Customer Responsibility Matrix
Your side of the split — an actionable checklist, and how to get the full 110-practice CRM.
The Customer Responsibility Matrix (CRM) is the formal document that states, for every CMMC Level 2 practice, whether it's satisfied by the provider, by you, or shared — and exactly what each side's portion is. It's the same kind of artifact AWS provides to us as their customer; we produce the equivalent for ours.
Downloads
| File | Covers | Format |
|---|---|---|
| Bedrock CMMC SaaS CRM | The hosted platform — all 110 CMMC L2 practices, provider/customer split | CSV, v1.0 (2026-07-29) |
| Bedrock C3PAO deployment CRM | Self-hosted assessor app — all 110 practices for partners running it in their own environment | CSV, v1.0 (2026-07-29) |
Both open directly in Excel or Google Sheets and are designed to drop into an assessment package. Each row carries the CMMC practice ID, NIST SP 800-171r2 and 800-53 mappings, the practice statement, the responsibility assignment, and each side's portion.
For each practice, the CRM marks responsibility as:
| Value | Meaning |
|---|---|
| Foxx Cyber (Provider) | The platform satisfies this by design; you inherit it |
| Customer | Your environment must satisfy this; the platform does not |
| Shared | Both parties do part — the matrix states each side's portion |
| N/A | Not applicable to the deployment |
Your responsibilities, as a checklist
The customer-side portions of the CRM boil down to a manageable list. If you run the platform CRM through your program, expect your side to include:
Accounts and access
- Decide who in your organization gets an account, and at what role.
- Enable MFA for your users (available per-user today) and make it policy.
- Remove access promptly when people leave or change roles — deactivate the Bedrock account as part of your offboarding checklist.
- For MSP/RP relationships: grant partner users access to client organizations deliberately, and review those grants periodically.
Data handling
- Apply your CUI handling policy to what you upload — use evidence pointers where policy prohibits placing artifacts in a commercial cloud (see Where CUI Lives).
- Govern how exported packages and reports are transferred and stored once they leave the platform.
Your environment
- Keep the endpoints and browsers your team uses patched and protected.
- Cover mobile-device, portable-storage, and alternate-work-site policies in your own program — no SaaS provider can do these for you.
- Train your personnel (security awareness, insider threat) and screen them per your own procedures.
Your program
- Review your organization's in-app audit activity as part of your own audit reviews.
- Maintain your own incident response plan; if we notify you of an incident affecting your data, your reporting obligations for your boundary are yours.
Deployment-specific CRMs
Partners who host Bedrock C3PAO in their own environment get a deployment-specific CRM: since the software runs inside the partner's boundary, the split shifts — the partner owns the hosting environment (network egress, VDI/OS hardening, physical control), while the application provides the in-app controls (RBAC, audit logging, local encryption). We maintain these per-partner, practice-by-practice.
The generic matrices above are downloadable at the top of this page. For a partner-specific CRM tailored to your deployment, contact your Foxx Cyber point of contact or open a support ticket.