Learn CMMC

Managing external service providers for CMMC

Your scope does not end at your firewall. Every cloud service, MSP and SaaS tool that stores, processes or transmits CUI is part of your assessment, and its compliance is part of yours.

Key takeaways

  • Any provider that stores, processes or transmits CUI for you is inside your assessment scope.
  • A cloud service holding CUI generally needs FedRAMP Moderate equivalency. That covers the provider's side of the line, not yours.
  • Document the shared responsibility boundary. "Our cloud provider handles that" is not evidence.
  • Provider status changes. Watch it as part of continuous monitoring.

What an ESP is

An external service provider is any third party that stores, processes or transmits CUI on your behalf. If CUI flows through it, the provider is part of your CMMC scope and its compliance is part of yours. Common types:

  • Cloud platforms: AWS, Azure, Google Cloud, Microsoft 365, and any SaaS where CUI lives.
  • Managed service providers and MSSPs that run your infrastructure, monitoring or network.
  • SaaS applications that touch CUI: project management, file sharing, collaboration.
  • Communication services: email, VPN, file transfer.

The guide's glossary covers the ESP-versus-cloud-service confusion, and requirement 3.1.20 is where external systems enter the standard.

CUI handling and classification

Classify every provider by how it handles CUI. A provider can do one, two or all three:

  • Stores: CUI at rest, in storage, archives, backups, databases.
  • Processes: works on CUI, as SaaS, analytics or data services do.
  • Transmits: moves CUI between systems, as email, VPN and transfer services do.

In Bedrock CMMC

Each provider has a profile with its handling flags, certifications, contract dates and requirement flow-down. When a certification lapses or a contract nears renewal, you know. See provider management.

Compliance requirements for ESPs

  • Cloud services handling CUI generally need FedRAMP Moderate equivalency or higher.
  • Subcontractors that handle CUI under your contract need their own compliance, flowed down contractually.
  • Managed service providers must demonstrate controls equivalent to your level for the services they provide.

For each provider, hold and maintain:

  • Shared responsibility matrix: which controls are theirs and which are yours.
  • Customer responsibility matrix: the configurations and settings you must apply on their platform.
  • Provider system security plan, or the relevant excerpts.
  • Authorization letter: the FedRAMP authorization, CMMC certificate or equivalent, with dates and scope.

Control inheritance and flow-down

Inheritance is a provider implementing a control on your behalf. It decides which of the 110 requirements you implement yourself and which your providers cover:

  • Fully inherited: the provider handles it entirely, as with physical protection in a FedRAMP data centre.
  • Partially inherited: shared, as when the provider encrypts at rest and you manage the keys.
  • Customer responsibility: yours, even on their platform, as with access policies and user management.

Flow-down is the contractual side. If your DoD contract requires Level 2 and you subcontract work involving CUI, the subcontractor must meet Level 2 too, and it is your contract that says so. Primes managing that across a supply base is the problem Bedrock Flowdown exists to solve.

Managing ESP risk

Provider compliance is not a one-time check. Status changes, contracts expire, services evolve. Ongoing management means:

  • Contract tracking, so compliance clauses stay in effect through renewals.
  • Status monitoring: FedRAMP and CMMC status, and changes to the provider's posture.
  • Incident notification written into the contract, so you hear about incidents that touch your CUI.

A provider losing its authorization affects your posture the same day. Controls you inherited may no longer be covered. Watch provider status as part of your monitoring program.

Common mistakes

  • Missing providers. Teams adopt tools without IT knowing. If CUI touches an untracked service, an assessor will find the gap.
  • Treating FedRAMP as the end of the job. It covers the provider's responsibilities, not the customer-side controls and the documented boundary.
  • No responsibility matrices. Without them, inherited controls cannot be verified.
  • No flow-down clauses. Without them, gaps in a subcontractor's controls are your gaps.
  • Assessed once, never again. A provider compliant at assessment time may not be eighteen months later.

Questions people ask

What is an external service provider in CMMC?

Any third party that stores, processes or transmits CUI on your behalf: cloud platforms, managed service providers, SaaS applications, email and transfer services.

Do my cloud providers need FedRAMP?

Providers that handle CUI generally need FedRAMP Moderate equivalency or higher. Services that never touch CUI are outside the boundary and do not.

What is control inheritance?

A provider implementing a control on your behalf. It can be full, partial or none, and it must be documented in your system security plan with the responsibility matrices to back it.

How do I track provider compliance?

Keep an inventory with handling type, certifications, contract dates and the responsibility boundary, and review it on the same cadence as your other controls.

Keep the proof, not just the plan.

Bedrock CMMC tracks every objective, links the evidence behind it, calculates the SPRS score and keeps the POA&M honest, in one package with a chain of custody an assessor can follow.