Managed IT and Managed Security · Leesburg, VA

CMMC

Can an MSP Help With CMMC, and Is the MSP in Scope?

Yes. A managed service provider can run many of the controls CMMC Level 2 asks for, but its services then fall inside your assessment. 32 CFR 170.16(c)(3) says an external service provider used to process, store or transmit CUI must be documented in your System Security Plan, described in the provider's service description and customer responsibility matrix, and its services assessed within your scope against all Level 2 requirements.

Capital Cyber. Sources are listed at the end of the article.

What an MSP Typically Runs

Many of the 110 NIST SP 800-171 Rev 2 requirements are daily IT operations: account management, multi-factor authentication, patching and flaw remediation, malware protection, audit logging and review, backups, configuration baselines and boundary protection. An MSP that runs these is doing the work an assessor will examine.

Why the MSP Comes Into Scope

Under 32 CFR 170.16(c)(3), the use of the provider, its relationship to you and the services it provides are documented in your SSP and in its service description and customer responsibility matrix, and the services used to meet your requirements are assessed as part of your assessment. Your own infrastructure connecting to the provider is in scope too, per 170.19(c)(2).

In practice that means the MSP needs to show its tools and procedures meet the requirements it takes on, and the split of responsibilities has to be written down before the assessment, not explained during it.

Cloud Services Are Held to a Different Test

A cloud service that processes, stores or transmits CUI must be FedRAMP Authorized at the Moderate baseline or higher, or meet security requirements equivalent to that baseline (32 CFR 170.16(c)(2)). DFARS 252.204-7012(b)(2)(ii)(D) sets the same FedRAMP Moderate equivalence test for any external cloud provider holding covered defense information.

How We Split the Work

Capital Cyber runs the IT and security. The CMMC work, the gap assessment, the System Security Plan and the POA&M, is delivered by our Compliance Division, Capital Cyber Compliance, so the documents describe the controls we actually run. Capital Cyber Compliance is not an Authorized C3PAO, which is what lets the same firm remediate what it assessed.

Frequently Asked Questions

4 QUESTIONS
Does using an MSP reduce my CMMC scope?

No. Services an external service provider uses to meet your requirements are assessed within your scope, and your infrastructure that connects to it is in scope too (32 CFR 170.16(c)(3) and 170.19(c)(2)).

What is a customer responsibility matrix?

A document that sets out which security requirements the provider meets and which remain yours. 32 CFR 170.16(c) expects it to be documented or referred to in your System Security Plan.

Does a cloud service holding CUI need FedRAMP?

It must be FedRAMP Authorized at Moderate or higher, or meet equivalent security requirements (32 CFR 170.16(c)(2); DFARS 252.204-7012(b)(2)(ii)(D)).

Is Capital Cyber a C3PAO?

No. Capital Cyber and its Compliance Division, Capital Cyber Compliance, are not an Authorized C3PAO and do not certify anyone.

Talk it through in 30 minutes.

A call is a conversation, not a pitch. Tell us how your business runs and we will tell you what we would manage.

Looking for CMMC? Our Compliance Division, Capital Cyber Compliance, delivers it.

Book a 30-Minute Call