Cyberuptive

CMMC Level 2 · ESP scoping · Buyer diligence

A single global SOC MDR cannot hold your CUI. Here is the regulatory reason why.

Under 32 CFR Part 170 and DFARS 252.204-7012, an MDR provider that touches your CUI is not just a vendor. It is inside your CMMC assessment scope. A global-SOC architecture cannot pass that scope. This is why, with the exact regulatory citations and a five-question buyer diligence framework.

Executive summary

The rule is not "US-persons." The rule is "assessed as part of your assessment."

The most common mistake a defense contractor makes when shopping MDR for a CUI environment is treating "US-persons SOC" as the finish line. It is not the finish line. It is the first checkbox. The CMMC Level 2 Scoping Guide (p. 9) states that an External Service Provider is inside your assessment "if it meets CUI Asset and/or Security Protection Asset criteria." An MDR provider that observes, investigates, or responds to activity on your CUI environment holds Security Protection Data by definition. That places the provider inside your scope, and the provider’s architecture inside the assessor’s scope.

A single global SOC, one analyst pool, one SIEM tenant, one ticketing system, one identity plane, one detection-engineering team, spanning multiple international jurisdictions, cannot be walled off at the queue level. The assessor does not stop at the queue. The assessor asks where your Security Protection Data lives, who can reach it, under what background-check standard, and under what jurisdictional authority. If the answer to any of those questions crosses a non-US boundary, the provider has not segregated the environment. It has scheduled it.

The regulatory boundary

Three sources establish the ESP boundary. Read them in this order.

1. DFARS 252.204-7012(b)(2)(ii)(D): the FedRAMP equivalency rule

The clause is explicit: "If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline." The DoD CIO December 2023 memo defines equivalency as either full FedRAMP Moderate/High authorization or a FedRAMP 3PAO assessment showing 100% control compliance with a full body of evidence, SSP, SAP, SAR, and closed-out POA&Ms.

A commercial MDR platform delivered from a global multi-tenant SIEM does not carry a FedRAMP authorization or a 3PAO body of evidence by default. That does not mean the MDR provider is unusable everywhere, it means the provider is not, on its own, eligible to touch CUI in a CMMC Level 2 environment.

2. 32 CFR § 170.4: the ESP definition

The CMMC Program Rule (effective December 16, 2024) defines an External Service Provider to include cloud service providers, managed service providers, and managed security service providers whose services affect the protection of CUI or Security Protection Data. Under 32 CFR § 170.19(c)(2), the ESP relationship must be documented in the contractor’s System Security Plan and the ESP’s services are assessed as part of the contractor’s assessment.

The contractor cannot outsource the assessment obligation to the provider. The provider’s architecture becomes the contractor’s exhibit.

3. CMMC Level 2 Scoping Guide: the Security Protection Asset rule

The Scoping Guide (p. 5) is the sentence buyers should memorize: "Security Protection Assets are part of the CMMC Assessment Scope and are assessed against Level 2 security requirements that are relevant to the capabilities provided." The Guide then names its canonical example: "an External Service Provider (ESP)… that provides a security information and event management (SIEM) service may be separated logically and may not process CUI, but the SIEM does contribute to meeting the CMMC requirements within the OSA’s CMMC Assessment Scope."

Translated: an MDR provider that never touches your CUI can still be in scope on the basis of the Security Protection Data (SIEM logs, EDR telemetry, ticketing metadata, detection rules containing environment context) it holds. Logical separation does not remove the provider from scope. It only changes what evidence the provider must supply.

Why a single global SOC fails the boundary

Seven layers a segregated SOC separates. A queue only touches one.

Facility segregation is a physical decision. But the ESP boundary the assessor evaluates spans seven operational layers. A "US-persons SOC" claim built as a scheduling rule on top of a global platform touches only one of them.

LayerGlobal SOC + US-persons queueSegregated federal-grade SOC
FacilityShared with commercial operationsDedicated to CMMC-scoped work
Identity planeSingle global directorySeparate federal identity tenant
SIEM tenancyMulti-tenant, shared platformFedRAMP-authorized federal tenant
Ticketing systemGlobal ticketing schemaFederal ticketing, no commercial pivot
Detection engineeringGlobal content library, global maintainersFederal-scoped content, US-persons maintainers
Escalation pathGlobal on-call, cross-jurisdictionalUS-persons on-call, documented escalation
PersonnelUS-persons queue on shared poolDedicated US-persons analyst pool, no cross-touch

A C3PAO assessing a Level 2 environment can request evidence of separation at every one of these layers. The provider whose answer to six of the seven layers is "shared" is not offering a segregated service. It is offering a scheduling policy.

Under contract by November 2025?

If your MDR was chosen before the CMMC final rule, it is time to test it.

We run a 30-minute working session with your compliance lead and your MDR account team. Same five questions, on the record. You walk out with either a validated CMMC-eligible provider or a documented gap for your C3PAO.

Buyer diligence framework

Five questions to send your MDR provider before signing.

Copy-paste these into the provider evaluation email. Each question ties to the exact regulatory obligation it tests. If the provider cannot answer any one of them with an artifact, a package ID, a diagram, a written statement, a named reference, they are not yet ready to serve a CMMC Level 2 CUI environment.

  1. Q1

    ESP status

    "Are you an External Service Provider under 32 CFR § 170.4 for our environment, and will you hold our Security Protection Data?" If yes, the provider is inside your assessment scope and must be documented in the SSP. If the provider says no, ask how their SOC observes your CUI environment without SIEM logs or EDR telemetry.

  2. Q2

    FedRAMP evidence

    "Provide your FedRAMP Marketplace package ID or your 3PAO body of evidence for FedRAMP Moderate equivalency." This tests DFARS 252.204-7012(b)(2)(ii)(D). A commercial vendor without one of these two artifacts cannot process CUI-bearing telemetry as an external cloud service.

  3. Q3

    Segregation diagram

    "Send the physical and logical segregation architecture diagram for CMMC-scoped work." The diagram must show facility, identity, SIEM tenancy, ticketing, detection engineering, escalation, and personnel separation from any commercial or international operations. If the answer is a marketing page or a PDF one-pager, ask again.

  4. Q4

    Personnel exhibit

    "Provide the role-by-role personnel access statement for our environment." Who touches what, in what geography, under what background-check standard, and under what emergency-access procedure. This becomes a contractual exhibit: not a portal setting.

  5. Q5

    Named reference

    "Give us one named CMMC Level 2 defense contractor whose last assessment relied on you as an ESP, under NDA if needed." If the provider has never been named as an ESP in a real assessment, you are their first, which means the C3PAO is running the experiment on your contract.

How Cyberuptive is structured

Segregated by design, not by scheduling.

Cyberuptive operates a physically and logically segregated US-persons SOC on US soil for CMMC-scoped and CUI-bearing workloads. The delivery stack used for federal work runs on FedRAMP-authorized platforms. Cyberuptive is a Cyber AB Registered Provider Organization. Personnel access to those environments is restricted at the facility, identity, and tooling layer: not by feature toggle. Our US federal-grade SOC is physically and logically segregated from any current or future international facility; US customer telemetry never crosses into a non-US environment, and international commercial work is contracted and delivered separately from US federal and defense engagements. Tier-one security platforms trust Cyberuptive as a delivery partner for regulated markets.

If you are running a CMMC Level 2 assessment in the next twelve months and your current MDR was chosen before the December 2024 CMMC final rule, the five questions above will tell you in a week whether you have a provider or a project.

Frequently asked questions

Buyer questions we answer weekly.

  • Can a single global SOC MDR provider hold CUI under CMMC Level 2?

    Not without wholesale architectural change. A single global SOC pool shares identity, tooling, ticketing, escalation, and detection engineering across every jurisdiction its analysts sit in. Under 32 CFR § 170.4 and the CMMC Level 2 Scoping Guide, an MDR provider that processes your CUI or your Security Protection Data is an External Service Provider whose services are assessed as part of your assessment. A global SOC cannot document facility segregation, cannot document US-persons access to CUI, and cannot meet the DFARS 252.204-7012(b)(2)(ii)(D) FedRAMP Moderate equivalency requirement without segregating a federal enclave from its global platform.

  • What is a Security Protection Asset and why does it matter for MDR?

    The CMMC Level 2 Scoping Guide (p. 5) defines Security Protection Assets as assets that provide security functions or capabilities within the assessment scope, and states they "are part of the CMMC Assessment Scope and are assessed against Level 2 security requirements that are relevant to the capabilities provided." A SIEM, EDR, MDR platform, or ticketing system that receives your telemetry, alerts, or incident metadata is a Security Protection Asset. Even if it does not hold CUI directly, its role in protecting the CUI environment brings it inside the assessment scope.

  • Is a US-persons queue on a global SOC platform enough for CMMC?

    No. A US-persons routing rule on top of a global multi-tenant platform still shares the underlying identity system, the same SIEM tenant, the same ticketing schema, the same detection content, the same platform administrators, and the same emergency-access paths as the rest of the global platform. The CMMC assessment boundary is drawn at the facility and tenancy layer, not at the queue.

  • Is eSentire CMMC certified?

    No. eSentire’s own partner communications state that "while eSentire is not itself CMMC-certified due to its global SOC model, our approach helps suppliers build the capabilities required to meet CMMC Level 1 and Level 2 expectations." eSentire operates a shared analyst pool across multiple international geographies. For CMMC Level 2 environments that require US-persons access to CUI, a global SOC pool without physical and logical segregation for federal work does not meet the ESP boundary the CMMC Program Rule sets under 32 CFR § 170. See the source.

  • Is Arctic Wolf FedRAMP authorized?

    No. Arctic Wolf is not listed as authorized on the FedRAMP Marketplace as of August 2026. Independent security firms note that "Arctic Wolf provides security monitoring that supports several NIST 800-171 controls, but it is not FedRAMP authorized." Defense contractors using Arctic Wolf for a CUI environment should document the risk acceptance in the SSP and consult their C3PAO before assessment.

  • What does DFARS 252.204-7012(b)(2)(ii)(D) require of my MDR provider?

    It states, "If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline." If your MDR provider’s SIEM, SOAR, or ticketing platform receives CUI-bearing telemetry, it falls under this clause. The DoD CIO December 2023 memo further requires either full FedRAMP Moderate/High authorization or a FedRAMP 3PAO assessment showing 100% compliance with SSP, SAP, SAR, and closed-out POA&Ms.

  • Does an MDR provider automatically become an ESP under CMMC?

    Almost always, if the provider observes, investigates, or responds to activity on a CUI environment. The CMMC Level 2 Scoping Guide (p. 9) states an ESP is in scope "if it meets CUI Asset and/or Security Protection Asset criteria." The Scoping Guide gives a SIEM as its canonical example. An MDR is a SIEM plus analysts plus response, it is squarely inside the ESP definition.

  • What should I ask an MDR provider before I sign the contract?

    Five things, in writing: (1) whether they are an ESP under 32 CFR § 170.4 for your environment; (2) their FedRAMP Marketplace package ID or 3PAO body of evidence for FedRAMP Moderate equivalency; (3) the physical and logical segregation diagram; (4) the role-by-role personnel access statement with background-check standard; (5) a named CMMC Level 2 reference the C3PAO or RPO can confirm. If any one of these is unavailable, the provider is not yet operating at a CMMC-eligible tier.

  • Can a global-SOC MDR ever become CMMC-eligible?

    Yes, but only by building a segregated federal enclave that meets the ESP boundary requirements in its own right. Several federal-tier providers have done exactly that: CrowdStrike Falcon Complete GovCloud, Trustwave Government Solutions, Quzara Cybertorch, and Microsoft Defender Experts in GCC High deployments run distinct federal enclaves separated from their global commercial platforms. Global operations alone do not disqualify a company, the absence of a segregated federal enclave does.

Related reading: MDR for CMMC Level 2: The 4 disqualifiers buyers miss · Cyberuptive MDR service overview · CMMC 2.0 compliance services

Talk to a Honolulu human, not a sales bot.

Run the five questions on us.

Send us the same diligence email you would send any other MDR provider. We will answer every one of the five questions in writing before you have to schedule a call. That is the point.