Almost no contractor implements all 110 requirements alone. Your cloud platform, your MSP, your email provider — each may handle some of your security controls for you. CMMC lets you take credit for that, but only if you can show exactly who is responsible for what. That is the job of the shared-responsibility matrix.

External Service Providers, defined

An External Service Provider (ESP) is any outside party that handles, stores, or processes your CUI, or that provides security protections for the systems that do. Cloud providers and MSPs are the common examples. When an ESP performs a control on your behalf you may inherit that control — but the responsibility to prove it does not vanish; it moves.

The shared-responsibility matrix

A shared-responsibility matrix walks the requirements and, for each, records who implements it: you, the ESP, or both. ‘Both’ is the most common and most misunderstood answer — a cloud provider may encrypt the disk while you remain responsible for who has access. Inheriting a control you have not documented is the same, to an assessor, as not having it.

Get it in writing

Two things make inheritance real: the matrix itself, and the contractual language (plus the provider’s own documentation) backing each inherited control. Ask each ESP for their customer responsibility matrix, reconcile it against your SSP, and close any control that neither party clearly owns — those gaps are where programs quietly fail.

See how we map inheritance across your providers.