J. Nolan
ISI, Virginia, United States
Keywords: Managed Service Provider (MSP) Risk, CMMC Compliance, CUI Safeguarding, Third-Party IT Risk, Defense Industrial Base Compliance
Emerging technology companies pursuing Department of War contracts frequently outsource IT infrastructure to a managed service provider (MSP), often before compliance requirements are fully understood. This creates a liability many companies do not realize they have accepted. CMMC and its underlying Controlled Unclassified Information (CUI) safeguarding requirements apply regardless of whether systems are managed internally or by a third party, and responsibility for meeting them does not transfer simply because IT operations have. Most MSPs are capable general IT providers that were never specifically engaged to meet defense-specific safeguarding requirements, because the contractor assumed compliance was already included. Gaps in configuration, access control, or data handling frequently go unnoticed until a CMMC assessment identifies them, at which point the contractor, not the MSP, owns the finding. Drawing on patterns observed across compliance readiness engagements with cleared and cleared-track contractors, this poster identifies where MSP relationships most commonly introduce CMMC risk, the specific questions organizations should ask their MSP proactively, and how CUI safeguarding responsibility should be explicitly assigned and verified rather than assumed by default.