Compliance / CMMC 2.0
Cybersecurity Maturity Model Certification for MSPs
The Department of Defense's certification framework for protecting controlled unclassified information across the defense industrial base — reaching well past prime contractors into the small manufacturers, machine shops, and suppliers that touch a DoD contract.
Why this reaches an MSP, not just the client
A CMMC requirement doesn't stay with the prime contractor — it flows down the supply chain to any subcontractor handling CUI, which means a small manufacturer or parts supplier an MSP already serves can suddenly need to demonstrate specific technical controls to keep a contract, and the MSP managing their systems becomes part of that evidence.
What the Nexus compliance module tracks
- Posture tracked against CMMC's practice domains — access control, incident response, system and information integrity, and the rest — using the same three-state model (implemented, partial, planned) as every other framework here
- Evidence attached directly to the practice it supports, the documentation trail a CMMC assessment actually asks for rather than a claim without backing
- Credential vault access logging and rotation tracked as direct evidence for the access-control and identification-and-authentication domains
- A QBR rollup that gives a small supplier's leadership a plain-language posture summary ahead of a formal assessment, not a surprise
This describes what the module tracks against CMMC 2.0 — not a claim that Nexus or any client on it is certified or audited against it. See the compliance & QBR module for the full picture, or read the blog for more on how we think about compliance tooling.
Other frameworks
SOC 2
The audit framework a lot of your clients' own customers require them to answer for — and that requirement flows straight down to you as their MSP.
NIST CSF
A widely-adopted, vendor-neutral structure for cybersecurity posture — Identify, Protect, Detect, Respond, Recover — that shows up in RFPs, cyber-insurance questionnaires, and board conversations alike.
HIPAA
If any client handles protected health information, HIPAA's Security Rule reaches your MSP the moment you touch their systems — business associate agreement or not.
Ready to see CMMC 2.0 posture tracked for real?
Join the design-partner cohort and we'll walk through the control mapping for your own clients.