If my MSP manages our infrastructure, are they in my CMMC scope?
Yes, if your Managed Service Provider (MSP) manages infrastructure that processes, stores, or transmits Controlled Unclassified Information (CUI), or provides security services for such systems, they are within your CMMC scope. The MSP's systems, personnel, and processes interacting with your CUI environment must meet the applicable CMMC requirements, as they become an integral part of your organisation's CUI enclave. This necessitates careful contractual agreements and evidence collection.
When an MSP manages an organisation's infrastructure that handles CUI, the MSP effectively becomes an External Service Provider (ESP) critical to the organisation's CMMC compliance. Their systems and personnel directly support the CUI environment, necessitating that their operational practices align with the organisation's CMMC level. This means the MSP's security controls, policies, and procedures relevant to the CUI environment must be assessed and verified. Organisations must ensure contractual agreements with MSPs explicitly define CMMC responsibilities, including requirements for incident reporting, access control, and audit support, to maintain a defensible CUI enclave.
A common misconception is that outsourcing infrastructure management transfers CMMC responsibility entirely. However, the prime contractor or subcontractor remains accountable for ensuring CMMC compliance across their entire CUI boundary, including services provided by third parties. Organisations must actively engage with their MSPs to gather evidence of control implementation, conduct regular reviews, and ensure the MSP's environment meets CMMC requirements. Failure to adequately vet and monitor an MSP's CMMC posture can lead to significant compliance gaps, potentially resulting in failed assessments and contractual penalties for non-compliance with Department of Defense (DoD) contracts.
Sources
- CMMC Model v2.0, Scoping Guide, Section 2.2 External Service Providers (ESPs)
- CMMC Assessment Process (CAP) Guide, Section 3.2.3 External Service Providers (ESPs)