2 min read

The CMMC Shared Responsibility Matrix: Who Owns Which Control

If you use a cloud service provider or a managed IT partner, you do not inherit their compliance. You inherit a split. A shared responsibility matrix is the document that draws the line between what your provider secures and what you still have to do yourself, and your C3PAO will ask for it. Get this wrong and you can fail an assessment on controls you assumed someone else owned.

What a Shared Responsibility Matrix Actually Is

A shared responsibility matrix maps every applicable NIST SP 800-171 control to one of three states. The provider is fully responsible, you are fully responsible, or responsibility is shared between you. For each of the 110 controls in your scope, there should be a clear answer to the question: who implements this, and who can prove it.

This is different from a provider's marketing claim that they are FedRAMP authorized. FedRAMP authorization covers the infrastructure layer. It does not configure your access controls, write your policies, or train your people. Those gaps land on you.

Which Controls Are Most Often Mis-Assigned

Certain control families are where contractors most often assume the provider has them covered when they do not. Watch these closely:

  • Access Control (AC): the platform offers role-based access, but you define the roles, approve the accounts, and review them.
  • Audit and Accountability (AU): the provider generates logs, but you decide what to review, how often, and you keep the records.
  • Identification and Authentication (IA): MFA may be available, but enabling it for every account and enforcing it is your job.
  • Configuration Management (CM): the provider hardens its infrastructure, but your tenant settings, baselines, and approved software list are yours.
  • Awareness and Training (AT): no cloud provider trains your staff on insider threat or CUI handling. That is entirely on you.

How to Build Yours Without Guessing

Start with your provider's own documentation. Reputable cloud and managed service providers publish a customer responsibility matrix or a CMMC inheritance statement. Pull it, then map each line to your SSP. Where the provider claims a control, cite their attestation as your evidence. Where responsibility is shared, document exactly what you do on your side. Where you own the control outright, treat it like any other internal control with a policy, a procedure, and a dated artifact.

Do not accept a one-line claim of full coverage. An assessor will want to see the boundary drawn control by control, not a blanket assurance.

Shared Responsibility Checklist

  • Obtain the customer responsibility matrix from every provider in your CUI boundary.
  • Map each of the 110 controls to provider, shared, or you.
  • For inherited controls, store the provider attestation as evidence in your SSP.
  • For shared controls, write down precisely what your side implements.
  • Confirm no control is left unassigned or assumed.
  • Re-review the matrix whenever you change providers or add a new tool to scope.

CMMC Operator provides compliance readiness resources for informational and planning purposes only. This article is not legal advice, an assessment determination, or a substitute for a qualified C3PAO or GRC advisor. Validate your shared responsibility assignments against your providers' current documentation and your own assessment scope.