Back to CMMCReady
StormCloud Gov — CMMCReady Program

CMMC Level 2
Shared Responsibility Matrix

A complete mapping of all 110 NIST SP 800-171 controls showing which are Inherited from StormCloud Gov, which are the OSC's responsibility, and which are Shared — so you know exactly what you own before assessment day.

1

All CUI is hosted inside StormCloud Gov enclaves (no external CUI systems unless explicitly connected via ECR-Connector).

2

StormCloud Gov provides the secure enclave platform, hypervisor, network, storage, Corvette SIEM, VPN/Zero Trust access, and managed security services.

3

The OSC/contractor owns policies, HR, business processes, and in-enclave application data/workflows.

*

AC 3.1.20 is Customer unless the ECR-Connector is used (then Inherited). PL/CA 3.12.1 is Shared in hybrid scenarios and Inherited for 100% VDI-only deployments.

All Controls
110
Inherited — Primarily StormCloud Gov
90
StormCloud Gov
Customer — Primarily OSC
7
OSC Only
Shared — Both Must Implement
23
Both Must Implement
No controls match your search. Try a different keyword or filter.

Ready to See How This Applies to Your Organization?

Take the free CMMCReady Fit Check to understand exactly which controls you inherit from StormCloud Gov and what your team needs to implement.