If your IT is handled by a managed service provider - an MSP, the company that runs your Microsoft 365, patches your machines, and picks up the phone when something breaks - there's a comfortable assumption waiting to bite you: "we'll just have our MSP handle CMMC." Some of it, they absolutely can. But the single most important part of Level 1 is one your MSP is legally not allowed to do for you, and a surprising number of shops don't find that out until they're staring at the submission screen.
This guide draws a clean line: what your MSP typically owns, what you share, and what stays yours no matter how good your provider is. It's written for the owner who wants to know exactly where "my MSP has it" stops being true.
What your MSP can genuinely own
A competent MSP already does most of the technical work Level 1 asks for, often without calling it "compliance." Of the 15 requirements, these are the ones a provider can implement and operate for you:
- Identity and authentication - individual accounts, no shared logins, multi-factor authentication. If your MSP set up Microsoft 365 or Google Workspace properly, this is largely done.
- The managed boundary - firewall configuration, keeping remote administration locked down, separating your public website from your internal network.
- Patching and malware protection - timely security updates across workstations and servers, antivirus that's deployed, updating, and scanning. This is bread-and-butter MSP work.
- External connection control - your MSP knows every remote-access tool and integration touching your systems, because they set most of them up.
That's a real chunk of the 15, and it's why "our MSP handles it" feels true. For the technical controls, it mostly is.
What you and your MSP share
A second group needs both parties - the MSP configures, but only you can supply the business reality:
- Access scoped to the job - your MSP sets the permissions, but only you can say who should reach the contract folder and who shouldn't. Getting this wrong is one of the most common gaps we see, because the MSP defaults to "everyone can open everything" unless told otherwise.
- Media disposal - the MSP can wipe drives on decommissioned machines, but the retired towers in your storage room and the paper in your shredder are on-site realities they may not even know exist.
- The external-connections list - the MSP knows the technical connections; you know the business ones (the prime's portal, the customer's file-share) that need to be on the approved list.
What stays yours - always
Here's the part that surprises people. Three things cannot be delegated to an MSP, and the first one is the whole ballgame.
The affirmation is yours, by law. Your Level 1 self-assessment goes into SPRS with an affirmation certified by a senior official of your company - not your MSP. The MSP can prepare everything, hold the SPRS access, even enter the assessment. But the person who checks the box and legally attests that all 15 requirements are met must be an official of the contractor. That affirmation carries False Claims Act exposure. "Our MSP said we were fine" is not a defense if the posture turns out to be wrong - you affirmed it.
The other three:
- Physical and visitor control. Escorting visitors, the sign-in sheet, tracking who holds keys and door codes - none of this lives in a cloud console. It's your front desk, your facility, your habit. An MSP can't do it from their office, and it's one of the most commonly missing requirements precisely because everyone assumes it's covered elsewhere.
- The accuracy of what gets attested. Even when the MSP does the technical work, you're the one certifying it's true. That means you need to actually understand your posture - the gap report, the evidence - well enough to stand behind it, not just forward a vendor's assurance.
- Flow-down to your own subcontractors. If you hold the contract directly and sub work out, FAR 52.204-21(c) requires you to put the clause substance into those subcontracts. An MSP can't write clause language into your subcontract agreements - that's your contract paperwork, not their console. It's a contract-administration duty, not a technical control, so it sits outside what any provider can own for you.
One more wrinkle if you contract directly rather than through a prime: your MSP is an External Service Provider (ESP) in CMMC's terms, and using one doesn't move the boundary off your books. You still own the scoping decision - what's in, what's out - and you still own the affirmation. A good ESP makes the work easier; it doesn't make the responsibility theirs.
Want to know which of the 15 your setup already covers and which are still on you? The free 5-question check gives you a quick read in about three minutes, no email to start.
The question to ask your MSP this week
Not "do you handle CMMC?" - that invites a comfortable yes. Ask instead: "Which of the 15 Level 1 requirements do you own, which do we share, and which are entirely on us?" A good MSP will give you a clear division that looks a lot like the three groups above. A vague "don't worry, we've got it" is itself the warning sign - because at least three of the 15 are things they structurally cannot have.
You should also ask what evidence they can hand you on request. Level 1 isn't just doing the work; it's being able to prove you did it - the Entra export, the antivirus status screenshot, the patch report. An MSP that can produce those quarterly makes your compliance nearly self-maintaining. One that can't is doing the work but leaving you unable to demonstrate it.
If you're an MSP reading this
You already do most of Level 1 for your defense-adjacent clients. What tends to be missing isn't the technical work - it's the assessment structure around it: the scored gap report that tells a client exactly where they stand, the plain-English policies mapped to their environment, the evidence checklist that turns your console exports into an audit-ready folder, and the SPRS walkthrough that gets them to affirmation. That's the layer we built, and it's designed to sit on top of the technical foundation you've already laid - per client, without you reinventing the documentation each time. If you manage this across a handful of clients, reach out and we'll talk about how it works at more than one-off scale.
Where does your shop stand right now?
Five yes/no questions, instant grade, no email required. Know before you're asked.
Take the free 5-question check