CMMC20X
BlueprintThe five principles
Principle 05 of 05

Ecosystem-Wide Over Contractor-Only

A contractor cannot prove every safeguard alone. Cloud and managed-service providers hold part of the evidence; the contractor still owns the result.

The Blueprint states the principle. This page explains why it matters, what changes, and where the limits remain.

The traditional approach

Consider a contractor using Microsoft 365 through an MSP. Microsoft operates the cloud service. The MSP may configure accounts and logging. The contractor chooses who receives access, trains its people, and approves procedures. A C3PAO assesses the contractor. No single party holds the whole answer.

This creates fragmentation:

  • The provider describes a feature without stating which customer configuration it requires.
  • The MSP supplies a screenshot without identifying the tenant, collection date, or account coverage.
  • The contractor assumes the provider or MSP owns a requirement that remains its responsibility.
  • The assessor has to reconstruct the handoff before testing whether the safeguard works.

The repeated paperwork is expensive. The responsibility gap is dangerous.

The CMMC 20X approach

A provider supplies a record for the security function it performs: what it does, which service and period the evidence covers, what the customer must configure, and what remains outside the service. The contractor adds its configuration and operating evidence. The assessor tests the combined claim.

In practice

TraditionalCMMC 20X
Evidence copied without contextSource, service, customer, date, coverage, and limits travel with it
Provider responsibility impliedProvider and customer tasks listed separately
Every tool defines its own packageTools exchange the same required fields and validation results
Provider claim accepted automaticallyAssessor decides whether it supports the contractor’s implementation

The DIB compliance ecosystem

OSAs / Contractors

Organizations seeking CMMC certification to bid on or maintain DoD contracts.

RPOs / Advisors

Registered Practitioner Organizations helping clients achieve compliance.

C3PAOs / Assessors

Certified Third-Party Assessment Organizations conducting CMMC assessments.

MSPs & MSSPs

Managed service providers supporting DIB client IT and security operations.

What changes for each party

For RPOs & advisors

Advisors can reuse a sound evidence method without turning their advice into the contractor’s affirmation:

  • Map the client’s actual systems and responsibilities.
  • Review evidence collected from those systems.
  • Help fix gaps without certifying their own work.

For C3PAOs

Assessors receive facts with enough context to test them:

  • Source, date, scope, and collection method are visible.
  • Provider and contractor evidence are connected but not merged.
  • Conflicts and missing coverage arrive as open questions.

For MSPs & MSSPs

Providers state exactly what their service contributes:

  • Which safeguards or functions the service performs.
  • Which evidence the provider can supply.
  • Which settings and operating tasks remain with the customer.
  • Which changes make the old evidence stale.

For contractors (OSAs)

Contractors can assemble the complete claim without pretending they operated every component:

  • Reuse provider evidence where it actually applies.
  • See the customer work the provider does not cover.
  • Change providers without losing the history of the contractor’s own decisions.

This does not require a coalition

It requires public evidence fields and clear rules for how contractors and reviewers may use provider records. Competing tools and service companies can implement those rules without joining one organization or accepting one vendor’s platform.

The contractor owns its assertion. The provider owns its service evidence. The assessor owns the finding. Government defines how those records may affect CMMC status and retains its program decisions.

What every exchanged record needs

  • Producer — who created the record and for which customer or service
  • Coverage — which system, function, accounts, data, and period it covers
  • Customer work — configuration and operating tasks left to the contractor
  • Limits — exclusions, unresolved conditions, and expiration or change triggers
  • Review state — whether the record is an assertion, software result, human finding, or authorized decision

What each participant can do now

  1. Make boundaries explicit. State systems, data flows, providers, and responsibilities before exchanging evidence.
  2. Keep the source attached. Preserve where the evidence came from, when and how it was collected, what it covers, and what it cannot prove.
  3. Separate roles. Keep producer assertions, machine analysis, reviewer judgment, and authorized decisions distinguishable.
  4. Design for change. Define when provider, architecture, scope, or risk changes make inherited evidence stale.
Where this leads

The Blueprint shows how contractor and provider evidence joins one claim without hiding who owns each part. Theecosystem map follows the handoffs in more detail.