10.1 Cloud Service Providers (CSPs): FedRAMP Moderate Equivalency & DFARS 7012

Key Takeaways

  • DFARS 252.204-7012(b)(2)(ii)(D) requires an external cloud service used for covered defense information to provide security equivalent to FedRAMP Moderate and support the clause’s incident-response duties.
  • A FedRAMP authorization applies to the specific cloud service offering and impact baseline; vendor reputation or an unrelated authorized product does not establish coverage.
  • Under current DoD FedRAMP Moderate equivalency policy, the contractor validates a complete body of evidence showing 100% baseline implementation at assessment conclusion and an annual FedRAMP-recognized 3PAO assessment.
  • The contractor remains responsible for reporting an applicable cloud compromise; it must ensure the CSP has an incident plan, promptly notifies the contractor, and supports DFARS 252.204-7012(c)–(g).
  • The CRM identifies inherited, shared, and customer responsibilities, and the assessment team verifies the OSC’s actual implementation rather than accepting blanket cloud inheritance.
Last updated: August 2026

Cloud Service Providers: FedRAMP Moderate, Equivalency & Shared Responsibility

Cloud use does not transfer an organization’s CMMC or contractual responsibility to a vendor. The correct analysis identifies the information handled, the exact cloud service offering, the governing contract clause, the FedRAMP route, the on-premises connection, and every customer responsibility. Product names and marketing labels are not evidence.

The two governing routes

When an external cloud service provider stores, processes, or transmits covered defense information for performance of a contract containing DFARS 252.204-7012, paragraph (b)(2)(ii)(D) requires the contractor to ensure that the cloud service meets security requirements equivalent to the FedRAMP Moderate baseline. The contractor must also require the provider to support the duties in paragraphs (c) through (g), including cyber-incident reporting, malicious-software submission, preservation, forensic access, and damage assessment.

For CMMC Level 2, 32 CFR part 170 recognizes two acceptable routes for the particular cloud service offering:

  1. It is FedRAMP Authorized at Moderate or higher and its current Marketplace record covers the offering and boundary being used; or
  2. It meets the current DoD requirements for FedRAMP Moderate equivalency.

The OSC’s infrastructure connecting to the cloud remains in the CMMC Assessment Scope. Customer responsibilities from the provider’s Customer Responsibility Matrix (CRM) must be documented in, or referenced by, the OSC’s SSP and demonstrated during assessment.

A CSP is not treated like a non-cloud ESP that is simply assessed against all Level 2 requirements within the OSC assessment. The rule gives a qualifying CSP the FedRAMP route, while the CMMC team verifies that route and assesses the OSC-controlled and shared responsibilities.

FedRAMP authorization is offering-specific

A Marketplace listing must match the cloud service offering, impact level, authorization boundary, and status actually used. One authorized product does not authorize every product sold by the same company. Likewise, a government-oriented brand name, SOC 2 report, ISO 27001 certificate, or vendor statement does not independently establish FedRAMP authorization or DoD equivalency.

For an authorized offering, the team should identify the Marketplace record and authorization package available to the customer, then reconcile the CRM with the OSC’s architecture. If the OSC uses an add-on, region, identity provider, endpoint path, or integration outside the authorization boundary, the Marketplace listing does not silently extend to it.

Current FedRAMP Moderate equivalency evidence

A non-authorized cloud service may qualify only through the current DoD equivalency process. As of this guide’s update, the policy requires a body of evidence supported by an annual assessment by a FedRAMP-recognized 3PAO. The contractor—not the cloud vendor’s marketing department—must validate that the body of evidence meets the policy and provide the CRM to DIBCAC or the C3PAO assessor as applicable.

The evidence set includes the system boundary and SSP, assessment plan and report, the FedRAMP Moderate control results, the CRM, supporting test material, and continuing-monitoring information required by the policy. At the conclusion of the equivalency assessment, the offering must demonstrate 100% implementation of the applicable FedRAMP Moderate baseline. Operational findings discovered after that point may be managed through the required continuing-monitoring process, but an unresolved baseline control gap cannot be treated as government-accepted risk because equivalency has no federal authorizing official accepting that risk.

Do not confuse the current annual 3PAO assessment requirement with older summaries that described a report as current for three years. Also do not turn the CMMC assessment into a second FedRAMP authorization: the CCA team evaluates whether the required body of evidence exists and supports the claimed route, then evaluates the OSC’s responsibilities.

Incident reporting and cloud support

DFARS 252.204-7012 defines rapid reporting as within 72 hours of discovery of a covered cyber incident. It also requires preservation and protection of images of known affected systems and relevant monitoring or packet-capture data for at least 90 days after submission of the incident report, plus malicious-software handling, requested forensic access, and damage-assessment support.

The current DoD equivalency policy makes the allocation clear: the contractor remains responsible for the contractually required report when the cloud offering is compromised. The contractor must confirm that the CSP has an incident-response plan, follows it, promptly provides notification and technical facts, preserves what the clause requires, and supports the contractor and DoD. A contract can assign operational tasks to the CSP, but it does not erase the contractor’s accountability to meet its own clause.

A scenario stating only that “the CSP reports directly” is incomplete. Ask who holds the contract, what the provider agreement requires, how fast the CSP must notify the contractor, and whether the contractor can assemble and submit the required report within 72 hours.

Shared responsibility

The CRM allocates each capability to the CSP, the customer, or both. The allocation depends on the actual offering and configuration, not a generic IaaS/PaaS/SaaS slogan.

Responsibility typeExample assessment question
CSP-implementedDoes the authorization or equivalency package cover the physical facility, hypervisor, or managed platform capability being inherited?
SharedWhich party enables logging, defines retention, reviews alerts, and responds when the service generates events?
OSC-implementedDid the OSC provision users correctly, enforce applicable MFA, restrict sharing, protect endpoints, train personnel, and maintain its incident process?

A FedRAMP High service can still be used insecurely by its customer. For example, the provider may supply MFA capability while the OSC leaves it disabled for a class of users. The CRM and the tenant configuration—not the provider’s badge—decide whether the applicable objective is satisfied.

Assessment workflow

A defensible cloud review follows this sequence:

  1. Trace whether FCI, CUI, CDI, or security protection data enters the service.
  2. Identify the exact service offering, region, tenant, boundary, and connections.
  3. Confirm the FedRAMP Authorized Moderate-or-higher listing or evaluate the current equivalency body of evidence.
  4. Reconcile the CRM with the SSP, network diagram, asset inventory, data flows, contracts, and incident procedures.
  5. Evaluate every OSC or shared responsibility against the applicable CMMC objectives using adequate evidence.
  6. Confirm that provider notification, preservation, and cooperation allow the contractor to meet applicable DFARS duties.

Suppose an OSC stores CUI in a SaaS offering. The provider’s Marketplace listing covers the service, but the CRM assigns identity policy, external sharing, and endpoint access to the customer. The team may inherit covered platform capabilities, yet it must still examine the OSC’s tenant settings, users, devices, procedures, and evidence. “FedRAMP authorized” is therefore an input to the assessment, not a universal MET result.

Test Your Knowledge

A cloud analytics offering that processes CUI is not listed on the FedRAMP Marketplace. What evidence supports the DoD FedRAMP Moderate-equivalency route?

A
B
C
D
Test Your Knowledge

A qualifying external CSP suffers a compromise affecting the OSC’s covered defense information. Which allocation matches current DoD policy?

A
B
C
D
Test Your Knowledge

An OSC uses a FedRAMP High SaaS offering but claims MFA is fully inherited. What should the CMMC team do?

A
B
C
D