If you have three managed security proposals on your desk and they all list the same frameworks, the same tool logos and the same certification acronyms, the certifications are not the deciding factor. The deciding factor is scope: what each provider will put in writing that they own, what evidence they will hand you, and what happens to your obligations when they miss something.

This is not a knock on certifications. It is a recognition that a certification tells you a provider has passed a bar, not that they will do your specific work. Almost everyone selling to you has cleared the same bar. So you have to test something else.

Why do all the proposals look identical?

Because most of them are built from the same source material. Search for CMMC or NIST SP 800-171 guidance right now and you will find a long shelf of near identical vendor blog posts, all restating that SP 800-171 Rev. 2 contains 110 security requirements across 14 control families and that CMMC Level 2 is built on that same set. That is accurate. It is also public, which means it is not a differentiator.

The same effect shows up in proposals. Control family checklists, framework mappings and tool stacks converge because the underlying standard is published and the tool market is consolidated. When the inputs are identical, the output reads identical. Your job as a buyer is to ask the questions the template does not answer.

There is a second reason to look past the marketing right now. Commentary about CMMC rollout timing has been noisy, and you will see confident claims in both directions about what phase the program is in and when clauses appear in solicitations. Treat rollout timing as something to verify against the current rule text and your actual contracts, not something to take from a vendor blog or a LinkedIn post. What is not in dispute: if your contracts carry DFARS 252.204-7012, you owe implementation of NIST SP 800-171, and if they carry 252.204-7019 and 7020, you owe a current self assessment score in SPRS. Those obligations do not wait on certification scheduling. A provider who cannot speak clearly to that distinction is telling you something.

Which certifications actually matter, and who holds them?

Ask a simple question: does the certification belong to the company, to a person, or to a product, and will the certified person touch my account?

  • Company level attestations, such as a SOC 2 report on the provider's own operations, tell you about the provider's internal controls. Ask for the report, not the badge, and read the scope section and the exceptions.
  • Individual credentials belong to people. A firm can hold impressive resumes and still staff your account with a tier one technician. Ask who is assigned, what they hold, and whether that is contractual or aspirational.
  • Product claims deserve the most skepticism. No software product makes you CMMC certified. Certification applies to an organization being assessed, not to a tool in its stack. A vendor who says otherwise is either careless or hoping you will not check.

There is one certification question that is genuinely load bearing for defense work: whether cloud services used to process, store or transmit CUI meet the FedRAMP Moderate baseline or the DoD equivalency requirement described in DFARS 252.204-7012. That is a concrete, checkable claim. Ask for the specific evidence a provider would put in front of an assessor, not a sentence in a proposal.

Is the MSSP inside my compliance boundary or outside it?

This is the question most buyers skip, and it is the one that changes the price of everything.

Under CMMC scoping guidance, an external service provider is not automatically out of scope just because it is external. If a provider processes, stores or transmits your CUI, its services are in scope for your assessment. If it does not handle CUI but provides security protection to your in scope environment, it can still fall in scope as a security protection asset. The specifics live in the CMMC scoping and assessment guidance and have been revised over time, so confirm the current version rather than relying on a provider's summary.

The practical translation for a buyer:

  • Ask the provider to state, in writing, whether they will handle CUI in the course of delivering the service.
  • Ask what happens to your assessment if the answer is yes. Do they expect to be assessed as part of your scope, do they hold their own certification, or have they not thought about it?
  • Ask where your data, logs, tickets and backups physically live, and who at the provider can read them.

A provider who has genuinely done this work will answer in minutes because they have answered it before. A provider who has not will change the subject to their SIEM.

What should I ask for before I sign anything?

Ask for artifacts, not demos. A dashboard tour proves the tool works. It does not prove the provider produces the documents that survive scrutiny.

Request these, redacted:

  1. A customer responsibility matrix. This is the line by line split of who implements each requirement, you or them. If it does not exist, every gap is yours by default.
  2. A sample deliverable from a comparable client. A redacted gap assessment, a System Security Plan excerpt, a POA&M, or a monthly report. Look at whether findings are specific and actionable or generic.
  3. Their incident response runbook for your scenario. If DFARS 252.204-7012 applies to you, there is a rapid reporting obligation to DoD and a requirement to be able to report through DIBNet, which involves obtaining the right certificate in advance. Ask who files, who drafts, who preserves images, and how fast.
  4. Onboarding plan with named milestones. Not a phase diagram. Dates and owners.
  5. Offboarding terms. How you get your data, configurations and documentation back, in what format, on what timeline.

Then ask one interview question that is hard to fake: describe the last time you found a real problem at a client of my size and what you did in the first hour. Vague answers are the answer.

What contract terms decide whether this relationship works in year two?

Year one is implementation and everyone is attentive. Year two is where the value is either sustained or quietly abandoned. The terms that matter:

  • Scope change process. What counts as included, what triggers a change order, and who decides. Ambiguity here is where budgets go to die.
  • Evidence cadence. Contractual commitment to produce the documentation you will need for an assessment or a customer questionnaire, on a stated schedule, not on request.
  • Personnel continuity. Named team, notification when it changes, and a rule about who can be assigned.
  • Data ownership and portability, stated plainly.
  • Flow down obligations. If you are a defense supplier, your prime's clauses flow to you and some flow to your providers. Confirm the provider accepts the ones that apply.
  • Limitation of liability, read honestly. Most managed services cap liability at some multiple of fees. That is normal. Just know it before an incident, not after, and understand that the regulatory obligation stays with you regardless of what the contract says about damages.

What are the red flags?

  • "We will make you compliant." Compliance is an outcome of your operations. A provider contributes to it. Nobody sells it to you as a finished good.
  • A proposal with no customer responsibility matrix.
  • Certification claims about products rather than organizations.
  • Confident statements about regulatory timing with no citation.
  • Unwillingness to show a redacted deliverable.
  • A gap assessment that arrives as a tool generated score with no narrative, no evidence references and no prioritization.
  • Pressure to sign before scope is defined. Scoping is the work. A provider who wants to skip it is planning to bill you for it later.
The Good Sign

The inverse is worth noticing

Providers who ask you uncomfortable questions early, who tell you what they will not do, and who put boundaries in writing are usually the ones who have been through an assessment with a client and remember what it cost them. If you want to see how a provider like that structures the work, our managed compliance services page shows the model.

Frequently asked questions

What is the difference between an MSP and an MSSP?

An MSP manages IT operations: help desk, endpoints, networks, patching, uptime. An MSSP is accountable for security outcomes: monitoring, detection, response, and in many cases the documentation and control implementation behind a framework. Many firms do both, which is fine, but you should confirm which set of obligations is actually in your contract rather than assuming security is bundled.

Does hiring an MSSP make my company CMMC compliant?

No. CMMC certification applies to the organization seeking the contract, not to its vendors or tools. A capable provider can implement and operate a large share of the required controls and produce the evidence, but the assessment, the attestation and the legal exposure remain yours. Ask any provider to state in writing which specific requirements they own.

Do I still have to meet NIST SP 800-171 if CMMC assessment timing changes?

If your contracts include DFARS 252.204-7012, the requirement to implement NIST SP 800-171 comes from that clause and exists independently of the CMMC assessment program. Clauses 252.204-7019 and 7020 separately require a current self assessment score posted in SPRS. Confirm which clauses are in your specific contracts, because that, not the news cycle, determines what you owe.

Is my MSSP part of my CMMC assessment scope?

It can be. Under CMMC scoping guidance, an external service provider that processes, stores or transmits CUI is in scope, and a provider that supplies security protection to your in scope environment can be in scope as a security protection asset. Get the provider's position in writing and verify it against the current scoping guidance rather than a vendor summary.

What single document tells me the most about an MSSP?

The customer responsibility matrix. It forces the provider to state, requirement by requirement, what they do and what you do. Proposals persuade, and matrices commit. If a provider cannot produce one for the framework you care about, you are looking at a tool vendor with an account manager.

How do I compare two MSSPs whose pricing is close?

Stop comparing price against features and start comparing price against owned obligations. Total the number of requirements each provider contractually owns, add the artifacts they commit to produce on a schedule, and subtract anything they exclude. Two proposals within a few percent on price are often very far apart on who is holding the risk.

Your next step

If your next step is figuring out where you actually stand against the 110 requirements before you sign with anyone, apply for the in-kind CMMC Gap Assessment Grant through the Cyber Grants Alliance.

Apply for the CMMC Gap Assessment Grant

Sources

  • DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting (acquisition.gov)
  • DFARS 252.204-7019 and 252.204-7020, NIST SP 800-171 DoD Assessment Requirements (acquisition.gov)
  • NIST SP 800-171 Rev. 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (csrc.nist.gov)
  • CMMC Program rule, 32 CFR Part 170, and the associated DoD CMMC scoping and assessment guidance (dodcio.defense.gov)
  • Todyl, CMMC 2.0 Compliance Guide for MSPs Serving DoD Contractors, referenced as an example of vendor guidance that restates the same public standard