10.2 External Service Providers (ESPs/MSPs/MSSPs) & Shared Responsibility Matrices
Key Takeaways
- Under the CMMC definition, an external provider is an ESP when CUI or Security Protection Data is processed, stored, or transmitted on the provider’s assets.
- For a non-cloud ESP handling CUI, the services are included in the OSA’s assessment scope and assessed as part of the OSA assessment; a separate ESP CMMC certification is voluntary, not automatically mandatory.
- For an ESP handling Security Protection Data without CUI, the services are assessed as Security Protection Assets; a provider handling neither CUI nor SPD is not an ESP under the CMMC definition.
- The OSA documents the relationship in its SSP, the ESP service description, and the Customer Responsibility Matrix, then demonstrates the provider and customer evidence for each responsibility.
- Remote administration, identity, cryptography, auditability, incident support, and provider connections are evaluated according to the actual service and applicable objectives, not generic MSP checklists.
External Service Providers: Scope, CRM & Evidence
Outsourcing IT or cybersecurity does not outsource CMMC accountability. An OSA must understand what the provider’s assets do with CUI and Security Protection Data (SPD), document the relationship, and include the appropriate services in the assessment. The provider’s marketing category—MSP, MSSP, SOC, help desk, backup vendor, or consultant—does not decide the result.
Use the regulatory definition
32 CFR part 170 defines an External Service Provider (ESP) as external people, technology, or facilities used to provide or manage IT or cybersecurity services on the organization’s behalf. For CMMC purposes, CUI or SPD must be processed, stored, or transmitted on the provider’s assets for that provider to meet the ESP definition.
SPD includes security-relevant material such as log or configuration data. A remote administrator may therefore bring a service into the ESP analysis even when the provider does not store document-level CUI: its management platform, ticket system, SIEM, credentials, or support workstation may process SPD.
The §170.19 decision table
For Level 2, first decide whether the provider is a CSP. Cloud services that handle CUI use the FedRAMP Authorized or FedRAMP Moderate-equivalent route. For a provider that is not a CSP, apply the following rules:
| What the non-cloud provider handles on provider assets | CMMC treatment |
|---|---|
| CUI, with or without SPD | The services are in the OSA’s assessment scope and are assessed as part of the OSA assessment. |
| SPD without CUI | The services are in scope and assessed as Security Protection Assets. |
| Neither CUI nor SPD | The provider does not meet the CMMC definition of an ESP. Other scope or contract facts may still matter. |
A non-cloud ESP that handles CUI is not automatically required to arrive with its own Final Level 2 certificate. Section 170.19 expressly permits the ESP to undergo a certification assessment voluntarily to reduce the effort required during customer assessments. If it does, the minimum assessment type is dictated by the OSA’s DoD contract requirement. The team still verifies that the ESP certificate covers the relevant service boundary and does not treat it as proof of customer-controlled responsibilities.
Required relationship documentation
The OSA documents the ESP’s use, relationship, and services in the SSP. The service is described in the ESP’s service description and Customer Responsibility Matrix (CRM). The CRM assigns the provider, OSA, or both to the implementation and evidence for each relevant responsibility.
A document titled “shared responsibility matrix” may be useful, but the regulation uses CRM. Its label is less important than accuracy. A good CRM identifies service boundaries, data and administrative flows, provider assets, people, facilities, authentication paths, evidence sources, incident duties, changes, and exit responsibilities. A spreadsheet does not satisfy a requirement by itself; the described controls must operate.
Evidence by service function
| Provider function | Questions for the qualified team |
|---|---|
| Remote administration | Which provider endpoints, identities, management tools, and connections process SPD or reach the scope? Are access, MFA, privilege, and session controls implemented as the applicable objectives require? |
| Managed logging or SOC | Where do logs and alerts reside? Who protects them, reviews events, escalates incidents, preserves evidence, and demonstrates the relevant AU, SI, and IR objectives? |
| Backup or recovery | Does the service store CUI, where are copies and keys, which boundary applies, and how are media, access, restoration, and disposal responsibilities shown? |
| Firewall, EDR, or vulnerability service | Which security capabilities are provided, which provider assets hold SPD, and what configurations, activities, people, and test evidence demonstrate operation? |
| Help desk or ticketing | Can tickets, attachments, screen captures, credentials, or remote sessions contain CUI or SPD, and how are those paths controlled? |
The assessment methods remain Examine, Interview, and Test. The team chooses adequate and sufficient evidence for each objective and uses focused, nonstatistical sampling where CAP permits. A generic SOC report, ISO certificate, service brochure, or CRM assertion does not replace objective-level evidence.
Remote access without invented mandates
Provider access is evaluated under the same applicable CMMC requirements as other access. The team determines whether named accounts and MFA meet IA objectives, whether privileges are limited and attributable, whether remote connections and CUI transmissions have the required protection, and whether audit events defined by the organization support accountability.
Do not invent universal settings. CMMC does not prescribe one jump-host product, a 15-minute timeout for every service, full video recording of every session, or a particular RMM vendor. If cryptography is used where FIPS-validated cryptography is required, verify the actual module and validated configuration. If the session never transmits CUI, do not claim that the session alone proves a CUI-transmission requirement; evaluate the real data and security function.
The provider should use nonprivileged functions for nonsecurity work and elevate only as authorized. Shared accounts require special scrutiny because the objectives require accountability to individuals; a controlled privileged-access system may provide individual attribution, but a generic password with no traceability does not.
Contracts and incident support
The contract or service agreement should make it possible for the OSA to obtain evidence and meet its own duties. Relevant terms may cover authorized services, change notification, incident escalation, evidence access, retention, subcontractors, data return, and sanitization. The exact clauses depend on the prime contract, data, and provider relationship; CMMC does not impose one universal MSP contract template.
When DFARS 252.204-7012 applies, the contractor must be able to evaluate and rapidly report a covered incident. An ESP may detect, contain, or investigate events under the agreement, but the OSA cannot assume that outsourcing monitoring transfers every legal reporting decision. Notification timing should leave the contractor enough time to meet any applicable 72-hour deadline.
Scenario method
For an ESP scenario, work in this order:
- Identify the data handled on provider assets: CUI, SPD only, or neither.
- Decide whether the provider is a CSP.
- Apply the correct row of §170.19 rather than assuming a certificate requirement.
- Trace the service in the SSP, service description, CRM, asset inventory, network diagram, and data flow.
- Assess provider and OSA responsibilities against the applicable objectives.
- Confirm that any separate provider status covers the actual service boundary and only reduces work where justified.
An MSSP that stores SIEM logs and administers the OSC’s firewall processes SPD. Its service is assessed as a Security Protection Asset if it does not handle CUI. An off-site non-cloud backup provider storing CUI has its services assessed within the OSA’s scope against the Level 2 requirements. Either provider may voluntarily obtain its own appropriate CMMC status, but the rule does not turn voluntary certification into an automatic prerequisite.
An MSSP stores only the OSC’s security logs and remotely manages its firewall; no CUI is present on MSSP assets. How is the service treated?
A non-cloud backup ESP stores the OSC’s CUI on the ESP’s systems. What does §170.19 require?
What documentation connects an ESP’s duties to the OSA assessment?