUI from non-CUI | MacTech | vault-platform |
| 3.13.3 | Separate user functionality from system management functionality | MacTech | vault-platform |
| 3.13.4 | Prevent unauthorized and unintended information transfer | MacTech | azure-per-MAC-SEC-312 |
| 3.13.5 | Implement subnetworks for publicly accessible system components | MacTech | vault-platform |
| 3.13.6 | Deny network communications traffic by default | MacTech | vault-platform |
| 3.13.7 | Prevent remote devices from simultaneously connecting to the system and other resources | MacTech | vault-platform |
| 3.13.8 | Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI in transit | MacTech | vault-platform |
| 3.13.9 | Terminate network connections after defined period of inactivity | MacTech | vault-platform |
| 3.13.10 | Establish and manage cryptographic keys | MacTech | azure-per-MAC-SEC-312 |
| 3.13.11 | Employ FIPS-validated cryptography | MacTech | azure-per-MAC-SEC-312 |
| 3.13.12 | Prohibit remote activation of collaborative computing devices | MacTech | vault-platform |
| 3.13.13 | Control and monitor the use of mobile code | MacTech | vault-platform |
| 3.13.14 | Control and monitor the use of VoIP | MacTech | vault-platform |
| 3.13.15 | Protect the authenticity of communications sessions | MacTech | vault-platform |
| 3.13.16 | Protect CUI at rest | MacTech | azure-per-MAC-SEC-312 |
| 3.14.1 | Identify, report, and correct system flaws in a timely manner | MacTech | vault-platform |
| 3.14.2 | Provide protection from malicious code at appropriate locations | MacTech | vault-platform |
| 3.14.3 | Monitor system security alerts and advisories | MacTech | vault-platform |
| 3.14.4 | Update malicious code protection mechanisms | MacTech | vault-platform |
| 3.14.5 | Perform periodic scans and real-time scans of files from external sources | MacTech | vault-platform |
| 3.14.6 | Monitor systems to detect attacks and indicators of potential attacks | MacTech | vault-platform |
| 3.14.7 | Identify unauthorized use of organizational systems | Shared | vault-platform |
Source: docs/vault-edition/data/vault-responsibility-map.json · SHA-256 27528f3aae99142b9cf19daf4f64e445e438cdc75c4ea21312c09749b539f407 · synced 2026-09-16 · served live from Trust Codex
How to read it against a competitor
Enclave vendors quote inheritance percentages. Ask for the matrix behind the percentage: which controls, which axis (the vendor versus you, or Microsoft versus the vendor), and at what granularity. This one is the vendor-versus-you axis at control granularity, with the statements an assessor will read, and it is generated from the same file our own assessment package uses.
What EnclaveWatch does to keep the MacTech-carried rows evidenced every week is on the EnclaveWatch page. How our own enclave scores against the same 110 is on the proof page.