The Cybersecurity Maturity Model Certification, CMMC, is currently the most important information security framework for thousands of businesses across the country. Businesses that wish to work with the Department of Defense, or a DoD subcontractor, are quite likely to need to earn their CMMC certification in order to win those contracts.
For those businesses that haven't been paying attention, this can come as a significant surprise. The September 2025 Final Rule for CMMC mandates CMMC for nearly every business within the DoD ecosystem that handles FCI or CUI.
If you're not sure whether or not you handle those kinds of information, read our guide.
Where things get tricky is when you're not a direct contractor or subcontractor; instead, you provide services to those entities. Managed Service Providers and External Service Providers have to do some serious analysis to determine what their requirements are with regard to CMMC. Fortunately, that's what this guide is for.
All of this follows recent clarifications from the Cyber-AB. ESPs (and other subcontractors) had, for a while, been operating under the assumption that because they didn't work directly with the DoD, they didn't need CMMC. After numerous high-profile supply chain attacks, it's more clear than ever that this isn't an appropriate stance.
It's all about the flow of information. Wherever sensitive information touches needs to be secured, no matter how far down the chain it goes.
BLUF - Bottom Line Up Front
CMMC is the top US security framework for firms that want DoD contracts or subcontracts. The Sept 2025 Final Rule makes CMMC mandatory for almost every DoD ecosystem firm that handles FCI or CUI. MSPs and ESPs must check data flow and contracts. Four outcomes: exempt (COTS, staff agencies, temporary access), no CMMC, client scope via SPAs, or full CMMC when FCI or CUI exist on your systems.
MSP or ESP: Which Are You?
First, some definitions. As far as CMMC and the DoD are concerned, what is an MSP, what is an ESP, and which one are you?
MSPs, Managed Service Providers, are not a technical definition within the CMMC ecosystem. In fact, it was removed from the CMMC documentation in one of its revisions for further clarity. Instead, the term MSP is an industry term for a business that provides some kind of service for clients, usually some kind of IT service.
ESPs are defined in the CMMC documentation. They're third-party organizations providing services to DoD contractors or subcontractors. They aren't directly working with the DoD, hence the name "external", but they are still part of the overall ecosystem.
MSPs are a subset of ESPs, but not all ESPs are MSPs.
Fortunately, for the purposes of this post, the specific terminology doesn't hugely matter. It's all about the information.
Follow the Information: FCI, CUI, and SPAs
By now, you are likely familiar with FCI and CUI, but SPAs might be less common.
They are, however, critical to determining whether or not you need CMMC.
- FCI: Federal Contract Information, less sensitive but still sensitive information the government wants to secure. Generally, if FCI is all you handle, CMMC Level 1 is all you need.
- CUI: Controlled Unclassified Information, sensitive information that needs to be protected because of the potential for damage it represents if it leaks. Must be secured with CMMC Level 2 or higher.
SPAs are Security Protection Assets. They're sensitive information, but not necessarily information that could be damaging if it's released. It's things like firewall logs, SIEMs, and other assets. It's not FCI or CUI itself, but it is critical information relating to the security surrounding it.
The sorts of logs and artifacts we talk about storing in the Ignyte Platform as part of the proof package you need to achieve certification are at least partially made up of SPAs.
Four Possibilities with CMMC for ESPs
There are four possible situations you can be in as an ESP, and the situation you're in will determine whether or not you need CMMC, and how you engage with CMMC as a whole.
Possibility #1: CMMC Exemptions
The first possibility is that you're somewhere within the CMMC ecosystem, but you technically don't actually need CMMC, because you're part of one of the exemptions. There are three main exemptions.
The first is COTS products, or Commercial Off-The-Shelf products. These are products or services that are offered to the general public and to the DoD ecosystem in the same way. The DoD doesn't need special notebooks or pencils, special server racks, or special versions of Adobe Acrobat to function.
The second is people, or rather, staffing agencies. If you're an ESP providing staffing for DoD contractors, it's not your responsibility to be CMMC-certified. Rather, it's the responsibility of the contractor to train the people they hire. This helps prevent cases where you need to either maintain a roster of government-trained temps, or otherwise train people who will never work within the scoping boundary.
The third is temporary access services. These are external services you provide to CMMC-certified contractors that technically access systems with controlled information on them, but that access isn't constant or fully necessary. For example, if your ESP provides a vulnerability scanner, or you're a penetration testing firm, you access systems containing CUI to do your job, but you don't use or retain that access. You can be exempted from CMMC if you fall into this category as an ESP.
Possibility #2: No CMMC Required
The second possibility is that you're an ESP that has no need for CMMC, despite providing services to CMMC-certified businesses.
This occurs when your business doesn't actually handle or process any of the three kinds of sensitive information, not even SPAs.
One of the most common examples is the archetypal MSP providing IT support services. You have staff who are trained at troubleshooting hardware and software issues. When your clients have problems, they call you, and you send a tech out to analyze the situation.
The tech may be working on computers that access CUI systems. The tech may be in a secured area within the physical boundary. But that doesn't mean your business or your systems need to be CMMC-certified for your tech to work. You don't need to access or touch the CUI, FCI, or SPAs to do your job.
Following the flow of information, none of the sensitive information enters your systems as an MSP/ESP, so there's no reason for you to be secured as if it were.
Possibility #3: Part of Client Assessments
The third possibility, and the one that trips up the most MSPs, has to do with SPAs.
If you're an MSP or ESP that interacts with SPAs but not with FCI or CUI, then you're technically within scope for CMMC, with a twist. It's not your scope.
When you provide a service that creates or accesses SPAs for your clients, then those SPAs are part of the system boundary and proof that your clients need to prove that they're CMMC-ready.
Say, for example, that you're a provider of corporate firewalls. You don't process or handle FCI or CUI. It technically passes through your firewall, but it's encrypted, and you don't have access to it. You provide logs of firewall access and blocking to your client.
Your client needs those firewall logs to prove they have a firewall that works and is effective. That makes you part of your client's scope. Not your own scope, but your client's.
What this means is that while your client needs CMMC, you don't. You provide assets for your client's certification, but you do not need to be certified yourself.
This possibility has been the cause of a lot of headaches over the last year. MSPs have long off-loaded the responsibility to their clients, but with expanded CMMC rules, those clients now need their MSPs to provide specific documentation and data so they can be certified. MSPs that fail to provide appropriate documentation can jeopardize the certification for their clients and cause no end of problems.
In practice, this mostly just means knowing what kind of information your clients will need, and how to provide it in an appropriate format. Surprisingly, that low bar is still hard to clear for some companies.
Possibility #4: Full CMMC Required
The fourth possibility is that your ESP provides some kind of service that does place FCI or CUI on your own systems. Following the flow-down of information and, along with it, security requirements, you would be required to have CMMC certification, typically Level 2.
There are a lot of possible ESPs that provide these kinds of services. Remote monitoring and management services and tools, remote data collection, services that manage Microsoft GCC High and similar government-aimed services, and so on are all common examples.
Another common example is data backup services. Even if the data is encrypted, if it's stored on your systems for the purposes of backing it up in case of disaster, you need the CMMC boundary to keep it secured.
When you need CMMC, you may have a lot of work ahead of you. But once you have it, you'll be in a good position to provide your services to more contractors with the DoD. This opens up further contracts now that you have a full awareness of your responsibilities, along with validated security.
Yes, being surprised that you need CMMC, facing down potential penalties, a big investment in future security, and a whole lot of work is intense. The rewards, however, can be very worth the investment.
Practical Guidance: How to Find Your Responsibilities
If you're an MSP or ESP, it's important that you know what your responsibilities are. So, how do you figure them out?
The easiest option is to look at the contracts you sign, or want to sign, with clients. If any of them are part of the overall DoD ecosystem, then they'll have a hefty responsibility to secure FCI and CUI. That extends to their subcontractors, and will be expressed through requirements in their contracts.
You can also follow a flowchart.
Do you have any customers or clients that are part of the DoD ecosystem, no matter how far down the chain? If no, then you're fully in the clear. You can continue to investigate CMMC if you want to be aware of it, and if you want to offer subcontracting services down the line, but you don't need to.
If yes, do you provide SPAs to those clients? If you don't provide any sort of Security Protection Assets to your clients, then you likely aren't going to be part of their scope. You can talk with your client's representative to be certain, but truthfully, you should already have had this conversation before you signed a contract.
Some MSPs reach this point and look up information like this post because of a point of contention. If you've believed you're exempt from CMMC, but your clients now insist that you're part of their scope (or worse, you need CMMC yourself), you may be skeptical. Our goal is to help you understand your responsibilities.
Do you handle, store, process, transmit, or otherwise interact with FCI or CUI? If so, you need CMMC yourself. CMMC for your clients is up to them to determine, again following the flow of information. But if you handle that information in any way yourself, you will need a full CMMC implementation, usually at Level 2.
We have a more thorough guide to ESP scoping here, for further information.
Finally, you can also talk to experts like us. Here at Ignyte, we're part of the CMMC ecosystem ourselves, and we've worked with clients in every possible placement within the overall system. We can help ask you the right questions, guide you on finding the relevant information, and determine if you need CMMC yourself.
If it turns out that you do need CMMC, we can help you with that as well. We're an accredited C3PAO for CMMC, meaning we can provide both information and assessments to CMMC hopefuls, along with consultations and more. We even designed the Ignyte Assurance Platform as a way to facilitate helping as many businesses as possible adhere to security frameworks, including CMMC, FedRAMP, ISO 27001, and more.
All you need to do to get started is reach out. One simple contact form is all that stands between you and clarity. Let us know what you need, and we'll help set you on the right path.

Dan Page is a seasoned Cybersecurity and Risk Management Executive known for advancing security programs aligned with complex regulatory frameworks and critical business objectives. With over 12 years in information security, his expertise began in the U.S. Army Signal Corps, where he led global communications and secured classified networks supporting Special Operations missions. Post-military, he specializes in security architecture for CUI, ITAR data, and federal cloud workloads. Currently, as Senior Cybersecurity Manager at Ignyte Assurance Platform, Dan guides organizations through compliance with CMMC, FedRAMP, ISO 27001, PCI, and NIST standards. A CISSP, CRISC, CISM, PMP, and ITIL-certified professional, he is also a cybersecurity lecturer and community volunteer advocating workforce development.
BLUF - Bottom Line Up Front





