The cloud half of the Shared Responsibility Matrix.
This library covers inheritance, authorization, and the CRM an assessor can use.
Explainer
Why CUI cloud is listed on its own terms
Crosswalk
FedRAMP Moderate and CMMC Level 2
Crosswalk
NIST SP 800-171 Rev 2 to Rev 3 family crosswalk
Templates
CRM templates by service type
Policy
Claims you cannot put on a cloud page
Scoping
Security Protection Assets, without a FedRAMP bar
Collateral
Print, event, and social collateral
NIST SP 800-171 family crosswalk
Rev 2 to Rev 3. 110 → 97 requirements, 14 → 17 families.
| Rev 2 | Family | Rev 3 | What changed |
|---|---|---|---|
| 3.1 | Access Control | 03.01 | Renumbered · 22 Rev 2 requirements |
| 3.2 | Awareness and Training | 03.02 | Renumbered · 3 Rev 2 requirements |
| 3.3 | Audit and Accountability | 03.03 | Renumbered · 9 Rev 2 requirements |
| 3.4 | Configuration Management | 03.04 | Renumbered · 9 Rev 2 requirements |
| 3.5 | Identification and Authentication | 03.05 | Renumbered · 11 Rev 2 requirements |
| 3.6 | Incident Response | 03.06 | Renumbered · 3 Rev 2 requirements |
| 3.7 | Maintenance | 03.07 | Renumbered · 6 Rev 2 requirements |
| 3.8 | Media Protection | 03.08 | Renumbered · 9 Rev 2 requirements |
| 3.9 | Personnel Security | 03.09 | Renumbered · 2 Rev 2 requirements |
| 3.10 | Physical Protection | 03.10 | Renumbered · 6 Rev 2 requirements |
| 3.11 | Risk Assessment | 03.11 | Renumbered · 3 Rev 2 requirements |
| 3.12 | Security Assessment and Monitoring | 03.12 | Renamed from Security Assessment |
| 3.13 | System and Communications Protection | 03.13 | Renumbered · 16 Rev 2 requirements |
| 3.14 | System and Information Integrity | 03.14 | Renumbered · 7 Rev 2 requirements |
| — | Planning | 03.15 | New family in Rev 3 |
| — | System and Services Acquisition | 03.16 | New family in Rev 3 |
| — | Supply Chain Risk Management | 03.17 | New family in Rev 3 |
Rev 3 renumbers every family to a two-digit form, regroups requirements, and adds organization-defined parameters that the customer sets. Requirement-level mappings between revisions are not one-to-one. Use the NIST publications as the source of record: Revision 2, Revision 3.
CRM templates in queue
- IaaS Customer Responsibility Matrix
- PaaS Customer Responsibility Matrix
- SaaS holding CUI
- Identity / IAM
- Logging / SIEM
- Backup / immutable storage
- VDI / enclave
- Email and collaboration
FedRAMP Moderate is not CMMC Level 2
An OSC still owns customer controls. GCC High is a cloud community, not a certificate. Attach the CSP CRM to the SSP before the C3PAO asks.
Banned public claims
Do not write CMMC certified cloud, CMMC ready region, or guaranteed Level 2 if you host there. Say authorized, in scope, and inherited.