Compliance / CMMC 2.0

Cybersecurity Maturity Model Certification for MSPs

The Department of Defense's certification framework for protecting controlled unclassified information across the defense industrial base — reaching well past prime contractors into the small manufacturers, machine shops, and suppliers that touch a DoD contract.

Why this reaches an MSP, not just the client

A CMMC requirement doesn't stay with the prime contractor — it flows down the supply chain to any subcontractor handling CUI, which means a small manufacturer or parts supplier an MSP already serves can suddenly need to demonstrate specific technical controls to keep a contract, and the MSP managing their systems becomes part of that evidence.

What the Nexus compliance module tracks

  • Posture tracked against CMMC's practice domains — access control, incident response, system and information integrity, and the rest — using the same three-state model (implemented, partial, planned) as every other framework here
  • Evidence attached directly to the practice it supports, the documentation trail a CMMC assessment actually asks for rather than a claim without backing
  • Credential vault access logging and rotation tracked as direct evidence for the access-control and identification-and-authentication domains
  • A QBR rollup that gives a small supplier's leadership a plain-language posture summary ahead of a formal assessment, not a surprise

This describes what the module tracks against CMMC 2.0 — not a claim that Nexus or any client on it is certified or audited against it. See the compliance & QBR module for the full picture, or read the blog for more on how we think about compliance tooling.

Ready to see CMMC 2.0 posture tracked for real?

Join the design-partner cohort and we'll walk through the control mapping for your own clients.