CMMC Managed Compliance Services: What to Outsource, What You Still Own, and How to Choose (2026)
Bottom line up front
CMMC managed compliance services are ongoing, outsourced services that run the IT and security work behind your Cybersecurity Maturity Model Certification (CMMC) — usually a bundle of a managed service provider (MSP), a managed security service provider (MSSP), often a CUI enclave, and readiness support. For most defense contractors handling Controlled Unclassified Information (CUI) without a full internal security team, they are the practical path to Level 2. Here’s the part the provider landing pages won’t tell you: the company you hire to make CMMC easier can be the exact reason you fail your assessment.If your provider’s tools, logs, or cloud process, store, or transmit your CUI or Security Protection Data, that provider is pulled into yourassessment — and a provider that can’t prove its own security posture can take you down with it.
Fast verdict: which CMMC managed service do you actually need?
Most contractors don’t need “a CMMC provider.” They need the right combinationof operations, readiness, evidence tooling, and — only when the contract requires it — an independent assessor. Find your row.
| Your situation | Start here | Don’t hire yet | Why |
|---|---|---|---|
| FCI only, Level 1 (Self) | Light managed IT to hold the 15 safeguards | A C3PAO | Level 1 is an annual self-assessment. There is no third-party certification path for Level 1. |
| CUI, no System Security Plan yet | A readiness consultant (RPO) to scope and document, plus managed IT/security as needed | A C3PAO | Scope and evidence come before any assessment. Booking an assessor first wastes money. |
| CUI, weak or thin IT/security operations | A CMMC-capable MSP/MSSP | A standalone GRC platform on its own | Software tracks controls. It doesn’t operate them. |
| CUI living in email, files, and endpoints | A managed CUI enclave or CMMC-capable cloud/MSP | A full enterprise rebuild before you’ve scoped | Isolating CUI in a smaller boundary can shrink the assessment and the cost. |
| Your current MSP touches CUI, logs, or admin tools | An ESP scope review and a customer responsibility matrix | Any vague “CMMC package” | Your MSP’s role has to be documented and assessed. See the scope section below. |
| Contract names Level 2 (C3PAO) | Readiness support now, a separate C3PAO later | The same firm for both readiness and the assessment | By rule, anyone who helped prepare you in the prior three years can’t be on your assessment. |
| Contract names Level 3 | A Level 3-experienced readiness team and a DIBCAC plan | A generic Level 2-only shop | Level 3 is government-assessed and builds on a Level 2 (C3PAO) certification for the same scope. |
The hard truth — and why it’s good news
No legitimate engagement can both prepare or implement your CMMC program and then independently certify that same work. By rule and Cyber AB policy, anyone who served as a consultant to prepare your organization for anyCMMC assessment within the prior three years is barred from your Level 2 certification — and that bar covers the assessor’s whole organization and every member of its assessment team. So “one company, audit included” is either impossible or a conflict of interest. That forces a clean division: operations and readiness on one side, certification on the other. It makes the buying decision cleaner.
Get oriented in 60 seconds
Not sure which category fits? Our CMMC Managed Services path assessment turns your level, environment, and CUI footprint into a shortlist of provider types — and flags the scope traps specific to your setup. No sales calls until you ask for them. Don’t submit CUI, contract numbers, network diagrams, credentials, or other sensitive details.
Check my managed-service fit →What “CMMC managed compliance services” actually means
CMMC managed compliance services are outsourced services that help operate, monitor, document, and maintain the controls a defense contractor needs for CMMC readiness — typically managed IT, managed security, readiness consulting, evidence tooling, and CUI enclave operations. They are not a single product, and they are not the certification itself. The formal assessment that produces your CMMC status is a separate function performed under different rules.
The confusion is understandable, because “managed compliance” gets used as a catch-all. In practice it’s a bundle, and the pieces do very different jobs. Here’s the map we wish every contractor had before their first vendor call.
The DCR Managed-Compliance Shared-Responsibility Matrix
This is the table competitors don’t publish, because most of them sell one column of it. It shows what a provider can run, what stays yours no matter what you pay, the trigger that pulls each service into your assessment, and the evidence to demand before you sign.
| Service category | What the provider can run | What you still own | Scope trigger to verify | Evidence to demand before signing | Red flag |
|---|---|---|---|---|---|
| Managed IT (MSP) | Identity, endpoints, patching, device hardening, backup coordination, help desk, admin support | Your CUI/FCI boundary, policies, user behavior, affirmations, final responsibility for whether controls actually work | Its admin tooling, backups, or endpoints process, store, or transmit your CUI or Security Protection Data | Asset inventory, patch reports, admin-access model, endpoint baseline, evidence mapped to NIST SP 800-171 Rev. 2 | “We’ll make you CMMC compliant” without naming the assessor |
| Managed security (MSSP / SOC / MDR) | Logging, 24/7 monitoring, alert triage, vulnerability management, incident escalation | Incident-reporting decisions, the DFARS reporting workflow, evidence retention, business-impact calls | Its SIEM/MDR/logging tools store your CUI or Security Protection Data (log data counts) | Log-retention policy, alert samples, incident-response runbook, escalation SLA in writing, evidence ownership | A SOC that can’t say whether its logs are Security Protection Data |
| Readiness consulting (RPO) | Gap assessment, System Security Plan (SSP) and Plan of Action and Milestones (POA&M) support, control mapping, mock interviews | Actual implementation, a truthful self-assessment, your affirming official, the remediation budget | Consulting creates an independence conflict if the same firm later tries to assess the same scope within three years | Cyber AB Marketplace listing, staff credentials, defined deliverables, a clean handoff plan to an independent assessor | An RPO that also offers to “handle your C3PAO” for the same engagement |
| CUI enclave / managed secure cloud (CSP) | A controlled boundary for CUI, isolated users and data, supported data flows | Correct CUI identification, business-process design, keeping CUI inside the enclave | The cloud service stores, processes, or transmits CUI | FedRAMP Moderate authorization or documented equivalency evidence, the customer responsibility matrix, a data-flow diagram, tenant baseline | “Just buy GCC High” with no CUI workflow map |
| GRC / compliance platform | Control tracking, evidence workflow, dashboards, task ownership, exports | The accuracy of the evidence and whether controls truly operate | The platform stores your CUI or Security Protection Data | NIST Rev. 2 mapping, export format, access logs, data-handling statement, retention policy | Treating a 100%-complete dashboard as proof of compliance |
| C3PAO assessment partner | The formal Level 2 certification assessment, when a contract requires it | Readiness, remediation, truthful scope, and provider independence | A solicitation or contract names Level 2 (C3PAO) | Current Cyber AB Marketplace authorization, a scope agreement, a conflict-of-interest disclosure | A C3PAO that also sold you the implementation for the same scope |
The single most useful takeaway: a serious managed-compliance arrangement usually means MSP plus MSSP, frequently plus an enclave, plus a readiness consultant— and a separate assessor at the end. One credential, one vendor, one invoice through certification is not how the program is built.
Can you actually outsource CMMC compliance?
You can outsource the work. You cannot outsource the accountability.An MSP or MSSP can operate your technical and security controls and produce the evidence behind them, but you — the contractor — still own your assessment scope, your contract obligations, your truthful self-assessment results, your Supplier Performance Risk System (SPRS) submissions, your annual affirmation, and every remediation decision. A provider runs the controls. You answer for them.
That distinction matters because of how status is represented to the government. When a solicitation includes the CMMC clause, your company affirms its compliance. A named affirming official— a senior company official, not your MSP — attests that the controls are in place. If that affirmation is wrong, the exposure is yours, including under the civil False Claims Act, which the Department of Justice has been applying to cybersecurity misrepresentations.
The independence rule: your helper can’t be your grader
The rule that reshapes the whole buying decision
The organization that prepares or manages your compliance can’t also certify it.Cyber AB policy, implementing 32 CFR § 170.8(b)(17)(ii)(G), bars CMMC Ecosystem members from participating in a Level 2 certification assessment when they “previously served as a consultant to prepare the organization for any CMMC assessment within 3 years.” Per the Cyber AB Code of Professional Conduct, that bar applies to the C3PAO as an organization and every member of the assessment team.
Practically, that means your managed-compliance partner is your operations and readinesspartner. The certification comes from someone else. Anyone selling you a one-stop “we’ll get you certified” package is either misunderstanding the rule or ignoring it. See the C3PAO directory and the self-assessment vs. C3PAO guide.
You don’t have to guess whether your MSP is in scope.If your current provider touches your CUI, Security Protection Data, logs, or admin credentials, that relationship has to be documented and assessed. Get matched with providers who will map it with you — and put the responsibilities in writing before money changes hands.
Get matched with source-checked provider options for a scope review →Does your MSP need to be CMMC certified?
Not automatically — and there is no Cyber AB “certified MSP” credential to look for.Under 32 CFR § 170.4, your MSP or MSSP becomes an External Service Provider (ESP) “for the CMMC Program” only when CUI or Security Protection Data — such as log or configuration data — is processed, stored, or transmitted on the provider’s assets. Whether the provider needs its own assessment depends on what it touches; the question is never “is this a certified MSP?”
“CMMC-certified MSP” is a marketing phrase, not a credential. The things that actually exist and that you can verify are:
- C3PAO(CMMC Third-Party Assessment Organization) — authorized to perform Level 2 certification assessments.
- RPO(Registered Provider Organization) — registered with the Cyber AB to provide readiness consulting; staffed by RPs (Registered Practitioners).
- CCP (Certified CMMC Professional) and CCA(Certified CMMC Assessor) — individual certifications held by people on assessment teams.
So when an MSP says it’s “CMMC certified,” the right response is a question: certified as what? The legitimate green flags are that the firm holds RPO status, employs RPs/CCPs/CCAs, has passed its own CMMC Level 2 assessment as a contractor, or runs an enclave with verifiable FedRAMP standing.
DoD OIG finding: C3PAO authorization gaps (January 2025)
In January 2025, the DoD Office of Inspector General published an audit (Report No. DODIG-2025-056) of how third-party organizations get authorized to perform CMMC Level 2 assessments. Reviewing 11 of 48 C3PAOs, the OIG reported the Department authorized two without a signed C3PAO Agreement and Code of Professional Conduct, four without verifying the certification of their quality control leads, seven without confirming a certified assessor was on staff, and tenwithout verifying a certified quality control lead — the result, per the OIG, of no quality-assurance process. The takeaway: verify a provider’s current Cyber AB Marketplace status and credentials directly. Don’t take the brochure’s word for it.
How managed services change your CMMC scope (the part that decides pass or fail)
Managed services enter your CMMC assessment scope when a provider, its tools, or its cloud processes, stores, or transmits your CUI or Security Protection Data.Under 32 CFR § 170.19, your scope must be defined beforeassessment, and any External Service Provider relationship — what it does, how it connects to you, and who’s responsible for what — has to be documented in your System Security Plan and described in a customer responsibility matrix. Get this wrong and a great IT vendor becomes the reason you don’t pass.
Two terms govern everything here. An External Service Provider (ESP)is external people, technology, or facilities you use to provision or manage IT or cybersecurity services — and, for CMMC, one that has CUI or Security Protection Data on its assets. A Cloud Service Provider (CSP) is an ESP that delivers cloud computing services; a managed enclave or hosted CUI environment is typically a CSP. What the provider triggers depends entirely on what it touches.
The DCR ESP Scoping Consequence Table
| If your provider… | Its type under 32 CFR Part 170 | What the provider must do | What it means for your assessment | Primary source |
|---|---|---|---|---|
| Stores, processes, or transmits your CUI in its cloud | CSP handling CUI | Be FedRAMP Moderate authorized, or meet FedRAMP Moderate equivalency — 100% of the baseline, assessed by a FedRAMP-recognized 3PAO, documented in a Body of Evidence, with no POA&Ms left open from that assessment | Its FedRAMP authorization or equivalency evidence, service description, customer responsibility matrix, and your connecting infrastructure become assessment-critical. If a CUI-hosting cloud can’t meet the DFARS 252.204-7012 FedRAMP requirement, your use of it can block a defensible CMMC path | DFARS 252.204-7012(b)(2)(ii)(D); DoD CIO memo, Dec. 21, 2023; 32 CFR § 170.19 |
| Manages your IT/security and handles your CUI, but not as a cloud offering | ESP (not a CSP) handling CUI | No separate CMMC certification required by the rule | Its CUI-handling services are assessed within your assessment boundary against all Level 2 requirements and documented in your SSP, service description, and customer responsibility matrix. The ESP may voluntarily obtain its own CMMC certification to reduce assessment effort | 32 CFR § 170.19(c)(2) |
| Handles only Security Protection Data — e.g., a SIEM that stores your logs but never touches CUI | ESP/CSP handling only SPD | Provide a responsibility matrix describing the split of duties; not required to meet FedRAMP for SPD alone | Its systems are treated as Security Protection Assets, in scope and assessed against the requirements relevant to the capabilities they provide | 32 CFR § 170.19; DoD CMMC Level 2 Scoping Guide |
| Is itself a direct DoD contract holder | A contractor in its own right | Holds its own CMMC status at its required level | Doesn’t substitute for your obligation; verify separately | 32 CFR Part 170 |
| Touches no CUI or Security Protection Data | Not an ESP under the rule | Nothing CMMC-specific | Minimal assessment impact, but the determination has to be justifiable and documented | 32 CFR § 170.4; § 170.19 |
What “FedRAMP Moderate equivalent” really demands
If a provider tells you their cloud is “FedRAMP equivalent,” that claim has a specific, demanding meaning — and you inherit the responsibility to verify it. On December 21, 2023, the DoD CIO issued a memo defining FedRAMP Moderate equivalency. To qualify, a cloud service must demonstrate 100% of the FedRAMP Moderate baseline (built on NIST SP 800-53 Rev. 5), assessed by a FedRAMP-recognized third-party assessment organization, documented in a Body of Evidence, with no plans of action left open from that assessment. A verbal “we’re equivalent” is not that. Before you sign, get the FedRAMP authorization listing or the equivalency Body of Evidence in writing.
The five asset categories that define your boundary
CMMC Level 2 scoping (32 CFR § 170.19(c)(1), Table 3) sorts every asset into one of five buckets:
This is the highest-stakes decision on the page
If you’re evaluating a managed provider and you can’t yet answer “which of these buckets do their tools fall into?” — get matched with providers who will map it with you and put the responsibilities in writing before money changes hands.
Get matched with source-checked CMMC provider options →Which managed compliance model fits your situation?
The right model depends on your required CMMC level, your assessment path, your CUI footprint, your current IT maturity, and your environment.Most companies don’t need every service. They need the specific combination that matches where they are — and skipping the ones they don’t need is how a six-figure problem becomes a manageable one.
Start with your level, because it sets the assessment path
Level 1 (Foundational)
Applies to companies handling only FCI. It covers the 15 basic safeguarding requirements in FAR 52.204-21 and is met through an annual self-assessment. No third party. Most Level 1 companies need basic managed IT, not a heavy managed-compliance program.
Level 2 (Advanced)
Applies to companies handling CUI. Requires implementing all 110 security requirements in NIST SP 800-171 Revision 2, organized into 14 control families, assessed using NIST SP 800-171A. The assessment is either a triennial self-assessment or a C3PAO certification assessment— set by your contract clause. This is where serious managed compliance lives. See CMMC Level 1 vs Level 2 vs Level 3.
Level 3 (Expert)
Applies to the most sensitive programs. Layers 24 selected requirements from NIST SP 800-172on top of the Level 2 baseline and is assessed by the government — specifically DCMA DIBCAC. Level 3 requires a Final Level 2 (C3PAO) status for the same scope first.
NIST Rev. 3 red flag worth memorizing
NIST published Revision 3 on May 14, 2024 and withdrew Revision 2 in its own catalog. For CMMC, that changes nothing right now. CMMC Level 2 is anchored to Revision 2 through 32 CFR Part 170, reinforced by a DoD class deviation issued May 2, 2024, requiring contractors under DFARS 252.204-7012 to keep complying with Revision 2. C3PAO assessors are notauthorized to assess against Revision 3, and SPRS scores are calculated against Revision 2’s 110 requirements. If a provider tells you “Rev. 3 is the standard now, we’ll build to that,” treat it as a red flag — they’d be aligning your documentation to a baseline your assessor can’t use.
Then segment by environment
- Commercial Microsoft 365 or commercial cloud:if a commercial cloud service stores, processes, or transmits CUI for the contract, it must meet the DFARS 252.204-7012 cloud requirement. Many ordinary commercial tenants won’t satisfy that without a compliant architecture.
- Microsoft GCC High or AWS GovCloud: common CUI-capable choices; the right answer depends on your data, your existing stack, and cost. We compare them in the GCC High for CMMC guide.
- A managed CUI enclave: isolates CUI in a smaller boundary so the rest of your business stays out of scope.
- On-premises or hybrid, or manufacturing/OT environments: more complex scoping, often more managed-security work.
And segment by who you are in the supply chain
A prime and a small subcontractorbuy differently. A sub handling only FCI may need a light touch. A sub handling CUI under a prime’s flow-down needs at least Level 2 — and managed services are often how a 30-person shop reaches a bar it could never staff internally. See CMMC providers for small business for a side-by-side comparison.
What a real CMMC managed compliance program does every month
A serious managed-compliance program keeps controls operating and evidence current on a continuous cadence — not in a panic the month before assessment.The goal is a defensible, always-on record mapped to your scope and to NIST SP 800-171 Rev. 2. If a provider can only describe a one-time project, they’re selling readiness, not management.
| Cadence | What happens | Evidence it produces |
|---|---|---|
| Weekly | Patch exceptions, vulnerability triage, privileged-access changes, alert review | Tickets, scan reports, exception approvals |
| Monthly | Access reviews, endpoint-compliance checks, log review, POA&M updates, evidence sampling | Access-review records, SIEM summaries, POA&M status |
| Quarterly | SSP updates, policy review, vendor/ESP review, incident-response tabletop, risk review | SSP version history, updated responsibility matrix, tabletop report |
| Annually | Self-assessment support, affirmation support, leadership review, training refresh | Assessment record, affirmation package, training logs |
Evidence has to map to controls, not vibes
The fastest way to test a provider is to ask which control a given artifact proves. A defensible program ties its monthly outputs to specific NIST SP 800-171 Rev. 2 control families. Here’s the mapping to expect for the families that generate the most assessment evidence.
| Control family (NIST SP 800-171 Rev. 2) | Example monthly artifact | Why an assessor cares |
|---|---|---|
| Access Control (AC) | Access-review records, privileged-account changes | Confirms least privilege is enforced, not just documented |
| Audit & Accountability (AU) | SIEM/log-review summaries, retention proof | Confirms logging is on, reviewed, and retained |
| Configuration Management (CM) | Change tickets, baseline-deviation reports | Confirms changes are controlled against a known baseline |
| Identification & Authentication (IA) | MFA enrollment/exception reports | Confirms multifactor is actually applied to in-scope systems |
| Incident Response (IR) | IR tickets, tabletop reports | Confirms a working process, not a binder |
| System & Information Integrity (SI) | Patch/vulnerability reports, malware-protection status | Confirms flaws are found and fixed on a cadence |
| Risk / Security Assessment (RA/CA) | POA&M updates, SSP deltas | Confirms gaps are tracked and the SSP reflects reality |
Two principles separate strong providers from weak ones.First, every artifact should carry an owner, a date, the source system, the control it maps to, and where it’s retained. “We monitor everything” is not evidence. Second, evidence has to be fresh. A screenshot from fourteen months ago is a liability. When an assessor or a prime asks for proof, you want a current record, not an archaeology project.
How much do CMMC managed compliance services cost?
Expect roughly $8,000 to $20,000 per month for Level 2-grade managed compliance, with basic managed IT lower and full managed-security coverage at the top of that band. That recurring fee is separate from one-time readiness, any enclave licensing, and the independent C3PAO assessment.
For the assessment, the DoD’s small-entity estimate in the CMMC Final Rule puts a Level 2 (C3PAO) certification assessment plus initial affirmation at about $101,752, and roughly $104,670over the three-year cycle including annual affirmations — a figure that includes contractor and ESP support and an estimated $31,234 C3PAO engagement component. For a small contractor, realistic first-year totals for Level 2 commonly land between $75,000 and $150,000-plus. See our full CMMC Level 2 cost guide for a line-item estimator.
Your managed-services fee is not your assessment fee.Anyone who folds “certification” into a monthly managed-compliance price is blurring two things the rule keeps strictly separate.
Comparing quotes that don’t cover the same scope?Get matched by what you actually need — MSP, MSSP, RPO, enclave, or assessment — so you’re not stacking a help-desk contract against a full security-operations program.
Request scoped quotes from matched providers →What we verified for this guide
As of June 2, 2026.
- CMMC phased rollout — 32 CFR § 170.3(e) and DoD CIO CMMC program materials. Phase 1: November 10, 2025 – November 9, 2026; Phase 2 begins November 10, 2026.
- The CMMC Program Rule (32 CFR Part 170), effective December 16, 2024, including scoping rules in § 170.19, the ESP definition in § 170.4, and the customer responsibility matrix requirement.
- The conflict-of-interest rule in 32 CFR § 170.8(b)(17)(ii)(G) and the Cyber AB Code of Professional Conduct v2.0 (the three-year consultant prohibition).
- The acquisition rule, effective November 10, 2025, including contract clause DFARS 252.204-7021 and solicitation provision DFARS 252.204-7025, plus safeguarding and cloud requirements in DFARS 252.204-7012.
- NIST SP 800-171 Revision 2 (110 requirements, 14 families), its withdrawal on May 14, 2024, and its continued status as the CMMC Level 2 baseline under the DoD class deviation of May 2, 2024.
- The DoD CIO FedRAMP Moderate equivalency memo, December 21, 2023.
- DoD’s small-entity cost estimates in the CMMC Final Rule cost analysis — Federal Register, October 15, 2024.
- The DoD OIG audit of C3PAO authorization — Report No. DODIG-2025-056, January 10, 2025.
CMMC managed compliance services: frequently asked questions
These are the short answers to the questions that come up right after a contractor decides it may need outside help. Each is written to stand on its own.
What are CMMC managed compliance services?
They are outsourced services that help operate, document, monitor, and maintain parts of a CMMC readiness program — managed IT, managed security, readiness consulting, evidence tooling, or CUI enclave operations. They do not replace the contractor’s responsibility or a required certification assessment.
Can my MSP make us CMMC compliant?
An MSP can operate technical controls and produce evidence, but it cannot make your scope, score, status, or affirmation decisions, and it cannot answer for them. Final accountability stays with the contractor.
Does my MSP need to be CMMC certified?
Not automatically. Under 32 CFR § 170.4, the question is whether the provider is an ESP — which for CMMC means CUI or Security Protection Data is on its assets — and whether it is a Cloud Service Provider. There is no Cyber AB certified-MSP credential.
What’s the difference between an MSP, an MSSP, an RPO, and a C3PAO?
An MSP runs IT operations; an MSSP runs security operations; an RPO provides readiness consulting; and a C3PAO performs the formal Level 2 certification assessment when a contract requires it.
Can the same firm prepare us and assess us?
No. Under 32 CFR § 170.8(b)(17)(ii)(G) and the Cyber AB Code of Professional Conduct, anyone who served as a consultant preparing you for any CMMC assessment within the prior three years is barred from your Level 2 certification — and the bar applies to the C3PAO organization and every assessment-team member.
Does my cloud provider need to be FedRAMP authorized for CMMC?
If the cloud service stores, processes, or transmits CUI, it must be FedRAMP Moderate authorized or meet FedRAMP Moderate equivalency as defined in the DoD CIO memo of December 21, 2023, under DFARS 252.204-7012. The contractor is responsible for verifying it.
Is GCC High required for CMMC?
Not universally. The requirement is to protect CUI per your contract, DFARS, and the CMMC scoping rules. Microsoft GCC High is one common architecture; AWS GovCloud, a managed enclave, or other compliant environments can also work.
Is a CUI enclave better than full-enterprise CMMC?
It can be, when CUI is limited and the workflow can be isolated. It fails when users constantly move CUI between the enclave and ordinary business systems. Map the data flow before buying the boundary.
What is a customer responsibility matrix?
A customer responsibility matrix (CRM) defines what the provider owns, what you own, and what’s shared for the provider’s services, mapped to the relevant CMMC requirements. 32 CFR § 170.19 requires the ESP’s service description and CRM to be documented.
How much do CMMC managed services cost?
Commonly about $8,000 to $20,000 per month for Level 2-grade coverage, separate from one-time readiness and the independent C3PAO assessment. The DoD’s small-entity estimate for that assessment plus initial affirmation is about $101,752, roughly $104,670 over three years.
Is NIST SP 800-171 Revision 3 required for CMMC Level 2 right now?
No. NIST published Revision 3 in May 2024 and withdrew Revision 2 in its own catalog, but CMMC Level 2 remains anchored to Revision 2 under 32 CFR Part 170 and a DoD class deviation. C3PAOs assess against Revision 2, and SPRS scores use Revision 2’s 110 requirements.
What’s the bottom-line first step?
Find your contract clause, map where your FCI, CUI, and Security Protection Data live, classify your current providers and tools by scope, and request a customer responsibility matrix before you sign any managed-compliance statement of work.
Need help deciding what type of CMMC provider you need?
You don’t have to make this expensive decision alone, and you don’t have to start with a dozen cold calls. Tell us your level, your timeline, and your rough CUI footprint, and we’ll match you with source-checked provider options that fit your scope — readiness, managed operations, enclave, or assessment.
Get matched with source-checked CMMC provider options →Related guides
- CMMC External Service Provider Requirements: What MSPs, MSSPs & CSPs Actually Have to Do
- CMMC MSSP Providers: Scope, Evidence & Cost Guide (2026)
- CMMC Managed Service Providers: When Your MSP Is In Scope
- CMMC Level 2 Self-Assessment vs. C3PAO: Which Assessment Path Applies to You
- CMMC Level 2 Cost in 2026: Budget Ranges and Estimator
- Best CMMC Providers for Small Business
- GCC High for CMMC: When You Need It and When You Don’t
- CMMC Managed Enclaves: Scope Reduction Without GCC High Migration
- C3PAO Directory: Authorized CMMC Level 2 Assessors
- CMMC Readiness Checklist
Sources
- 32 CFR Part 170 — eCFR (current), incl. § 170.4 (ESP definition), § 170.8 (conflict of interest), § 170.19 (scoping and CRM), § 170.23 (flow-down); Federal Register Oct. 15, 2024.
- DFARS 252.204-7021 and 252.204-7025 (eff. Nov. 10, 2025), and 252.204-7012 — Acquisition.gov / eCFR Title 48.
- NIST SP 800-171 Rev. 2 and 800-171A — NIST Computer Security Resource Center; NIST SP 800-172 (Level 3).
- DoD CIO FedRAMP Moderate Equivalency Memo, December 21, 2023.
- DoD CIO CMMC Level 2 Scoping Guide — dodcio.defense.gov.
- DoD class deviation requiring NIST SP 800-171 Rev. 2 — May 2, 2024.
- DoD OIG Report DODIG-2025-056, January 10, 2025.
- Cyber AB Code of Professional Conduct v2.0 and Marketplace — cyberab.org. Last checked June 2, 2026.