

About Author
Hannah Lloyd
Hannah Lloyd is CRO and co-founder of enhanced.io. She leads global new business generation and works directly with MSP partners to build and sell security practices.
enhanced.io, the channel-only Open XDR SOCaaS for MSPs
TL;DR
Customer accountability, MSP delivery responsibility and vendor evidence are three separate things, and CMMC evidence gets confused when they're treated as one.
Scope comes first: where CUI lives, which systems are in scope, and how access changes the boundary.
The evidence chain runs across logging, endpoint controls, incident response, network enforcement and governance records.
A five-question test tells you whether a platform supports a practice or actually produces defensible evidence for it.
enhanced.io is a channel-only Open XDR SOCaaS built exclusively for MSPs, with 400+ integrations across endpoint, network, cloud, identity and IoT/OT, reporting against frameworks including CMMC.
An evidence pack checklist and pre-attestation review cadence close out the piece.
Separate the three roles before you separate anything else
I was on a call a few weeks ago with a partner who'd just been asked by their client's prime contractor for CMMC evidence, and the first ten minutes were spent working out whose job it actually was to provide it. That confusion is more common than you'd think, and it's worth untangling before anything else.
The client owns accountability for their own compliance. The MSP owns responsibility for delivering the controls they've contracted to deliver. The vendor, us in this case, owns the evidence that a specific control is actually operating, not just switched on. What tends to happen when these three get blurred together is everyone assumes someone else is holding the evidence, and nobody actually is, right up until the assessor asks for it.
Scope comes before anything else
Before any evidence conversation makes sense, scope has to be nailed down. Where does controlled unclassified information actually live in this environment. Which systems touch it, directly or indirectly. And here's the bit that catches people out: how does access change the boundary. A system that only stores CUI is one thing. A system where an administrator with broad access can reach it is a different boundary entirely, and that's the version most partners haven't mapped when they first ask us for help.
The evidence chain, surface by surface
Once scope is settled, the evidence chain runs across five areas, and each one needs its own proof, not a general assurance that it's covered.
Logging: can you show, on demand, what was logged, for how long, and who reviewed it.
Endpoint controls: can you show the control was actually enforced on the relevant devices, not just installed.
Response: can you show a documented incident response process was followed the last time it was tested or invoked.
Network enforcement: can you show that network-level controls, segmentation and monitoring, actually applied to in-scope systems.
Governance records: can you show policy documents were reviewed, approved and dated, not just written once and left alone.
The five-question test for a platform's evidence claims
What I've seen work is running any platform through five questions before trusting its compliance claims.
Does it store evidence with a timestamp, not just a current-state dashboard. Does it retain that evidence for as long as the framework requires, not just for the life of the subscription. Can a partner export it in a format an assessor will accept, rather than a proprietary screen only the vendor can read. Does it map specifically to named practices, rather than a general reassurance of coverage. And can someone other than the vendor's own team verify the evidence is accurate.
Recent CMMC guidance in the channel has made a related point worth sitting with: supporting a large number of practices is not the same as satisfying them. The five questions above are how you tell the two apart before a client's assessment date, not during it.
An evidence pack checklist and pre-attestation review
Build a client's evidence pack around the five areas above, not around a generic compliance folder. Before any attestation, run a pre-attestation review: confirm scope hasn't drifted since the last review, confirm each piece of evidence is current and dated, and confirm the client's own leadership has actually seen and signed off on what's being attested to.
This is the same discipline behind enhanced.io's own reporting, a named Fractional Security Director who owns making sure a partner's evidence is defensible before an assessor ever asks the question, not after. It's worth reading alongside our overview of which US compliance frameworks MSPs need to report against, since CMMC rarely sits in isolation from a partner's other reporting obligations.
About enhanced.io
enhanced.io is a channel-only Open XDR SOCaaS built exclusively for MSPs, with 400+ integrations across endpoint, network, cloud, identity and IoT/OT. Reporting is built against named frameworks, including CMMC, with a named Fractional Security Director who owns the evidence trail rather than leaving it to a dashboard. We also cover why SOC 2 compliance matters and how MSPs in the UK and EU demonstrate compliance, alongside a broader look at why compliance matters for MSPs right now. Our guide to the best SOC as a service model for MSPs covers how reporting fits into the wider service. If threat and security risk reporting is the gap you're trying to close before an assessment, get in touch and we'll walk through what an evidence pack looks like in practice.
FAQ
What is the difference between a platform supporting a CMMC practice and proving it?
Supporting a practice means the platform has a feature that touches on it. Proving it means the platform produces dated, specific, exportable evidence that the practice was actually operating at a given point in time. A lot of platforms do the first well and the second not at all.
Who is responsible for CMMC evidence, the client, the MSP or the vendor?
Does scope change if an administrator has broad access to a system holding CUI?
How long should CMMC evidence be retained?
What should be in an MSP's evidence pack before an assessment?
Can an MSP use one platform's compliance dashboard as the only evidence for an assessor?