Blog / Compliance

Compliance
July 21, 2026 · 6 min read · Nexus Team

CMMC for the Small MSP With One Client That Touches Defense Contracting

Most small MSPs will never touch CMMC. Then one client — a machine shop, a software vendor, a logistics company — mentions they're bidding on a subcontract that flows down from a prime defense contractor, and suddenly the MSP is staring at a compliance framework built for defense primes, wondering which parts of it apply to a twelve-person client with a file server and a shared inbox.

CUI is the word that determines everything

CMMC's scope hinges entirely on whether a system touches Controlled Unclassified Information — a defense-specific data category with its own marking and handling rules, distinct from ordinary business-confidential data. A client that only ever sees a purchase order and ships a commodity part typically never receives CUI. A client that receives technical drawings, specifications, or performance data under a subcontract almost certainly does. The flow-down clause in the subcontract itself — not the client's guess about their own risk — is where this gets answered, and MSPs should treat 'the contract says' as authoritative over 'the client thinks.'

The level a small subcontractor is likely to face

  • CMMC Level 1 covers Federal Contract Information handling and maps to a short, largely procedural set of controls — the level most commodity subcontractors without CUI exposure will need
  • CMMC Level 2 maps to the 110 controls in NIST SP 800-171 and is where CUI-handling subcontractors land — a materially heavier lift involving system security plans, access control, and often a third-party assessment
  • The level isn't chosen by the MSP or the client — it's specified in the contract or flow-down clause, and getting it wrong in either direction wastes months of remediation effort on the wrong control set

Where MSPs actually get this wrong

The recurring failure mode isn't ignorance of CMMC — it's scoping the wrong boundary. An MSP hardens the client's whole network to NIST 800-171 when only one segregated project folder and the three laptops that touch it ever handle CUI. Properly scoping the CUI enclave — a separate network segment, separate credentials, sometimes a separate cloud tenant — is usually cheaper and faster than a full-network uplift, but it requires the MSP to actually map data flow before writing a system security plan, not after.

The question isn't 'is my client a defense contractor.' It's 'does any system my client uses ever receive, store, or transmit CUI' — and that answer can be yes for a company that has never spoken to the Department of Defense directly.

Nexus's compliance module tracks NIST CSF posture today, and CMMC's Level 2 control set overlaps heavily with 800-171 — but CMMC assessment and certification is a formal, third-party process with its own scoring methodology that sits outside what any posture-tracking tool can assert on a client's behalf. Where the platform helps is in giving an MSP evidence-backed visibility into which of those overlapping controls are actually implemented before a formal assessor ever shows up, which is a different thing than claiming certification — that determination stays with the accredited assessor, not the tooling.

Follow the build as it ships.

Nexus is live in our own MSP operations and opening to a limited design-partner cohort. Join the private-preview list.