Guide

How to evaluate an SPA tool or service.

Start with the data the service will hold in your deployment. The category follows that fact. A vendor’s phrase for the product does not select the row in 32 CFR § 170.19.

Not legal advice. This is a plain-language reading aid for contractors and the providers who support them. It is not a CMMC assessment, not a FedRAMP determination, and not a substitute for 32 CFR Part 170, the contract, or advice from counsel. Templates and worksheet results are starters. Replace every example with your own facts.

Settle the CUI question first

Ask whether the service processes, stores, or transmits CUI, including file contents, message bodies, and document text. The Level 2 Scoping Guide uses those three verbs: used by the asset, at rest, and transferred.

The CMMC Program FAQ (B-Q8) says encrypted CUI remains CUI until it is formally decontrolled. Do not treat encryption as a “no.”

If an external cloud holds CUI

DFARS 252.204-7012(b)(2)(ii)(D) and Table 4 require that cloud provider to meet the FedRAMP requirements in the clause. The December 2023 DoD memorandum is the Department’s description of equivalency for that case. It says equivalency does not confer FedRAMP authorization.

The FAQ (E-Q2) says an external cloud provider must still meet that bar to store encrypted CUI. Ask for the authorization, or for the body of evidence the memorandum describes, for the offering you would actually use. This is the question the directory is for.

If it protects the environment and does not hold CUI

Scope it as a Security Protection Asset. Table 4 assesses a provider that holds security protection data without CUI as an SPA, whether or not that provider is a cloud service provider. FedRAMP is not the sentence in that cell.

You still document it, and it is still assessed against the Level 2 requirements relevant to what it does. “Not FedRAMP” does not mean “out of scope.”

Read the provider relationship

The FAQ (E-Q5) separates two cases. If the cloud tenant is licensed to you, a managed provider that resells or administers it is not, on that fact alone, the cloud service provider. If that managed provider contracts for the cloud and modifies the basic service, the FAQ says it may itself be a cloud service provider, and the FedRAMP question can apply.

Write down which contract you signed and whose tenant it is.

What to ask before you buy

These are buying questions. They are not additional CMMC requirements. Use the vendor survey when you want them in a file.

  • What data categories enter the service, and which of them can be CUI?
  • Can you turn off ingestion of content so the service keeps security events and not files or message bodies?
  • Where does primary storage sit, and where do backups and older logs sit?
  • Which of your staff can open our tenant, and is that access standing?
  • Which logs can we export, and can we keep a copy in a system we control?
  • Which tasks do you perform, which stay with us, and will you put that split in a responsibility matrix?
  • How are we notified of an incident, and what will you preserve?
  • If you do handle CUI, what FedRAMP authorization or equivalency body of evidence do you have for this offering, not for a different one?

People are in the guide’s examples

The Level 2 Scoping Guide lists people among Security Protection Asset examples, including consultants who provide cybersecurity services and managed-service personnel who maintain systems. The FAQ (E-Q4) addresses an IT support provider and a managed security provider when no CUI is sent to either: both are in the assessment, against applicable requirements, and the FAQ says they do not need their own CMMC certification.

A person’s access to your environment is part of the scoping write-up. A logo on a service is not.

What a marketing sentence does not settle

A claim that a tool is ready for CMMC, or a general assurance report, is not the customer responsibility matrix § 170.19 describes, and it is not a FedRAMP authorization. Ask for the data-flow, the responsibility split, and, only if CUI is in the service, the cloud authorization or equivalency evidence. Then categorize the deployment with the scope check.