At recent CyberAB Town Halls, CEO Matthew Travis clarified critical points about External Service Providers (ESPs) and their impact on your organization's Cybersecurity Maturity Model Certification (CMMC) assessment. This clarification is essential for Organizations Seeking Assessment (OSAs) who utilize outsourced services.
External Service Providers (ESPs) are third-party entities contracted to manage, consult, process, store, or transmit your organization's information. They may be called by a variety of names with broad or narrowly defined responsibilities: Managed Services Providers (MSPs), Managed Security Services Providers (MSSPs), Infrastructure-as-a-Service, Help Desk, Solutions Architects, and more. The services they provide are what matters to you as an OSA.
ESPs may provide the following services:
Staff augmentation— traditional IT
Procurement services
Infrastructure as a Service (IaaS)
IT security services (MSSP)
Security Protection Data (SPD) refers specifically to data stored or processed by Security Protection Assets that are used to protect an OSA's environment. In the CMMC Level 2 Scoping Guide, SPDs are defined as “security-relevant information which, if disclosed, could aid an attacker in the compromise of the system. It includes, but is not limited to:
Matthew Travis explained, referencing 32 CFR Table 4 §170.19(c)(2)(i):
The implications are significant:
Ultimately, this could impact your business’s ability to win contracts.
For OSAs, this reality underscores the importance of clearly understanding your ESP's role and scope of service. For many businesses it is not transparent to them what exactly is being handled by their managed services or security services provider. Remember that CMMC Level 2 assessments inspect 340 objectives: find out what portion of those objectives are shared between you and your ESP, what is wholly owned by the ESP, and what you are entirely responsible for.
Once you understand what your ESP is responsible for, encourage or require those ESPs handling CUI to proactively pursue independent CMMC certification. This will assist you in the timing and scheduling of your business’s assessment.
For ESPs handling SPD, make sure to coordinate with them for their availability during your assessment time period.
Taking these steps can mitigate your overall assessment cost and complexity significantly.
MNS Group recognized this critical compliance issue early and proactively pursued CMMC Level 2 certification. As one of the first MSPs to achieve this certification, MNS Group ensures significant cost savings and peace of mind for OSAs during the certification process.
As the CyberAB continues to clarify these rules, it's crucial to stay ahead of changes. Engage your ESPs now to understand their current certification status and compliance readiness.
What's your take? Should ESPs proactively certify to alleviate this burden, or should OSAs bear this responsibility?
Stay informed and proactive in navigating CMMC compliance effectively.