CMMC · Vendor vetting
Does your MSSP need its own CMMC certification?
No, not under the final CMMC rule. But if your provider touches CUI or your security logs, its people, tools, and processes are assessed as part of your assessment. That makes vetting them your problem.
Published September 30, 2026 · Cyberuptive, Honolulu
The short answer
No. Under the final CMMC program rule, a managed security provider that isn't a cloud service provider doesn't need its own CMMC certificate to support you. But that's not the same as "doesn't matter." If the provider handles your CUI or your security data, its services sit inside your assessment scope, and your assessor will look at them.
The rule says it in one table. When a non-cloud External Service Provider (ESP) processes, stores, or transmits CUI, "the services provided by the ESP are in the OSA's assessment scope and shall be assessed as part of the OSA's assessment." When it handles only Security Protection Data, such as your logs, its services "shall be assessed as Security Protection Assets" (32 CFR 170.19(c)(2)). The same section adds that an ESP "may voluntarily undergo a CMMC certification assessment" to reduce the work during its clients' assessments.
Earlier drafts of the rule would have required ESPs to get certified. The final rule, effective December 16, 2024, dropped that requirement (A-LIGN).
Is your provider an ESP at all?
32 CFR 170.4 defines an ESP as "external people, technology, or facilities that an organization utilizes for provision and management of IT and/or cybersecurity services on behalf of the organization." Then it narrows it: to count as an ESP in the CMMC program, "CUI or Security Protection Data (e.g., log data, configuration data), must be processed, stored, or transmitted on the ESP assets" (32 CFR 170.4).
Security Protection Data covers more than people expect. The definition includes log files generated or ingested by a security tool, configuration data, vulnerability status of in-scope assets, and passwords that grant access to the in-scope environment. A SOC that collects your logs into its SIEM holds SPD. So does an MSP with admin credentials to your domain.
| What your provider touches | Cloud service provider | Not a cloud service provider |
|---|---|---|
| CUI (with or without SPD) | Must meet the FedRAMP requirements in DFARS 252.204-7012 | Services in your scope, assessed as part of your assessment |
| SPD only (logs, configs, credentials) | Services assessed as Security Protection Assets | Services assessed as Security Protection Assets |
| Neither CUI nor SPD | Not an ESP under CMMC | Not an ESP under CMMC |
Source: Table 4, 32 CFR 170.19(c)(2)(i).
For Security Protection Assets at Level 2, the rule tells assessors to "assess against Level 2 security requirements that are relevant to the capabilities provided." A SOC won't be tested on your physical visitor logs, but it will be tested on access control, audit logging, incident response, and personnel practices for the parts of the service it runs.
Where FedRAMP comes in
The FedRAMP question only applies to cloud providers that hold your CUI. DFARS 252.204-7012(b)(2)(ii)(D) says a contractor using an external cloud provider for covered defense information must ensure it meets "security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline," plus the clause's incident reporting, malware, preservation, and forensic access requirements (DFARS 252.204-7012).
That's why data flow matters more than vendor marketing. Some commercial MDR providers say in their contract terms that they don't want CUI at all. Arctic Wolf's current supplemental terms, for example, say it "does not require access to or delivery of Customer's Controlled Unclassified Information" and may stop ingesting data if CUI shows up (Arctic Wolf MDR terms). That's a reasonable position for a commercial service. It just means you have to design your logging so CUI never lands there, and document that in your SSP.
The Phase 2 pause doesn't change this
The Department of War suspended CMMC Phase 2 on July 13, 2026, so contracting officers can't currently require Level 2 (C3PAO) certifications (Morgan Lewis). Self-assessments and annual affirmations are still in force wherever a contract includes them, and DoW has said it will keep enforcing the underlying requirements through self-assessments and selected DoW-led assessments (Inside Government Contracts). Your self-assessment still has to cover your ESPs honestly. An SPRS score that ignores what your MSSP does is still a score you signed. More in what the Phase 2 pause changed.
See ours first
Ask for our customer responsibility matrix
We'll send the Cyberuptive service description and customer responsibility matrix mapped to the NIST SP 800-171 requirements our SOC supports, so your assessor sees exactly who owns what.
The questions to ask before you sign
These come straight from what the rule and DFARS require. A provider that can't answer them in writing will cost you time during your assessment.
- Will you store, process, or transmit our CUI, our SPD, or both? The answer decides which row of the table you're in.
- Can we see your service description and customer responsibility matrix? 32 CFR 170.19(c)(2)(ii) says both must describe the services, and your SSP must document the relationship.
- Where is your SIEM or data lake hosted, and is that platform FedRAMP Moderate or equivalent? This only matters if CUI will reach it, but you should know either way.
- Who can see our data, and from where? Some contracts allow access from outside the US by non-US citizens. Whether that's a problem depends on your data. See whether SOC analysts need to be US persons.
- How do you support DFARS 72-hour reporting? You file the report yourself. Your provider should hand you a complete draft in time. See our incident response retainer.
- Have you voluntarily completed a CMMC assessment? Not required, but it can shorten your assessment.
- Is an RPO badge the same as a certification? No. A Cyber AB Registered Provider Organization is authorized to give CMMC advice. It isn't a certification of the provider's own environment. Cyberuptive is an RPO, and we'll tell you that distinction up front.
Where Cyberuptive fits
We're a US-owned MSSP headquartered in Honolulu. For CMMC-scoped clients, we deliver SOC and MDR from a segregated US environment staffed by US-persons analysts, and we give you a service description and CRM that map our responsibilities to the NIST SP 800-171 requirements we support. Your organization still owns its CMMC status. We make sure the part we run holds up when your assessor asks about it. See CMMC compliance services and MDR for CUI environments.
Frequently asked questions
Does an MSSP need CMMC certification to support a defense contractor?
No. Under 32 CFR 170.19, an External Service Provider that is not a cloud service provider does not need its own CMMC certification. Its services are in the contractor's assessment scope and are assessed as part of that assessment. The rule notes that an ESP may voluntarily undergo a CMMC certification assessment to reduce the effort during its clients' assessments.
What counts as an External Service Provider under CMMC?
32 CFR 170.4 defines an ESP as external people, technology, or facilities used to provide IT or cybersecurity services on your behalf. To count as an ESP in the CMMC program, the provider must process, store, or transmit CUI or Security Protection Data, such as log data or configuration data, on its assets.
If my SOC provider only stores my logs, is it in scope?
Yes. Log files are Security Protection Data under 32 CFR 170.4. A provider that holds SPD but not CUI is in your assessment scope, and its services are assessed as Security Protection Assets against the Level 2 requirements relevant to the capabilities it provides.
Does a cloud-hosted SIEM need FedRAMP?
Only if it stores, processes, or transmits CUI. In that case DFARS 252.204-7012(b)(2)(ii)(D) requires the cloud provider to meet security requirements equivalent to the FedRAMP Moderate baseline. A cloud provider that holds only Security Protection Data is assessed as a Security Protection Asset instead.
What documents should an MSSP give me for my CMMC assessment?
At minimum, a service description and a customer responsibility matrix (CRM). 32 CFR 170.19 says the ESP relationship and services must be documented in your SSP and described in the ESP's service description and CRM.
Is a CMMC RPO the same as a certified provider?
No. A Registered Provider Organization is authorized by the Cyber AB to give CMMC advice and consulting. It is not a CMMC certification of the provider's own environment and does not let the RPO perform certification assessments. Cyberuptive is an RPO.