A defense contractor hires a CMMC-focused MSP in Q1 2026. The MSP builds out their GCC High tenant, enforces MFA across all users, deploys endpoint detection and response, configures Intune for device management, writes the System Security Plan, and submits the SPRS score. Six months and $280,000 later, the contractor has a well-organized compliance program and a C3PAO assessment scheduled for September.
The assessment starts well. Then the assessor reaches SC.3.187, organization-controlled key management.
"Who holds the encryption keys for your CUI files?"
The MSP manages the M365 tenant. Microsoft holds the encryption keys by default. The contractor can't demonstrate that key management is under their organizational control rather than their vendor's. SC.3.187 is non-deferrable. The assessment pauses.
This is the specific compliance gap that CMMC MSPs — even competent, experienced ones — structurally cannot close for you. Understanding exactly what an MSP delivers, what it doesn't, and what you remain responsible for is the question that should come before the contract, not after the assessment.
What Does "CMMC MSP" Mean?
The term "CMMC MSP" describes a managed service provider that has built out service offerings aligned to CMMC Level 2 requirements. In the CMMC ecosystem, providers carry different designations that matter for what they can actually do:
MSP (Managed Service Provider): Handles IT infrastructure, operations, and management. May have CMMC-specific offerings but carries no formal CMMC credential by itself. Manages your GCC High tenant, endpoints, network, and helpdesk.
RPO (Registered Practitioner Organization): Registered with the Cyber Accreditation Body (Cyber-AB). An RPO can provide CMMC advisory services, gap assessments, implementation consulting, and documentation work — including SSP authoring and POA&M development. An RPO cannot conduct formal CMMC assessments.
C3PAO (Certified Third-Party Assessment Organization): The only body that can conduct an official CMMC Level 2 assessment and grant certification. C3PAOs are entirely separate from the MSP/RPO role — you cannot hire your compliance partner as your assessor.
MSSP (Managed Security Service Provider): Focused specifically on security services — SIEM management, threat detection, incident response, vulnerability scanning. Often engaged alongside an MSP for CMMC.
Many vendors in the market blend these roles. An MSP may also be an RPO. Some offer end-to-end CMMC services across infrastructure, documentation, and assessment readiness. The credential that matters for CMMC purposes is the Cyber-AB registration, not the vendor's marketing description.
An MSP Can Build Your Digital Fortress, But They Don't Own the Keys
Managed Service Providers excel at configuring networks, deploying MFA, and managing cloud environments like GCC High. But under CMMC Level 2, infrastructure security is only half the battle. If your encryption keys are held by a third-party cloud provider, or if your files become completely vulnerable the moment they leave your corporate network, you are carrying a hidden audit failure.
What a CMMC MSP Does Well
A well-configured CMMC MSP handles the majority of the infrastructure work required for Level 2 compliance. If you're a defense contractor with an in-house IT team of 1–5 people, this delegation makes sense. The controls an MSP is genuinely equipped to own:
GCC High / M365 Environment: Building, configuring, and maintaining a Microsoft 365 Government Community Cloud High environment provides a pre-configured platform for many required controls. Conditional access policies, data loss prevention rules, Teams configuration, SharePoint permissions — these live in the MSP's operational lane.
Endpoint Management: Intune-based device management, EDR deployment, OS configuration baselines, patch management, encryption at rest on managed endpoints — standard MSP services that map directly to CMMC CM and IA domain requirements.
Multi-Factor Authentication: MFA deployment and enforcement across users and systems is table stakes for any competent CMMC MSP. This is one of the most commonly failed controls in assessments, so getting it right early matters.
Audit Logging and SIEM: Log collection, centralized storage, alerting, and basic review processes are typically within the MSSP layer of a CMMC engagement. The AU domain requires more than enabling logging — it requires demonstrating that logs are actively managed and reviewed.
Documentation Infrastructure: Building the SSP template, maintaining the component inventory, managing the evidence binder for assessment — RPO-credentialed MSPs typically handle this work as part of a managed compliance service.
SPRS Score Submission: Calculating the self-assessment score and submitting to the SPRS portal is an administrative function MSPs commonly perform on behalf of clients. Note: the contractor bears legal responsibility for the accuracy of whatever is submitted.
What a CMMC MSP Cannot Do for You
Here is the category most contracts don't clarify clearly enough.
Organization-Controlled Key Management (SC.3.187)
This is the control that creates the most assessment complications in MSP-managed environments. SC.3.187 requires that encryption keys for CUI remain under your organization's control — not your vendor's, and not a shared key managed by a cloud provider.
In a standard GCC High M365 deployment, Microsoft manages encryption by default using Microsoft-controlled keys. This is called Microsoft-managed keys or service-managed keys. Under this architecture, Microsoft can technically access your encrypted content without your active authorization. That's the control gap.
Microsoft provides Customer Key functionality for M365 — an additional service that allows organizations to provide their own encryption keys, which Microsoft then uses within their encryption infrastructure. Customer Key shifts key management closer to organizational control, but the keys still run through Microsoft's key management service (Azure Key Vault). Whether this fully satisfies SC.3.187 for CMMC purposes is an assessment question, not a settled standard. Some C3PAOs accept it; others scrutinize the specific architecture.
What your MSP cannot provide is file-level encryption where your organization holds the root keys and can revoke access to individual files regardless of where those files travel — to a contractor's personal laptop, to a subcontractor's SharePoint, to an offboarding employee's local folder. That architecture requires a solution where the cryptographic control lives with you, not with any cloud provider or managed service layer.
CUI That Leaves the Managed Environment
Your MSP's GCC High environment has a boundary. When CUI exits that boundary — downloaded to a device, forwarded to a subcontractor, sent via email — it's outside the scope of what your MSP manages. Every CUI file that leaves the controlled environment is either:
- Protected by file-level encryption your organization controls, or
- An undeclared scope gap that your assessor will find
MSPs manage the container. They cannot manage the content once the content moves. This is the architectural distinction that drives most assessment complications in MSP-managed programs.

SSP Accuracy and Legal Accountability
Your MSP may author your System Security Plan. Your organization's authorized representative signs it. That signature transfers legal accountability for the document's accuracy to you.
If the SSP asserts that SC.3.177 is met — FIPS 140-3 validated encryption — and the assessor finds that the encryption modules in use aren't validated or aren't operating in FIPS-approved mode, your organization bears the compliance finding. Not the MSP. The SSP is your declaration.
This matters particularly under the DoJ's Civil Cyber-Fraud Initiative, which applies the False Claims Act to contractors who knowingly misrepresent their cybersecurity posture. Your MSP's implementation choices are reflected in your SSP submission. Know what's in it.
Assessment Escort and Evidence Defense
Your C3PAO will ask questions that require organizational knowledge your MSP staff may not have: how specific access decisions were made, why certain systems were included or excluded from scope, the history of a particular control implementation. Evidence review requires people who can speak to decisions made across your CUI environment over time.
MSP engineers can demonstrate that a control is implemented and show the configuration. Explaining why architectural decisions were made, documenting the decision logic for scoping choices, and defending assessment findings requires organizational ownership of the compliance program — not just technical configuration.
Is Your MSP Inside Your Assessment Boundary?
If your MSP manages systems that process, store, or transmit your CUI — which GCC High deployments effectively do — they may qualify as an External Service Provider (ESP) within your CMMC assessment boundary.
Under the CMMC rules, ESPs that are part of your assessed environment can be included in your C3PAO assessment rather than requiring independent CMMC certification. This is a practical accommodation. But it means the C3PAO will examine your MSP's implementation and controls as part of your assessment, not just yours.
If your MSP is operating as an ESP in your boundary:
- Their configurations and implementations are subject to assessment scrutiny
- Gaps in their implementation are your compliance gaps
- You need to understand what they've implemented, not just that they've implemented something
The MSP relationship that works well operationally can create assessment complications if the contractor doesn't have clear visibility into what their MSP has built and why.
Closing the MSP Container Gap with Theodosian
The fundamental limitation of an MSP-only approach isn't a lack of competence; it's an architectural boundary. MSPs are built to manage containers: networks, servers, identity platforms, and cloud tenants. But CMMC Level 2 specifically regulates the content: the Controlled Unclassified Information itself.
This is where Theodosian steps in to complete your compliance architecture. Instead of forcing you to build complex, multi-million dollar network perimeters or relying entirely on shared-key cloud environments, Theodosian embeds zero-trust cryptographic protection directly into individual files.
By layering data-centric security on top of your MSP’s infrastructure, you effortlessly secure the high-weight compliance domains that leave standard MSPs struggling:
- True Organization-Controlled Key Management (SC.3.187): Theodosian utilizes a decentralized, zero-knowledge cryptographic architecture. Your organization—not Microsoft, not your MSP, and not a third-party cloud provider—holds absolute control over the root keys. You can satisfy your C3PAO auditor with mathematical proof that no unauthorized external entity can read your data.
- Persistent Protection Beyond the Perimeter: The exact millisecond a contractor downloads a file to a personal device or forwards a document to a subcontractor, Theodosian's FIPS 140-3 validated encryption stays intact. The file defends itself dynamically, validating user identity and device posture before granting access, regardless of where it travels.
- Instant, Automated Revocation: If a vendor leaves or an account behaves anomalously, you can instantly "drop the gate" and freeze access to specific data objects globally. Every downloaded copy renders itself unreadable instantly, turning a manual IT headache into automated enforcement.
Theodosian doesn't replace your MSP; it supports them. It gives your IT partners definitive technical control that protects your data at the content level, allowing you to confidently sign off on your SSP and submit an airtight SPRS score.
Six Questions to Ask Any CMMC MSP Before You Sign
- Are you a Cyber-AB registered RPO, and which specific staff hold RP (Registered Practitioner) credentials? This tells you whether advisory services are backed by formal credentials or just experience.
- Who holds the encryption keys for CUI in the architecture you're recommending? The answer needs to include a clear explanation of whether keys are Microsoft-managed, Customer Key, or something else — and how that maps to SC.3.187.
- What happens to CUI that leaves your managed environment? If the answer is "we have DLP rules to prevent that," follow up: DLP rules are a control, not a guarantee. What protects the content if a file escapes the container?
- Who signs the SSP, and who conducts the accuracy review before it's submitted? You need to understand the sign-off chain and what verification the MSP performs before you put your name on the document.
- What does your C3PAO relationship look like, and can you refer three clients who've passed assessments? Track record matters more than certifications in a program this young.
- What's excluded from your service scope, and what do we own independently? Get the gap list in writing. A well-run CMMC MSP should be able to tell you exactly what they don't cover, because they know the boundary better than you do.
What You Own No Matter Who You Hire
Regardless of how comprehensive your CMMC MSP engagement is, there are things that are structurally yours:
- SPRS score legal accountability. Whatever gets submitted to SPRS, you own the accuracy representation.
- CUI scope decision. You decide what's in scope. Your MSP implements controls within that scope. If you've underscoped, the MSP's perfect implementation of a small scope leaves you with a large gap.
- Key management for CUI that travels. Files that leave the MSP's managed environment need protection that travels with them. This is your gap to close — not with an MSP service, but with a file-level control architecture.
- Organizational culture and training. CMMC requires training for all CUI handlers. Your people need to understand what CUI is, what they're not allowed to do with it, and what to do when something goes wrong. No MSP can build that culture for you.
- Incident response execution. The incident response plan your MSP documents needs to reflect how your actual organization responds to an incident. Your leadership team needs to know the plan, own the roles, and be able to walk an assessor through it.
Stop Trying to Make Infrastructure Solve a Data Problem
Your MSP's responsibility stops at the boundary of the environment they manage. When an engineer downloads a schematic or an external vendor handles a contract, that data escapes your MSP’s control entirely. By baking FIPS 140-3 validated encryption directly into the files themselves, you ensure your data continuously defends itself on any endpoint, under any user, anywhere in the world.
FAQs: CMMC MSP
Does my MSP need its own CMMC certification?
If your MSP is operating within your assessment boundary as an ESP, they can be assessed alongside you in your C3PAO assessment rather than needing independent certification. If they're outside your boundary, providing services that don't touch CUI, they may not need certification at all. The scoping determination matters here, and it's worth resolving with your MSP before the C3PAO arrives.
Can my CMMC MSP also be my C3PAO assessor?
No. CMMC rules prohibit a consulting or implementation partner from assessing the work they helped create. The C3PAO conducting your formal assessment must be independent of the RPO or MSP who prepared you. This is an independence requirement, not a preference.
What's the difference between an MSP and an MSSP for CMMC?
An MSP focuses on IT operations and infrastructure management. An MSSP focuses on security operations — threat monitoring, SIEM management, incident response. CMMC Level 2 requires elements of both. Many CMMC service providers blend both capabilities under a single engagement, which is typically more efficient for small-to-mid DIB contractors than managing two separate vendor relationships.
Should I expect my MSP to attend my C3PAO assessment?
Yes, if they implemented the controls being assessed. Your assessor will ask technical questions that require the people who built the environment. MSP engineers should be available during the assessment for technical interviews. But organizational decision-makers — your IT Director, CISO, or operations lead — need to be present to answer questions about scope decisions, business processes, and the organizational context behind control implementations.