Webinar on Demand: MSPs, CSPs, and Your NIST or CMMC Assessment
The latest Smithers Information Security Services Cybersecurity webinar features a discussion of CSPs, MSPs, and how they relate to your NIST / CMMC assessment.
Quick answer: Under CMMC, cloud service providers handling Controlled Unclassified Information (CUI) must meet the FedRAMP Moderate baseline or a documented equivalent, per DFARS 252.204-7012. The contractor, not the cloud provider, bears responsibility for confirming and documenting this compliance. Standard commercial Microsoft 365 plans do not qualify without a GCC High or equivalent configuration.
Defense contractors preparing for CMMC certification often assume their cloud infrastructure is a solved problem, especially if they already use well-known platforms like Microsoft 365 or a major cloud provider. This assumption is one of the most consequential mistakes an organization can make during CMMC preparation. Cloud misconfigurations and unauthorized platforms are among the most common deficiencies found during assessments, and they carry real legal exposure under the False Claims Act.
This post clarifies what FedRAMP equivalency actually requires, how the shared responsibility model applies in a CMMC context, and what steps contractors should take to evaluate whether their current cloud setup supports or undermines their compliance goals.
DFARS clause 252.204-7012 requires that any cloud service used to process, store, or transmit Covered Defense Information (CDI) meet the FedRAMP Moderate baseline or an equivalent standard. This requirement predates CMMC itself, but CMMC assessments now formally evaluate whether contractors have satisfied it. Under CMMC's System and Communications Protection (SC) domain, organizations using cloud services for CUI must ensure those services meet FedRAMP Moderate or equivalent standards.
FedRAMP and CMMC certify different things, and understanding this distinction matters. FedRAMP authorizes a specific cloud service, confirming that the service itself meets federal security requirements. CMMC certifies an organization, confirming that the contractor protects CUI regardless of where or how it operates, whether on-premises, hybrid, or in the cloud. A defense contractor that also delivers a cloud service to the government could need both certifications simultaneously. FedRAMP and CMMC stack; neither substitutes for the other.
Using an already-authorized FedRAMP service is the cleanest compliance path. When a contractor instead relies on a platform that claims equivalency without formal FedRAMP authorization, the burden of proof shifts entirely to the contractor. That documentation burden is substantial, and it must hold up under C3PAO or DIBCAC scrutiny.
This is where many contractors get tripped up. Standard commercial Microsoft 365 plans do not meet the FedRAMP Moderate threshold without a GCC High or equivalent configuration. The distinction isn't cosmetic. Commercial cloud environments are built for general business use and lack the data residency controls, personnel screening requirements, and boundary protections that FedRAMP Moderate demands.
Storing or processing CUI on a cloud platform that hasn't achieved FedRAMP Moderate authorization, or a documented equivalent, is flagged repeatedly during CMMC assessments as a significant compliance gap. This applies not just to primary storage systems but to every tool in the CUI environment, including email, collaboration platforms, backup systems, and any third-party application that touches sensitive data.
Contractors evaluating their cloud environment should ask a direct question about every platform in use: does this specific service hold FedRAMP Moderate authorization, or has equivalency been independently documented and verified? If the answer is unclear, that platform is a liability, not an asset, in a CMMC assessment.
Cloud computing operates on a shared responsibility model, where the cloud provider secures certain layers of the environment and the customer secures others. CMMC does not change this division of labor, but it does change who answers for the result.
When a contractor moves CUI to the cloud, certain physical protections, like data center security, facility access controls, and hardware maintenance, become the cloud provider's responsibility. But the contractor remains responsible for ensuring those controls actually meet DoD requirements. Delegating infrastructure to a cloud provider does not delegate accountability. If an assessor finds a gap in the provider's configuration, the contractor's certification is the one at risk.
This means contractors need documented evidence, not assumptions, that their cloud provider's controls satisfy the applicable NIST SP 800-171 requirements. A provider's general security reputation is not sufficient evidence. Formal FedRAMP authorization, or a rigorously documented equivalency assessment, is what assessors expect to see.
Even when using a FedRAMP-authorized platform, the contractor is responsible for configuring it correctly. Authorization confirms that a service can be operated securely; it does not guarantee that a specific customer has deployed it securely. Common contractor-side configuration responsibilities include:
A contractor that purchases a FedRAMP-authorized platform but fails to configure it to the required baseline has not achieved compliance. It has purchased the potential for compliance and left the hard part undone.
A practical evaluation should start with a full inventory of every cloud service that touches CUI, directly or indirectly. For each platform, contractors should confirm three things: whether the service holds FedRAMP Moderate authorization, whether the specific configuration in use matches the security baseline, and whether the platform and its role in the CUI environment are documented in the SSP.
Gaps identified during this process should feed directly into a Plan of Action and Milestones (POA&M), with realistic timelines for remediation. Given that migrating to a compliant cloud environment often involves licensing changes, data migration, and staff retraining, contractors should treat this evaluation as a priority item early in CMMC preparation rather than a detail to resolve just before assessment.
Cloud misconfigurations aren't just a technical liability. Since 2021, the Department of Justice's Civil Cyber-Fraud Initiative has pursued False Claims Act cases against organizations that misrepresent their cybersecurity compliance in government contracts. In fiscal year 2024 alone, those actions resulted in more than $14 million in recoveries. A contractor that certifies compliance while knowingly storing CUI on a non-compliant cloud platform is not just risking a failed assessment. It's exposing itself to civil liability.
Cloud infrastructure decisions made years before a CMMC assessment can quietly determine whether that assessment succeeds. Contractors that treat cloud configuration as a one-time purchasing decision, rather than an ongoing compliance responsibility, consistently discover gaps at the worst possible time: during the assessment itself.
The path forward starts with an honest inventory of every cloud service touching CUI, a clear-eyed comparison against the FedRAMP Moderate baseline, and documentation that can withstand assessor scrutiny. Organizations that aren't confident in their current cloud posture should treat that uncertainty as an immediate priority, not a future task.
Not necessarily. CMMC, through DFARS 252.204-7012, requires cloud services handling CUI to meet the FedRAMP Moderate baseline or a documented equivalent. FedRAMP authorization is the cleanest path to satisfying this, but a rigorously documented equivalency assessment can also meet the standard.
No. Standard commercial Microsoft 365 plans do not meet the FedRAMP Moderate threshold required for CUI. Contractors typically need Microsoft 365 GCC High or an equivalently configured environment to satisfy this requirement.
Both, but accountability ultimately rests with the contractor. The cloud provider secures certain infrastructure layers under the shared responsibility model, but the contractor must verify and document that those controls meet CMMC requirements. A provider's failure becomes the contractor's compliance gap.
This is flagged as a significant compliance deficiency and can prevent certification. Depending on severity, it may require a documented Plan of Action and Milestones, migration to a compliant platform, or in cases involving misrepresented compliance, exposure to False Claims Act liability.
Timelines vary based on the size of the organization and the complexity of the existing environment, but migrations involving licensing changes, data transfer, and staff retraining commonly take several months. Contractors should begin this evaluation early in their CMMC preparation timeline rather than close to an assessment date.