4 min read

Mac Tools and CMMC: Which Are ESPs, CSPs, or Neither?

The category follows what the service does with CUI, not what the vendor calls itself. Apple Business Manager, Jamf self-hosted versus cloud, and Iru mapped onto the 32 CFR 170.4 definitions.
The category follows the data. Not the vendor name. 32 CFR 170.4

Quick answer: the category follows what the service does with CUI, not what the vendor calls itself. 32 CFR 170.4 defines External Service Provider, Cloud Service Provider, and Security Protection Asset separately, and a single product can land in different categories at two different companies. This is a framework for reasoning, not a ruling on your environment.

What is the difference between an ESP and a CSP?

32 CFR 170.4 defines an External Service Provider as "external people, technology, or facilities that an organization utilizes for provision and management of IT and/or cybersecurity services on behalf of the organization." A Cloud Service Provider is defined more narrowly as "an external company that provides cloud services based on cloud computing."

A Security Protection Asset is a different axis entirely: an asset "providing security functions or capabilities for the OSA's CMMC Assessment Scope." A service can be an ESP and its platform can be a Security Protection Asset at the same time.

Why the distinction pays: under 32 CFR 170.19(c) a Security Protection Asset is assessed only "against Level 2 security requirements that are relevant to the capabilities provided." Under 32 CFR 170.16(c)(3)(ii), where a non-CSP ESP is used, "the ESP services used to meet OSA requirements are assessed within the scope of the OSA's assessment against all Level 2 security requirements." One lane is a subset. The other is everything.

And the FedRAMP question is separate again. It attaches under DFARS 252.204-7012(b)(2)(ii)(D) only where a cloud service provider stores, processes, or transmits covered defense information.

Is Apple Business Manager an ESP?

Apple Business Manager is an Apple-operated cloud service that holds your organisation's device enrollment records, Apple Account relationships, and app licence assignments. On the plain text of the definition it is external technology used for the provision and management of IT services on your behalf, which reads as an ESP.

Does it handle CUI? In a normal deployment, no. It holds device serial numbers, enrollment state, and purchasing records. That is organisational data, and some of it is sensitive, but it is not CUI unless you have put CUI there.

The honest position is that Apple Business Manager is the root of trust for your whole Mac deployment and belongs in the SSP and the asset inventory whatever label you attach. Losing control of it means losing control of enrollment. We covered the mechanics in Apple Business Manager for CMMC.

Is self-hosted Jamf Pro different from Jamf Cloud?

Yes, and it is the clearest example of why the vendor name is the wrong unit of analysis.

Self-hosted Jamf Pro running on infrastructure inside your own boundary is not an external cloud service. There is no external CSP in the path, so the FedRAMP conditional in DFARS 252.204-7012 has nothing to attach to. The server becomes an asset in your environment like any other, and its categorisation depends on what it does.

Jamf Cloud is a vendor-operated cloud service. It is external, and the analysis becomes the one in the previous section. Jamf holds no FedRAMP authorization as of August 2026. Its published posture is SOC 2, ISO 27001, and StateRAMP Authorized, and StateRAMP is the state and local programme rather than FedRAMP. In December 2025 Jamf announced an intent to pursue FedRAMP High and DoD IL5, which is an intent and not a status.

Same product name. Two different compliance conversations.

Where does Iru (formerly Kandji) land?

Kandji rebranded to Iru on October 22, 2025, and has since expanded beyond Apple into Windows and Android management. If your documentation still says Kandji, it is stale, and if your vendor evaluation still treats it as Apple-only, that is out of date too.

Categorically it sits where any vendor-operated cloud MDM sits. It is external technology managing IT on your behalf, so it reads as an ESP, and its platform provides security capability for your scope, so it reads as a Security Protection Asset. We found no FedRAMP authorization for Iru, Addigy, Mosyle, or any other Mac-first platform. That is a finding from absence of evidence rather than from a Marketplace query, so confirm it yourself before it goes in front of an assessor.

How do you document each one?

The same four elements every time, and the order matters:

  • What the service does. Plainly, in one or two sentences.
  • What data it holds. Specifically enough that a reader can check whether CUI is among it.
  • The category you assigned and why. Cite the definition you applied.
  • What that category means for assessment. Which requirements are relevant, or that the full set applies.

32 CFR 170.16 also requires that External Service Provider relationships be documented in the SSP, and that customer responsibility items from a cloud provider be documented or referenced there. A shared responsibility matrix is the usual home for that, and it is worth building before the assessment rather than during it.

For the FedRAMP question specifically, see does your Mac MDM need FedRAMP authorization.

Sources

  • 32 CFR 170.4 definitions; 170.16(c)(2), 170.16(c)(3)(ii); 170.19(c)
  • DFARS 252.204-7012(b)(2)(ii)(D)
  • Jamf Trust Center compliance page; Jamf press release, December 2, 2025
  • Iru newsroom and Computerworld coverage of the October 22, 2025 rebrand

Verified against primary sources on August 1, 2026. Asset categorisation is a per-deployment determination and this article is not a ruling on yours. Not legal advice.