CMMC20X
Your part in the security system

Prove the part your service performs. Name what remains with the customer.

A provider logo on a diagram proves nothing. The provider needs to identify the security function, evidence, limits, and customer configuration.

The position

State what the service does and what the customer must do.

Provider evidence can support a customer’s claim. It does not prove how the customer configured or used the service, or determine the customer’s assessment result.

Security responsibility

What you own. What others need from you.

The six roles perform different work and hold different authority. These are the facts this role has to supply, receive, and keep current.

Owns
The provider is responsible for accurately describing its service, people, hosting, data handling, configuration, and security work.
Produces
A current service description, customer responsibility matrix, operating evidence, known limits, and notices when the service changes.
Receives
The customer’s scope, intended use, information types, contract requirements, and the work the customer will perform.
Rechecks when
Notify affected customers when architecture, hosting, subprocessors, data paths, safeguards, responsibilities, or available evidence change.
See how all six roles work together
In practice

Three ways to apply it.

  1. 01

    State which assessment objectives the service supports and which remain with the customer.

  2. 02

    Let authorized customers export the service facts an assessor needs; do not label raw telemetry as a passing finding.

  3. 03

    Tell every affected customer when a service change may invalidate one of its claims.

Challenge the model

What does this role page miss?

Bring a real or synthetic handoff, conflict, responsibility boundary, or decision this model needs to handle.

Start a technical discussion