CMMC Level 1 · GuideSEC / GDE

Guide

What Does CMMC Level 1 Require of My MSP or IT Provider?

Short Answer

The CMMC rule writes the Level 1 requirements for your organization, not for your provider. Nothing in the Level 1 sections of 32 CFR Part 170 requires a managed service provider to hold its own CMMC status or pass its own assessment. What the provider does still counts. The DoD Level 1 Assessment Guide says a requirement is MET when adequate evidence shows that the enterprise or an external service provider implements its objectives. The self-assessment, the scope, and the affirmation remain yours.

Why the Confusion Exists

The CMMC rule defines an External Service Provider with Level 2 in mind. Under 32 CFR 170.4, an ESP is external people, technology, or facilities that an organization uses for provision and management of IT or cybersecurity services on its behalf. The same definition adds that, in the CMMC Program, CUI or Security Protection Data must be processed, stored, or transmitted on the ESP's assets for it to be considered an ESP. FCI is not named.

The Level 1 material still uses the term. 32 CFR 170.19(b)(3) asks a supplier scoping a Level 1 self-assessment to consider the External Service Providers within its environment that process, store, or transmit FCI. The DoD CMMC Assessment Guide, Level 1, says an ESP may include cloud service providers, managed service providers, managed security service providers, or cybersecurity-as-a-service providers (page 9). The rule itself does not define managed service provider as a separate term.

The detailed provider rules in 32 CFR Part 170 sit in the Level 2 and Level 3 sections and turn on whether a provider handles CUI or Security Protection Data. Much of what is written about providers describes those rules, such as the customer responsibility matrix and the System Security Plan, without saying they come from the Level 2 and Level 3 sections.

What the Current Authority Says

Level 1 obligations are written for the Organization Seeking Assessment, which is your company. Under 32 CFR 170.15, the organization conducts the self-assessment, submits the results in SPRS, and affirms. Under 32 CFR 170.19(b), it specifies its Level 1 scope before the self-assessment. Under 32 CFR 170.22, the affirmation comes from the Affirming Official, a senior level representative from within the organization.

For providers at Level 1, the rule says only that scoping should consider the External Service Providers within the environment that process, store, or transmit FCI. The DoD CMMC Scoping Guide, Level 1, Version 2.13, repeats this and lists external service provider personnel among the people to consider (page 4). Neither document sets a separate assessment, status, or document for the provider at Level 1.

The provider rules sit in the Level 2 and Level 3 sections. Table 4 to 32 CFR 170.19(c)(2)(i), the documentation of a provider in the System Security Plan and customer responsibility matrix under 32 CFR 170.19(c)(2)(ii), and the conditions in 32 CFR 170.16(c)(3) all appear in the Level 2 scoping and assessment sections. In the preamble to the final rule, DoD states that the rule sets requirements for the organization seeking assessment, not for the ESP, and that ESPs are not subcontractors on a DoD contract and are not bound by subcontractor flowdown requirements (89 FR 83136 to 83137).

The DoD CMMC Assessment Guide, Level 1, Version 2.13, explains how a provider's work counts. It states that satisfaction of a security requirement may be accomplished by other parts of the enterprise or an ESP, and that a requirement is considered MET if adequate evidence is provided that the enterprise or ESP implements the requirement objectives (pages 8 to 9).

What This Means

The Level 1 text gives your provider no CMMC status to hold, no assessment of its own to pass, and nothing to file in SPRS. Any terms between you and your provider come from your agreement with it, not from the Level 1 rule.

What the provider does for you is still part of your self-assessment. If it manages your user accounts, firewall, patching, or malware protection, those services are part of how the 15 requirements are met, and your self-assessment needs adequate evidence of them. That evidence often has to come from the provider, so it helps to ask for it early.

Whether a provider and the systems it runs are part of your Level 1 scope is the scoping decision you make. 32 CFR 170.19(b)(3) asks you to consider providers that process, store, or transmit FCI when you make it.

The determinations and the affirmation stay with your company. A provider can do much of the work, but each MET, NOT MET, or N/A is recorded in your self-assessment, and your own senior Affirming Official affirms the result in SPRS.

Primary Sources

Source Authority

Primary Authority
32 CFR § 170.4
Framework Version
CMMC Assessment Guide, Level 1 v2.13 (September 2024)
Written By
AssessrLog, from the primary sources listed above

How we verify this reference

Cite This Page

“What Does CMMC Level 1 Require of My MSP or IT Provider?.” AssessrLog, a product of ProfytAI Pte. Ltd.. https://assessrlog.com/cmmc/guides/what-does-cmmc-level-1-require-of-my-msp/

Build the Record Behind This

AssessrLog is the self-serve system of record for your Level 1 self-assessment. Scope your FCI, work all 59 objectives at your own pace, log each determination with its evidence, and hand your official a clean, defensible package. The determination is always yours to make.