

If your MSP manages IT for any company in the defense supply chain, Cybersecurity Maturity Model Certification (CMMC) 2.0 compliance is your problem too. Defense contractors cannot outsource accountability of complying with CMMC controls, but they can outsource their implementation, and that puts MSPs directly in the middle of every assessment that follows. But, what does CMMC 2.0 mean for MSPs?
Every client that is a DoD contractor handling Controlled Unclassified Information (CUI) or Federal Contract Information (FCI) must meet CMMC 2.0 as a final rule. The question is not whether your customers need to comply but rather whether your practice is built to support it. This guide covers the requirements, who they apply to, and how to enforce them if your clients fall within scope.
As a framework, CMMC 2.0 establishes three levels of cybersecurity requirements tied to the sensitivity of the federal information a defense contractor handles:
The practical reality for MSPs: Level 2 is likely where your customers are, and the 110-practice requirement set is where your security stack either earns its place or exposes gaps.
On July 13, 2026, the Department of War suspended CMMC Phase II, pausing the mandatory C3PAO certification gate that was scheduled to enter solicitations on November 10, 2026. A CMMC Reform Task Force was stood up to conduct a 60-day review of the program, with conclusions expected around mid-September 2026.
Read this carefully: the pause is not a repeal of the security obligations for organizations in Level 2.
NIST SP 800-171 Rev. 2 safeguarding requirements and DFARS 252.204-7012 and 252.204-7020 compliance obligations are still intact. CMMC Phase I self-assessments at Level 1 and Level 2, along with the annual affirmation, are the only levels a contracting officer may currently designate. The CMMC clause under DFARS 252.204-7021 is still prescribed for use through November 2028.
Under the pre-suspension model, a C3PAO assessor reviewed the environment independently. That external check absorbed a significant portion of the verification burden. In a self-attestation world, that check disappears, shifting the full burden of verification back onto the contractor and, by extension, onto the MSP managing their environment.
The DOJ has consistently pursued False Claims Act (FCA) actions tied to DFARS 252.204-7012 noncompliance. The Civil Cyber-Fraud Initiative is active, and settlements like the case against DIB contractor LOGZONE have already demonstrated enforcement reaches NIST SP 800-171 self-assessments. FCA violations have resulted in fines reaching hundreds of thousands of dollars.
For MSPs, this creates a specific exposure scenario. If a DIB customer self-attests to a score your environment cannot support, and DOJ investigates, the trail leads to the systems, configurations, and controls you manage. It is critical MSPs work with customers to attest carefully and build environments that are defensible by evidence, not assumption.
The CMMC Reform Task Force opened a Request for Information (RFI) as part of its 60-day review. MSPs and defense contractors can submit formal comments directly through the federal rulemaking portal at regulations.gov. Search for the active CMMC-related docket and submit under your organization name or as an individual. If compliance costs have affected your practice, quantify them. Assessment preparation hours, tooling investments, staff training, and customer churn tied to compliance friction are all relevant data points. The Task Force is evaluating whether the current program structure imposes disproportionate burden on small and mid-sized contractors and their service providers. A specific, documented comment from an MSP carries more weight than a general objection. The window is open now.
Even with the Phase II suspension in place, the underlying compliance obligations have not changed. If your DIB customers have not started scoping, they are behind. Because assessment preparation depends heavily on the security stack their MSP has built and documented, waiting compounds the problem.
The cost of starting late is not just a gap remediation project. It is a contract eligibility problem with real consequences attached.
Before any tool gets deployed or any policy gets written, the scope has to be defined correctly. A poorly scoped assessment costs more, takes longer, and produces weaker evidence.
Start by identifying where CUI lives. Map every system, device, and user that processes, stores, or transmits CUI. That boundary defines your CMMC Assessment Scope. Everything inside it is subject to the 110 practices. Everything outside it, properly documented, is not.
From there, the scoping work breaks into four areas:
Here is a practical overview of each domain, what it demands, and where your stack needs to deliver:
This is where MSP engagements go wrong. CMMC compliance responsibility is not evenly distributed, and it is not transferable. Getting the boundaries right before assessment protects everyone.
End customers are always accountable for CMMC compliance. The MSP can build the environment, configure the tools, and produce the evidence, but the contractor still owns the result. Key responsibilities that fall on the customer include:
No managed service agreement changes that accountability chain.
The Supplier Performance Risk System (SPRS) is the federal portal where defense contractors submit their NIST SP 800-171 self-assessment scores. Every contractor subject to DFARS 252.204-7019 must post a current score before receiving a DoD contract award. The score ranges from negative 203 to 110, calculated by assigning point values to each of the 110 practices and deducting for unmet requirements.
MSPs do not submit scores on behalf of contractors. The submission is made by an authorized representative of the contracting organization, who attests to its accuracy. Your role is to ensure the environment you manage can support the score your customer submits. An inflated score tied to a deficient environment is the scenario that draws DOJ attention. Make sure the evidence exists before the attestation goes in.
MSPs carry responsibility for IT operational controls and for continually reviewing and adapting the quality of the security environment they deliver based upon how the Contractor's environment changes. That means configuring and managing the security platform correctly, enforcing endpoint security controls, implementing compliant network security, assisting in GRC documentation, translating SOC activity into audit-ready evidence, maintaining continuous monitoring and audit trails, conducting pre-assessment gap reviews, supporting vulnerability scans and remediation tracking, and facilitating incident response testing.
One boundary that catches MSPs off guard: physical security, personnel security, maintenance, and media protection are out of scope for the MSP. Those domains belong entirely to the contractor.
This question does not have a single answer, and that ambiguity is exactly why it catches MSPs off guard.
If your MSP accesses, processes, stores, or transmits CUI as part of delivering services to a DIB customer, your systems are likely in scope for that customer's CMMC assessment. That means your environment, your tools, and your configurations get evaluated as part of their assessment boundary. You do not necessarily need your own separate CMMC certification, but the systems you operate on behalf of that customer do need to meet the applicable requirements.
The cleaner path for most MSPs is to architect the managed environment so that CUI stays within the contractor's boundary and the MSP accesses it only through controlled, documented mechanisms. That limits scope creep into your own infrastructure. Where that separation is not possible, document the access model clearly in the SSP and treat your relevant systems as in-scope assets. Ambiguity in that boundary is a liability during assessment and a larger one if DOJ ever comes looking.
Security vendors like Todyl operate as a Security Protection Asset (SPA) provider. Its responsibility is securing and operating its own platform and serving as a reliable evidence partner. That means providing compliance attestations when requested, delivering platform-level documentation, and providing ESP evidence. Todyl is not accountable for individual CMMC requirements, cannot fulfill PE, PS, MA, or MP controls, and drafts or unverified claims from any party are not evidence.
Todyl supports and helps demonstrate compliance across the full 110-practice requirement set. No single tool covers everything, and Todyl does not claim otherwise. What it does is consolidate the capabilities that cover the most ground, reduce the fragmentation that makes evidence collection painful, and give MSPs a coherent platform to operate from.
Here is how each module maps to the CMMC domains:
SIEM supports CMMC Level 2 by demonstrating compliance across over 40 of the 110 practices. Its core strengths are Audit and Accountability (AU), Access Control and Identity Monitoring (AC/IA), Incident Response (IR), Configuration and Change Management (CM), System and Information Integrity (SI), and Risk and Security Assessment (CA/RA).
For CMMC purposes, SIEM centralizes audit log collection and correlation, provides the audit trails that prove controls are working, detects unauthorized access and suspicious activity, monitors communications for unauthorized data transfers, and supports continuous monitoring requirements across Security Assessment (CA).
The AU domain requires that every logged event trace back to an individual user. If it is not logged, it did not happen, and an assessor will treat it accordingly.
Endpoint Security supports and demonstrates 20-plus Level 2 practices, with core strength in System and Information Integrity (SI). It continuously monitors endpoints, automatically updates malicious code protection, detects and blocks unauthorized software installation, and generates the forensic telemetry that supports both audit trails and incident response evidence.
For Configuration Management (CM), endpoint tools detect and block unauthorized software at the device level. For SI, continuous endpoint monitoring is the mechanism that turns a malicious code defense policy into an observable, enforceable reality.
MXDR supports and demonstrates 20-plus Level 2 practices with Incident Response (IR) as its core strength. It fulfills the continuous monitoring mandate that runs through nearly every CMMC domain, provides the documented operational IR capability that assessors look for, and produces audit-ready evidence of threat detection, investigation, and response activity.
For MSPs that do not run an internal SOC, MXDR delivers a formalized security operations function with the documentation to support it. For the IR domain specifically, CMMC requires that incident handling capabilities be built, tested, and documented, and that all incidents get tracked and reported. MXDR supports all three.
LAN Zero Trust (LZT) enforces zero trust policies on internal networks, directly supporting Access Control (AC) and System and Communications Protection (SC) requirements. It restricts access to unauthorized ports and protocols, limits internal network access to authorized connections, and demonstrates least-privilege enforcement at the network layer.
The SC domain is the largest in CMMC Level 2, covering 16 requirements. Every boundary, pathway, and channel through which CUI flows falls under its scope. LZT is the enforcement mechanism that makes internal access controls auditable.
SOAR executes automated containment actions in response to SIEM alerts, terminates unauthorized user sessions for Access Control (AC) violations, disables accounts in response to System and Communications Protection (SC) policy violations, and automatically disables terminated employee accounts that engage in potentially malicious behavior.
The value for CMMC is specificity: SOAR produces records of every enforcement action taken during an event, turning incident response from a described process into documented evidence.
GRC serves as the demonstration layer across virtually all 110 Level 2 practices. Its core strength is Security Assessment and the System Security Plan (CA), but its scope runs across every domain: Risk Assessment (RA), Awareness and Training (AT), Access Control (AC/IA), Incident Response (IR), Configuration Management (CM), Personnel and Physical Security (PS/PE), Maintenance and Media Protection (MA/MP), and System Integrity and Communications (SI/SC).
Policies, procedures, assessments, and evidence artifacts that assessors require all live in GRC. For domains where Todyl's technical controls do not apply, like PE and MP, GRC provides the process documentation that satisfies the requirement.
In a self-attestation environment, GRC is how you prove compliance evidence, showcasing requirements directly rather than just claiming them. In conversations with the DOJ, that proves a major difference maker.
Clarity on this matters, because overpromising on compliance tooling is how MSPs and contractors end up with indefensible attestations.
Todyl does not act as a panacea for all CMMC Level 2 components. It does not provide a silver bullet for any individual practice, nor does it offload compliance responsibility from the contractor or the MSP. GRC documentation alone does not constitute comprehensive compliance. Todyl also does not eliminate the need for other solutions, including MFA systems and vulnerability scanners.
A platform that supports 110 practices is not the same as a platform that satisfies them. The contractor still has to implement controls, enforce them, and prove it.
The CMMC Reform Task Force report lands around mid-September 2026. Whatever it produces, the underlying obligation to protect CUI and FCI is not going away. Neither is DOJ enforcement under the Civil Cyber-Fraud Initiative.
Contact Todyl to see how the platform maps to CMMC Level 2 and how your practice can support defensible compliance for defense contractor clients today and for whatever the Reform Task Force finalizes next.
Evaluate your security posture against AI-powered attacks and get recommendations to close any gaps.
Subscribe to our newsletter to get our latest insights.