Skip to main content
Greypike's CMMC Knowledge Base

If you cannot find information about a compliance topic, please contact us for free support.

< All Topics
Print

CMMC Compliant MSP? How to Verify What Yours Claims

Being told you already have a CMMC compliant MSP is a comfortable thing to hear. You asked your IT provider where you stand and got a reassuring answer, something like you are covered, or our stack is CMMC compliant, or we handle all of that. It is worth about ten minutes of verification, because if it turns out to be wrong you will find out at the worst possible moment, which is the week a prime asks for documentation.

The point here is not that your provider is dishonest. Most are not. The point is that the word compliant means something specific in this context, the obligation sits with you rather than with them, and there is a short list of documents that either exists or does not. This article is part of Something Just Happened and You Need CMMC: A Triage Guide.

Three documents settle whether you have a CMMC compliant MSP

Ask for these by name. Give a deadline. The response tells you everything.

  1. The System Security Plan. A document describing your environment, your boundary, and how each of the 110 requirements in NIST SP 800-171 is met or not met at your company specifically. If what comes back describes the provider’s environment rather than yours, or arrives as a generic template with your name inserted, it is not a System Security Plan.
  2. The scoring worksheet. All 110 requirements, each marked implemented or not, with the point deductions applied and a total. It should show the assessment date and who performed it.
  3. The Plan of Action and Milestones. Every open gap, with a named owner and a target date. A real environment always has some. A POA&M that is empty is a warning sign, not a triumph.

If all three exist and describe your company, your provider has done serious work for you and you should say so. If they do not exist, then whatever your provider has been doing, a NIST SP 800-171 assessment is not part of it.

What a CMMC compliant MSP usually means by that phrase

What you hearWhat it usually meansDoes it satisfy the requirement
“Our stack is CMMC compliant”They use products marketed toward the defense sectorNo. Tools are inputs. Compliance is a documented state of your environment.
“We’re SOC 2 certified”They passed an audit against a different framework, covering their own operationsNo. SOC 2 does not map to the 110 requirements and it assesses them, not you.
“We’re a CMMC compliant MSP”Marketing language. There is no such certification for a provider to hold on your behalfNo, and the phrase itself should slow you down.
“We put you in GCC High”A real and genuinely useful step. See Microsoft 365 GCC vs GCC High for CMMCPartially. The tenant addresses a subset of requirements. It does not address policy, training, physical security, personnel screening or most of the rest.
“We did your assessment and posted your score”Actual compliance workLikely yes. Ask for the three documents above and verify the SPRS entry yourself.

The uncomfortable part: the obligation is yours

DFARS 252.204-7012 obligates the contractor. The annual affirmation in SPRS is signed by a senior official at your company, not at your provider. If the score is wrong, it is your name on it and your company that answers for it.

You can delegate the work. You cannot delegate the accountability, and no contract with a provider changes that. This is the single most expensive misunderstanding in the small contractor market, and it is worth saying out loud in a leadership meeting so that everyone understands who owns the risk.

Questions to put to a CMMC compliant MSP directly

Send these in an email. Written answers are worth far more than a call, both for your own clarity and for the file.

  • Do you store, process or transmit our controlled unclassified information, or do you provide security protection for the systems that do?
  • Which of the 110 requirements do you consider yourself responsible for, and which remain ours? Provide it as a written matrix.
  • What is our current SPRS score, when was the assessment performed, and who performed it?
  • Does our environment use FIPS validated cryptography for controlled information at rest and in transit? Name the validated module. Note that FIPS 140-2 certificates move to historical status on September 21, 2026, so a certificate number alone is no longer a complete answer.
  • If we experience a cyber incident, who reports it to DIBNet within 72 hours, and does that person hold a DoD medium assurance certificate today?
  • Do you use offshore staff or subcontractors with administrative access to our systems?

For what a provider is actually on the hook for under the rules, rather than under its own marketing, see CMMC Requirements for Managed Service Providers.

That last question matters more than it looks. Administrative access to a system holding controlled information is a scoping question, and an answer involving personnel outside the United States needs to be understood before, not after, a customer asks.

Fix the contract, not just the conversation

If your provider handles controlled information or protects the systems that do, the relationship needs to be documented properly. That means a responsibility matrix showing who owns which requirement, a written commitment that they will support your assessment with evidence when you ask, incident notification obligations with a timeline that lets you meet the 72 hour reporting window, and clarity on where your data physically resides.

Providers who do this work well will welcome the conversation because it protects them too. Providers who resist it are telling you something useful. If a prime is asking you the same questions in a spreadsheet, your prime just sent you a cybersecurity questionnaire covers how to answer with what your provider gives you.

If the answer comes back empty

You are not in crisis, you are simply at the beginning rather than the end. Assume no assessment has been done, and plan accordingly. The realistic path is scoping your boundary, writing a System Security Plan, scoring yourself honestly, posting the score and working a Plan of Action and Milestones. A focused company can produce all of that in a quarter. See 90 days to get compliant for how that quarter is spent.

Whether you keep the provider is a separate decision from whether you keep the schedule. Plenty of capable IT firms are excellent at operations and have simply never been asked to do compliance work. Ask clearly, judge the answer, and decide.

Frequently asked

Questions about this topic

Can a CMMC compliant MSP be certified on our behalf?
No. Certification applies to the organization holding the contract obligation, which is you. A provider can be assessed for its own environment and can carry out much of the work for you, but no provider certification transfers to your company or satisfies your obligation.
Does SOC 2 mean our provider meets NIST SP 800-171?
No. SOC 2 is a different framework with different criteria, and it assesses the provider’s operations rather than your environment. It can be useful evidence about the provider, and it is not a substitute for scoring your own systems against the 110 requirements.
Our provider moved us to GCC High. Are we compliant now?
Not by itself. A government community cloud tenant addresses a meaningful subset of the technical requirements. Policy, training, physical protection, personnel screening, incident response, media handling and audit review still have to be implemented and documented by you.
Who signs the annual affirmation?
A senior official of your company. It is a statement to the federal government that your posted score accurately reflects your environment. Your provider cannot sign it and your provider does not carry the consequences if it is wrong.
What if our provider refuses to give us a responsibility matrix?
Treat that as a material answer. A provider handling controlled information should be able to state in writing which requirements they cover. If they will not, you either need to produce the matrix yourself from what you can observe, or find a provider who will participate.
Is it worth switching providers over this?
Often not immediately. Switching is disruptive and expensive, and many capable firms simply have not been asked for compliance work before. Ask the questions, give them a reasonable window to respond, and judge by the response rather than by the marketing on their website.

The audit is gone. The liability isn't.

Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.

Talk to Greypike about SPRS Attestation Assurance

Greypike Inc.

SBA-certified Veteran-Owned Small Business

Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff

CAGE 9WVS6 · UEI N6CJNGDARFM5

(703) 214-9246 info@greypike.com greypike.com

Tags:
Table of Contents