CMMC for MSPs

    CMMC for MSPs and MSSPs: External Service Provider Obligations

    If you manage IT, security, or compliance services for defense contractors, you're an External Service Provider under 32 CFR Part 170. That status carries real obligations: you may need your own CMMC certification, you must publish a Customer Responsibility Matrix, and your clients' assessors will inspect what you control on their behalf. This page covers when MSPs need to certify, how inheritance actually flows to clients, and what a clean ESP package contains.

    What 32 CFR 170 says about ESPs

    The CMMC Program rule defines an External Service Provider (ESP) as anyone outside the contractor's boundary that handles, processes, stores, or transmits CUI, or that provides security-relevant services. MSPs and MSSPs almost always fit one or both.

    If the MSP processes, stores, or transmits CUI: the MSP itself must be CMMC Level 2 certified, separately from the client. That's the strict reading of the rule and the safest assumption for a 2026 assessment.

    If the MSP only provides security-relevant services without touching CUI (vulnerability scanning, EDR management, log monitoring of non-CUI systems): the MSP doesn't need its own cert, but its controls are inspected as part of the client's assessment.

    How inheritance flows to clients

    An MSP closes objectives for a client only via a documented Shared Responsibility Matrix — sometimes called a Customer Responsibility Matrix in MSP parlance. Each NIST 800-171A objective is marked MSP-owned, shared, or client-owned. Without it, the client's C3PAO will treat every objective as client-owned and the inheritance evaporates. Athena auto-extracts the CRM from your client contracts and surfaces missing rows.

    What an ESP package must contain

    • CRM/SRM document per client, mapped to all 320 NIST 800-171A objectives.
    • MSP's own SSP excerpts for inherited controls — the client's assessor needs evidence the MSP actually implements what the CRM claims.
    • Service Level Agreement language covering incident notification, evidence access, audit cooperation, and CUI handling.
    • MSP's CMMC certification (if applicable) with score, level, and assessment date.
    • Personnel screening attestation for any MSP staff with access to client CUI environments.
    • Subprocessor disclosure — every tool/vendor the MSP uses in the client's pipeline.

    Common MSP failure modes

    • Same-stack-for-everyone trap. One CRM for 30 clients won't survive a single C3PAO assessment. Each client needs a tailored CRM.
    • "We're SOC 2 so we're fine." SOC 2 doesn't map cleanly to NIST 800-171A. Inheritance requires explicit NIST objective mapping.
    • Hidden subprocessors. MSPs that pipeline client data through unauthorized clouds. DoD looks at the whole chain.
    • No way to scale assessments. Manually rebuilding each client's CRM is unsustainable; automation is now table-stakes.

    How Athena helps MSPs scale CMMC delivery

    Athena's MSP portfolio view lets you manage CMMC posture across every client in a single dashboard — shared CRMs, per-client SSPs, evidence inheritance, and assessor-ready exports. Add a client in minutes; clone the controls you already implement; surface only the gaps unique to that client's CUI flow. See the partners program for revenue share and co-selling terms.

    Frequently asked questions

    Does my MSP need its own CMMC Level 2 certification?

    If your MSP processes, stores, or transmits CUI on behalf of clients, yes — DoD's strict reading of 32 CFR 170 requires a separate MSP certification. If you only provide security-relevant services without touching CUI, you don't need a cert, but your controls are inspected during each client's assessment.

    What is a Customer Responsibility Matrix (CRM)?

    The MSP-specific term for a Shared Responsibility Matrix — a document that maps every NIST 800-171A assessment objective to either the MSP, the client, or both. Without a CRM, the client's C3PAO assumes everything is client-owned and the inheritance disappears.

    Can one CRM cover all my clients?

    No. CRMs must be client-specific because each client's CUI flow, service tier, and contracted scope differ. A common base template is fine to accelerate authoring, but each delivered CRM must be tailored.

    What happens if my client's assessor can't reach me?

    Your client fails the inheritance. C3PAOs require evidence access for any objective the client claims to inherit from an MSP. Build assessor cooperation into your SLA from day one — including evidence response SLAs and named MSP points of contact.

    Further reading

    Related Athena pages and authoritative external references.

    Ready to act on this?

    Run the free Quick Score, then walk through the Assessment Pack.