Vendor and Cloud Due Diligence for CMMC and CUI Handling

Your cloud tools and service providers can put CUI in scope. Learn what to ask vendors, what to put in writing, and how to document shared responsibility.

3 min readBy Ironfield Cyber Team

Defense subcontractors do not run in isolation. Email, file storage, collaboration tools, backup, remote support, and your managed IT provider may all touch controlled information. Under CMMC and NIST SP 800-171, using an external provider does not remove your responsibility. It changes how you demonstrate that requirements are met.

Vendor due diligence means asking the right questions before you send CUI anywhere, writing down the answers, and revisiting them over time.

Start With a Vendor Inventory

List every external service that stores, processes, or transmits CUI, or that has access to systems that do:

  • Cloud email and collaboration platforms
  • File storage and document management
  • Backup and disaster recovery providers
  • Managed IT, security monitoring, and help desk
  • Remote support and remote access tools
  • Engineering, design, or specialized software hosted by vendors
  • Printing, shredding, and disposal services

Include vendors that have administrative access to your environment, even if they do not store data. For each, note what data they touch, who owns the relationship, and whether CUI is involved.

Questions to Ask Cloud Providers

If a provider will hold or process CUI, the general expectation is that it meets security requirements equivalent to the ones you must meet, and, for cloud services, applicable federal authorization or equivalent requirements. The details are in the DFARS and CMMC rules and related guidance, so verify the current language.

Ask:

  1. Will you provide documentation of your security authorization or compliance status for handling CUI?
  2. Where is data stored and processed, and who can access it, including support personnel?
  3. How is data encrypted in transit and at rest, and who controls the keys?
  4. What are your incident detection and notification commitments, and do they support the timelines in our contracts?
  5. Which security responsibilities are yours, and which are ours?
  6. How do we obtain logs and evidence for our assessment?
  7. What happens to our data when the contract ends?

Request a responsibility matrix if the vendor has one. It shows which controls the vendor handles, which you handle, and which are shared.

Managed Service and Security Providers

A provider that manages your systems or security tools may itself be in scope for your assessment. Under the CMMC framework, external service providers are treated according to the services they provide and their access to CUI. Discuss with them early:

  • Whether they are prepared to support your assessment
  • Which of their staff, tools, and systems touch your environment
  • How they protect their administrative access to your systems
  • How they document the controls they perform on your behalf

Put It in Writing

Contracts and service agreements should reflect your needs:

  • Clear statements of responsibility for specific security controls
  • Incident notification timeframes that align with your own reporting duties
  • Provisions for access to evidence and cooperation in assessments
  • Data location, return, and deletion terms
  • Restrictions on subcontracting by the vendor without notice
  • Flow-down of CUI handling requirements

Have counsel review. Many standard terms of service do not cover these items, and you may need to negotiate or choose a different provider.

Document Shared Responsibility

In your system security plan, describe each external provider, the services it supplies, and how responsibility is divided. Reference the vendor documentation you gathered. Assessors will want to see that you understand what the vendor covers and have evidence to back it up.

Monitor Over Time

Due diligence is not a one-time exercise. Review vendors annually and when something changes:

  • A vendor changes ownership, hosting location, or product
  • The vendor reports a security incident
  • Your use of the service expands to cover CUI
  • Authorization or certification status changes

Maintain a contact for security issues at each vendor.

Manage Access

Limit and monitor vendor access. Require individual accounts, multifactor authentication, and logging of vendor activity. Remove access when work ends.

Avoid Common Missteps

  • Assuming a popular tool is fine for CUI without checking
  • Using a consumer-grade service for convenience
  • Letting departments adopt tools without review
  • Failing to include the managed provider in scoping

Where We Can Help

Ironfield Cyber helps defense subcontractors inventory vendors, evaluate cloud services for CUI use, and document shared responsibility for assessment. If you are unsure whether your tools are suitable, we can review them with you.