Schedule a call

Free template

CMMC shared responsibility matrix

All 14 NIST SP 800-171 families, with the typical split and why. A starting point for the conversation you should be having before you sign anything — no email required.

Most contractors don't fail on the controls they got wrong. They fail on the ones both parties assumed the other had.

This is based on NIST SP 800-171 Revision 2, the revision DFARS 252.204-7012 currently points to, which contains 110 security requirements across 14 families. CMMC Level 2 assesses those against 320 assessment objectives.

Download as CSV

The download adds the four empty columns below for you to fill in per objective.

How to read the split

P Provider
Usually the provider's to implement — technical, and lives in the environment they run.
C Customer
Usually yours — organisational, about people and premises, and cannot be outsourced to a technology partner.
S Shared
Genuinely shared — the provider supplies capability, you supply policy, decisions or execution.

The pattern is stable across the industry because it follows what a technology provider can physically control. A provider claiming P across the board has not read the framework.

The matrix

CMMC Level 2 shared responsibility by NIST SP 800-171 family
# Family Controls Typical split Why
3.1 Access Control (AC) 22 P Provider Tenant configuration, conditional access, session control and remote access all live in the environment.
3.2 Awareness and Training (AT) 3 C Customer Your staff, your training records. A provider can supply material; they cannot make your people attend.
3.3 Audit and Accountability (AU) 9 P Provider Log generation, retention, protection and review are platform functions.
3.4 Configuration Management (CM) 9 P Provider Baselines, change control and least functionality are provider-managed — though approving changes stays with you.
3.5 Identification and Authentication (IA) 11 P Provider Identity, MFA, password policy and replay resistance.
3.6 Incident Response (IR) 3 S Shared The provider detects and contains; you own the 72-hour DIBNet report and the decision to make it.
3.7 Maintenance (MA) 6 S Shared The provider handles system maintenance; you control physical and off-site maintenance of your own equipment.
3.8 Media Protection (MP) 9 S Shared The provider covers digital media and encryption; you own physical media, labelling and sanitisation.
3.9 Personnel Security (PS) 2 C Customer Screening and termination procedures are yours. Non-negotiably.
3.10 Physical Protection (PE) 6 C Customer Your premises. The cloud datacentre is inherited from Microsoft; your office is not.
3.11 Risk Assessment (RA) 3 S Shared The provider can scan and report; accepting or rejecting risk is a business decision and yours.
3.12 Security Assessment (CA) 4 S Shared The provider supplies evidence; you own the System Security Plan, the POA&M and the SPRS affirmation.
3.13 System and Communications Protection (SC) 16 P Provider Boundary protection, encryption in transit and at rest, and network separation.
3.14 System and Information Integrity (SI) 7 P Provider Patching, malicious code protection, monitoring and alerting.
Total 110

The three rows that decide your outcome

3.12 (CA) — your System Security Plan, your POA&M, and the SPRS affirmation signed by a named senior official. A provider can supply every piece of evidence and still not own this. With Phase II suspended and no external assessor scheduled, this is the row carrying your risk.

3.6 (IR) — the 72-hour DIBNet report under DFARS 252.204-7012 is your obligation. A provider who detects and contains an incident has not discharged it. Agree in advance who decides the clock has started.

3.9 (PS) and 3.2 (AT) — personnel screening and training. No provider does these for you, and nothing technical breaks when they lapse, so they lapse quietly.

Filling it in properly

The table above is family level. A real matrix goes to objective level — all 320 of them — because a family is rarely all-or-nothing. Configuration Management is the clearest case: a provider managing your baseline still needs you to approve changes, so the family reads P while individual objectives inside it read S.

For each row, agree four things and write them down:

  1. Who implements it — the control itself.
  2. Who produces the evidence — often a different party from whoever implements it.
  3. Who retains the evidence, and where — evidence you cannot retrieve on demand is evidence you do not have.
  4. What happens on exit — whether the evidence and documentation leave with you.

How to use this against a provider

Send it to every provider you are considering, including us, and ask them to complete it at objective level for the scope they are quoting.

  • A provider who has one already will return it quickly.
  • A provider who has never built one returns a brochure, or a version marked P almost everywhere — a claim they cannot support, since no technology provider screens your staff or secures your premises.
  • The C rows are the useful ones. A provider willing to tell you plainly what you must own is describing the engagement accurately.

Prepared by Cloud Kings. Reflects NIST SP 800-171 Rev 2 and the regulatory position as of 4 August 2026; control counts are from the publication itself, while the typical split is our characterisation of common industry practice rather than a standard. The CMMC Reform Task Force reports around mid-September 2026 and may change parts of this. Not legal advice.