Vertical Deep-Dive • CMMC for MSP Clients

CMMC Compliance Your Defense Clients Cannot Afford To Fail

Every MSP serving the Defense Industrial Base supply chain needs a CMMC Level 2 answer. Petronella Technology Group puts four CMMC Registered Practitioners on your bench, delivers gap assessments through assessment readiness, and keeps your client relationship intact under your contract.

The CMMC 2.0 Landscape for MSPs

CMMC 2.0 is no longer a future requirement. The Department of Defense has codified the rule. Prime contractors are flowing down CMMC Level 2 requirements to subcontractors, and subcontractors are calling their MSPs asking for help. The MSP that can answer "yes, we handle CMMC" keeps the client and wins a five-to-six-figure compliance engagement. The MSP that says "we don't do that" loses the client to a specialized compliance firm that will eventually take over the managed-services contract too.

The challenge is not the credential alone. Earning a CMMC Registered Practitioner designation requires passing the CCA exam and maintaining continuing education, but the real barrier is depth of experience across all 110 NIST SP 800-171 practices. An MSP with one newly certified RP and no track record of delivering gap assessments, authoring System Security Plans, or walking clients through C3PAO assessments is going to struggle with the first engagement. That is where Petronella comes in.

The MSP's Compliance Gap

Most MSPs can install endpoint protection, configure MFA, and manage a firewall. Those are necessary but not sufficient for CMMC Level 2. The 110 practices span 14 control families including access control, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, physical protection, personnel security, risk assessment, security assessment, system and communications protection, system and information integrity, and awareness and training.

Why AT-2 and AT-3 Custom Training Is the Moat

The awareness and training family is where most MSPs and their generic-training vendors fail. CMMC requires two distinct controls: AT-2 (role-based security awareness) and AT-3 (role-based security training). AT-2 covers general workforce awareness. AT-3 requires training specific to the roles and responsibilities of each user, administrator, and system operator touching CUI.

Generic security-awareness platforms like KnowBe4 satisfy AT-2. They do not satisfy AT-3 because they deliver the same phishing simulations and awareness modules to every employee regardless of role. A system administrator handling CUI in an enclave needs different training than a procurement clerk with email-only access. AT-3 compliance requires custom curricula mapped to job functions, documented per-role training plans, and evidence that each individual completed the training appropriate to their access level.

Petronella's MSP Stack includes the CMMC Bootcamp (67 lessons) and the 39-Layer Curriculum (54 lessons), both of which address AT-3 requirements with role-based training paths. This is the competitive moat that separates Petronella partners from MSPs that rely solely on commodity awareness platforms.

What Petronella Provides to MSP Partners

CMMC Bootcamp (67 Lessons)

Full CMMC Level 1 through Level 2 readiness curriculum delivered via the Training Academy. Covers SSP drafting, POA&M construction, audit-evidence packaging, and assessor preparation. Available immediately through MSP Stack membership.

39-Layer Curriculum (54 Lessons)

Petronella's signature sellable framework. Use it as your own commercial framework with regulated-SMB clients. Covers layered security from physical controls through application security. Remix rights included with membership.

SSP and POA&M Templates

Production System Security Plan starters and Plan of Action & Milestones templates used in real CMMC engagements. Plain-English editable documents, not locked PDFs. Updated quarterly as CMMC guidance evolves.

Gap Assessment Delivery

Full 110-practice gap assessment against your client's environment. Delivered as a prioritized remediation roadmap with effort estimates, tooling recommendations, and evidence-collection templates.

Named CMMC-RP on Your SOW

Cyber-AB requires the Registered Practitioner to be named on CMMC advisory deliverables. Petronella appears as the RP on the scoped work while your MSP keeps the client relationship and invoicing.

Assessment Readiness Walkthrough

Two-week dry run with a Petronella RP acting as the assessor. Surfaces documentation gaps and evidence chain-of-custody issues before the real C3PAO walks in the door.

Fleet for Compliance-Aware Prototyping

When a CMMC engagement also involves private AI infrastructure, the Petronella Fleet $75,000 Compliance-Aware Prototype tier maps CMMC Level 2, HIPAA, and NIST 800-171 controls directly onto the AI architecture. The prototype deliverable includes SSP artifacts, an audit-evidence package, and a compliance overlay document the MSP's end client can present to their C3PAO. This is increasingly common as DIB contractors adopt AI for engineering knowledge bases, ITAR-aware document drafting, and CUI-safe compliance workflows.

Operator Council for Serious MSPs

MSP owners at $3M to $15M in annual revenue who want peer calibration and strategic counsel alongside compliance capability should apply for the Petronella Operator Council. The Council is a 20-seat cohort with a 12-week async onboarding curriculum, monthly live Q&A with Craig Petronella, quarterly outside-expert sessions, P&L benchmarking, and a deal-flow channel that routes engagements to members with matching capacity.

Charter Cohort 1 pricing is $45,000 per year for the first 12 seats (25% below steady-state $60,000/yr). The onboarding curriculum includes dedicated CMMC weeks (Weeks 4 and 5) covering gap-assessment process, Level 2 delivery, and pricing strategy for compliance engagements.

Petronella's CMMC Bench

EngineerCredentialsRole
Craig PetronellaCMMC-RP, CCNA, CWNE, DFE #604180Founder, 22+ years cybersecurity delivery
Blake ReaCMMC-RPSenior engineer, partner engagement lead
Justin SummersCMMC-RPSenior engineer, assessment delivery
Jonathan WoodCMMC-RPSenior engineer, remediation and deployment

Petronella Technology Group is a CMMC Registered Practitioner Organization, BBB A+ rated since 2003, PPSB accredited, and operating from 5540 Centerview Dr, Raleigh, NC since 2002. Full practice details at CMMC compliance and CMMC assessment.

Who This Is Built For

  • MSPs serving DIB primes and subs with DFARS 7012, 7019, 7020, or 7021 clauses in active contracts
  • MSPs whose defense-contractor clients have received a CMMC Level 2 flow-down requirement with a deadline
  • MSPs that can handle IT operations but lack in-house CMMC-RP credentialed engineers for advisory and assessment work
  • MSPs that want to build internal CMMC capability over time using Petronella's curriculum and templates as the foundation
  • MSPs serving healthcare, legal, or financial clients with dual-compliance scope (HIPAA plus CMMC, or NIST 800-171 plus industry regulation)

What Does Not Fit

  • Clients with zero DoD exposure who do not need CMMC Level 2
  • Clients asking for CMMC Level 3 (requires a different specialized partner; Petronella refers)
  • Clients asking the MSP to rubber-stamp a self-attestation with no controls work (Petronella will not sign off on shortcuts)

Related MSP-Partners Resources

Frequently Asked Questions

Why not just get one of our engineers CMMC-RP certified?
You can, and many MSPs do over time. The bottleneck is depth of experience on the 110 practices, not the credential itself. Partners often start by renting Petronella's bench for their first two or three client engagements, then build internal capability using the SSP templates, evidence checklists, and assessment playbooks delivered as part of the work.
Does Petronella perform the formal C3PAO assessment?
No. Petronella is an RPO (Registered Practitioner Organization), not a C3PAO (Certified Third-Party Assessment Organization). Performing both advisory and assessment for the same client is a conflict of interest prohibited by Cyber-AB. Petronella prepares the client through assessment readiness and hands off to a C3PAO partner at the end. No hidden referral fee between Petronella and any C3PAO.
What if our client already failed a CMMC assessment?
Failed assessments are a common entry point. Petronella runs a failure-mode analysis against the assessor's report, produces a prioritized POA&M, and stands up remediation. Some clients reach readiness on a second attempt; some need to reduce CUI scope. Petronella advises honestly on which path fits.
How does the pricing work for the MSP?
MSP Stack membership at $1,997/mo gives your team access to all CMMC curriculum and templates for self-directed learning. When you bring a specific client engagement, Fleet prototyping and assessment work are scoped per engagement through a Discovery Call. The MSP invoices the end client at their discretion and manages the commercial relationship.
Can we use the 39-Layer framework with our own branding?
Yes. MSP Stack membership includes remix rights for the 39-Layer Curriculum. You can rebrand it as your own sellable framework for regulated-SMB clients. The curriculum content is yours to use in client-facing proposals, training materials, and marketing.
Non-Refundable & No-Guarantee Notice: All fees paid under membership, assessment, and compliance engagements are non-refundable. No guarantees of any business outcome — including CMMC certification pass rates, revenue lift, deal flow, or client compliance readiness — are made or implied. Results depend on MSP execution and end-client environment. Stripe checkout requires a confirmation checkbox acknowledging these terms.

Ready To Add CMMC To Your Service Catalog?

Apply for the Operator Council if you are building a serious compliance practice, or start with MSP Stack for self-paced curriculum and templates. Questions? Call (919) 348-4912 or contact us.