The Scoping Guide handles SaaS through the External Service Provider Considerations section. A CRM is almost always an ESP; if it provides on-demand network access to configurable resources, it is also a CSP per the guide's definition.
The four-cell ESP and CUI matrix from the guide
| ESP type | Processes CUI? | Requirement |
|---|---|---|
| ESP that IS a CSP | Yes | Must meet FedRAMP requirements per DFARS 252.204-7012. Services are in the OSA's assessment scope. |
| ESP that IS a CSP | No | Not required to meet FedRAMP. Services are still in the OSA's assessment scope if they provide security functions or other in-scope role. |
| ESP that is NOT a CSP | Yes | Requires assessment. ESP services used to meet OSA requirements are in the OSA's CMMC assessment scope. |
| ESP that is NOT a CSP | No | No own assessment required. Services are in the OSA's assessment scope. May voluntarily seek a C3PAO assessment. |
Why commercial CRMs are typically a problem
Most commercial CRM products are CSPs. If your sales team pastes contract clauses, technical specifications, or DoD correspondence into the CRM, the CRM is processing CUI. That triggers the top row of the matrix and the FedRAMP requirement. Most general-market commercial CRM tiers are not FedRAMP-authorized at Moderate or higher and therefore cannot lawfully hold CUI under DFARS 7012. CRM vendors that serve government customers typically offer separate government-tier products (FedRAMP-authorized variants), but the authorization status varies by product, by tier, and over time. The two authoritative sources to consult are:
- FedRAMP Marketplace at marketplace.fedramp.gov, which lists every authorized CSO with its impact level (Moderate, High) and authorization status. This is the only authoritative source for whether a specific cloud offering holds an active FedRAMP authorization.
- The CRM vendor's own compliance documentation: trust center, service trust portal, compliance pages. These typically list FedRAMP authorization status, DoD impact level designation, and any FedRAMP Equivalency posture for the specific product and tier.
Verify the specific product and tier you intend to use, not just the vendor brand. Vendor brands often span both authorized and unauthorized tiers.
The three workable strategies
- Move the CRM to a FedRAMP-authorized variant. Cleanest path. The CRM is a CUI Asset (and an ESP that is a CSP processing CUI); fully in scope, lawful under DFARS 7012.
- Treat the commercial CRM as a CRMA. Document in the SSP that the CRM is capable of but not intended to process CUI, with security policy and practices preventing CUI entry. Per the Scoping Guide, CRMAs are not required to be physically or logically separated from CUI Assets; they are managed by the OSA's risk-based policies. The assessor may conduct a limited check if your documentation raises questions about how the policy is enforced.
- Move CUI workflows out of the CRM. Contract artifacts, technical data, and DoD correspondence happen in a different system designed for CUI. The CRM stays a CRMA or Out-of-Scope depending on architecture.
OSA documentation per the guide
For any ESP in the assessment scope, the OSA must document:
- The use of the ESP, its relationship to the OSA, and the services provided, in the SSP and in the ESP's service description and Customer Responsibility Matrix (CRM).
- The security requirement objectives that are the provider's responsibility versus the OSA's.
- Agreements supporting the OSA's information security objectives (SLAs, MOUs, contracts).
Common errors
- Treating the CRM as out-of-scope without enforcing the restriction. A policy alone makes the CRM a CRMA at best, not Out-of-Scope, and CRMAs are still in the assessment scope for documentation purposes.
- Assuming SOC 2 equals FedRAMP. They are different programs. Only FedRAMP authorization satisfies DFARS 7012 for CUI in cloud services.
- Assuming a vendor brand is uniformly authorized. Vendors often offer both general-market and government-tier products. The authorization status varies by product and tier; verify the specific tier you intend to use, not just the brand.
- Missing the Customer Responsibility Matrix. Per the Scoping Guide, the CRM document from the ESP is required to evaluate which requirements are the OSA's responsibility.
Sources
Get help scoping your SaaS tools.
Wrightbrained Security offers Lead Assessor scoping consultations for CRMs and other SaaS tools: independent review of which products are CUI Assets, CRMAs, or Out-of-Scope, with the FedRAMP and ESP documentation an assessor will look for.
Talk with a Lead Assessor