
CMMC Compliance Guide · 2026-06-19 · 20 min
Key moments - from our scoring
Substance score
46 / 100
Five dimensions, 20 points each
Justice IT Consulting's Stacey and Brooke break down four critical clarifications from the DOD's updated CMMC FAQ that reshape how contractors and service providers approach compliance. Joint ventures don't automatically inherit parent-company CMMC certifications - the status depends entirely on the venture's structure and operations. Paper-only CUI that never enters electronic systems falls under DOD Instruction 5200.48 instead of CMMC Level 2, exempting small subs from $100K+ certification costs if they handle physical documents exclusively. Significant changes triggering reassessment include mergers that consolidate IT infrastructure, directory services, or organizational structure - not merely paperwork transactions. Most importantly, MSPs don't need their own CMMC certification, but they're absolutely in assessment scope if they touch security protection data (SPD) - covering RMM tools, SIMs, and any security infrastructure protecting CUI. The episode targets contractors managing subcontractor networks, MSPs supporting defense clients, and companies navigating M&A without derailing certifications.
No. Joint ventures must be assessed independently based on their own structure, operations, and how contracts flow to them. Parent certifications do not transfer to new joint venture entities.
No. Paper-only CUI is controlled under DOD Instruction 5200.48 instead of CMMC standards, provided the CUI is never scanned, transcribed, or digitized into any electronic system.
Mergers and acquisitions that consolidate IT infrastructure, directory services, or organizational structure (cage codes, ownership changes) trigger reassessment. Simply maintaining separate systems post-merger typically does not.
No, MSPs don't require independent certification, but they must participate fully in the client's assessment with complete documentation, policies, responsibility matrices, and CRMs for all security tools they deploy.
Yes. Any tool or vendor providing security protection (RMM, SIEM, monitoring, logging) is in assessment scope for security protection data (SPD), regardless of whether they see actual CUI. Security infrastructure is always in scope.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains several genuinely useful regulatory clarifications - paper-only CUI exemption under DoDI 5200.48, the SPD/SPA scoping distinction, and the ESP vs. CSP taxonomy - that practitioners would benefit from. However, the insight-per-minute ratio is dragged down by heavy filler, repeated hedging ('it depends,' 'all that kind of fun stuff'), and meandering explanations that dilute the substantive content.
that paper CUI uh just has to be controlled like like a paper CUI uh by DOD I DOD instruction 5200.48
They may not be in scope for CUI, but they're in the assessment scope
The content is almost entirely interpretive - explaining what the DoD FAQ says rather than offering first-principles analysis or contrarian takes. The SPD/SPA distinction and paper-CUI carve-out are underappreciated in general discourse, giving modest credit, but there is no original framing or pushback against the regulatory guidance itself.
SPD is the data, so security protection data. If something processes security protection data or holds it, then it's a security protection asset, right?
They will be an external service provider, which is external service provider is the whole umbrella, and then there's uh and that's an ESP.
Brooke is a working CMMC practitioner at a consulting firm with hands-on assessment experience, which gives credibility for this niche topic. However, no credentials (CCP, CCA, C3PAO affiliation) are established, the firm appears small, and the knowledge - while real - reflects practitioner familiarity rather than authoritative expertise at scale.
We we set through the whole assessment with our clients. That's just what we do.
We have a tendency to be you know a completely outsourced IT department for uh for our clients
There are a handful of concrete references - DoDI 5200.48, a $100K certification cost estimate, and the five-criteria CSP test - that anchor the discussion. However, no named companies, no case study data, no timelines or contract-level specifics are offered, and the $100K figure is dropped without sourcing or range context.
that paper CUI uh just has to be controlled like like a paper CUI uh by DOD I DOD instruction 5200.48
there's no way that they're gonna spend you know$100,000 just on certification
Stacey's questions are well-structured and target genuine points of confusion in the practitioner audience, but she never follows up when Brooke hedges, never asks for a concrete example when answers stay abstract, and allows rambling answers to go unchallenged. The format is a scripted Q&A rather than a probing conversation.
If an MSP provides infrastructure or support for an environment that contains CUI, does that MSP automatically need its own CMMC certification?
Let's say an MSP provides IT support and an MSSP manages security tools, but neither vendors ever directly receive CUI. Many companies assume that means these providers are out of scope. Would that be true?
Computed from the transcript - who did the talking, and the words that came up most.
Submit any questions you would like answered on the podcast! The Department of Defense just updated its CMMC FAQ document - and the clarifications inside answer some of the most common (and costly) assumptions contractors make. In this episode, Brooke and Stacey break down what changed for joint ventures, paper-only CUI, significant change triggers, and how MSPs and MSSPs actually fit into assessment scope. If you're navigating a merger, working with subcontractors, or relying on an MSP to manage your environment, this episode clears up exactly where you stand - and where you don't.
Transcribed and scored by The B2B Podcast Index.
1 - > Stacey: Hey there. 2 - > Welcome to the CMMC Compliance Guide podcast. 3 - > I'm Stacy. 4 - > Brooke: And I'm Brooke.
5 - > Stacey: From Justice IT Consulting, where we help 6 - > businesses like yours navigate CMMC and NIST 800-171 7 - > compliance. 8 - > We're hard guns getting companies fast-tracked to 9 - > compliance, but today we're here to give you all the secrets for 10 - > free. 11 - > So if you want to tackle it yourself, you're equipped to do 12 - > so. 13 - > Let's dive into today's episode and keep your business on track.
14 - > Today we're talking about several new clarifications that 15 - > recently came out in the Department of Defense's updated 16 - > CMMC frequently asked questions document. 17 - > We're talking about things like joint ventures, whether 18 - > paper-only CUI requires an assessment, what actually counts 19 - > as a significant change after certification, and how MSPs and 20 - > MSSPs fit into assessment scope. 21 - > So let's dive right into it. 22 - > Okay, Brooke, let's start with joint ventures because we see 23 - > more and more contractors teaming up to pursue 24 - > opportunities.
25 - > A lot of people assume that if both companies already have a 26 - > CMMC status, then the joint venture automatically inherits 27 - > that status. 28 - > Is that really how it works? 29 - > Brooke: Well, not necessarily. 30 - > Or merged with or acquired.
31 - > Well, if it's a joint venture, I guess they're buying it anyway, 32 - > or investing in it or whatever. 33 - > But um so it really it wholly depends on how you're doing 34 - > business and what you intend to do, uh how how that contract 35 - > comes down to that company that's doing the work, right? 36 - > Uh so you know, if you're if uh I mean there's a ton of 37 - > different ways, I guess, to look at it, but you know, if a uh 38 - > joint venture or a you know PE company or something came in and 39 - > bought a company out and is going to change the structure of 40 - > that company and how it works, then you very well might have 41 - > something to worry about, but the they won't inherit the 42 - > controls or they won't inherit the certification at all.
43 - > Stacey: So another clarification that caught a lot of people's 44 - > attention involved hard copy CUI. 45 - > We've talked to companies that keep everything on paper and 46 - > assume CMMC doesn't really apply to them. 47 - > What does that new guidance say about that? 48 - > Brooke: Well, you know, this is interesting.
49 - > It's bad for the uh for the manufacturers, but for the 50 - > construction folks, it's even worse. 51 - > You know. 52 - > They say, well, what about, you know, I know uh I know so-and-so 53 - > over here, you know, they're not uh they're not CMMC certified, 54 - > and they they have no they're not even gonna bother going to 55 - > get it, you know, and and uh, you know, all that kind of fun 56 - > stuff. 57 - > And I won't tell you some of the other things they said, but uh, 58 - > you know, they're they're very worried about that.
59 - > Um so uh a little while back the Army came out and said, hey, you 60 - > know what? 61 - > If all you do is give paper CUI to a sub, right, uh, and they 62 - > don't have they don't put it in any of their electronic systems, 63 - > they just use that paper, they don't copy it, they don't scan 64 - > it, they don't nothing. 65 - > They don't, you know, retype it or anything. 66 - > It's not digitized.
67 - > Right, it's not digitized, they don't go, you know, draw it 68 - > themselves into their systems, then then um then that papers 69 - > that paper CUI uh just has to be controlled like like a paper CUI 70 - > uh by DOD I DOD instruction 5200.48. 71 - > Uh so there are controls around it, but that company does not 72 - > have to have a level two certification. 73 - > They don't have to be assessed to CMMC standards, right?
74 - > And so uh that was a that was a godsend for a bunch of, 75 - > especially contractors, uh that are contractoring out to all 76 - > these small companies that there's no way that they're 77 - > gonna spend you know$100,000 just on certification, right? 78 - > Um so uh so if you have paper CUI, it doesn't go into any 79 - > electric uh electronic systems, uh doesn't get transcribed or 80 - > you know, put in any way in any uh electronic systems, then yes, 81 - > that that does not require uh uh the same level of protection, it 82 - > does not require CMMC level two certification or assessment.
83 - > Stacey: So one of the big questions that we hear often is 84 - > that after a company achieves uh their compliance, what happens 85 - > next? 86 - > So what specifically qualifies as a significant change that 87 - > could require reassessment? 88 - > Brooke: Uh yeah, so you you want to stay away from the uh the uh 89 - > significant change. 90 - > So uh they've they've come out, and I'm sure they'll come out 91 - > again and try to explain what significant means.
92 - > Uh but they did specifically call out mergers and 93 - > acquisitions, right? 94 - > Uh that that likely would uh if there is a merger of companies, 95 - > you know, again, this is also going to depend on how they do 96 - > business. 97 - > If they if they merge, but the companies do still do business 98 - > as how they used to with the separate systems and all that, 99 - > then likely, no likely, because I don't know every particular 100 - > instance, but uh likely it wouldn't require a reassessment.
101 - > But when you start wanting to gain the efficiency of having 102 - > one company rather than two, having one IT department, having 103 - > one directory, having one, you know, all that kind of fun 104 - > stuff, that changes the scope. 105 - > So that will absolutely 100% uh require reassessment. 106 - > And so you want to stay away from those kinds of changes. 107 - > You want to pay attention to when your certification date is 108 - > coming up again, you know.
109 - > Oh, hey, it's uh it's uh a year out, so let's start planning 110 - > this and let's get ready to cut over, and then you know, you 111 - > could have to figure out how that works exactly. 112 - > But uh, you know, uh at that point you'd want to wait until 113 - > that point to do something. 114 - > Otherwise, you will have to go through that reassessment, and 115 - > it will be a complete reassessment. 116 - > And if the systems are merged and all that, you may feel 117 - > comfortable going through just straight to the certification 118 - > assessment.
119 - > Um but you know, early in the game like this, I would still 120 - > think about doing a mock, even though you may have done two 121 - > mocks and two certifications already. 122 - > You know, if you merge systems, um it really depends on uh on a 123 - > number of factors. 124 - > But really, if you do that, consider doing going ahead and 125 - > doing another mock again, right? 126 - > So uh but yeah, it's uh those kinds of changes that change the 127 - > scope um or change how the company will do will receive 128 - > contracts, those you know, cage codes, stuff like that, high 129 - > level, highest level owner, all that kind of fun stuff, that 130 - > that very well may uh cause a reassessment, cause an 131 - > invalidation of your current certification, I should say, 132 - > which will require a new assessment.
133 - > Stacey: I can imagine that you probably want to move 134 - > strategically with that because not only is it the reassessment, 135 - > but it's the reassessment cost added there. 136 - > So it's not cheap. 137 - > Brooke: Right. 138 - > That that's not cheap, and you know, all the work to get there 139 - > is not cheap, you know, and and uh so you know it's a it's it's 140 - > a process that you need to plan very well for and think about 141 - > all the risk involved.
142 - > Stacey: Aaron Powell All right. 143 - > Let's jump into managed service providers because this is 144 - > another area where there are a lot of assumptions. 145 - > So if an MSP provides infrastructure or support for an 146 - > environment that contains CUI, does that MSP automatically need 147 - > its own CMMC certification? 148 - > Brooke: Aaron Powell Not at all.
149 - > Um so the uh the MSP does not need their own certification. 150 - > Uh it will make things easier uh for the assessor and for the OSC 151 - > and for the MSP. 152 - > Um OSC is going to be the organization seeking 153 - > certification, which is the contractor that has the contract 154 - > that hired the MSP, basically, right? 155 - > Um so uh but it doesn't require uh the MSP to have a 156 - > certification, although it is helpful.
157 - > What it will require of the uh MSP uh is that they're part of 158 - > that assessment. 159 - > And so what I can tell you is being part of that assessment uh 160 - > is no small task. 161 - > It's it's uh it's a lot of prep, it's a lot of uh you know, 162 - > sitting down and going through it. 163 - > Uh you've got to have somebody knowledgeable uh about CMMC and 164 - > about your systems, uh about the policies involved, the uh 165 - > responsibility matrices involved, and all that kind of 166 - > fun stuff.
167 - > You've got to have somebody, uh somebody or somebody's uh 168 - > familiar with all that to sit through uh through the 169 - > assessment. 170 - > So uh there's I'm sure they might be we we set through the 171 - > whole assessment with our clients. 172 - > That's just what we do. 173 - > Uh and we devote a lot of time to it.
174 - > We do devote a lot of time, of course, to prep. 175 - > But um I'm sure that they could probably uh set it to where the 176 - > MSP doesn't necessarily have to be there every day, but um or 177 - > maybe not all day every day. 178 - > Uh but there are there are quite a few uh we say there's tons and 179 - > tons of documentation, which is true. 180 - > There's not many of the controls that you can just do technically 181 - > and not have you know documentation uh uh to back well 182 - > you have to really have to have documentation for everything, 183 - > but there's there's not a lot that the that are just the 184 - > company um themselves with no MSP at all.
185 - > Um so the MSP dependent on what the MSP does, of course. 186 - > We have a tendency to be you know a completely outsourced IT 187 - > department for uh for our clients, so we do a lot for 188 - > them. 189 - > So we've there's I don't see how we could not be on the call 190 - > every day with the uh with the assessors in the company. 191 - > So um so there's there's a lot of time commitment, there's uh 192 - > all sorts of documentation and proof and everything else that 193 - > the MSP will uh have to have ready and and show uh during the 194 - > assessment.
195 - > Uh so there's it's a it's a tall ask. 196 - > And if you have more than one, if if you're an MSP and you have 197 - > more than one client, then you know you might look at getting a 198 - > certification. 199 - > You know, is it expensive? 200 - > Yes, it is.
201 - > Uh will it help you and your clients with this? 202 - > Will it help you with anything else down the road? 203 - > You know, so those are the questions you have to ask 204 - > yourself if you're an MSP. 205 - > Um but short answer is no, you don't have to have a 206 - > certification if you're an MSP, but you do have to have your 207 - > ducks in a row, you have to have all your documentation.
208 - > You you absolutely have to have your uh customer responsibility 209 - > matrix. 210 - > And and the that's a CRM, so the CRMs of all your security 211 - > products that you use to secure their environment. 212 - > Stacey: Aaron Powell Here's another situation we see pretty 213 - > often. 214 - > Let's say an MSP provides IT support and an MSSP manages 215 - > security tools, but neither vendors ever directly receive 216 - > CUI.
217 - > Many companies assume that means these providers are out of 218 - > scope. 219 - > Would that be true? 220 - > Brooke: Well, they're maybe out of scope for the CUI, but uh you 221 - > got to understand the different categories uh of data. 222 - > Uh one is uh the CUI, of course, controlled unclassified 223 - > information.
224 - > Uh the other one is uh SPD or SPA. 225 - > Uh SPD is the data, so security protection data. 226 - > If something processes security protection data or holds it, 227 - > then it's a security protection asset, right? 228 - > So if you hold a process SPD, then you're an SPA.
229 - > So um and that includes people, that includes MSPs, that 230 - > includes whatever security tool you might have. 231 - > And so when you're thinking about a security, you're 232 - > anything, any of your tools that help secure the environment of 233 - > the CUI are going to be in scope as far as being uh being in the 234 - > assessment scope. 235 - > They may not be in scope for CUI, but they're in the 236 - > assessment scope. 237 - > You will be assessed on those security controls.
238 - > Uh if you provide a SIM that's a cloud-hosted SIM, uh SIM is a 239 - > security uh information and event uh monitor. 240 - > Uh so if you provide that, that'll be in scope. 241 - > You'll have to have a CRM for it. 242 - > It'll have to say what uh what you do and what what the SIM 243 - > vendor does.
244 - > Um, you know, and then you'll have to make sure that the SSP 245 - > says, you know, what exactly you do and what the client's 246 - > responsible for. 247 - > Um well we generally write that in the SSP, but in the in your 248 - > CRM, that would be what is in your CRM in detail, uh actually. 249 - > So uh but nevertheless, uh even if you never see CUI, uh you're 250 - > still in the assessment scope for security, uh for security 251 - > protection. 252 - > Any security that protects uh CUI in any manner is gonna be in 253 - > scope.
254 - > Your your RMM, your remote monitoring and management tool, 255 - > uh is gonna be in scope. 256 - > It'll be in scope at least for SPD because it provides updates, 257 - > you can run scripts with it, uh monitor the machine, uh get 258 - > alerts from it, all that kind of fun stuff. 259 - > Those are all security actions. 260 - > You can't say they're not, uh, but you have to uh also make 261 - > sure it's configured uh to where uh you don't have a chance of 262 - > seeing CUI when you hop on somebody's machine, right?
263 - > Uh so there are ways to scope that out of CUI, but you have to 264 - > know how to do that. 265 - > And you also have to be able to get the CRM for that for that 266 - > RMM tool. 267 - > Um in any case, uh you are still in the assessment scope for the 268 - > question. 269 - > You're still in the assessment scope with SPD as an MSP.
270 - > Is that enough TLAs for you? 271 - > That would be a TLA, it would be a three-letter acronym. 272 - > So there's a bunch of those. 273 - > Stacey: Yeah, there's plenty in CMMC.
274 - > Brooke: Yeah, plenty. 275 - > CMC, the military, MSP, the IT world. 276 - > Yeah. 277 - > Stacey: All right.
278 - > We're gonna wrap up with this final question that creates a 279 - > lot of confusion. 280 - > If my MSP manages my cloud environment, does that 281 - > automatically make them a cloud service provider? 282 - > Brooke: Aaron Powell It does not. 283 - > Um, there are uh there's five basic rules that uh you can look 284 - > at that the DOD laid out that shows why you would or would not 285 - > be uh a cloud service provider.
286 - > But most MSPs are not going to be considered a cloud service 287 - > provider. 288 - > You have to have a um something that the user that the end user 289 - > can uh provision easily and quickly by themselves, right? 290 - > Something that doesn't require uh the MSP's intervention. 291 - > Um we don't really have any of that on our side.
292 - > I'm sure there may be some MSPs that have automated some of 293 - > those things. 294 - > Um but there's also a difference between uh just playing 295 - > automation and being a cloud service provider. 296 - > So there are like five bullets that you have to worry about, 297 - > five things you have to worry about. 298 - > Uh but most of the time an MSP is not gonna be a cloud service 299 - > provider.
300 - > They will be an external service provider, which is external 301 - > service provider is the whole umbrella, and then there's uh 302 - > and that's an ESP. 303 - > So there's ESPs that are CSPs, which is a cloud service 304 - > provider. 305 - > So ESP that is a CSP, or ESPs that are not a CSP. 306 - > That's how they define that.
307 - > So uh they're all they're all ESPs. 308 - > Uh but if you're a CSP, then that you're your own category, 309 - > right? 310 - > If you're not a CSP, then you're just one of the rest. 311 - > And so that could be your SIM tool if it's cloud hosted.
312 - > That could be um the that could be the MSP, um, that could be uh 313 - > your RMM tool, that could be a whole lot of things. 314 - > So the short answer to your question is no, that does not 315 - > automatically make an MSP a cloud service provider, a CSP. 316 - > Stacey: Before we wrap up today's episode, we actually 317 - > have a listener question from FedCon. 318 - > So Austin was um in beautiful Washington, D.
C. 319 - > over the week and he actually met one of our listeners. 320 - > We didn't get their name, unfortunately, but thank you so 321 - > much for submitting a question. 322 - > Um It's always wonderful when we get to hear from you guys in 323 - > person.
324 - > It's pretty awesome that we get to put a face to the name most 325 - > of the time. 326 - > So but without further ado, the question is if I give a 327 - > subcontractor access to my systems for CUI, do I need to do 328 - > all the training, awareness, and screening for them too? 329 - > Brooke: Yes. 330 - > Uh and it also depends on what that contractor is doing for you 331 - > uh and what they have access to.
332 - > But yes, they'll they'll need to do the same thing uh that your 333 - > employees do is you know, take the training. 334 - > So if they're uh for us, you know, if we hire a contractor in 335 - > here to come be a uh technician, you know, and and help our 336 - > customers, absolutely thousand percent, they do have to take 337 - > all this all the cybersecurity training. 338 - > Uh but now if you hire a contractor to come in and sweep 339 - > the floors, probably not. 340 - > You know.
341 - > So uh but uh yes, the the uh most of the time I don't know 342 - > about most of the time. 343 - > The way I think about a contractor, uh, you know, to 344 - > come in and work in your business, they're gonna need 345 - > that training. 346 - > Not necessarily all the time, depends on what they're doing 347 - > for you. 348 - > Uh, but I would I would depend on if it if they're a part of 349 - > your business doing the main part that that brings uh you 350 - > know security protection day or CUI or uh you know something 351 - > adjacent there, then yes, they're gonna have to do all the 352 - > all the trading and everything.
353 - > And if you have them doing something significant in your 354 - > enterprise anyway, or in your company anyway, then I would 355 - > argue that yes, you're gonna want to they're gonna you're 356 - > gonna want to make sure that they're trained on cybersecurity 357 - > and trained on the things they need to be trained on to be 358 - > secure and safe and do their job well. 359 - > So short answer is yes, longer answer is maybe. 360 - > Stacey: Wonderful. 361 - > All right.
362 - > Well, thank you so much for answering all those questions, 363 - > Brooke. 364 - > Brooke: No problem. 365 - > Stacey: If you have any questions about what we covered, 366 - > please reach out to us. 367 - > We're here to help fast track your compliance journey.
368 - > Text, email, or call in your questions, and we'll answer them 369 - > for free here on the podcast. 370 - > You can find our contact info at cmc compliance guide.com. 371 - > Stay tuned for our next episode.
372 - > Until then, stay compliant, stay secure, and make sure to 373 - > subscribe.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.