Managed CUI Vault · responsibility matrix

Of 110 controls, we carry 64. 44 are shared. 2 stay yours.

Moving CUI into the Managed Vault changes your CMMC problem from 110 controls you own to a short list you share or keep. This is the exact list: every NIST SP 800-171 Rev 2 requirement, who carries it, what MacTech does as vault operator, what you still do as subscriber, and the evidence you keep.

Per control, not per assessment objective. The 320 objectives are adjudicated individually in Trust Codex; responsibility at that granularity is published only once every objective has been assigned. Rows marked azure-per-MAC-SEC-312 ride on Microsoft Azure services under the separate Microsoft/MacTech matrix.

64

MacTech carries

Implemented and evidenced by the vault operator.

44

Shared

Vault provides the mechanism; you operate part of it and keep evidence.

2

You carry

Outside the vault boundary: your people, your policy.

110 of 110 controls. Click a row for the provider and customer statements.

ControlTitleWho carries itInherited from

Source: docs/vault-edition/data/vault-responsibility-map.json · SHA-256 27528f3aae99142b9cf19daf4f64e445e438cdc75c4ea21312c09749b539f407 · synced 2026-09-16 · served live from Trust Codex

How to read it against a competitor

Enclave vendors quote inheritance percentages. Ask for the matrix behind the percentage: which controls, which axis (the vendor versus you, or Microsoft versus the vendor), and at what granularity. This one is the vendor-versus-you axis at control granularity, with the statements an assessor will read, and it is generated from the same file our own assessment package uses.

What EnclaveWatch does to keep the MacTech-carried rows evidenced every week is on the EnclaveWatch page. How our own enclave scores against the same 110 is on the proof page.