CMMC ANSWER ENGINE

My MSP manages my IT — does my MSP need to be CMMC-certified?

JWJil Wright, Lead CMMC Certified Assessor · Last verified 2026-05-14

The MSP question is everywhere because almost every defense contractor relies on outside IT support. The CMMC Assessment Scope — Level 2 v2.13 (ESP Considerations section, citing 32 CFR § 170.19(c)(2)) is the governing source.

The threshold: what data resides on the MSP's assets?

The Scoping Guide's first test is whether data — CUI or Security Protection Data — resides on the MSP's assets. SPD includes:

  • configuration data required to operate a Security Protection Asset,
  • log files generated by or ingested by an SPA,
  • data related to the configuration or vulnerability status of in-scope assets, and
  • passwords that grant access to the in-scope environment.

If neither CUI nor SPD lives on MSP-owned assets, the MSP is not an ESP for CMMC purposes.

The four ESP patterns from the Scoping Guide

MSP typeProcesses CUI on its assets?Outcome
ESP that IS a CSPYesCSP must meet FedRAMP requirements per DFARS 252.204-7012. Services in OSA's assessment scope.
ESP that IS a CSPNoNot required to meet FedRAMP. Services in OSA's assessment scope if they provide security functions or other in-scope role.
ESP that is NOT a CSPYesESP requires assessment. The ESP services used to meet OSA requirements are within the OSA's CMMC assessment scope.
ESP that is NOT a CSPNoNo own CMMC assessment required. Services are in the OSA's assessment scope. ESP may voluntarily request a C3PAO assessment if it makes that business decision.

When is an MSP also a CSP?

The matrix above splits on whether the MSP is also a Cloud Service Provider, and the answer changes the FedRAMP picture. The L2 Scoping Guide gives a precise definition.

Per the Scoping Guide, “An ESP would be considered a CSP when it provides its own cloud services based on a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing that can be rapidly provisioned and released with minimal management effort or service provider interaction.”

The test: Does the MSP host its own cloud platform offering — its own SaaS, PaaS, or IaaS service — or does it just manage someone else’s cloud on your behalf?

Most MSPs are not CSPs. The Scoping Guide is explicit on this:

  • “An ESP (not a CSP) that provides technical support services to its clients would be considered a Managed Service Provider. It does not host its own cloud platform offering.”
  • “An ESP may utilize cloud offerings to deliver services to clients without being a CSP.”
  • “An ESP that manages a third-party cloud service on behalf of an OSA would not be considered a CSP.”

So an MSP that runs your Microsoft 365 GCC High tenant, your AWS GovCloud account, your Azure Government subscription, or your on-premises infrastructure is an ESP — but not a CSP. The cloud platform belongs to the underlying provider, not to the MSP.

An MSP is a CSP when it sells you its own hosted platform. Examples:

  • An MSP-branded backup-as-a-service running on infrastructure the MSP owns and operates.
  • An MSP-hosted SIEM platform where the MSP’s tenant aggregates data from many client environments.
  • An MSP-built ticketing or PSA system delivered as a multi-tenant SaaS.
  • An MSP that wraps a third-party cloud and re-sells it under its own brand with the MSP as the contracting party.

Why the distinction matters for CMMC:

  • An MSP that IS a CSP and processes CUI on its own platform must meet FedRAMP requirements per DFARS 252.204-7012 — the FedRAMP burden falls on the MSP-as-CSP.
  • An MSP that is NOT a CSP and processes CUI requires assessment, but the FedRAMP requirement attaches to whatever underlying cloud the MSP uses on your behalf (AWS GovCloud, Azure Government, your M365 GCC High tenant) — not to the MSP itself.

Determining which side of the line your MSP sits on is the prerequisite for reading the right row in the matrix above.

When an MSP is clearly in scope as an ESP

Most MSPs serving DIB contractors fall into one of these patterns and become ESPs:

  • The MSP runs a SIEM for your environment. Logs from your CUI Assets land on the MSP's SIEM — that's SPD on MSP assets, and possibly CUI fragments in log content. The MSP becomes an ESP and the SIEM is in your scope.
  • The MSP holds privileged credentials to your CUI Assets, in their own PAM system or password vault. Those credentials are SPD on MSP assets — ESP, in scope.
  • The MSP runs your patch management or EDR console. Configuration data and operational data live on MSP assets — ESP, in scope.
  • The MSP backs up your CUI Assets to MSP-owned storage. If the backups contain CUI, the MSP is an ESP that processes CUI on its own assets — assessment-required pattern.

By contrast, a pure staff-augmentation MSP — technicians who log into your environment with your credentials, use your tools, and leave nothing on MSP infrastructure — is not an ESP for CMMC purposes.

Why hiring a certified MSP often pays back

Even when the rule does not require the MSP to hold its own CMMC certification, choosing one that does carries practical advantages:

  • Independent verification of the MSP's controls. If you're relying on the MSP for security functions, an independent assessment of those functions reduces your supply-chain risk.
  • Assessor-fluent staff. A certified MSP's personnel have been through the assessment process themselves and understand what evidence the assessor will look for — they can present the MSP-side controls in the form the assessor expects.
  • Mature documentation. Certified MSPs typically have CRMs, SRMs, and SSPs already developed to assessment quality, which speeds your own assessment preparation.
  • Lower scoping risk. A certified MSP has thought through the OSA-vs-MSP responsibility split and can articulate it cleanly.
  • Better incident response coordination. A certified MSP understands DFARS 7012 incident reporting timelines and can coordinate with you under pressure.

The CMMC Marketplace at cyberab.org/Catalog lists C3PAOs and other organizations with assessor credentials. CMMC-certified MSPs are not a separate listing category but can be identified by their published CMMC posture and the credentials of their staff (CCPs and CCAs).

What you must document regardless of pattern

Per the Scoping Guide ESP Considerations section, the OSA's SSP must include:

  • The use of the ESP, its relationship to the OSA, and the services provided.
  • The ESP's service description and Customer Responsibility Matrix (or Shared Responsibility Matrix).
  • The agreements supporting the OSA's information security objectives (SLAs, MOUs, contracts).

Common errors

  • Assuming the MSP is automatically out-of-scope because they're a separate company. If MSP personnel administer your CUI environment, they are People SPAs (per the L2 Scoping Guide Table 2), and the MSP relationship is in your assessment scope.
  • Assuming the MSP needs CMMC certification because they touch your environment. Often they don't — if they're staff augmentation, or an ESP-not-CSP that doesn't process CUI on its own assets, no MSP assessment is required.
  • Treating SPD as if it were not in scope. Configuration data, log data, passwords are Security Protection Data per the Scoping Guide; if they reside on MSP assets, the MSP is an ESP — even if the MSP never sees CUI directly.
  • Missing the Customer Responsibility Matrix. The CRM (or SRM) is required documentation regardless of which ESP pattern applies.

Sources

  • CMMC Assessment Scope — Level 2 (v2.13) — External Service Provider Considerations — link
  • 32 CFR Part 170 — § 170.19(c)(2) — ESP requirements — link
  • DFARS 252.204-7012 — link
Rulebook version: CMMC 2.0 Final Rule (32 CFR 170); CMMC Assessment Scope — Level 2 v2.13
// READY WHEN YOU ARE

Is your security posture keeping you up at night?

Thirty minutes, no slide deck. Tell us what you're up against and we'll tell you honestly whether we can help.