Free template
CMMC shared responsibility matrix
All 14 NIST SP 800-171 families, with the typical split and why. A starting point for the conversation you should be having before you sign anything — no email required.
Most contractors don't fail on the controls they got wrong. They fail on the ones both parties assumed the other had.
This is based on NIST SP 800-171 Revision 2, the revision DFARS 252.204-7012 currently points to, which contains 110 security requirements across 14 families. CMMC Level 2 assesses those against 320 assessment objectives.
The download adds the four empty columns below for you to fill in per objective.
How to read the split
- P Provider
- Usually the provider's to implement — technical, and lives in the environment they run.
- C Customer
- Usually yours — organisational, about people and premises, and cannot be outsourced to a technology partner.
- S Shared
- Genuinely shared — the provider supplies capability, you supply policy, decisions or execution.
The pattern is stable across the industry because it follows what a technology provider can physically control. A provider claiming P across the board has not read the framework.
The matrix
| # | Family | Controls | Typical split | Why |
|---|---|---|---|---|
| 3.1 | Access Control (AC) | 22 | P Provider | Tenant configuration, conditional access, session control and remote access all live in the environment. |
| 3.2 | Awareness and Training (AT) | 3 | C Customer | Your staff, your training records. A provider can supply material; they cannot make your people attend. |
| 3.3 | Audit and Accountability (AU) | 9 | P Provider | Log generation, retention, protection and review are platform functions. |
| 3.4 | Configuration Management (CM) | 9 | P Provider | Baselines, change control and least functionality are provider-managed — though approving changes stays with you. |
| 3.5 | Identification and Authentication (IA) | 11 | P Provider | Identity, MFA, password policy and replay resistance. |
| 3.6 | Incident Response (IR) | 3 | S Shared | The provider detects and contains; you own the 72-hour DIBNet report and the decision to make it. |
| 3.7 | Maintenance (MA) | 6 | S Shared | The provider handles system maintenance; you control physical and off-site maintenance of your own equipment. |
| 3.8 | Media Protection (MP) | 9 | S Shared | The provider covers digital media and encryption; you own physical media, labelling and sanitisation. |
| 3.9 | Personnel Security (PS) | 2 | C Customer | Screening and termination procedures are yours. Non-negotiably. |
| 3.10 | Physical Protection (PE) | 6 | C Customer | Your premises. The cloud datacentre is inherited from Microsoft; your office is not. |
| 3.11 | Risk Assessment (RA) | 3 | S Shared | The provider can scan and report; accepting or rejecting risk is a business decision and yours. |
| 3.12 | Security Assessment (CA) | 4 | S Shared | The provider supplies evidence; you own the System Security Plan, the POA&M and the SPRS affirmation. |
| 3.13 | System and Communications Protection (SC) | 16 | P Provider | Boundary protection, encryption in transit and at rest, and network separation. |
| 3.14 | System and Information Integrity (SI) | 7 | P Provider | Patching, malicious code protection, monitoring and alerting. |
| Total | 110 | |||
The three rows that decide your outcome
3.12 (CA) — your System Security Plan, your POA&M, and the SPRS affirmation signed by a named senior official. A provider can supply every piece of evidence and still not own this. With Phase II suspended and no external assessor scheduled, this is the row carrying your risk.
3.6 (IR) — the 72-hour DIBNet report under DFARS 252.204-7012 is your obligation. A provider who detects and contains an incident has not discharged it. Agree in advance who decides the clock has started.
3.9 (PS) and 3.2 (AT) — personnel screening and training. No provider does these for you, and nothing technical breaks when they lapse, so they lapse quietly.
Filling it in properly
The table above is family level. A real matrix goes to objective level — all 320 of them — because a family is rarely all-or-nothing. Configuration Management is the clearest case: a provider managing your baseline still needs you to approve changes, so the family reads P while individual objectives inside it read S.
For each row, agree four things and write them down:
- Who implements it — the control itself.
- Who produces the evidence — often a different party from whoever implements it.
- Who retains the evidence, and where — evidence you cannot retrieve on demand is evidence you do not have.
- What happens on exit — whether the evidence and documentation leave with you.
How to use this against a provider
Send it to every provider you are considering, including us, and ask them to complete it at objective level for the scope they are quoting.
- A provider who has one already will return it quickly.
- A provider who has never built one returns a brochure, or a version marked P almost everywhere — a claim they cannot support, since no technology provider screens your staff or secures your premises.
- The C rows are the useful ones. A provider willing to tell you plainly what you must own is describing the engagement accurately.
Prepared by Cloud Kings. Reflects NIST SP 800-171 Rev 2 and the regulatory position as of 4 August 2026; control counts are from the publication itself, while the typical split is our characterisation of common industry practice rather than a standard. The CMMC Reform Task Force reports around mid-September 2026 and may change parts of this. Not legal advice.