Shared-Responsibility Matrix (You · MSP · Cloud)
Quick answer: Most optimistic scores hide in the gaps between “we thought the MSP did that” and “the cloud console was never configured.” Map each control family to you, yourMSP, and your cloud/SaaS—then put the truth in the SSP.
Download matrix PDFSSP guidance
How to use it
- List in-scope systems and where CUI actually lives.
- For each control family (or key controls), mark who configures, who monitors, who evidences.
- Flag every “shared” cell—shared without evidence is a gap.
- Update the SSP so responsibilities match contracts and reality.
Why this sells readiness work
When the matrix is full of blanks or “assumed,” you are not ready for a defensible score—or a C3PAO. That is exactly when a Defensibility Review or gap assessment helps. We still do not certify you.