Updated September 29, 2026
Your MSP, the managed service provider that runs your computers and email for a monthly fee, says it "handles CMMC." That's worth about as much as the paragraph it's written in. The MSP operates the tools. You own the decisions, the checks, and the signature.
CMMC is the Defense Department's program for making sure suppliers protect the sensitive drawings and technical data they handle. Under it, a senior official at your company must affirm every year, on the DoD's supplier website (SPRS), that you meet the security requirements (DFARS 252.204-7021). Your MSP can't sign that for you, and it won't be the one answering for it. If the affirmation turns out to be wrong, the government's questions come to your company, and possibly under a fraud statute, not to your IT vendor.
Where it breaks: a departure
A machinist gives notice and leaves on Friday. Here's how that goes at most shops with an MSP.
The office manager emails the MSP on Monday: "Please disable Dave." The MSP disables Dave's Microsoft 365 account and closes the ticket. Nobody mentions that Dave also had a VPN login for working from home, a login to the CAM software's license portal, and a guest link to the file share of the prime (the larger contractor you work under). Three months later, the quarterly access review turns them up. Or it doesn't, because nobody runs one.
Nobody did anything wrong in their own lane. The MSP removed what it was told about. The office manager assumed the MSP knew everything Dave had. The security standard behind CMMC asks that controlled data stay protected when someone leaves (requirement 3.9.2 in NIST SP 800-171), and it falls straight into this gap. An assessor who pulls one departed employee and finds a live login marks it not met.
The fix is to split each recurring job and give each part an owner:
| Job | You | Your MSP |
|---|---|---|
| New access | Approve it: who, what system, why | Grant exactly that, in a ticket |
| Departure | List every account and device the person had | Remove each one, and report back what it removed |
| Access review, quarterly | Compare the list of who should have access with the MSP's export of who does | Produce the export |
| Configuration change | Approve the change and its risk | Test it, deploy it, record it |
| Security alert | Decide on business impact and whether to report | Investigate, contain within agreed limits, escalate |
| Annual SPRS affirmation | Sign it | Supply accurate facts |
The departure row is the one to rehearse. Next time someone leaves, have their manager fill in the list before emailing the MSP. Have the MSP send back what it removed. Compare the two, and file both with the ticket. That pair of lists is exactly what an assessor asks to see.
Six lines for the agreement
Most MSP agreements say nothing about evidence, the records that prove the work was done, and that's where shops get stuck at assessment time. At renewal, ask for these in writing:
- Every quarter, the MSP delivers a list of all accounts, devices, and admin rights on the systems that hold your controlled data, in a file you can open without their portal.
- Departure tickets list every account removed, not just "user disabled."
- Critical logs, the systems' record of who signed in and what changed, are kept at least six months. That's the floor CISA, the federal cybersecurity agency, sets for MSPs. We'd ask for twelve. CISA MSP advisory, May 2022
- Suspected incidents reach your named contact within a set number of hours, day or night. It has to be early enough for you to report to DoD within the 72 hours your contract's DFARS 7012 clause allows.
- You keep copies of your configuration records, change tickets, and logs after the contract ends.
- Anything the MSP doesn't manage, such as the engineers' Macs or the shop-floor PCs, is listed by name so someone else can own it.
Number 5 is the one people skip. A provider portal that closes on the last day of the contract takes your evidence history with it, and there's no rebuilding it before your next assessment.
Ask for their customer responsibility matrix too: a table, control by control, of what they do and what's left to you. If they don't have one, the table above is a start. How to read one · Is the MSP itself in scope?
