# Shared responsibility matrix — SPA vendor

STARTER TEMPLATE. Every cell below is a prompt. Not a completed matrix. Not legal advice. Not a finding that any particular requirement is the vendor’s job.

32 CFR § 170.19 says an external service provider’s service description and customer responsibility matrix describe the responsibilities of the organization and the provider for the services provided. Security Protection Assets are assessed against Level 2 requirements relevant to the capabilities provided. Do not copy every Level 2 requirement into the vendor column.

Fill this only after you know the service does not process, store, or transmit CUI. If it does, this matrix is the wrong cover sheet. Use the FedRAMP authorization or the December 2023 DoD equivalency body of evidence for that cloud offering, and still record the split of duties.

Provider: [legal name]
Service: [name]
Customer: [legal name]
Date: [date]
CUI in this service: [No — basis: ] or [Yes — stop and recategorize]

| Topic | Provider does | Customer does | Evidence to keep | Status |
| --- | --- | --- | --- | --- |
| Service description and boundary | [What the provider documents about the service] | [What the customer adds about how it is used] | [Document titles] | Prompt — replace |
| Data categories ingested | [What the provider says enters the service] | [What the customer configures, including any block on content] | [Vendor answer and configuration export] | Prompt — replace |
| CUI check | [How the provider describes whether CUI can be present] | [How the customer confirmed the answer for this deployment] | [Questionnaire and sample review method, with no CUI pasted here] | Prompt — replace |
| Data location, backups, and older logs | [Regions, facilities, subprocessors] | [What the customer records in the inventory and diagram] | [Location statement and diagram] | Prompt — replace |
| Identity for administrators | [Provider identity, or support for the customer identity provider] | [Accounts, roles, and joiners and leavers] | [IdP configuration] | Prompt — replace |
| Privileged access by provider staff | [Standing or per request, approval, logging, revocation] | [When the customer approves access] | [Access procedure] | Prompt — replace |
| Logging the customer can use | [Which logs, format, retention, forwarding] | [Where the customer keeps its copy, and review] | [Export sample description, not CUI] | Prompt — replace |
| Configuration of the control | [What the provider sets and will not change without notice] | [What the customer must set] | [Build or configuration record] | Prompt — replace |
| Vulnerability information about the customer environment | [What the provider produces] | [What the customer remediates on its own assets] | [Report location] | Prompt — replace |
| Incident notice | [How and when the provider notifies the customer, and what it preserves] | [How the customer handles the notice under its own plan and contract] | [Contract clause and procedure] | Prompt — replace |
| Change notice | [Location, subprocessors, administrative model] | [How the customer updates the plan] | [Notice address] | Prompt — replace |
| Return or deletion of customer data | [What the provider does at the end of the service] | [What the customer requests and records] | [Procedure] | Prompt — replace |
| Support during an assessment | [Service description, data flow, and this matrix] | [Inventory, plan, and diagram] | [Where the packet is kept] | Prompt — replace |

Add rows for capabilities this service actually provides. Delete rows that do not apply.

The provider’s signature on this file is optional. A signature is not a CMMC certification and is not a FedRAMP authorization.
