Updated September 30, 2026
You don't need an assessor on staff to sell CMMC readiness, because readiness is the work you already do: configuring, patching, logging, and keeping records. What you can't sell is the result, since only an accredited assessment firm can issue a CMMC certificate, and the firm that prepared a client is barred from assessing it.
Some terms first, for anyone newer to defense work. CMMC is the Defense Department's program for checking that its suppliers protect sensitive data. CUI (controlled unclassified information) is the sensitive part: drawings, specs, and technical data the government marks as controlled. A C3PAO is one of the accredited third-party firms that run the official assessment. Your client, the company being assessed, is the OSC (organization seeking certification). And you, if you manage its computers and accounts, are almost certainly part of what the C3PAO will look at.
Why are you in your client's assessment at all?
Because of what sits on your tools. The CMMC rule defines an External Service Provider (ESP) as an outside party that provides IT or security services, and it adds one condition: CUI or Security Protection Data has to live on the provider's assets (32 CFR 170.4). Security Protection Data is defined broadly. It covers configuration data, logs, vulnerability status of in-scope machines, and passwords that grant access to the environment.
Read that list against your stack. Your RMM (remote monitoring and management tool) holds configuration and patch status for every client endpoint. Your PSA (ticketing system) holds admin notes. Your password vault holds the keys to the tenant. You are an ESP.
The scoping table in 32 CFR 170.19(c)(2) then sorts you into one of two lanes. If you hold Security Protection Data but no CUI, your services are in the client's assessment scope and get assessed as Security Protection Assets, meaning against the Level 2 requirements relevant to what you do. If you hold CUI on your own systems, say a file server in your rack or a hosted desktop you run, your services get assessed as part of the client's assessment against all Level 2 requirements. DoD's scoping guide even lists "managed service provider personnel who implement system maintenance" as a standard example of a security protection asset (CMMC Scoping Guide, Level 2, v2.13, Table 2).
In practice, that means a person from your company sits in the assessment. The Cyber AB's procedure manual for assessors tells the team to confirm before the assessment starts that ESP personnel "will be present and actively participating" (CMMC Assessment Process v2.0, activity 1.6). When the assessor interviews your tech about a requirement your matrix says you own, the tech has to show the same command of it the client's own staff would (activity 2.18). "I'd have to check with the NOC" doesn't count as an answer.
Do you need your own CMMC assessment?
Usually not. The scoping guide is direct about the common case: an ESP that is not a cloud provider and doesn't store, process, or transmit CUI does not need its own CMMC assessment, because its services are assessed inside the client's (Scoping Guide v2.13, p. 10). Managing a client's Microsoft 365 or Google Workspace tenant doesn't make you a cloud provider either. The guide says an ESP managing a third-party cloud service for a client is not a CSP.
Three situations change the answer.
You host CUI yourself. Then your service is assessed against every Level 2 requirement in each client's assessment, and the assessor will want to know before the assessment starts whether you hold FedRAMP Moderate, a FedRAMP Moderate equivalent, or your own Level 2 certificate, as appropriate (CAP v2.0, activity 1.7).
You sell your own cloud platform. Then you're a cloud service provider, and if CUI lives there the FedRAMP rules in DFARS 252.204-7012 apply (how the equivalency route works).
You get tired of being assessed twenty times. The rule lets an ESP volunteer for its own C3PAO assessment "to reduce the ESP's effort" in its clients' assessments (32 CFR 170.19(c)(2)(ii)). The procedure manual says an assessment team seeing a valid ESP certificate may treat your responsibilities as validated, but it still checks that they're being maintained, and your people still show up to answer questions (CAP v2.0, activity 2.19). For an MSP with many defense clients, that math can work. For one with two, it rarely does.
What can you sell, and what must you never say?
The line is simple. You can sell anything that makes the controls true and keeps the records. You can't sell a verdict.
| Sell this | Never claim this |
|---|---|
| Remediation projects scoped from a gap list: MFA rollout, disk encryption, log retention, admin account cleanup | "We'll get you certified" or "CMMC certified environment" |
| Managed controls on a monthly fee: patching, endpoint protection, backups, alerting on logging failures | That your service makes the client compliant by itself |
| Evidence upkeep: quarterly account exports, change tickets, departure checklists | That you can assess, or later assess, a client you prepared |
| The responsibility matrix for your services, kept current | A credential you don't hold |
The reason for the right-hand column is in the rule itself. A Certificate of CMMC Status comes only from a C3PAO or DoD's own assessors (32 CFR 170.4, "CMMC Status"). The rule also requires the CMMC code of conduct to bar its members, the assessors, practitioners, and registered firms, from exaggerating "the services that they or their company are capable or authorized to deliver." The same code bars a consultant from taking part in a Level 2 certification assessment of a company it helped prepare within the past three years (32 CFR 170.8(b)(17)(ii)). You can be the preparer or the assessor for a client. Never both.
If you want a badge, the Cyber AB registers consulting firms and MSPs as Registered Practitioner Organizations. It costs $6,000 to apply and $5,000 a year to renew, and an RPO does not conduct certified assessments (Cyber AB, consulting and implementation roles). It's optional. Nothing in the rule requires it to configure Intune for a defense client.
What will the C3PAO ask you for?
The responsibility matrix. The rule requires each ESP's services to be documented in the client's System Security Plan (SSP) and described in the ESP's service description and customer responsibility matrix, or CRM (32 CFR 170.19(c)(2)(ii)). A CRM is a table of who does each security job: the client, you, or the cloud provider.
The assessor checks three things about that table (CAP v2.0, activity 2.17). Is it current? Does it include every party with security duties? Does it cover every in-scope requirement you perform wholly, partly, or jointly with the client? Then the assessor tests your claims instead of taking them on faith, using the examine and test methods on what the client says it inherits from you (activity 2.18).
Here's where it goes wrong. Your contract says the MSP "handles logging." The matrix marks audit logging as yours. The assessor asks to see the alert that fires when a server stops sending logs, which is requirement 3.3.4 in the NIST standard behind CMMC. Your tech opens the RMM, finds the alert rule disabled since a tool migration in the spring, and the requirement goes down for your client. Logging-failure alerts were seventh on DoD's own list of the requirements contractors most often fail (DCMA DIBCAC briefing, Oct. 2022).
A matrix row that holds up names the requirement, the party, the tool, and the evidence. "AU, MSP" doesn't. "3.3.4: MSP. Log-forwarding failure alert in the RMM pages the on-call tech. Evidence: alert rule export and the last test ticket, monthly" does. How to read and build one · The split of daily work with your client
How do MSPs actually price this?
No two price sheets agree. The best survey data is about structure, not rates. In an MSP Success reader survey published in March 2025, 67% of MSPs said they already offer compliance services. 56% use tiered pricing, 37% fold compliance into an all-inclusive package, and 34% bill hourly or by project. 63% said most clients don't include compliance in their IT budgets at all (MSP Success, March 2025).
That last number is your sales problem. The client has a number in its head, and it's usually the assessment fee. DoD estimates a small company spends $104,670 over three years on a C3PAO assessment and its annual affirmations. The same analysis says it assumes "no nonrecurring engineering costs" because the security work is presumed done already (CMMC final rule, cost analysis). The remediation that makes the requirements true sits outside DoD's number, and it's yours to sell.
A structure that survives procurement has three lines. Remediation is a fixed-scope project quoted from a named gap list, so the client can see exactly what each dollar closes. Managed controls are a per-user or per-device monthly fee, priced like the rest of your stack. Evidence upkeep is its own monthly line, because quarterly exports and departure reports are labor, and clients who don't pay for them stop getting them. How a client should order the fixes
Timing matters too. On July 13, 2026, DoD suspended the phase that would have required C3PAO certificates in new contracts from November (DoW implementing memo). The same memo says the 7012 cybersecurity requirements "remain in effect," and self-assessments continue. Your clients still owe the 110 requirements and an honest score. What the pause changed
Where Garde1 fits
Garde1 is software, not an assessment firm. It reads the systems you already run for the client: Microsoft 365, Entra ID, Intune, Google Workspace, NinjaOne, Jamf, and Okta. Then it runs a mock assessment against all 110 Level 2 requirements, objective by objective. A mock assessment is a practice run. It doesn't certify anyone. Its job is to turn your client's gaps into a list you can quote, with each finding naming the account, device, or setting behind it. "Improve MFA coverage" isn't a line item. "Four Entra accounts without a registered second factor, including svc-scanner" is. What a mock should check
When a finding is a setting, Garde1 can make the change in the tool, in Entra, Google Workspace, Jamf, or NinjaOne for example. It uses a separate write permission the client grants for that purpose. Read access for collection stays separate, so the client can revoke write without losing visibility. And from the scope, Garde1 generates the responsibility matrix with three columns for the client, your company, and each cloud provider, so the table the assessor checks matches the environment the assessor sees.
Questions MSP owners ask
Does our RMM alone put us in scope? If it stores configuration data, patch status, or credentials for in-scope machines, yes. Those are Security Protection Data under 32 CFR 170.4, and your service gets assessed as a security protection asset.
Do we need to become an RPO to sell this? No. It's a Cyber AB registration, not a legal requirement for doing the work.
Can we be the assessor for a client after we fix their environment? No. You'd need to be part of a C3PAO, and the three-year consulting bar would still stop you for any client you prepared.
If we move a client to Microsoft's government cloud, are we now a cloud provider? No. Managing a third-party cloud service for a client doesn't make you a CSP under DoD's scoping guide. Microsoft's FedRAMP status is what the assessor checks for the cloud itself.
What's the first thing to fix in our own shop? Your matrix. Write one row per requirement you touch, with the tool and the evidence, and have the tech who'd answer in an interview read it. Who else is in scope
