Why MSPs and MSSPs Are Building Their CMMC Practices on Kiteworks
CMMC 2.0 Phase 1 enforcement is in effect and isn’t going anywhere: contractors handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) must self-assess and attest to NIST SP 800-171 controls now, with False Claims Act exposure for false attestations. Phase 2 — the requirement for independent C3PAO third-party assessment of Level 2 and Level 3 contractors — is a different story: on July 13, 2026, the Department of War suspended it, along with “all pending and future CMMC milestones,” pending a 60-day “top-to-bottom” review of the program.
DoD/DoW Chief Information Officer Kirsten Davies wrote in the July 13 memo that the current CMMC program “imposes significant and often prohibitive burdens” on small and non-traditional defense businesses, and tasked a new CMMC Reform Task Force with recommending a framework that lowers barriers to entry while still protecting CUI. The task force’s findings are due within 60 days, putting a decision point around mid-September 2026. Until then, DoW will rely on self-assessments and select government-led assessments rather than C3PAO audits. Level 1 self-assessment (for FCI) and Level 2 self-assessment (for CUI), which took effect in November 2025, remain mandatory in current and future contracts.
The companies affected by CMMC as a whole still span the full breadth of the defense industrial base — aerospace systems integrators, small manufacturers, IT vendors — and the vast majority are small to mid-sized businesses with no dedicated compliance staff. They are looking for a trusted advisor who can guide them through the CMMC compliance roadmap and deliver the technology infrastructure needed to pass a C3PAO assessment whenever the third-party requirement resumes.
That opening is where MSPs and MSSPs come in. An MSP credentialed as a Registered Practitioner Organization (RPO) under the CMMC Accreditation Body framework can advise clients on assessment preparation, configure their environments, and manage ongoing compliance as a service. But the practice only works if the platform the MSP deploys actually satisfies the underlying NIST SP 800-171 controls — whether they’re being verified through today’s self-assessment or a future C3PAO audit.
Choosing a platform that claims CMMC readiness without documented certifications is not just a technical shortcoming. Under the False Claims Act, falsely certifying that a contractor is CMMC compliant when it is not carries civil penalties that can reach $28,619 per false claim, plus treble damages. The platform decision is a business and legal decision as much as a technical one.
Kiteworks was designed for this environment. The platform delivers unified CMMC 2.0 compliance across every channel through which Controlled Unclassified Information moves, backed by certifications that satisfy DoD requirements without ambiguity.
Key Takeaways
1. The defense industrial base remains the most clearly defined compliance services market in managed IT — suspension or not.
An estimated 80,000+ DIB contractors will eventually need CMMC Level 2 certification, and most lack internal compliance staff. The July 2026 suspension pauses the C3PAO third-party assessment deadline, not the underlying NIST SP 800-171 self-assessment obligation or the contract risk behind it. MSPs and MSSPs that build a credible CMMC practice now capture a recurring, mandate-driven revenue stream — and are positioned to move fastest once third-party assessment requirements resume.
2. Platform choice determines whether a CMMC practice succeeds or fails.
Many vendors claim CMMC alignment without carrying the certifications DoD requirements actually recognize. An MSP that deploys an unqualified platform exposes its clients to failed assessments and, under the False Claims Act, exposes both parties to civil penalties of up to $28,619 per false claim plus treble damages.
3. Kiteworks addresses 90% of CMMC 2.0 Level 2 requirements out of the box.
That coverage spans the control families a C3PAO will scrutinize most carefully — access control, audit and accountability, configuration management, identification and authentication, and system and communications protection — giving clients the strongest possible starting point before the assessment begins.
4. Kiteworks holds a real FedRAMP Moderate Authority to Operate, not a self-attested equivalency claim.
That authorization has been confirmed by a certified third-party assessment organization every year since June 2017, and it satisfies the DFARS 7012 cloud security requirement without any additional equivalency determination from the contractor.
5. A single-tenant architecture and unified audit log make CMMC assessments faster and cleaner.
Each DIB client gets a dedicated Kiteworks environment with no shared infrastructure. Every CUI channel interaction — email, file sharing, managed file transfer, SFTP, data forms — feeds into a single immutable audit log, giving the assessor or the contractor’s own compliance team a complete, tamper-evident evidence package without the MSP having to assemble it manually.
CMMC 2.0 Compliance Roadmap for DoD Contractors
The CMMC Opportunity MSPs and MSSPs Cannot Ignore
The CMMC Final Rule established a phased compliance timeline. Level 2 requirements — which map directly to all 110 controls in NIST 800-171 — apply to any contractor that handles Controlled Unclassified Information under a DoD contract. Under the original rollout, Level 2 contractors would eventually need assessment by an accredited C3PAO; as of July 13, 2026, the Department of War has suspended that third-party assessment ramp-up (originally set to begin Nov. 10, 2026) pending its 60-day reform review, while Level 1 and Level 2 self-assessment obligations remain in force. With over 80,000 contractors ultimately in scope for Level 2, the market for qualified CMMC advisors is not theoretical — it is immediate, documented, and growing as contract renewals bring more of the supply chain into scope, regardless of which assessment mechanism DoW lands on.
The compliance obligation does not end with a single assessment event, which is part of what makes the DIB a strong market for managed services. Contractors must keep their security controls operational, update their System Security Plan when significant changes occur, address any findings through a POA&M process, and keep their self-assessment score current in the Supplier Performance Risk System (SPRS). That discipline applies whether a contractor is self-attesting today or holds — or is pursuing — full C3PAO certification once Phase 2 resumes. It is exactly the kind of ongoing operational burden that MSPs are built to take off clients’ plates.
There is also a supply chain risk management dynamic worth understanding. When a prime contractor gets certified, pressure cascades down to its subcontractors. When a Tier 1 subcontractor passes its assessment, the Tier 2 suppliers handling the same FCI come into focus. An MSP embedded in a certified contractor’s compliance program is in a good position to serve that contractor’s subcontractor relationships as requirements propagate down the chain. The CMMC compliance checklist gives MSPs a structured inventory of all 110 Level 2 controls to map against client environments — an essential starting point for scoping each new engagement accurately before work begins.
Why the Platform Beneath the Practice Is Everything
CMMC Level 2 requires satisfying 110 controls across 17 domains. Those controls govern how users authenticate, how CUI moves across systems, how access events are logged, and how incidents are detected and reported. No single platform addresses all 110 — policies, procedures, and additional tooling are always required — but the platform determines how many controls the client starts with documented and covered, versus how many must be built from scratch.
That starting-point difference matters enormously in practice. A client deploying a platform that covers 40% of Level 2 requirements faces a substantially longer and more expensive road to certification than one that starts at 90%. The MSP’s assessment preparation timeline, the likelihood of a first-attempt pass, and the total engagement cost all follow from that baseline. Kiteworks addresses 90% of CMMC Level 2 requirements out of the box, giving RPOs the best possible foundation before the CMMC gap analysis even begins.
Platform selection also carries legal weight that many MSPs underestimate — arguably more now than before the Phase 2 suspension, since self-attestation rather than third-party audit is currently the primary compliance mechanism DoW is relying on. DFARS 7012 specifies that cloud services handling CUI must meet FedRAMP Moderate security requirements. Vendors who offer self-attested FedRAMP equivalency are not the same as vendors with a confirmed FedRAMP Moderate Authority to Operate. Whether that distinction is examined through a contractor’s own SPRS self-assessment today or a C3PAO audit once Phase 2 resumes, it is the difference between a finding and a clean result. Deploying a platform that cannot pass that test puts clients in a documented compliance gap, and under the False Claims Act, that gap becomes legal exposure the moment the contractor certifies compliance to the DoD. A formal risk assessment that maps each cloud service used by DIB clients against the FedRAMP Moderate baseline — confirming authorization status through the official Marketplace rather than vendor attestation — is the due diligence step that closes this exposure for MSPs before a self-assessment package is submitted.
How Kiteworks Covers CMMC Level 2 from the Start
Most organizations attempting CMMC compliance assemble separate tools for email security, file sharing, managed file transfer, SFTP, and data forms. Each tool has its own security posture, its own logging format, and its own policy enforcement model. That fragmentation creates real assessment complexity: an assessor — whether reviewing a self-assessment or conducting a C3PAO audit — must evaluate each system independently against the relevant control families, and a gap in any one of them becomes a finding against the entire assessment. Data classification disciplines applied uniformly across all channels — rather than separately in each tool — are a prerequisite for demonstrating consistent CUI handling.
Kiteworks works differently. It is a unified secure data exchange that governs CUI across Kiteworks secure email, Kiteworks secure file sharing, secure managed file transfer, Kiteworks SFTP, and Kiteworks secure data forms through a single control plane. Access policies, DLP rules, malware scanning, and anomaly detection apply once across all channels, rather than being configured and maintained separately in five different products.
The compliance impact is direct. Control families like Access Control (AC), Audit and Accountability (AU), and System and Communications Protection (SC) apply to every system through which CUI flows. In a unified platform, those controls are documented, centralized, and demonstrable in a single location. Kiteworks enforces FIPS 140-3 validated encryption in transit and at rest, generates immutable audit logs for every interaction, and produces automated compliance reports that support CMMC Level 2 documentation requirements without manual assembly. Attribute-based access control (ABAC) policies evaluate user role, content sensitivity, and request context at every CUI access event — ensuring that a compromised account or misconfigured permission cannot silently reach content outside its authorized scope, which is the kind of granular access evidence an assessor will look for in the AC domain.
For an MSP building a CMMC practice, that starting-point coverage changes the client conversation entirely. Instead of arriving with a lengthy remediation roadmap, the MSP walks in with a platform that already handles the hardest technical controls. The engagement focuses on policy documentation, environment configuration, and assessment preparation — work the MSP can deliver efficiently and at scale across multiple clients. The CISO Dashboard gives the MSP real-time visibility into each client’s CUI activity across all channels, enabling proactive compliance monitoring between assessment cycles. The Kiteworks Private Data Network architecture that underlies all of this delivers the unified governance posture — one policy engine, one audit trail, one hardened deployment — that makes CMMC self-assessment documentation coherent rather than assembled from five disconnected systems.
FedRAMP Authorization and What It Actually Means for DFARS
The most common compliance gap in CMMC implementations is also the most avoidable: deploying a cloud service provider that does not actually meet the DFARS 7012 security requirement.
DFARS 7012 requires cloud services that process, store, or transmit CUI on behalf of a DoD contractor to be either FedRAMP Moderate Authorized or to meet equivalent security requirements. The equivalency path exists, but it requires meaningful documentation — a detailed comparison of the CSP’s controls against the FedRAMP Moderate baseline and a letter submitted to the DoD CIO. It is not a checkbox. As CMMC enforcement has matured, the DoD has signaled increasing scrutiny of equivalency claims, and several early assessments have produced findings specifically tied to unqualified cloud services.
Kiteworks holds an actual FedRAMP Moderate authorization, a formal Authority to Operate issued by the Joint Authorization Board and confirmed by an accredited 3PAO every year since June 2017. That is not a marketing claim. It is a documented federal authorization that satisfies FedRAMP compliance requirements under DFARS 7012 without any equivalency determination from the contractor. For an MSP deploying Kiteworks for a DIB client, the cloud service question has a definitive, documented answer.
That matters directly for False Claims Act exposure. A contractor that falsely certifies CMMC compliance — including falsely attesting that its cloud service meets the required security standard — faces civil penalties up to $28,619 per false claim plus treble damages. An MSP that deploys a platform without actual FedRAMP authorization places its client in that exposure window. The Kiteworks authorization closes that risk. Organizations that have mistakenly relied on a vendor’s FedRAMP equivalency claim should treat the switch to an actually authorized platform as an urgent remediation, not a future roadmap item.
This point carries more weight, not less, after the Phase 2 suspension: with third-party C3PAO verification paused, DoW is leaning on self-attestation to enforce the CMMC baseline. Every contractor’s SPRS score and self-assessment package is now the primary evidence DoW sees — which means a false attestation about cloud security is closer to the surface, and closer to direct False Claims Act exposure, than it was when a C3PAO audit stood between attestation and enforcement. Data governance documentation that maps each cloud service handling CUI to its FedRAMP authorization status — maintained as a living record rather than a point-in-time snapshot — is the organizational practice that makes self-attestation defensible under scrutiny.
Building a Recurring Revenue CMMC Practice
The business case for MSPs and MSSPs goes well past a single engagement — and the July 2026 Phase 2 suspension makes the recurring-revenue argument stronger, not weaker. Contractors must maintain their NIST SP 800-171 self-assessment and SPRS score continuously today, respond to incidents under documented incident response procedures, and be ready to convert that self-assessment posture into a C3PAO-ready program once the CMMC Reform Task Force’s recommendations take effect. New and renewed contracts already reference current self-attestation status, which means any gap in the compliance program has direct contract consequences now — with the added exposure that a false self-attestation, unlike a failed third-party audit, creates direct False Claims Act liability.
Kiteworks supports that ongoing relationship. Each DIB client receives a fully isolated single-tenant instance — dedicated infrastructure and dedicated encryption keys, with no shared CUI exposure across the MSP’s client base. The MSP configures, monitors, and reports on each environment independently. The platform’s SIEM integrations feed CUI activity data into the MSP’s security operations tools in real time, enabling proactive compliance monitoring rather than scrambling to prepare for a scheduled audit.
This lets the MSP offer platform management, security monitoring, policy governance, and assessment preparation as a continuous engagement rather than a series of one-off projects. That model generates predictable revenue, deepens client relationships, and builds switching costs that protect the account over time. The CMMC gap analysis that starts the relationship becomes the foundation for a compliance management program with defined deliverables and clear renewal logic.
The DIB is not a discretionary market, even with Phase 2 on pause. Contractors that handle CUI under DoD contracts are required to self-assess and attest — not encouraged, not incentivized, required — and DoW’s own stated intent is to return within 60 days with a “scalable, realistic” assessment framework, not to abandon third-party verification altogether. That translates directly into sustained demand for qualified MSP partners who can deliver the right platform, configure it correctly, and keep clients audit-ready under whichever assessment model DoW ultimately adopts. Kiteworks gives MSPs 90% out-of-the-box Level 2 coverage, a FedRAMP Moderate authorization that satisfies DFARS 7012 without workarounds, and a unified CUI governance model that holds up under self-assessment and C3PAO scrutiny alike. MSPs that also serve clients with ITAR compliance obligations will find that Kiteworks’ single-tenant architecture and FIPS-validated encryption satisfy those requirements as well, enabling a single platform to serve the full regulated defense supply chain.
To learn how Kiteworks helps MSPs and MSSPs build high-margin, recurring CMMC practices for their defense industrial base clients, schedule a custom demo today.
Frequently Asked Questions
A Registered Practitioner Organization (RPO) is a Cyber-AB-authorized status for consultative organizations — including MSPs — that deliver non-certified CMMC advisory services through the employment of Registered Practitioners (RPs). RPOs help contractors with gap analysis, control implementation guidance, and System Security Plan preparation, but they cannot conduct a Certified CMMC Assessment; that authority belongs exclusively to C3PAOs. To become an RPO, an organization registers with Cyber-AB, agrees to its Code of Professional Conduct, and employs or contracts at least one RP (an individual who has completed Cyber-AB-approved training and passed the required exam and background check). MSPs don’t strictly need RPO status to sell general managed services to defense contractors, but without it they cannot use the Cyber-AB RPO designation or logo, and clients increasingly expect it as a baseline credibility signal — particularly now, with C3PAO third-party assessments suspended and self-attestation carrying more direct legal weight. Use the CMMC compliance checklist as a structured reference for every Level 2 control an RPO engagement must address. The CMMC Level 2 requirements guide provides the domain-by-domain breakdown that helps MSPs scope and price engagements accurately before work begins.
DFARS 252.204-7012 requires that any cloud service handling CUI on behalf of a DoD contractor be either FedRAMP Moderate Authorized or meet a documented equivalency standard. Kiteworks satisfies this the direct way: it holds an actual FedRAMP Moderate Authority to Operate, issued by the Joint Authorization Board and reconfirmed by an accredited 3PAO every year since June 2017. An MSP deploying Kiteworks doesn’t need to build or defend a FedRAMP equivalency package for the client — the authorization already exists and satisfies the DFARS 7012 cloud security requirement without an additional equivalency determination. MSPs should verify authorization status through the official FedRAMP compliance documentation rather than vendor marketing materials — the Marketplace listing is the authoritative record that a self-assessment package or C3PAO assessor will reference. Organizations should also review their supply chain risk management practices to confirm that subcontractors receiving CUI through Kiteworks-governed channels are themselves meeting applicable DFARS and NIST 800-171 obligations at their tier.
It means an MSP starting a CMMC engagement on Kiteworks begins from roughly 96 of the 110 NIST SP 800-171 practices already documented and technically enforced by the platform — spanning the control families (access control, audit and accountability, configuration management, identification and authentication, system and communications protection) that get the most scrutiny in any assessment, self- or third-party. In practice, that narrows the MSP’s job to policy documentation, environment configuration, and the remaining controls that depend on the client’s own procedures and physical environment, rather than building a security architecture from zero. That translates into shorter engagements, a higher first-attempt pass rate, and the ability to run more concurrent client engagements profitably. See the full control mapping in Kiteworks’ CMMC 2.0 compliance documentation. A risk assessment conducted against the remaining 10% of controls — the policy, physical, and procedural domains that Kiteworks does not directly address — gives the MSP the prioritized remediation roadmap that makes a first-attempt pass achievable.
Each Kiteworks DIB client runs in its own dedicated, isolated environment with its own encryption keys, not a shared multi-tenant instance. That removes an entire category of scoping questions for an assessor: there’s no shared infrastructure to account for, no other tenant’s data inside the CUI boundary, and no multi-tenant isolation controls to independently verify. Combined with a single, immutable audit log covering every channel — email, file sharing, managed file transfer, SFTP, data forms — the assessor gets one clean evidence package instead of five fragmented ones. That holds true whether the review is a contractor’s own self-assessment today or a C3PAO audit once Phase 2 resumes. MSPs should document each client’s data governance boundary — the specific Kiteworks instance, the channels in scope, and the CUI types handled — in the System Security Plan, since assessors will cross-reference the SSP against the deployed architecture. Data minimization policies that restrict CUI to only the channels and user roles that operationally require it further reduce the evidence burden by keeping the assessment boundary as narrow as possible.
CMMC compliance isn’t a point-in-time event. Contractors must keep their security controls operational, update their System Security Plan when the environment changes, remediate findings through a POA&M, and keep their self-assessment score current in SPRS — work that continues through the full three-year certification cycle and resets at reassessment. That’s a natural recurring-services model for an MSP: platform management and monitoring, periodic control reviews, POA&M tracking, SIEM-fed compliance monitoring through tools like the Kiteworks CISO Dashboard, and reassessment preparation, billed as a continuous engagement rather than a one-time project — the same model that applies whether the client is self-attesting today or preparing for a C3PAO audit once Phase 2 resumes. A documented incident response plan that covers CUI-bearing ransomware or credential compromise scenarios — with defined DFARS 252.204-7012 reporting timelines and rollback procedures — is a high-value MSP deliverable that most DIB clients lack and that directly supports NIST 800-171 IR domain compliance.
No — not on the self-assessment side. On July 13, 2026, the Department of War suspended CMMC Phase 2, meaning the ramp-up of mandatory third-party C3PAO assessments (originally due to begin Nov. 10, 2026) is paused pending a 60-day reform review, with a report expected around mid-September 2026. Phase 1 requirements — Level 1 self-assessment for FCI and Level 2 self-assessment for CUI, both in effect since November 2025 — remain in force, and DoW has said programs can continue to include self-assessment requirements in contracts. Contractors should keep their NIST SP 800-171 self-assessment, SSP, POA&M, and SPRS score current and treat the suspension as a planning window, not a compliance holiday: DoW’s stated goal is a “scalable, realistic” replacement for the current C3PAO model, not the end of third-party verification. MSPs should use the 60-day window to conduct a risk assessment of each client’s current NIST 800-171 control posture against the full 110-control set — identifying gaps that could surface as False Claims Act exposure under the current self-attestation regime and closing them before the CMMC Reform Task Force releases its recommendations.
Additional Resources
- Blog Post
CMMC Compliance for Small Businesses: Challenges and Solutions - Blog Post
CMMC Compliance Guide for DIB Suppliers - Blog Post
CMMC Audit Requirements: What Assessors Need to See When Gauging Your CMMC Readiness - Guide
CMMC 2.0 Compliance Mapping for Sensitive Content Communications - Blog Post
The True Cost of CMMC Compliance: What Defense Contractors Need to Budget For