Which subcontractors, consultants, and MSPs belong in my CMMC scope?

Consultants on your laptops are users. Your MSP is assessed inside your scope. Cloud holding CUI needs FedRAMP Moderate. Subs holding CUI need their own level.

Outside payroll, different roles. MSP: administers. Consultant: handles data. Payroll: verify separation. Working guide.
In this guide

Updated September 29, 2026

Your vendor list has an outside IT company, two consultants, a coating subcontractor, and a payroll company, and nobody can agree which of them "count." Sort them by what they touch. A consultant working on your accounts and laptops is treated like one of your employees. Your outside IT company gets examined as part of your assessment. A cloud service that holds CUI must meet the government's cloud security standard. A subcontractor that takes CUI into its own systems is outside your assessment, and it owes you its own CMMC status. Sister companies you own follow a different test.

Two terms carry this post. CUI (controlled unclassified information) is the drawings, specs, and technical data the government marks as sensitive. Your scope is everything the assessor examines when CMMC, the Defense Department's cybersecurity check for suppliers, comes around. Get the sort wrong in one direction and you pay to secure vendors who never needed it. Get it wrong in the other and the assessor finds a vendor you left out, which can sink the assessment on its own.

The sort

Who What they touch What it means for you The rule behind it
Consultant using your laptops and accounts Whatever you give them access to Named account, same training and security rules as staff They're a user of your systems
MSP (managed service provider, your outside IT company) Your accounts, devices, and backups, with admin rights Examined during your assessment, as a tool that protects your systems. Its own "CMMC compliant" badge doesn't excuse it, and you don't wait for it to get certified A provider that doesn't store, process, or send CUI "does not require its own CMMC assessment" and is assessed inside yours as a Security Protection Asset (final rule, 89 FR 83092)
Cloud service that stores CUI The CUI itself Must be FedRAMP Moderate, the government's cloud security standard, or prove it's equivalent. Get its FedRAMP listing or equivalency package, plus the chart of which security duties it handles and which stay with you (what "equivalent" means) 32 CFR 170.19 points to DFARS 252.204-7012(b)(2)(ii)(D)
Subcontractor that receives CUI or FCI (federal contract information: non-public order details) Your contract data, in its own systems Outside your scope. You must pass down the CMMC clause, and it must hold the right CMMC level before you award the work DFARS 252.204-7021(f); 7012 flows down too, per its paragraph (m). Flow-downs during the pause
Payroll company Payroll only Out, once you've confirmed it gets nothing but payroll None

One support ticket tells you most of it

An engineer's CAD program (the design software your drawings live in) crashes. The MSP takes remote control of ENG-03, grabs a diagnostic bundle, and opens a ticket with the CAD vendor. Ten minutes of ordinary support, and it answers the scoping question better than a vendor list. What did the remote session show on screen? What's in the bundle, and whose file share does it sit on? Did a drawing, or a screenshot of one, get attached to the vendor's ticket? Which MSP account did the work, and does it have its own name and a second login step like a phone code?

If a drawing went to the CAD vendor, the vendor now holds CUI and you've grown your scope by accident. Change the support procedure first. Tickets as a CUI path

Send your MSP these questions

List services, not company names. An MSP that manages your laptops, runs your logins, answers the help desk, and does backup is four rows. Then send them this:

For each service you provide us, please list: the tools you use; the named accounts with admin access to our tenant and devices, and whether each has MFA; where diagnostic data and tickets from our environment are stored; which of our security requirements you perform and which remain ours; and the evidence you can export for each. Please use the attached responsibility matrix format.

Their answer becomes your responsibility matrix, the chart that says who does each security job: you, the MSP, or the cloud provider (how to build one). "Industry-standard security" in a master services agreement tells an assessor nothing. If you want backup for the ask, CISA's joint advisory on MSPs lists the duties on both sides (CISA advisory).

The last test is blunt. If this provider disappeared tomorrow, which of your safeguards would stop working, and which records could you still get to? If you can't answer, the matrix isn't finished. Splitting the work with your MSP

Mock assessment

Know what each provider actually does for you.

Garde1 records which provider does what for each requirement, split between you, your MSP, and your cloud provider.

Or start a 14-day trial

HOSTED ON FEDRAMP MODERATE AWS · ITAR-AWARE