Your client hired you to run their CUI environment. That decision moved your service inside their assessment.
Not next to it. Inside it.
Plenty of MSPs still read CMMC as the client's problem with a vendor questionnaire attached. If you process, store, or transmit the client's controlled unclassified information, or the security data that protects it, the service you sell sits in the CMMC Assessment Scope and is assessed as part of your client's assessment.
When Does Your MSP Actually Meet the CMMC Definition of an External Service Provider?
Start with the data, not the service name.
Table 6 to § 170.19(d)(2)(i) sets the ESP scoping requirements and ends with the line that settles most arguments: "A service provider that does not process CUI or SPD does not meet the CMMC definition of an ESP." Identical wording sits in Table 4 to § 170.19(c)(2)(i) for Level 2 scoping. Two data types. That is the whole gate.
CUI you already track. SPD is where MSPs get caught. § 170.4 defines Security Protection Data as data stored or processed by Security Protection Assets that are used to protect an OSC's assessed environment. Its examples: configuration data required to operate a Security Protection Asset, log files generated by or ingested by one, data on the configuration or vulnerability status of in-scope assets, and passwords that grant access to the in-scope environment.
Read that against your own service catalogue.
→ SIEM ingesting logs from the client's CUI enclave: SPD. → Password vault holding credentials into that enclave: SPD. → RMM pushing configuration to in-scope endpoints: SPD. → Vulnerability scanning of in-scope assets: SPD.
What breaks: the MSP that tells its client "we never touch CUI" and treats that as the end of the conversation. The SPD row alone puts your service in scope.
Does the ESP Sit Inside the Client's Assessment Scope, or Does the Scope Stop at the Boundary?
It does not stop at the boundary.
Table 6 gives the non-CSP answer plainly. Where the ESP processes, stores, or transmits CUI, "The services provided by the ESP are in the OSA's assessment scope and shall be assessed as part of the OSA's assessment." Where the ESP handles SPD without CUI, the services "are in the OSA's assessment scope and shall be assessed as Security Protection Assets."
§ 170.17(c)(6) states it operationally for a CMMC Level 2 certification assessment: the ESP services used to meet OSA requirements are assessed within the scope of the OSA's assessment against all Level 2 security requirements. And § 170.17(c)(6)(iii) pulls the OSA's on-premises infrastructure connecting to your offering into the CMMC Assessment Scope too. Your tenancy and their jump host are both in.
Being categorised as a Security Protection Asset is narrower, not lighter. Table 3 to § 170.19(c)(1) requires Security Protection Assets to sit in the asset inventory, to have their asset treatment documented in the SSP, and to appear in the network diagram of the CMMC Assessment Scope, then be assessed against the Level 2 security requirements relevant to the capabilities provided.
Is the Service a CSP Service or Not, and Why Does Table 6 Send Those Two Down Different Routes?
Table 6 has two columns: a CSP, and not a CSP. Same rows, different destinations.
Where the ESP processes CUI, with or without SPD:
→ CSP column: "The CSP shall meet the FedRAMP requirements in 48 CFR 252.204-7012." → Not-a-CSP column: the services are in the OSA's assessment scope and shall be assessed as part of the OSA's assessment.
§ 170.17(c)(5) unpacks the CSP route: the offering is FedRAMP Authorized at the FedRAMP Moderate or higher baseline per the FedRAMP Marketplace, or it is not authorized but meets security requirements equivalent to that baseline in accordance with DoD Policy.
Where the ESP handles SPD without CUI, the columns converge. CSP or not, the services are in the OSA's assessment scope and are assessed as Security Protection Assets.
So the fork only bites on CUI. Host the client's CUI in your own multi-tenant platform and you are arguing FedRAMP Moderate or equivalency. Administer CUI inside the client's tenant and you are assessed against all Level 2 security requirements inside their assessment.
Two programs, two cost bases. Decide per service, and write the answer down before an assessor asks.
What Has to Appear in the Customer Responsibility Matrix, and Where Does It Land in the Client's SSP?
The customer responsibility matrix carries your half of the controls.
§ 170.19(c)(2)(ii) and § 170.19(d)(2)(ii) use identical wording: the use of an ESP, its relationship to the OSA, and the services provided need to be documented in the OSA's SSP and described in the ESP's service description and customer responsibility matrix, which describes the responsibilities of the OSA and ESP with respect to the services provided.
§ 170.17(c)(6)(iii) closes the loop. The security requirements from the CRM must be documented or referred to in the OSA's SSP. A CRM that lives only on your extranet does not satisfy that.
The sequence that survives an assessment:
- Classify every service against the two Table 6 axes: CUI, SPD without CUI, or neither. Per client and per contract, not per product line.
- Decide, for each in-scope service, whether you deliver it as a CSP offering. That choice routes you to FedRAMP or into the client's assessment.
- List the Level 2 security requirements each service is used to meet. That list is the spine of the CRM.
- Write the service description and the CRM against it: for each requirement, who implements, what the client must still do, which evidence exists.
- Get the CRM requirements documented or referred to in the client's SSP. Confirm in writing that they did it.
- Map the client's on-premises infrastructure connecting to your offering. It is in scope and it will be assessed.
- Check the client recorded the in-scope assets in the asset inventory, documented asset treatment in the SSP, and drew them into the network diagram.
- Confirm the minimum assessment type your client's DoD contract dictates for you, then decide whether to take your own certification assessment voluntarily.
What breaks: a CRM written like a sales sheet that marks every requirement "shared." Shared is not an implementation statement. Findings land per requirement objective, and an objective with no named owner and no evidence is heading for NOT MET.
What Happens to the Assessment If the SSP Is Not Current on the Day the Assessor Arrives?
The assessment does not happen.
§ 170.24(c)(5) is blunt. OSAs must have a System Security Plan in place at the time of assessment to describe each information system within the CMMC Assessment Scope. "The absence of an up to date SSP at the time of the assessment would result in a finding that 'an assessment could not be completed due to incomplete information and noncompliance with 48 CFR 252.204-7012.'"
That is not one NOT MET requirement. That is the engagement stopping with the C3PAO's travel already booked.
Because your CRM has to be reflected in that plan, every service change between assessments is an SSP maintenance event for your client. New log source, new tenant, new privileged access path. Move a responsibility across the CRM line and the plan is stale.
The evidence bar is equally unforgiving. § 170.24(b)(1) requires evidence to be in final form and not draft, and names working papers, drafts, and unapproved policies as unacceptable. One narrow relief valve exists: § 170.24(b)(1)(ii) provides that temporary deficiencies appropriately addressed in operational plans of action shall be assessed as MET. But § 170.4 defines a temporary deficiency as a feasible remediation with a known fix available or in process, and states it is not based on an "in progress" initial implementation. Something you never built does not qualify.
If a requirement is scored NOT MET, § 170.17(c)(2) allows re-evaluation during the CMMC Level 2 certification assessment and for 10 business days following the active assessment period, provided additional evidence is available, the change cannot limit the effectiveness of other requirements already scored MET, and the CMMC Assessment Findings Report has not been delivered. Ten business days is the whole window to produce an export you should have staged.
Which NOT MET Requirements Are Allowed on a POA&M, and Which Ones Are Barred Outright?
§ 170.24(c)(6) sets the baseline. For each NOT MET security requirement the OSA must have a POA&M, and a POA&M is not a substitute for a completed requirement. Not implemented is assessed as NOT MET whether or not a plan describes it.
§ 170.21(a)(2)(iii) then restricts what may sit on the plan. Six Level 2 requirements are named as barred:
→ AC.L2-3.1.20 External Connections (CUI Data) → AC.L2-3.1.22 Control Public Information (CUI Data) → CA.L2-3.12.4 System Security Plan → PE.L2-3.10.3 Escort Visitors (CUI Data) → PE.L2-3.10.4 Physical Access Logs (CUI Data) → PE.L2-3.10.5 Manage Physical Access (CUI Data)
Look at the third entry. The System Security Plan requirement itself cannot be deferred. The document that has to carry your CRM is the one thing you cannot promise for later. And for Level 1 self-assessments, § 170.21(a)(1) states a POA&M is not permitted at any time.
§ 170.21(b) defines the POA&M closeout assessment as a CMMC assessment that assesses only the NOT MET requirements identified with a POA&M in the initial assessment. Closure must be confirmed within 180 days of the Conditional CMMC Status Date. Miss it and the Conditional CMMC Status for that information system expires.
Who performs it depends on the track. § 170.21(b)(1)-(3) assigns the Level 2 self-assessment closeout to the OSA in the same manner as the initial self-assessment, the Level 2 certification closeout to an authorized or accredited C3PAO, and Level 3 to DCMA DIBCAC.
How Must Assessment Artifacts Be Hashed and Retained, and Who Holds Them for Six Years?
In an MSP-run environment most of the evidence is generated by the MSP. The retention duty is not yours. § 170.17(c)(4) puts it on the OSC. The hashed artifacts used as evidence must be retained by the OSC for six years from the CMMC Status Date. To show they have not been altered, the OSC must hash the files using a NIST-approved hashing algorithm and provide the C3PAO with a list of the artifact names, the return value of the hashing algorithm, and the hashing algorithm, for upload into the CMMC instantiation of eMASS.
Name, hash, algorithm. Three fields, and they go to the government.
On the self-assessment track, § 170.16(c)(4) requires the same six-year retention by the OSA. § 170.9(b)(9) requires C3PAOs to keep all assessment related records for six years unless the CMMC PMO authorizes otherwise.
Your side is delivery discipline. If the config export, the log sample, or the policy attestation lives only in your tenant, your client cannot hash it, cannot hand the list to the C3PAO, and cannot hold it for six years.
What breaks: offboarding. Contract ends, tenant is deprovisioned, and the artifact set standing behind a live CMMC Status walks out with it. Put export-and-hash in your assessment support runbook, not in a renewal conversation.
Which CMMC Status Flows Down to the Subcontractors in Your Client's Supply Chain?
§ 170.23(a) applies CMMC requirements to primes and subcontractors throughout the supply chain at all tiers that will process, store, or transmit any FCI or CUI in performance of the DoD contract or subcontract, and requires primes to flow the requirements down. The mapping:
→ FCI only, no CUI: Level 1 (Self) is required. → CUI: Level 2 (Self) is the minimum. → CUI, and the prime contract requires Level 2 (C3PAO): Level 2 (C3PAO) is the minimum. → CUI, and the prime contract requires Level 3 (DIBCAC): Level 2 (C3PAO) is the minimum.
Now read that beside § 170.19(d)(2)(ii): the minimum assessment type for the ESP is dictated by the OSC's DoD contract requirement. You do not set your own level. Neither does your client's procurement lead. It arrives from the prime.
Carry twenty defense-supplier clients and this is a third-party risk problem pointed back at you: twenty customer responsibility matrices, twenty SSPs, twenty flow-down levels, all keyed to contracts you will never read.
Timing, one line: Level 2 (C3PAO) as a condition of award belongs to Phase 2, which § 170.3(e)(2) defines as beginning one calendar year following the start date of Phase 1, so plan for around November 2026.
Answer Once, Map Every Client
Every obligation above is a mapping problem before it is a security problem. Which service touches CUI. Which touches SPD. Which Level 2 security requirement each is used to meet. Where that lands in whose SSP, and who holds the hashed artifact.
That is structured data, not a spreadsheet. Every obligation traced to a verbatim quote from the source text, so the customer responsibility matrix you hand a C3PAO is source-grounded, not generated. The audit pack is a query, not a project.
If you run CMMC assessment prep for defense-supplier clients, start at agrc.ai/managed-service-providers, and see the obligation engine underneath it at agrc.ai/platform.
Compliance AI you can put in front of an auditor.
FAQ: ESP, CRM and Assessment-Scope Questions MSPs Keep Asking
We only manage the client's firewall and SIEM. Are we an ESP? Test the data, not the service name. Table 6 to § 170.19(d)(2)(i) states that a service provider that does not process CUI or SPD does not meet the CMMC definition of an ESP, and § 170.4 lists log files ingested by a Security Protection Asset as Security Protection Data. A managed SIEM pulling logs from in-scope assets handles SPD, so the service is in the OSA's assessment scope as a Security Protection Asset.
Does our own CMMC certification remove us from the client's assessment scope? The rule frames it as effort reduction, not exemption. § 170.19(d)(2)(ii) notes the ESP may voluntarily undergo a CMMC certification assessment to reduce the ESP's effort required during the OSA's assessment.
Can the client put CRM gaps on a POA&M and close them later? Some, and not the one that matters most. § 170.21(a)(2)(iii) bars CA.L2-3.12.4 System Security Plan from a POA&M, along with AC.L2-3.1.20, AC.L2-3.1.22, PE.L2-3.10.3, PE.L2-3.10.4 and PE.L2-3.10.5. Whatever does go on a plan must clear a POA&M closeout assessment within 180 days of the Conditional CMMC Status Date, or the Conditional CMMC Status expires.
Who is responsible for keeping the evidence we produced? The assessed party. § 170.17(c)(4) requires the OSC to retain hashed artifacts for six years from the CMMC Status Date and to give the C3PAO the artifact names, hash return values, and algorithm for upload into eMASS. You generate them. They hold them. Make the handover a contractual step.


