Does Your MSP Need CMMC Certification? The External Service Provider Rules
Introduction
Most defense subcontractors ask their IT provider the wrong question: do you hold a CMMC certificate? The question that decides the assessment is narrower — does that provider touch our CUI, or the data protecting it?
The Short Answer
No. Your MSP generally does not need its own CMMC certificate. Under 32 CFR 170.19(c)(2), a non-cloud external service provider that handles CUI is assessed inside your assessment, not separately, and ESP certification is voluntary. The minimum assessment type is dictated by your DoD contract. What matters is whether the provider touches your CUI or your security protection data.
DoD said so in the preamble: “this rule does not require CMMC assessment or certification of ESPs that do not process, store, or transmit CUI. Services provided by an ESP are in the OSA’s assessment scope” (89 FR 83092).
Scope Does Not Move When the Clock Does
The final rule published October 15, 2024 and took effect December 16, 2024. Phase 1 began November 10, 2025 with the DFARS acquisition rule (90 FR 43560); under 32 CFR 170.3(e)(2), Phase 2 begins one calendar year later. Phases 1 through 3 say what DoD “intends to” put in solicitations; only Phase 4 says “will.” We cover that calendar in our reporting for Texas suppliers and in what to work on meanwhile. This post is about the boundary — data flow settles that, not a date.
What Actually Makes a Provider an ESP
Start at 32 CFR 170.4, and read the second sentence everyone skips:
“External Service Provider (ESP) means external people, technology, or facilities that an organization utilizes for provision and management of IT and/or cybersecurity services on behalf of the organization. In the CMMC Program, CUI or Security Protection Data (e.g., log data, configuration data), must be processed, stored, or transmitted on the ESP assets to be considered an ESP.”
That sentence is a gate. Table 4 to 170.19(c)(2)(i) puts it plainly: “A service provider that does not process CUI or SPD does not meet the CMMC definition of an ESP.” The gate only works if you know where your CUI lives — hence the CUI identification guide.
SPD is broader than people expect. Per 170.4 it “includes but is not limited to” configuration data required to operate a Security Protection Asset, log files generated or ingested by one, vulnerability status of in-scope assets, and passwords granting access to the in-scope environment. If your provider runs your SIEM, holds your firewall configs, or carries privileged credentials into the CUI enclave, it handles SPD — in scope even if no CUI crosses its systems.
The Decision Table
Table 4 to 170.19(c)(2)(i); its ESP rows repeat as Table 6 at 170.19(d)(2)(i) for Level 3:
| ESP scenario | CUI? | What it means for the ESP | What it means for you |
|---|---|---|---|
| Cloud service provider hosting CUI | Yes | “The CSP shall meet the FedRAMP requirements in 48 CFR 252.204-7012” | DFARS 252.204-7012(b)(2)(ii)(D) puts the duty on you — you “shall require and ensure” it. |
| Non-cloud ESP — managed IT, help desk, backup on your gear | Yes | No separate certificate. Services “shall be assessed as part of the OSA’s assessment” — per 170.17(c)(6)(ii), against all Level 2 requirements | You carry it. Document the relationship in your SSP; the ESP supplies a service description and CRM. |
| ESP or CSP holding only Security Protection Data — SIEM, EDR, RMM, log aggregation | SPD only | Assessed as Security Protection Assets. No FedRAMP trigger; DoD stated an offering that does not process, store, or transmit CUI needs no FedRAMP certification. | In scope, but narrower: assessed “against Level 2 security requirements that are relevant to the capabilities provided,” not all 110. |
| Neither CUI nor SPD — printer maintenance, an isolated app | No | Not an ESP under CMMC. No assessment, no certification | Nothing to document. Verify the isolation claim — assessors probe it. |
Where the FedRAMP Requirement Comes From
32 CFR 170 does not create the FedRAMP obligation. Per the preamble, those requirements “are set by DFARS clause 252.204-7012 and the DoD CIO policy memo on FedRAMP Moderate equivalency” and are “beyond the scope of this rule.”
Two things catch people out. The duty runs to the contractor — you “shall require and ensure” the provider meets requirements “equivalent to” the FedRAMP Moderate baseline — so your vendor’s marketing page is not the artifact, your flow-down is. Note “equivalent to,” not “authorized”: 170.16(c)(2) and 170.17(c)(5) allow Marketplace authorization at Moderate or higher, or equivalency per DoD policy. And FedRAMP is not all of paragraph (D) — it also requires compliance with paragraphs (c) through (g) on cyber incident reporting, malicious software, media preservation, forensic access, and damage assessment.
The Documents That Carry the Weight
Per 170.19(c)(2)(ii): “The use of an ESP, its relationship to the OSA, and the services provided need to be documented in the OSA’s SSP and described in the ESP’s service description and customer responsibility matrix (CRM).” Three artifacts must agree:
- Your SSP — names the provider, the services, and which requirements they cover. Open gaps go on a POA&M; your score and affirmation land in SPRS.
- The service description — what is delivered, in enough detail to map to controls.
- The CRM — who does what, line by line. Per 170.16(c)(2)(iii) its security requirements must be “documented or referred to in the OSA’s System Security Plan.”
The most common failure we see: a CRM assigning a control family to the provider while the SSP describes the customer handling it. Cheap now, expensive later.
A Compliant Vendor Does Not Shrink Your Scope
Section 170.16(c)(2)(iii) is direct: “the OSA’s on-premises infrastructure connecting to the CSP’s product or service offering is part of the CMMC Assessment Scope, which will also be assessed.” Endpoints, identity layer, network path — still yours, and 170.16(c)(3)(iii) says the same about a non-cloud ESP. Nor can you push a security tool out of scope: the Out-of-Scope Assets definition at 170.4 excepts “assets that provide security protection for a CUI asset.” At Level 3, 170.18(c)(5)(ii) adds that a CSP “does not relieve an OSC of its obligation to implement the 24 Level 3 security requirements.”
What to Ask a Provider
Skip “are you CMMC certified.” Ask:
- Which of our CUI systems do your people or tools reach, and by what path?
- Do you hold or ingest SPD from us — logs, configs, vulnerability data, credentials?
- Can you produce a CRM mapped to NIST SP 800-171 control identifiers today, not after we sign?
- Will your engineers sit for interviews and evidence review inside our assessment, and is that in the contract?
- If you host multi-tenant infrastructure carrying CUI, what is your FedRAMP position?
A voluntarily assessed provider is easier to work with, but it is not a status you take on. Your scope, your SSP, your SPRS entry.
At Level 1 none of this applies: 170.19(b)(3) asks only that OSAs “consider the people, technology, facilities, and External Service Providers (ESP) within its environment that process, store, or transmit FCI.” Our Level 1 versus Level 2 breakdown covers that boundary. Contract interpretation varies, so confirm your flow-downs with your own counsel.
Frequently Asked Questions
Does my MSP need to be CMMC certified?
Generally no. Under 32 CFR 170.19(c)(2)(ii) an ESP “may voluntarily undergo a CMMC certification assessment to reduce the ESP’s effort required during the OSA’s assessment,” and the minimum assessment type is dictated by your DoD contract. By default its services are assessed inside yours.
What if my IT provider never touches CUI?
Check whether it touches Security Protection Data — logs, firewall configs, vulnerability status, or privileged passwords into the in-scope environment. If so, it is an ESP and its services are assessed as Security Protection Assets. If neither, Table 4 to 170.19(c)(2)(i) says it is not an ESP under CMMC.
Does a FedRAMP-authorized cloud service reduce my scope?
No. Section 170.16(c)(2)(iii) states that your on-premises infrastructure connecting to the CSP offering is part of the assessment scope and will be assessed, and that the Customer Responsibility Matrix must be documented or referred to in your SSP.
Does the Phase 2 timing change what my MSP has to do?
No. The phase-in at 32 CFR 170.3(e) governs when DoD intends to insert CMMC requirements into solicitations. It does not touch the scoping rules in 170.19, which turn on whether your provider handles CUI or SPD.
Unsure where your providers land? Our CMMC compliance services cover ESP scoping, SSP and CRM alignment, and SPRS affirmation with 100% Texas-based support — or start with the self-assessment tool or our work with defense contractors.
Need Help With Cybersecurity?
LayerLogix provides expert cybersecurity solutions for businesses across Houston and nationwide.
Related Articles
Need Expert IT Support?
Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.