An outsourced provider enters a contractor’s CMMC assessment scope through the services and information they handle, including controlled unclassified information and security protection data. Under 32 CFR 170.19, non-cloud external services handling CUI are assessed within the contractor’s assessment, while a cloud service handling CUI must meet the applicable DFARS 252.204-7012 FedRAMP requirements. Services handling security protection data without CUI are assessed as security protection assets. The DoW CIO FAQ says a non-cloud MSP does not need its own CMMC assessment, but its relevant services still need coverage in the customer’s assessment and responsibility documentation.
Start with the service. “MSP,” “MSSP,” and “SOC” describe a business or function, but they do not settle the assessment boundary.
An outsourced help desk, security monitoring service, and hosted application may require different treatment even when one company sells all three. Draw those services separately before asking whether the provider has a certificate.
The provider scope table
32 CFR 170.19(c)(2) uses two questions: whether the provider is a cloud service provider, and whether its service handles CUI or security protection data, commonly shortened to SPD.
| Information handled | Cloud service provider | Non-cloud external service provider |
|---|---|---|
| CUI, with or without SPD | Meet the FedRAMP requirements identified in DFARS 252.204-7012 | Relevant services fall within the customer’s assessment scope |
| SPD without CUI | Relevant services are assessed as security protection assets | Relevant services are assessed as security protection assets |
| Neither CUI nor SPD | Does not meet this CMMC ESP definition | Does not meet this CMMC ESP definition |
Table 4 scopes the relevant services. This does not automatically place every system in the provider’s business inside the customer’s boundary.
SPD needs attention even when a provider says it never reads contract drawings. The DoW CIO FAQ, section E, addresses separate MSP and MSSP arrangements. Security services can matter to the assessment without holding the underlying CUI.
For the boundary record itself, use the CUI scoping guide.
Does the MSP need its own CMMC assessment?
A non-cloud MSP isn’t required to obtain its own CMMC assessment merely because it provides an in-scope service. Section E-A3 of the DoW CIO FAQ allows the MSP to elect its own assessment and explains how its services are addressed when it hasn’t done so.
The current FAQ’s E-A3 is explicit:
The MSP is not required to have its own CMMC assessment
Evidence is still needed. A provider’s lack of a standalone certificate does not remove the service from scope, and a certificate cannot describe every service sold under that provider’s brand.
Before relying on a provider’s assessment, compare the assessed boundary and services with the work being purchased. Record any gaps. The RPO, MSP and C3PAO role guide can help separate implementation support from assessment roles.
When is an MSP also a cloud provider?
The DoW CIO FAQ’s E-A5 looks at the relationships among the customer, MSP, and cloud provider. If the cloud tenant is subscribed or licensed to the organization seeking assessment, the MSP is not the CSP merely because it resells the service. If the MSP contracts with the CSP and modifies the basic cloud service, it may be a CSP.
“May” matters here. Classify the arrangement from the contract and service design. A reseller invoice alone is insufficient.
Request the subscription owner, service description, contract chain, and a diagram showing who operates each component. Then determine whether the organization is buying administration of its own tenant or a distinct cloud service from the MSP.
Cloud services holding CUI
DFARS 252.204-7012(b)(2)(ii)(D) requires the contractor to require and ensure that a cloud provider handling covered defense information meets security requirements equivalent to the FedRAMP Moderate baseline. The clause also addresses the provider’s compliance with paragraphs (c) through (g), covering incident reporting and related cooperation.
The CMMC FAQ identifies authorization and the Department’s equivalency requirements as routes to meeting the cloud baseline. A sales statement that a platform is “government ready” is insufficient evidence.
Identify the exact offering, boundary, and applicable supporting evidence. Customer configuration responsibilities still need owners.
Worked example: three providers, one contractor
This hypothetical example shows why the contract name alone is insufficient.
A manufacturer subscribes to a cloud tenant in its own name. An MSP administers the tenant. A separate MSSP receives security monitoring data. Assume the tenant stores CUI and the monitoring service handles SPD without CUI.
| Service | Initial treatment under the stated assumptions | Record to collect |
|---|---|---|
| CUI cloud tenant | Apply the CSP CUI requirements | Exact offering and FedRAMP authorization or equivalency evidence |
| Tenant administration | Evaluate the non-cloud ESP service within the customer’s assessment | Administration duties, access paths and assessment cooperation |
| SPD monitoring | Evaluate as security protection assets | Data description, security service boundary and responsibility allocation |
This is a starting classification, not a completed scope determination. If investigation shows that monitoring records contain CUI, the third row needs reconsideration.
In Deep Fathom’s view, the useful discovery question is “What information does this service actually receive?” Ask the operator who can demonstrate the data flow.
Build the responsibility record before the assessment
The program rule calls for the service relationships and responsibilities to be documented. Use a customer responsibility matrix with the system security plan. Our suggested working fields are:
- Service and boundary, including the information handled.
- Security requirement and the party operating the implementation.
- Customer configuration or oversight duties.
- Evidence the provider will make available, and how access will work.
- Incident contacts, response duties, and escalation arrangements.
- Changes that trigger a scope review, such as a new tenant or data feed.
The shared responsibility guide develops that allocation. A contract that says only “security included” leaves the practical questions open.
An offshore provider or international support team needs a separate review of access permissions, applicable export restrictions, and contract conditions. The CMMC scope table alone cannot establish whether a particular cross-border arrangement is permitted.
The pause does not answer the provider question
As of September 30, 2026, the DoW CIO program page says Phase II is suspended and the program remains in Phase I. That status belongs in assessment scheduling decisions. It does not establish that a contractor’s cloud, safeguarding, or incident-response obligations have disappeared.
Keep reviewing services against the contract and information flows. For a discussion with Deep Fathom, send a non-sensitive outline through contact: services used, tenant ownership, information categories, and the unresolved scope question. Don’t include CUI or credentials.
Sources and what they support
| Source | Use on this page |
|---|---|
| 32 CFR 170.19 | Provider scoping table and assessment responsibilities. |
| DoW CIO CMMC FAQ (July 2026) | External-provider and program explanations. |
| DFARS 252.204-7012 | Contract definitions, safeguarding, reporting, cloud and flowdown. |
| DoW CIO CMMC program status | Dated program status and assessment baseline. |