Keep one record of what you protect, how you protect it, and what changed.
A contractor can hire an MSP or advisor. It still owns its scope, safeguards, gaps, evidence, and organizational affirmation.
Know what you are affirming.
A tool, provider, advisor, or assessor may contribute evidence or judgment. None of them makes the supplier’s organizational assertion on its behalf.
What you own. What others need from you.
The six roles perform different work and hold different authority. These are the facts this role has to supply, receive, and keep current.
- Owns
- The contractor decides what is in scope, configures its safeguards, fixes its gaps, and signs its organizational affirmation.
- Produces
- A boundary and data-flow diagram, asset list, system security plan, implementation statements, evidence for each objective, and an explicit record of unresolved gaps.
- Receives
- Service evidence from providers, readiness help from advisors, findings from assessors, and contract requirements from a prime or Government.
- Rechecks when
- Recheck the record when CUI flow, systems, assets, providers, responsibilities, safeguards, or contract requirements change.
Three ways to apply it.
- 01
Ask whether an assessor can trace and test the claim, not whether a dashboard says the work is complete.
- 02
Record implementation facts and evidence as the work happens; generate the SSP and review package from that record.
- 03
Fix missing, conflicting, stale, or out-of-scope evidence before making or renewing the claim.
Continue from this role.
Follow the shared Blueprint, examples, analysis, and current work that apply most directly to this part of the system.
- 01
Follow the operating loop
Start with scope, implement the safeguards, record the facts, review them, decide, and update.
- 02
Prepare for examination
Read what assessment-ready means when an independent reviewer has to trace the claim.
- 03
Follow one worked claim
See a synthetic MFA record with one missing account, a conflict, and a human finding.
- 04
Compare the reform options
See how seven CMMC policy options change security coverage, supplier loss, queues, exposure, and cost.
What does this role page miss?
Bring a real or synthetic handoff, conflict, responsibility boundary, or decision this model needs to handle.
Start a technical discussion