Skip to content
Foxx Cyberfoxxcyber/docs

Customer Responsibility Matrix

Your side of the split — an actionable checklist, and how to get the full 110-practice CRM.

The Customer Responsibility Matrix (CRM) is the formal document that states, for every CMMC Level 2 practice, whether it's satisfied by the provider, by you, or shared — and exactly what each side's portion is. It's the same kind of artifact AWS provides to us as their customer; we produce the equivalent for ours.

Downloads

FileCoversFormat
Bedrock CMMC SaaS CRMThe hosted platform — all 110 CMMC L2 practices, provider/customer splitCSV, v1.0 (2026-07-29)
Bedrock C3PAO deployment CRMSelf-hosted assessor app — all 110 practices for partners running it in their own environmentCSV, v1.0 (2026-07-29)

Both open directly in Excel or Google Sheets and are designed to drop into an assessment package. Each row carries the CMMC practice ID, NIST SP 800-171r2 and 800-53 mappings, the practice statement, the responsibility assignment, and each side's portion.

For each practice, the CRM marks responsibility as:

ValueMeaning
Foxx Cyber (Provider)The platform satisfies this by design; you inherit it
CustomerYour environment must satisfy this; the platform does not
SharedBoth parties do part — the matrix states each side's portion
N/ANot applicable to the deployment

Your responsibilities, as a checklist

The customer-side portions of the CRM boil down to a manageable list. If you run the platform CRM through your program, expect your side to include:

Accounts and access

  • Decide who in your organization gets an account, and at what role.
  • Enable MFA for your users (available per-user today) and make it policy.
  • Remove access promptly when people leave or change roles — deactivate the Bedrock account as part of your offboarding checklist.
  • For MSP/RP relationships: grant partner users access to client organizations deliberately, and review those grants periodically.

Data handling

  • Apply your CUI handling policy to what you upload — use evidence pointers where policy prohibits placing artifacts in a commercial cloud (see Where CUI Lives).
  • Govern how exported packages and reports are transferred and stored once they leave the platform.

Your environment

  • Keep the endpoints and browsers your team uses patched and protected.
  • Cover mobile-device, portable-storage, and alternate-work-site policies in your own program — no SaaS provider can do these for you.
  • Train your personnel (security awareness, insider threat) and screen them per your own procedures.

Your program

  • Review your organization's in-app audit activity as part of your own audit reviews.
  • Maintain your own incident response plan; if we notify you of an incident affecting your data, your reporting obligations for your boundary are yours.

Deployment-specific CRMs

Partners who host Bedrock C3PAO in their own environment get a deployment-specific CRM: since the software runs inside the partner's boundary, the split shifts — the partner owns the hosting environment (network egress, VDI/OS hardening, physical control), while the application provides the in-app controls (RBAC, audit logging, local encryption). We maintain these per-partner, practice-by-practice.

The generic matrices above are downloadable at the top of this page. For a partner-specific CRM tailored to your deployment, contact your Foxx Cyber point of contact or open a support ticket.

Last updated July 29, 2026