What 32 CFR 170 says about ESPs
The CMMC Program rule defines an External Service Provider (ESP) as anyone outside the contractor's boundary that handles, processes, stores, or transmits CUI, or that provides security-relevant services. MSPs and MSSPs almost always fit one or both.
If the MSP processes, stores, or transmits CUI: the MSP itself must be CMMC Level 2 certified, separately from the client. That's the strict reading of the rule and the safest assumption for a 2026 assessment.
If the MSP only provides security-relevant services without touching CUI (vulnerability scanning, EDR management, log monitoring of non-CUI systems): the MSP doesn't need its own cert, but its controls are inspected as part of the client's assessment.
How inheritance flows to clients
An MSP closes objectives for a client only via a documented Shared Responsibility Matrix — sometimes called a Customer Responsibility Matrix in MSP parlance. Each NIST 800-171A objective is marked MSP-owned, shared, or client-owned. Without it, the client's C3PAO will treat every objective as client-owned and the inheritance evaporates. Athena auto-extracts the CRM from your client contracts and surfaces missing rows.
What an ESP package must contain
- CRM/SRM document per client, mapped to all 320 NIST 800-171A objectives.
- MSP's own SSP excerpts for inherited controls — the client's assessor needs evidence the MSP actually implements what the CRM claims.
- Service Level Agreement language covering incident notification, evidence access, audit cooperation, and CUI handling.
- MSP's CMMC certification (if applicable) with score, level, and assessment date.
- Personnel screening attestation for any MSP staff with access to client CUI environments.
- Subprocessor disclosure — every tool/vendor the MSP uses in the client's pipeline.
Common MSP failure modes
- Same-stack-for-everyone trap. One CRM for 30 clients won't survive a single C3PAO assessment. Each client needs a tailored CRM.
- "We're SOC 2 so we're fine." SOC 2 doesn't map cleanly to NIST 800-171A. Inheritance requires explicit NIST objective mapping.
- Hidden subprocessors. MSPs that pipeline client data through unauthorized clouds. DoD looks at the whole chain.
- No way to scale assessments. Manually rebuilding each client's CRM is unsustainable; automation is now table-stakes.
How Athena helps MSPs scale CMMC delivery
Athena's MSP portfolio view lets you manage CMMC posture across every client in a single dashboard — shared CRMs, per-client SSPs, evidence inheritance, and assessor-ready exports. Add a client in minutes; clone the controls you already implement; surface only the gaps unique to that client's CUI flow. See the partners program for revenue share and co-selling terms.