ControlMap

CMMC for MSPs

CMMC 2.0 is here.
Own the shift
with ControlMap.

CMMC 2.0 requirements create new expectations for DoD/DoW contractors and the MSPs who support them.

Start, scale, and conquer compliance with ControlMap by turning complex frameworks into repeatable workflows so your team can support CMMC confidently across every client.

  • Manage CMMC readinessRun NIST 800-171A assessments and track readiness from one workspace.
  • Build audit-ready deliverablesSupport SPRS reporting, SSPs, Shared Responsibility Matrix (SRM), CUI evidence, and more.
  • Standardize across clientsUse repeatable frameworks and workflows instead of manual mapping or third-party templates.

The compliance platform built for MSP service delivery

63+
Frameworks supported
40+
Native integrations
50+
Audit-ready templates

Why CMMC matters now

Help clients keep contract eligibility while building a repeatable service motion

CMMC 2.0 creates one of the largest compliance service opportunities MSPs have seen. Organizations handling Controlled Unclassified Information need to meet NIST 800-171 and CMMC Level 2 requirements to remain eligible for DoD (now DoW: Department of War) contracts, while Level 1 focuses on protecting Federal Contract Information.

CMMC readiness center of excellence logo

A major compliance service opportunity

An estimated 300k to 500k businesses are impacted globally.

Contract-driven urgency

Defense contractors and subcontractors must demonstrate cybersecurity maturity under CMMC 2.0.

A clear MSP advisory role

Clients need help scoping CUI, prioritizing gaps, collecting evidence, and staying ready over time.

Manage CMMC requirements in ControlMap

Turn CMMC complexity into repeatable MSP workflows

ControlMap helps you manage readiness, run assessments, and deliver audit-ready evidence aligned with NIST 800-171.

Frameworks

CMMC frameworks and assessments without manual mapping

ControlMap includes CMMC Level 1 and Level 2 frameworks mapped to NIST 800-171r2 and 800-171A so your team can launch readiness assessments quickly.

CMMC-native workflows in ControlMap
SPRS + SSP

Manage POA&Ms, SPRS scoring, and SSPs in one motion

Generate the evidence and planning artifacts clients need as they move from gap analysis to remediation and readiness review.

ControlMap system security plan builder
Evidence

Link CUI labels, controls, and evidence for audit readiness

Keep CMMC evidence organized by control and tagged for CUI, with traceability for assessor conversations and export-ready packages.

Audit-ready CMMC evidence in ControlMap

Why MSPs choose ControlMap for CMMC

ControlMap gives MSPs a purpose-built way to standardize CMMC delivery, prove readiness, and clarify responsibility across regulated client environments.

Shared accountability workflows in ControlMap

Purpose-built for MSPs

ControlMap enables MSPs to manage every client environment from a single workspace. Tenant cloning makes it easy to replicate proven CMMC setups across similar clients. This saves hours of manual work and helps ensure consistent delivery.

American flag representing CMMC defense contractor requirements

Trusted results

ControlMap aligns directly with DoD/DoW expectations and assessor requirements. Hundreds of MSPs supporting thousands of clients trust ControlMap to prepare for certification because of its consistent track record of success.

CMMC-native workflows in ControlMap

CMMC-native workflows

ControlMap includes CMMC Level 1 and Level 2 frameworks mapped to NIST 800-171r2 and 800-171A. You can launch readiness assessments and manage every requirement without manual mapping or third-party templates.

Audit-ready CMMC evidence in ControlMap

Audit-ready evidence

Evidence in ControlMap is automatically organized by control and tagged for CUI, giving auditors full traceability. Reports export in DIBCAC and eMASS formats, helping compliance packages meet federal and assessor standards.

FedRAMP Moderate equivalency badge

FedRAMP Moderate Equivalency

ScalePad is audited annually for SOC 2 and ISO 27001. ControlMap has mapped these controls to a FedRAMP Moderate equivalency assessment, validating adherence to stringent federal security controls.

Shared responsibility matrix workflow in ControlMap

Shared accountability

Define what is owned by your team and what is owned by the client with a built-in Shared Responsibility Matrix (SRM). Clients can access the same workspace, so both sides stay aligned on responsibilities and progress throughout the compliance process.

What compliance leaders are saying

Evidence management has been the biggest X-factor. Being able to drop everything into one central location—instead of dealing with back-and-forth file sharing—makes the whole process much more manageable. It’s hard to imagine going back to how we were doing it before. It’s really improved productivity.

Jacob Fitzgerald

Management Specialist, Automated Evidence & Audit Readiness

ControlMap provides an easy-to-use platform which allowed our GRC team to completely revamp the way we approach policy, governance, vendors, and risk management in a single platform. Previously, we were utilizing a handful of disparate solutions to provide these functions within our GRC program. Now our Risk Management Program is housed in a single platform, allowing for easier administration, navigation, and linking of information between policy, control mapping, evidence gathering, and risk treatment.

Kent G

Chief Information Security Officer

I use ScalePad ControlMap for Governance Risk and Compliance for strict frameworks like CMMC and NIST. It provides one management platform for myself and my team, enhancing communication between MSPs and clients.

Robert Duchesne

vCISO, Chief Executive Officer

Next step

HELP CLIENTS GET CMMC-READY AND
GROW YOUR COMPLIANCE BUSINESS.

ControlMap gives MSPs a repeatable way to guide clients through CMMC readiness, evidence collection, assessment workflows, and ongoing compliance operations.

Use ControlMap to:

  • Assess readiness against CMMC and NIST 800-171 requirements.
  • Organize evidence by control, owner, client environment, and CUI context.
  • Scale delivery with repeatable workflows across regulated clients.

CMMC FAQ

Common CMMC questions for MSPs

  • Has CMMC been cancelled?
    No. CMMC has been paused, not cancelled. Think of it this way: the requirement to take the third-party certification “exam” is currently paused, but the cybersecurity work needed to prepare for that exam, it has not gone away. MSPs supporting defence contractors should continue helping customers protect sensitive government information and meet NIST 800-171 Rev 2 requirements. The certification timeline may change, but customers with applicable defence contracts must still meet their current cybersecurity obligations.
  • What is the CMMC rollout timeline, and when will requirements actually appear in client contracts?
    The 48 CFR acquisition rule took effect November 10, 2025, so CMMC clauses are now appearing in new DoD solicitations under a phased three-year implementation. Phase 1 requires self-assessments (Level 1, and Level 2 self-assessment where specified). Later phases progressively require C3PAO certification for Level 2 contracts and phase in Level 3. The practical message for MSPs: any client bidding on new DoD work today can be asked for a current SPRS score, and clients targeting CUI-handling contracts should already be on the path to a C3PAO assessment. Waiting for the clause to show up in an RFP is too late.
  • When is an MSP considered “in scope” for CMMC 2.0, and do they need the same level as the client?
    An MSP is considered in scope for CMMC 2.0 when its people, processes, or systems can access, store, process, or transmit a customer's Controlled Unclassified Information (CUI), or when it handles Security Protection Data (SPD) generated by systems protecting CUI. Because many MSP tools collect SPD, this commonly brings MSPs into scope. In most cases, MSP services are assessed as part of the customer's CMMC assessment using the customer's System Security Plan (SSP) and a Shared Responsibility Matrix, rather than requiring a separate MSP certification. MSPs that never handle CUI or SPD are generally out of scope.
  • What certification or registration requirements apply to MSPs, MSSPs, RPOs, and consultants?
    CMMC certification is only required for organizations that hold DoD contracts directly. Under the final rule, MSPs and MSSPs acting as External Service Providers are not required to certify. Their services are assessed inside each customer's assessment instead. RPOs and C3PAOs must be listed in the Cyber AB marketplace. That said, an MSP supporting multiple Level 2 clients will be pulled into every one of those assessments, so voluntary Level 2 certification is often worth the investment. A C3PAO can accept the MSP's existing certification rather than re-evaluating its assets in each client engagement, which cuts assessment time, cost, and risk for everyone. It is also a genuine competitive differentiator in the DIB market.
  • How should MSPs scope their own tools and infrastructure for CMMC 2.0?
    Anything that can touch or administer CUI systems may come into scope, including RMM tools, PSA, ticketing, SIEM, and backup solutions. Common strategies include separate tenants or tool instances for CMMC customers, restricting technician access, using just-in-time privileged access, and avoiding agents inside the enclave when they are not needed. A clear Shared Responsibility Matrix (SRM) is essential to document what the MSP does and does not do.
  • When should organizations use a CMMC enclave, and how do you choose cloud vs. on-prem?
    An enclave is appropriate when only part of the environment needs to handle CUI, or when you want to sharply limit CMMC scope. Cloud-based enclaves such as GCC, GCC High, or compliant IaaS are often faster to deploy and easier to standardize. On-prem enclaves may be preferred for manufacturing equipment, legacy systems, or special connectivity needs.
  • When is Microsoft 365 GCC or GCC High required, and can customers stay in commercial tenants?
    CMMC 2.0 does not require Microsoft 365 GCC or GCC High by default. Because CMMC is based on NIST SP 800-171, the requirement is that any cloud service storing, processing, or transmitting Controlled Unclassified Information (CUI) meets applicable FedRAMP or equivalent requirements. Microsoft 365 Commercial may be appropriate for some CUI workloads when compliance and contractual requirements are met. GCC or GCC High is typically required when contracts, ITAR, export-controlled information, or data residency requirements specify those environments. The right Microsoft 365 tenant depends on your customer's regulatory and contractual obligations - not CMMC alone.
  • What expectations apply to third-party tools (RMM, backup, XDR, etc.) in CMMC environments?
    It depends on what the tool touches. If a cloud-based tool stores, processes, or transmits CUI, the provider is treated as a Cloud Service Provider and FedRAMP Moderate authorization (or DoD-approved equivalency) is mandatory under DFARS 252.204-7012. This is a hard requirement, not a maturity signal. If the tool handles only Security Protection Data, meaning logs, configurations, patch status, and scan results, FedRAMP is not required, but the tool and the provider's practices are assessed against the applicable NIST 800-171 requirements as Security Protection Assets within the client's scope. The practical takeaway for MSPs: map every tool in the stack to one of these two categories before an assessor does it for you.
  • How can MSPs design backup and disaster recovery for CUI without bringing their entire footprint into scope?
    Start from one principle: backups of CUI are CUI. That means a cloud backup vendor holding CUI backups is a Cloud Service Provider and must meet FedRAMP Moderate or equivalency, and a shared MSP backup repository containing even one client's CUI pulls the entire repository, and everyone with access to it, into that client's assessment scope. Segment backup infrastructure for CUI workloads: use dedicated repositories or tenants for CMMC customers, and ensure encryption, access control, and logging meet NIST 800-171 expectations. Avoid sending CUI backups into shared MSP platforms where other clients' data resides or where many technicians have broad access.
  • What are the practical steps from self-assessment to C3PAO audit, and what should be budgeted?
    Organizations typically start with scoping, gap analysis, and a NIST 800-171 self-assessment to generate an SPRS score, which must be submitted to the Supplier Performance Risk System. Next comes remediation: policies, technical controls, documentation, and evidence collection. Many then use an RPO or consultant for a readiness review before scheduling a C3PAO assessment. Assessors commonly recommend planning 12 to 18 months for a full CMMC implementation. Budget for remediation and ongoing control maintenance, not just the formal assessment, and remember that certification carries an annual affirmation signed by a senior Affirming Official. That affirmation is a legal attestation that creates False Claims Act exposure if the environment has drifted from its assessed state.
  • How do you identify and scope CUI, including derived data and physical artifacts?
    Start from contracts, flow-down clauses, and government or prime guidance to identify what is explicitly marked as CUI. Then analyze where that information flows, including CAD files, g-code, modified drawings, ERP systems, email, and physical printouts. Derived data can still be CUI if it reveals or is generated from CUI content. Document the scoping rationale so assessors can see how decisions were made.
  • How do CMMC 2.0 audits differ from SOC 2 or ISO 27001?
    SOC 2 and ISO 27001 are broader, risk-based frameworks that are often tailored to an organization’s chosen scope and controls. CMMC 2.0 Level 2 is tightly mapped to NIST 800-171, with a defined set of practices and assessment objectives that must be met. There is less flexibility to compensate with different controls.
  • What ongoing activities are required after achieving “110 of 110” to stay compliant?
    CMMC 2.0 is a continuous obligation with a formal cadence, not a one-time project. Certification is valid for three years, but an Affirming Official must submit an annual affirmation in SPRS confirming continued compliance. If certification was granted with a conditional status, POA&M items must be closed within 180 days or the certification lapses. In between, organizations must maintain policies, review logs, manage vulnerabilities, test incident response, update system security plans, track changes, and reassess risks. Recurring cyber hygiene tasks and documented evidence are critical so the organization can prove it is still operating at the assessed level, which is exactly the recurring-services opportunity for MSPs.
  • How can MSPs support both CMMC and non-CMMC clients without over-complicating operations?
    Define clear service tiers and reference architectures. For CMMC customers, use hardened baselines such as secure configurations, stricter MFA, logging, and separated tenants where feasible. For non-CMMC clients, apply a subset of the same controls with more flexibility. Align internal processes so technicians follow consistent playbooks with specific extra steps for regulated environments.
  • What are effective discovery questions and sales approaches for cost-sensitive SMBs?
    Anchor conversations in mission outcomes: contracts at risk, supply-chain expectations, and potential revenue loss if clients cannot meet CMMC requirements. Ask which contracts mention DFARS, CMMC, or NIST 800-171, what data they exchange with prime contractors, and what audits they have faced. Frame recommendations as a prioritized roadmap, not an all-or-nothing purchase.
  • How can a GRC platform help an MSP manage CMMC 2.0 evidence, scoping, and audits for clients?
    A GRC platform centralizes requirements, controls, assets, and evidence so each CMMC practice can be traced to policies, systems, owners, and proof. It helps manage scoping decisions, POA&Ms, a Shared Responsibility Matrix (SRM), and a living System Security Plan. For audits, organized evidence makes it easier to answer assessor questions without hunting through file shares and email threads.
  • If a client only handles FCI, are they required to be Level 2 certified?
    No. If a client only handles Federal Contract Information, they generally fall under CMMC Level 1 and complete an annual self-assessment aligned to FAR 52.204-21. Contract clauses should still be reviewed to confirm whether CUI is in scope, because CUI would drive Level 2 requirements.
  • What is Security Protection Data (SPD), and why does it matter to MSPs?
    Security Protection Data is the information generated or handled while protecting a CUI environment: system logs, configuration data, patch status, vulnerability scans, authentication data, and similar telemetry. None of it is CUI, but when an MSP's RMM, SIEM, or monitoring platform collects SPD from a client's CUI environment, that infrastructure becomes a Security Protection Asset inside the client's assessment scope. This is the single most common way MSPs end up in scope without realizing it. The DoD does not distinguish between a provider that touches CUI directly and a provider whose tooling forms the defensive perimeter around it. Both are assessed.
  • Does an MSP need its own CMMC certification?
    Not unless the MSP holds a DoD contract directly. The final rule removed mandatory ESP certification: an MSP's services are instead assessed within each customer's assessment, documented through the customer's SSP and a Shared Responsibility Matrix. The strategic question is scale. An MSP with one or two DIB clients can reasonably participate in each assessment, but an MSP with many defense clients will find voluntary Level 2 certification pays for itself, since assessors can accept the existing certification instead of re-examining MSP assets in every engagement. It also signals to prospective DIB clients that the MSP will simplify their certification rather than complicate it.
  • When does an MSP become a Cloud Service Provider (CSP) under CMMC?
    Using cloud tools to deliver managed services does not make an MSP a CSP, and remotely administering a client's environment, whether on-prem or cloud, does not require certification as long as CUI never resides on the MSP's own systems. The line is crossed when the MSP provides or materially modifies a cloud service that stores, processes, or transmits CUI: for example, hosting a multi-tenant VDI or file-sharing platform where client CUI lives. At that point the MSP is treated as a CSP and must meet FedRAMP Moderate or DoD-approved equivalency. Document which side of the line each service offering falls on before an assessor asks.
  • Are POA&Ms allowed under CMMC 2.0?
    Yes, but far more narrowly than MSPs coming from SOC 2 or ISO 27001 expect. A Plan of Action & Milestones is only permitted for a limited subset of lower-weighted requirements, and the highest-weighted controls must be fully met at assessment time. The organization must still achieve a minimum score to receive a conditional certification. All POA&M items must then be closed and verified within 180 days, or the conditional status lapses. There is no open-ended remediation window: treat a POA&M as a short runway, not a parking lot.
  • Can MSPs use offshore technicians or subcontracted help desks for CMMC clients?
    This is one of the biggest landmines in MSP service delivery. Anyone who can access systems containing CUI is in scope, including subcontracted labor, offshore NOCs, and third-party SOCs. For export-controlled CUI under ITAR, access by non-U.S. persons can itself be a violation regardless of CMMC status. MSPs supporting DIB clients should map exactly which personnel and subcontractors can reach CUI environments, restrict access for regulated clients to U.S.-based, documented staff where required, and reflect those boundaries in the Shared Responsibility Matrix. Many MSPs solve this with a dedicated, U.S.-staffed service tier for CMMC customers.
  • Which version of NIST 800-171 does CMMC assess against?
    CMMC 2.0 Level 2 assesses against NIST SP 800-171 Revision 2 and its assessment procedures in 800-171A, not the newer Revision 3 published in 2024. The final rule confirmed Rev 2 as the baseline, and DoD will announce any future transition through rulemaking with a defined changeover period. This matters in practice because clients (and auditors from other frameworks) frequently find Rev 3 online and assume it applies. Build your gap assessments, SSPs, and evidence libraries against Rev 2 today, and track DoD announcements before investing in Rev 3 alignment.
  • What are the incident reporting obligations in a CMMC environment?
    DFARS 252.204-7012 requires contractors to report cyber incidents affecting covered defense information to DoD through DIBNet within 72 hours of discovery, preserve affected system images and monitoring data for at least 90 days, and support DoD damage assessment if requested. For MSPs this is operational, not theoretical. If the MSP runs the client's security stack, the MSP's detection, escalation, and evidence preservation processes are what make 72-hour reporting achievable. Define incident roles, notification paths, and preservation responsibilities explicitly in the Shared Responsibility Matrix. An assessor will ask, and so will the client's counsel after an incident.
  • Should an MSP try to stay out of CMMC scope entirely, and can that actually work?
    Yes, but only through intentional planning - not by default. To stay out of CMMC scope, an MSP's people and tools must not access Controlled Unclassified Information (CUI) or Security Protection Data (SPD). This typically means the customer or a specialized provider manages the CUI environment, while the MSP supports only systems outside that boundary. The tradeoff is reduced service scope and greater coordination between providers. Rather than staying completely out of scope, many MSPs choose a subdivision model, using a dedicated team and toolset to support CMMC clients while keeping the rest of the business outside the assessment boundary.
  • What will a C3PAO assessor actually expect to see?
    A C3PAO assessor expects evidence mapped to assessment objectives, not just controls. NIST 800-171A breaks the 110 requirements into 320 assessment objectives, each scored met or not met with no partial credit. Assessors work through three methods: examine (documents, configs, screenshots), interview (asking your and the client's staff how things actually work), and test (watching a control operate). The SSP is the anchor document, and assessors check its claims against reality, so an accurate SSP beats an aspirational one. For MSP-supported clients, the Shared Responsibility Matrix determines who gets questioned per objective, so MSP technicians should expect interviews and should be ready to demonstrate the controls they own
  • How much documentation does CMMC actually require?
    CMMC requires more documentation than many organizations expect. At a minimum, you'll need a System Security Plan (SSP), policies and procedures, an asset inventory, network diagrams, a Shared Responsibility Matrix for external providers, a Plan of Action and Milestones (POA&M) for approved gaps, and evidence that controls are operating as intended. Assessors also expect records that demonstrate ongoing compliance, such as security training, vulnerability scans, log reviews, incident response testing, and change management. Using standardized templates helps reduce effort and makes documentation easier to maintain across multiple clients.
  • How do you create urgency with clients who will not act on CMMC?
    Move the conversation from cybersecurity risk to revenue risk, because the enforcement levers are already live. DFARS 252.204-7012, 7019, and 7020 clauses are binding in existing contracts today, CMMC clauses are now appearing in new solicitations under the phased rollout, and primes are actively flowing requirements down and disqualifying subcontractors who cannot show a current SPRS score. Add the legal dimension: the Department of Justice has pursued False Claims Act cases against contractors who misrepresented their compliance posture, which puts the client's leadership, not just their IT, on the hook. The most effective single question: which of your contracts come up for recompete in the next 18 months, and what happens to your revenue if you cannot bid?
  • How should MSPs turn CMMC into recurring revenue instead of a one-time project?
    CMMC is best delivered as an ongoing compliance service not a one-time project. After certification, organizations must continuously maintain evidence, review logs, manage vulnerabilities, track POA&Ms, monitor for configuration drift, and prepare for annual affirmations and future reassessments. These ongoing requirements create recurring opportunities for MSPs to provide compliance management alongside security operations. Rather than selling a single implementation project, MSPs can build predictable recurring revenue by helping customers maintain compliance readiness and supporting them throughout the entire CMMC lifecycle.