How Blackpoint Supports MSPs and Their Tenants on the CMMC Journey
CMMC continues to reshape the way companies do business with the federal government. Here’s how Blackpoint Cyber helps MSPs guide their customers in the Defense Industrial Base (DIB) toward certification.
What Is CMMC, and Why Should MSPs Care?
Initially announced on January 31, 2020, the Cybersecurity Maturity Model Certification (CMMC) is a federal program designed to protect the Defense Industrial Base (DIB) by mitigating federal data risk, standardizing protection practices, and improving cybersecurity preparedness among those involved with the U.S. government and the country’s defense. At its core, CMMC is intended to strengthen the protection of sensitive government data that flows across the DIB supply chain every day.
The CMMC Certification Program is overseen by the Department of Defense (DoD), also referred to as the Department of War (DoW), and the program’s governing body, the Cyber AB. This program builds upon previous federal initiatives, namely the Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012, issued in September 2017, which required DoD contractors to comply with the controls specified in NIST SP 800-171 Rev 2.
Later, DFARS 252.204-7019 further required DoD contractors to self-assess and enter their scores into the Supplier Performance Rating System (SPRS). A criticism of these practices was that self-attestation to compliance wasn’t providing the necessary assurance that adequate safeguards were in place to protect sensitive government data.
Thus, the CMMC program was born, seeking to standardize and codify requirements for DIB contractors to implement baseline cybersecurity protections to work with the government and enter or remain in the DIB supply chain. As a result, many DIB contractors are now required to obtain CMMC certifications through official Certified Third-Party Assessor Organization (C3PAO) assessments to be eligible for certain government contract awards.
Who Actually Needs to Comply?
DoD prime contractors and subcontractors that want to bid on contracts carrying the CMMC DFARS clause will need certification before contract award. The required level varies by role and by the regulated information an organization handles.
- Level 1: Some contractors, such as organizations handling Federal Contract Information (FCI), may need to meet Level 1 requirements.
- Level 2: Organizations handling Controlled Unclassified Information (CUI) may need to meet the higher requirements associated with Level 2.
- Level 3: Some organizations handling CUI may be required to meet Level 3 requirements, depending on the applicable contract.
Per the CMMC Program, DoD contracts will explicitly state which CMMC level a contractor must meet before award. Ultimately, safeguarding regulated, sensitive government data applies across the entire multi-tier DIB supply chain, from prime contractors down to small subcontractors, often several Kevin Bacons out in the supply chain.
MSPs can use this resource to learn more about regulated data governed by the CMMC program and to guide their compliance planning efforts.
Where Blackpoint Cyber Fits In
Blackpoint Cyber helps customers implement the controls required by NIST 800-171 by acting as an External Service Provider (ESP) that does not collect, store, process, or transmit any CUI.
With Privacy Mode enabled for tenants, Blackpoint can protect and safeguard CUI while never needing to access, collect, store, or transmit that regulated data itself, a distinction that has material impact on how an ESP is scoped in a customer’s compliance boundary.
To use Blackpoint Cyber as an External Service Provider, you’ll need to:
- Request the Customer Shared Responsibility Matrix. This document clarifies exactly which controls Blackpoint helps satisfy and which responsibilities remain with the customer, giving MSPs and tenants a clear map of the shared responsibility. The matrix is available through the Blackpoint Trust Center.
- Include Blackpoint Cyber in the System Security Plan (SSP). Documenting Blackpoint’s role as an ESP in the SSP is a foundational step for any organization seeking compliance.
- Enable Privacy Mode for your tenants. This configuration change allows Blackpoint’s SOC to keep protecting the environment while minimizing the risk of incidental transmission of regulated data from endpoints that have the SNAP Agent deployed to them. Privacy Mode is a technical control.
How Privacy Mode Works
For select alerts that warrant greater scrutiny, Blackpoint’s Security Operations Center (SOC) needs to dig deeper into the security alert to investigate indicators of compromise (IoCs) and identify the most effective response and remediation actions.
This process can involve pulling a file from an endpoint into a sandbox environment to extract Indicators of Compromise (IoCs) and run it through threat intelligence. Although Blackpoint SOC analysts do not actually view the ingested file contents during this portion of IoC analysis, the file itself is processed in Blackpoint’s cloud environment during this time.
Enabling Privacy Mode for a tenant mitigates the risk of incidental transmission of regulated data from a tenant’s environment into Blackpoint’s. When enabled, Privacy Mode restricts the SOC from pulling a file from an endpoint with the SNAP Agent installed for further investigation without Partner involvement.
Instead, the SOC must communicate with the Partner to obtain consent for this additional review and confirmation that there is no regulated data within the file contents before transfer. The SOC can therefore continue to investigate and respond to threats effectively in close coordination with the MSP, while mitigating the risk of incidentally exposing tenants’ Controlled Unclassified Information (CUI), Federal Contract Information (FCI), Covered Defense Information (CDI), or electronic protected health information (ePHI).
What This Means for MSPs
For MSPs managing multiple DIB clients across different CMMC levels, Blackpoint’s approach offers a way to deliver strong SOC-backed security response operations without adding unnecessary uncertainty to a customer’s compliance posture.
Partners should position Blackpoint correctly to their prospects or customers with CMMC requirements:
- Blackpoint is an ESP that stores, collects, processes, and transmits Security Protection Data (SPD). Blackpoint does not store, collect, process, or transmit CUI or FCI.
- Blackpoint should be documented in the customer’s SSP as an ESP.
- Partners will need to help their customers request, retain, and review Blackpoint’s Customer Shared Responsibility Matrix, available through the Trust Center.
- Partners will need to configure applicable tenants with Privacy Mode.
Following these steps gives MSPs a standardized, repeatable, defensible model to bring to every tenant working toward readiness and/or assessment.
The standardization and repeatability of this approach matters significantly. For better or for worse, CMMC compliance isn’t a one-time hurdle. It’s part of an ongoing relationship between the government and its supply chain.
MSPs who build well-documented ESP relationships now put themselves, and their tenants, in a stronger position for the long haul.
Official CMMC Resources
- DoD CIO – CMMC Program Overview — the official Department of Defense CMMC program page, covering the model, requirements, and rulemaking updates.
- Supplier Performance Risk System (SPRS) – CMMC — where contractors manage and submit their CMMC status information as part of the DoD’s supplier risk system.
Ready to Start the Conversation?
Request Blackpoint’s Customer Shared Responsibility Matrix and learn how to enable Privacy Mode across your managed tenants.
DATE PUBLISHEDSeptember 29, 2026
AUTHORBlackpoint Cyber
SHARE ON
The 2AM Test
Executive Guide
Most MDR evaluations focus on dashboards, not what a provider actually does when something is live. Learn the four questions that matter more than the demo: authority, speed, surface coverage, and proof.
*88–91% of ransomware attacks land outside business hours