Ecosystem-Wide Over Contractor-Only
A contractor cannot prove every safeguard alone. Cloud and managed-service providers hold part of the evidence; the contractor still owns the result.
The Blueprint states the principle. This page explains why it matters, what changes, and where the limits remain.
The traditional approach
Consider a contractor using Microsoft 365 through an MSP. Microsoft operates the cloud service. The MSP may configure accounts and logging. The contractor chooses who receives access, trains its people, and approves procedures. A C3PAO assesses the contractor. No single party holds the whole answer.
This creates fragmentation:
- The provider describes a feature without stating which customer configuration it requires.
- The MSP supplies a screenshot without identifying the tenant, collection date, or account coverage.
- The contractor assumes the provider or MSP owns a requirement that remains its responsibility.
- The assessor has to reconstruct the handoff before testing whether the safeguard works.
The repeated paperwork is expensive. The responsibility gap is dangerous.
The CMMC 20X approach
A provider supplies a record for the security function it performs: what it does, which service and period the evidence covers, what the customer must configure, and what remains outside the service. The contractor adds its configuration and operating evidence. The assessor tests the combined claim.
In practice
| Traditional | CMMC 20X |
|---|---|
| Evidence copied without context | Source, service, customer, date, coverage, and limits travel with it |
| Provider responsibility implied | Provider and customer tasks listed separately |
| Every tool defines its own package | Tools exchange the same required fields and validation results |
| Provider claim accepted automatically | Assessor decides whether it supports the contractor’s implementation |
The DIB compliance ecosystem
Organizations seeking CMMC certification to bid on or maintain DoD contracts.
Registered Practitioner Organizations helping clients achieve compliance.
Certified Third-Party Assessment Organizations conducting CMMC assessments.
Managed service providers supporting DIB client IT and security operations.
What changes for each party
For RPOs & advisors
Advisors can reuse a sound evidence method without turning their advice into the contractor’s affirmation:
- Map the client’s actual systems and responsibilities.
- Review evidence collected from those systems.
- Help fix gaps without certifying their own work.
For C3PAOs
Assessors receive facts with enough context to test them:
- Source, date, scope, and collection method are visible.
- Provider and contractor evidence are connected but not merged.
- Conflicts and missing coverage arrive as open questions.
For MSPs & MSSPs
Providers state exactly what their service contributes:
- Which safeguards or functions the service performs.
- Which evidence the provider can supply.
- Which settings and operating tasks remain with the customer.
- Which changes make the old evidence stale.
For contractors (OSAs)
Contractors can assemble the complete claim without pretending they operated every component:
- Reuse provider evidence where it actually applies.
- See the customer work the provider does not cover.
- Change providers without losing the history of the contractor’s own decisions.
This does not require a coalition
It requires public evidence fields and clear rules for how contractors and reviewers may use provider records. Competing tools and service companies can implement those rules without joining one organization or accepting one vendor’s platform.
The contractor owns its assertion. The provider owns its service evidence. The assessor owns the finding. Government defines how those records may affect CMMC status and retains its program decisions.
What every exchanged record needs
- Producer — who created the record and for which customer or service
- Coverage — which system, function, accounts, data, and period it covers
- Customer work — configuration and operating tasks left to the contractor
- Limits — exclusions, unresolved conditions, and expiration or change triggers
- Review state — whether the record is an assertion, software result, human finding, or authorized decision
What each participant can do now
- Make boundaries explicit. State systems, data flows, providers, and responsibilities before exchanging evidence.
- Keep the source attached. Preserve where the evidence came from, when and how it was collected, what it covers, and what it cannot prove.
- Separate roles. Keep producer assertions, machine analysis, reviewer judgment, and authorized decisions distinguishable.
- Design for change. Define when provider, architecture, scope, or risk changes make inherited evidence stale.