If you cannot find information about a compliance topic, please contact us for free support.
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
SPRS & Self-Assessment
-
CMMC Fundamentals
-
Contract Clauses & Flowdown
- DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires
- What DFARS 252.204-7012 Requires, in Plain English
- DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
- DFARS flowdown requirements: Which Clauses You Must Pass to Your Subcontractors
- Flowdown: Which Clauses You Must Pass to Your Subcontractors
- Who Is Exempt from CMMC, and Why "We Only Make Parts" Usually Isn't
- What to Do When a DFARS Clause Appears in a Contract You Already Signed
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
-
Trigger Events & Urgent Situations
- Cybersecurity Questionnaire From Your Prime? Do This
- CUI Marked Drawings You Were Not Expecting? Do This
- Expired SPRS Score and a Bid Due? Fix It This Week
- Dropped Without CMMC? What a Prime Can Actually Do
- 90 Days to CMMC Compliance: What Is Really Possible
- DFARS 7021 Clause Found After Award? Read This First
- CMMC Compliant MSP? How to Verify What Yours Claims
- CUI in Commercial Microsoft 365: What to Do Now
- CMMC Level 2 Certification an RFP Wants? Bid Anyway
- CMMC Trigger Events: A Triage Guide for Contractors
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
-
Artificial Intelligence (AI)
-
Comparisons & Alternatives
- GCC High vs GCC vs Commercial Microsoft 365 for CUI
- CMMC Compliance Options: Enclave, Environment or Service
- Enclave vs Full Remediation: Which CMMC Path Fits
- PreVeil vs GCC High for Small Defense Contractors
- CMMC Platform vs Consultant vs Doing It In House
- RPO vs C3PAO vs Consultant: Who Does What in CMMC
- CMMC Compliance Software for Small Manufacturers
- Azure Government vs AWS GovCloud for CUI Workloads
- Virtual Desktop Enclave vs Managed Laptops for CUI
- Free NIST 800-171 Tools vs Paid Platforms: The Gaps
- Build vs Buy Enclave: What In House Actually Costs
CMMC Compliant MSP? How to Verify What Yours Claims
Being told you already have a CMMC compliant MSP is a comfortable thing to hear. You asked your IT provider where you stand and got a reassuring answer, something like you are covered, or our stack is CMMC compliant, or we handle all of that. It is worth about ten minutes of verification, because if it turns out to be wrong you will find out at the worst possible moment, which is the week a prime asks for documentation.
The point here is not that your provider is dishonest. Most are not. The point is that the word compliant means something specific in this context, the obligation sits with you rather than with them, and there is a short list of documents that either exists or does not. This article is part of Something Just Happened and You Need CMMC: A Triage Guide.
Three documents settle whether you have a CMMC compliant MSP
Ask for these by name. Give a deadline. The response tells you everything.
- The System Security Plan. A document describing your environment, your boundary, and how each of the 110 requirements in NIST SP 800-171 is met or not met at your company specifically. If what comes back describes the provider’s environment rather than yours, or arrives as a generic template with your name inserted, it is not a System Security Plan.
- The scoring worksheet. All 110 requirements, each marked implemented or not, with the point deductions applied and a total. It should show the assessment date and who performed it.
- The Plan of Action and Milestones. Every open gap, with a named owner and a target date. A real environment always has some. A POA&M that is empty is a warning sign, not a triumph.
If all three exist and describe your company, your provider has done serious work for you and you should say so. If they do not exist, then whatever your provider has been doing, a NIST SP 800-171 assessment is not part of it.
What a CMMC compliant MSP usually means by that phrase
| What you hear | What it usually means | Does it satisfy the requirement |
|---|---|---|
| “Our stack is CMMC compliant” | They use products marketed toward the defense sector | No. Tools are inputs. Compliance is a documented state of your environment. |
| “We’re SOC 2 certified” | They passed an audit against a different framework, covering their own operations | No. SOC 2 does not map to the 110 requirements and it assesses them, not you. |
| “We’re a CMMC compliant MSP” | Marketing language. There is no such certification for a provider to hold on your behalf | No, and the phrase itself should slow you down. |
| “We put you in GCC High” | A real and genuinely useful step. See Microsoft 365 GCC vs GCC High for CMMC | Partially. The tenant addresses a subset of requirements. It does not address policy, training, physical security, personnel screening or most of the rest. |
| “We did your assessment and posted your score” | Actual compliance work | Likely yes. Ask for the three documents above and verify the SPRS entry yourself. |
The uncomfortable part: the obligation is yours
DFARS 252.204-7012 obligates the contractor. The annual affirmation in SPRS is signed by a senior official at your company, not at your provider. If the score is wrong, it is your name on it and your company that answers for it.
You can delegate the work. You cannot delegate the accountability, and no contract with a provider changes that. This is the single most expensive misunderstanding in the small contractor market, and it is worth saying out loud in a leadership meeting so that everyone understands who owns the risk.
Questions to put to a CMMC compliant MSP directly
Send these in an email. Written answers are worth far more than a call, both for your own clarity and for the file.
- Do you store, process or transmit our controlled unclassified information, or do you provide security protection for the systems that do?
- Which of the 110 requirements do you consider yourself responsible for, and which remain ours? Provide it as a written matrix.
- What is our current SPRS score, when was the assessment performed, and who performed it?
- Does our environment use FIPS validated cryptography for controlled information at rest and in transit? Name the validated module. Note that FIPS 140-2 certificates move to historical status on September 21, 2026, so a certificate number alone is no longer a complete answer.
- If we experience a cyber incident, who reports it to DIBNet within 72 hours, and does that person hold a DoD medium assurance certificate today?
- Do you use offshore staff or subcontractors with administrative access to our systems?
For what a provider is actually on the hook for under the rules, rather than under its own marketing, see CMMC Requirements for Managed Service Providers.
That last question matters more than it looks. Administrative access to a system holding controlled information is a scoping question, and an answer involving personnel outside the United States needs to be understood before, not after, a customer asks.
Fix the contract, not just the conversation
If your provider handles controlled information or protects the systems that do, the relationship needs to be documented properly. That means a responsibility matrix showing who owns which requirement, a written commitment that they will support your assessment with evidence when you ask, incident notification obligations with a timeline that lets you meet the 72 hour reporting window, and clarity on where your data physically resides.
Providers who do this work well will welcome the conversation because it protects them too. Providers who resist it are telling you something useful. If a prime is asking you the same questions in a spreadsheet, your prime just sent you a cybersecurity questionnaire covers how to answer with what your provider gives you.
If the answer comes back empty
You are not in crisis, you are simply at the beginning rather than the end. Assume no assessment has been done, and plan accordingly. The realistic path is scoping your boundary, writing a System Security Plan, scoring yourself honestly, posting the score and working a Plan of Action and Milestones. A focused company can produce all of that in a quarter. See 90 days to get compliant for how that quarter is spent.
Whether you keep the provider is a separate decision from whether you keep the schedule. Plenty of capable IT firms are excellent at operations and have simply never been asked to do compliance work. Ask clearly, judge the answer, and decide.
Frequently asked
Questions about this topic
Can a CMMC compliant MSP be certified on our behalf?
Does SOC 2 mean our provider meets NIST SP 800-171?
Our provider moved us to GCC High. Are we compliant now?
Who signs the annual affirmation?
What if our provider refuses to give us a responsibility matrix?
Is it worth switching providers over this?
Keep reading
More in Trigger Events & Urgent Situations
- 90 Days to CMMC Compliance: What Is Really Possible →
- CMMC Level 2 Certification an RFP Wants? Bid Anyway →
- CMMC Trigger Events: A Triage Guide for Contractors →
- CUI in Commercial Microsoft 365: What to Do Now →
- CUI Marked Drawings You Were Not Expecting? Do This →
- Cybersecurity Questionnaire From Your Prime? Do This →
- DFARS 7021 Clause Found After Award? Read This First →
- Dropped Without CMMC? What a Prime Can Actually Do →
- Expired SPRS Score and a Bid Due? Fix It This Week →
Free tools
Get to an honest number faster
You will run this more than once: after any material change to your environment, and again before every annual affirmation. Both are free, and both are yours to keep.
Neither is a certified assessment, and neither pretends to be.
Official sources
The audit is gone. The liability isn't.
Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.
Talk to Greypike about SPRS Attestation AssuranceGreypike Inc.
SBA-certified Veteran-Owned Small Business
Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff
CAGE 9WVS6 · UEI N6CJNGDARFM5