Schedule a call

Compliance

The CMMC controls nobody owns

Cloud Kings

Most contractors don’t fail on the controls they got wrong. They fail on the ones both parties assumed the other had.

There is a conversation that happens in almost every CMMC engagement, usually late, usually with an assessment date already booked.

Someone asks who owns 3.9 — personnel screening. The provider says that has always been the customer’s. The customer says they assumed it came with the managed service. Both are being honest. Nobody wrote it down.

Repeat that across a handful of controls and you have the single most common reason a contractor arrives at assessment less ready than they believed. Not a technical failure. A gap between two reasonable assumptions.

The document that prevents it is a shared responsibility matrix, and you should refuse to sign a CMMC engagement without one.

Why “we handle CMMC compliance” cannot be true

NIST SP 800-171 Rev 2 — the revision DFARS 252.204-7012 currently points to — contains 110 security requirements across 14 families. CMMC Level 2 assesses them against 320 assessment objectives.

A substantial share of those are not technical. They concern who you hire, what training they complete, who can walk into your building, and what your named senior official is willing to sign. No technology provider can do those for you, however good they are.

So when a provider says they handle CMMC compliance, the accurate version is always: they handle a defined subset, and the rest is yours. The only question that matters is whether they will tell you precisely which is which, in writing, before you sign.

A provider who will is describing the engagement. A provider who won’t is describing a brochure.

The controls that go unowned

Some rows go missing far more often than others. In rough order of how often they surprise people:

3.12 — Security Assessment. Your System Security Plan, your POA&M, and the SPRS affirmation signed by a named senior official. A provider can generate every piece of supporting evidence and still not own this. It is your document, your signature, your exposure.

This row matters more now than it did in June. With CMMC Phase II suspended on 13 July 2026, there is no third-party assessor scheduled to catch a posture that has quietly drifted — and the DOJ’s Civil Cyber-Fraud Initiative, which targets false cybersecurity certifications, did not pause. The affirmation is carrying more weight, not less.

3.6 — Incident Response. DFARS 252.204-7012 requires reporting a cyber incident to DIBNet within 72 hours. That obligation is yours. A provider who detects and contains an incident has done their part and has not discharged yours. Agree in advance who decides the clock has started — that decision, made badly at 2am, is how the 72 hours gets missed.

3.9 and 3.2 — Personnel Security and Awareness Training. Screening and training. Nobody does these for you, and nothing technical breaks when they lapse, so they lapse quietly.

3.10 — Physical Protection. You inherit the datacentre controls from Microsoft. You do not inherit anything about your own office. This one catches people who reason that “it’s all in the cloud.”

3.8 — Media Protection. The digital half is usually the provider’s. Physical media, labelling and sanitisation are usually yours, and are usually forgotten until someone asks what happened to the old laptops.

What a real matrix contains

Four columns, not one. For every objective:

  1. Who implements it.
  2. Who produces the evidence. Frequently a different party — a provider may implement a control while you hold the policy proving it is required.
  3. Who retains the evidence, and where. Evidence you cannot retrieve on demand is evidence you do not have.
  4. What happens on exit. Whether documentation and evidence leave with you if the relationship ends.

Family level is enough to start a conversation. Objective level is what you need before signing, because families are rarely all-or-nothing. Configuration Management is the clearest example: a provider owning your baseline still needs you to approve changes, so the family reads as theirs while specific objectives inside it are shared.

Ours, published

Read the CMMC Level 2 shared responsibility matrix →

Family-level, all 14 families, with the typical split and the reasoning for each. Free, no email required, and there is a CSV if you would rather fill it in as a spreadsheet.

We publish it for a straightforward reason. We tell prospects to demand this document from every provider they are considering, and it would be a poor look to say that without having one ourselves.

Use it on us too. Send it to us and to whoever else you are talking to, and ask each to complete it at objective level for the scope they are quoting. The answers will differ more than the sales conversations did.

It is the first of nine questions worth asking before you sign anything — the rest are in how to choose a CMMC partner.

Watch particularly for how much a provider marks as theirs. A matrix claiming provider ownership almost everywhere is not a strong offer — it is a claim that cannot be supported, because no technology provider screens your staff or secures your premises. The rows a provider is willing to hand back to you are the ones that tell you they have actually done this before.

If you want help working out where the line sits for your environment, we offer a free CMMC gap assessment for qualifying contractors. Schedule a call — it is the same conversation either way, and you keep the matrix regardless.


Reflects NIST SP 800-171 Rev 2 and the regulatory position as of 4 August 2026; the CMMC Reform Task Force reports around mid-September 2026 and may change parts of this. Last reviewed 4 August 2026. Not legal advice.

Frequently asked

What is a CMMC shared responsibility matrix?
A document that records, control by control, which obligations your technology provider implements and which remain yours. It should also say who produces the evidence, who retains it and where, and what happens to it if the relationship ends.
Can a provider handle CMMC compliance for me?
Not entirely, and any provider saying otherwise is describing a brochure. A substantial share of NIST SP 800-171 concerns who you hire, what training they complete, who can enter your building, and what your named senior official signs. No technology provider can do those for you.
Which controls get left unowned most often?
Security Assessment (3.12), because the System Security Plan, POA&M and SPRS affirmation are yours no matter who supplies the evidence. Incident Response (3.6), because the 72-hour DIBNet report is your obligation even when the provider detects and contains the incident. And Personnel Security and Awareness Training (3.9 and 3.2), which lapse quietly because nothing technical breaks when they do.
Is family level detailed enough?
It is enough to start the conversation and to see where a provider is vague. It is not enough to sign against. Families are rarely all-or-nothing — a provider managing your configuration baseline still needs you to approve changes — so agree the split at objective level before signing.
Do I have to give you my email to get the template?
No. It is a web page and a CSV download, both ungated. The template's job is to be read, quoted and linked, and an email wall would prevent all three.

Continue reading

Keep in the loop