CMMC requirements still apply: What MSPs need to know

The Department of War’s suspension of independent CMMC Level 2 assessments changed the compliance landscape, but it did not erase the cybersecurity requirements in defense contracts.

That distinction matters to every MSP serving the Defense Industrial Base (DIB).

Your clients may hear “assessment suspension” and conclude that CMMC no longer matters. Some may delay projects, reduce budgets or assume a self-assessment can be completed informally.

That would be a dangerous mistake.

Defense contractors must still protect sensitive contract information, assess their compliance, support their conclusions with evidence and legally affirm their results. The government is actively reviewing claims and penalizing misrepresentations.

The removal of an independent assessor does not eliminate accountability. It shifts more responsibility to the contractor—and often to the MSP advising the contractor.

For MSPs, CMMC is both a growth opportunity and a liability minefield. Knowing where your role ends, where assessment expertise begins and when independent guidance protects everyone—that’s what separates confident providers from exposed ones.

What has and hasn’t changed

On July 13, the Department of War suspended the CMMC Phase 2 requirement for independent Level 2 assessments by Certified Third-Party Assessment Organizations (C3PAO). Those assessments had been scheduled to begin Nov. 10, 2026.

The department also announced a 60-day review of the CMMC program. It cited high compliance costs and administrative burdens for small and nontraditional defense contractors.

The most expensive part of the program may change. Contractors may avoid spending $30,000 to $100,000 for a third-party assessment every three years.

However, the underlying contract requirements remain.

Defense contractors subject to DFARS 252.204-7012 defense contract clause must still:

  • Implement NIST SP 800-171 security requirements to protect Covered Defense Information (CDI), a subcategory of Controlled Unclassified Information (CUI)
  • Use appropriate cloud services for protected data
  • Report qualifying cyber incidents within 72 hours
  • Flow requirements to applicable subcontractors

CMMC did not create those obligations. It created a process to verify requirements that have appeared in defense contracts since 2017.

CMMC Level 2 self-assessments also remain. Contractors must use the official scoping and assessment guides. An authorized official must affirm the results in the Supplier Performance Risk System (SPRS).

Checking that box isn’t a formality—it’s a legal statement about the company’s cybersecurity compliance.

Why MSPs remain in the middle

Defense contractors turn to their MSPs first because MSPs manage many visible parts of their technology environment.

Clients ask simple questions:

  • Are we compliant?
  • Is our score accurate?
  • Are our cloud services acceptable?
  • Do we have enough evidence?
  • Can our executive safely affirm the results?

Those are not simple IT questions.

They involve contract interpretation, assessment scope, objective evidence, cloud authorization and potential False Claims Act liability. They often extend beyond an MSP’s normal service agreement and the systems MSPs manage.

An MSP may manage Microsoft 365, endpoints, firewalls, backups and multifactor authentication. Those systems matter, but they may represent only part of the CMMC environment.

The client may also use an ERP system, CAD tools, computerized machines, test equipment, engineering applications, customer portals and department-managed cloud services. Physical security and remote locations may also affect scope.

The MSP’s own people, tools and facilities can also become part of the assessment. CMMC includes Security Protection Assets (SPA) used to secure systems that handle protected information. Unlike the common definition of an asset, SPAs include the people, technology and facilities MSPs use to protect their clients.

The MSP must participate when its services implement required safeguards. It must explain what it does, how it does it and what evidence proves the control works.

A service invoice or product list will not answer those questions. Many prescribed documents are required, and missing just one can result in failing a government audit after a self-assessment.

Protected data is often created locally

Many defense contractors believe they do not handle CUI because the government never sent a clearly marked file.

That assumption can cost them contracts because the government considers data a contractor generates while performing work to be government property.

The DFARS 252.204-7012 clause in defense contracts protects data that is not limited to documents received from the government or a prime contractor.

A contractor may create protected information while performing the contract. Examples can include drawings, specifications, testing data, machine control data, reports and job records.

Subcontractors may create protected information too.

This means an MSP cannot determine scope by asking whether the client received a file labeled “CUI.” The assessment must follow the data contractors create through their workflows.

Where is contract-related information created? Where does it move? Who can access it? Which applications process it? Where is it backed up? Which vendors support those systems?

A missed data flow can invalidate the scope. A bad scope can produce a false sense of compliance.

Why 110 requirements are not enough

CMMC Level 2 includes 110 NIST SP 800-171 security practices. Many contractors and MSPs stop there.

The assessment process goes deeper. While ‘good enough’ may satisfy a self-assessment, you must follow the guide the government uses to audit self-assessments to be sure you are compliant.

The NIST SP 800-171A assessment guide contains 320 assessment objectives for the 110 practices. Every applicable objective must be satisfied before a requirement can be marked as met.

One missed objective can make the entire requirement unmet.

For example, one access control requirement contains six assessment objectives. The assessment guide also identifies multiple documents an assessor may review.

That is why a quick questionnaire cannot establish CMMC readiness. ”Yes, we are doing that…” isn’t good enough to pass the scrutiny of a government audit.

The contractor must show that each safeguard is properly implemented. It also needs policies, procedures, configurations, records, screenshots, reports and other objective evidence based on the document list in the assessment guide.

The evidence must match the environment. A policy that says passwords are reviewed does not prove reviews occurred. A firewall configuration does not prove access is periodically approved.

MSPs can create significant value by building repeatable evidence processes. They can capture configurations, export reports, preserve approvals and document recurring reviews.

That work can support premium services, stronger retention and recurring revenue. It also reduces the chaos of preparing evidence after a government review begins.

Cloud services create hidden exposure

FedRAMP requirements remain one of the most common and expensive CMMC problems.

Cloud services that process, store or transmit CDI must meet FedRAMP Moderate requirements or an accepted equivalent. Most commercial cloud applications do not meet that standard.

CDI may appear in email, file-sharing systems, ERP platforms, accounting applications, engineering tools, customer portals and cloud backups.

Using a FedRAMP data center is not enough. The cloud service itself must meet the requirement. An equivalent provider must also produce documentation supporting its claim.

Security Protection Data (SPD) is different.

SPD includes configurations, passwords, vulnerability findings, logs and alerts used by MSPs to protect CDI systems. MSP tools handling only that data do not need FedRAMP authorization.

That distinction may apply to RMM, PSA, documentation, vulnerability scanning, EDR, MDR and security information and event management platforms.

However, configuration matters.

An MSP tool should not upload, store or remotely access CDI files. If it does, the tool may become a CUI asset and face stricter requirements.

MSPs should document these boundaries and confirm that technicians understand them.

10 mistakes MSPs must avoid

MSPs can create major value for defense contractors. They can also create serious risks for their clients and themselves when they guess.

Common mistakes include:

  • Assuming the client has no CDI
  • Reviewing only MSP-managed systems
  • Ignoring department-managed cloud applications
  • Missing production and test equipment
  • Skipping a complete data flow analysis
  • Reviewing 110 requirements instead of 320 objectives
  • Assuming plans of action are always allowed
  • Missing FedRAMP cloud requirements
  • Treating MSP tools as automatically out of scope
  • Giving assessment advice without assessment expertise

These mistakes can delay awards, increase remediation costs and damage the client relationship.

They can also expose the MSP.

A client may claim that its MSP recommended an unsupported SPRS score. It may argue that the MSP failed to identify an in-scope system or approved an unacceptable cloud service.

The MSP’s master services agreement or errors and omissions insurance may not fully protect it. This risk increases when the MSP performs work resembling a formal assessment without certified assessors.

Self-assessments still create liability

Calling an assessment a self-assessment does not make it informal or optional.

An executive must legally affirm the company’s results, and the contractor must be able to support every claim with evidence.

The LOGZONE settlement with the U.S. Department of Justice shows what can happen when the numbers do not match reality. The contractor agreed to pay $507,144 after reporting a perfect score of 110. A later government assessment reportedly produced a score of negative 170.

That difference should get every MSP’s attention.

Problems may already exist based on an inflated score previously posted in SPRS.

A government review could lead to financial penalties, lost contracts or False Claims Act allegations. The contractor may then look to the MSP that advised it.

The suspension of independent assessments may increase this exposure. Without a third-party assessor, clients may rely more heavily on their MSP’s judgment, adding liability.

That is why independent validation still matters.

Strengthen your role with expert guidance

MSPs do not need to become CMMC assessment experts to serve defense contractors.

They do need to recognize when assessment guidance exceeds their qualifications.

A CMMC Certified Assessor can validate scope, interpret assessment objectives and identify evidence gaps. The assessor can also provide an independent view before the contractor submits its affirmation.

That does not replace the MSP.

The MSP still manages technology, implements safeguards, collects evidence and supports remediation. The assessor helps ensure that the work aligns with the official assessment process.

This partnership protects the client and the MSP.

It also creates a stronger business model. Defense contractors need ongoing help with security, documentation, cloud services, evidence and recurring reviews. They will pay for services that protect their eligibility for contracts.

The strongest MSPs will not pretend to know everything. They will define responsibilities in a Customer Responsibility Matrix. They will document what their services do and what the client must do.

They’ll bring in certified guidance when the risk demands it.

CMMC may change again after the department’s review. Defense contractors still must protect sensitive information, comply with their contracts and tell the truth about cybersecurity.

Independent assessments may be suspended, but the obligation to protect, comply and remain accountable is not.

Related: A brief history of CMMC and where it’s headed next .