Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should federal contractors respond when CMMC certification…
Governance, Ownership & Risk

How should federal contractors respond when CMMC certification does not cover GSA work?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 11, 2026 Domain: Governance, Ownership & Risk

They should treat the gap as a scope and governance problem, not a certification problem. That means separating evidence by contract path, validating assessor authority for each framework, and aligning notification and review processes to the stricter requirement set. Waiting for reciprocity is not a viable operating strategy.

When the certification scope does not match the work order

The practical issue is not whether the contractor is “certified,” but whether the certification evidence actually covers the contract path being performed. For federal contractors, the right response is to separate the CMMC-covered environment from the GSA engagement, then treat each path as its own control and evidence boundary. That prevents over-claiming compliance and keeps review decisions tied to the actual scope.

Once the work is split by contract path, evidence has to follow the scope. If a team uses one shared control set for both paths, the stronger regime can be diluted by weaker assumptions, and assessors may be asked to sign off on work they were not engaged to evaluate. Third-Party, B2B and Contractor Access Guide is useful here because contractor access often fails first at boundary definition, sponsorship, and time-bounded access.

Why reciprocity assumptions create governance drift

Reciprocity is tempting because it sounds efficient, but it only works when the receiving authority accepts the evidence set and the scope assumptions behind it. In practice, the gap appears when contractors assume one certification or one assessor can stand in for another program with a different purpose, contracting authority, or review trigger. The result is governance drift: teams delay action while waiting for a recognition path that may not exist.

The safer operating model is to treat equivalency as a question to validate, not a premise to rely on. IAM and IGA Basics helps frame that distinction, because access governance is about who can prove what, for which environment, under which approval chain. When the answer differs by contract, the evidence and approval model must differ too.

How to run the review and notification path correctly

The operational fix is to align notification, escalation, and review steps to the stricter requirement set, then use that set as the default until a formally accepted exception exists. That means validating which controls, attestations, and reviewer authorities apply to the GSA work, then ensuring the CMMC evidence does not get repurposed as a substitute unless the receiving process explicitly accepts it.

Access review discipline matters as much as certification status. A contractor can be technically compliant in one scope and still be out of bounds in another if permissions, shared accounts, or supporting workflows cross contract lines. Access Reviews and Certification Guide is relevant because the core control question is not simply “is access approved,” but “is the approval valid for this business path and still current.”

For teams managing both federal and commercial work, separation of duties and entitlement hygiene become the practical guardrails. Segregation of Duties (SoD) Guide reinforces the need to prevent one contract path from inheriting another path’s approvals, because cross-purpose access is where scope mistakes become audit findings.

Risk and Threat Considerations

The main risk is false assurance: an organisation believes it has satisfied the government’s expectations when it has only satisfied one programme’s scope. That can leave gaps in reviewer authority, evidence retention, or access control for the GSA work, and those gaps often persist until an audit, dispute, or incident forces revalidation.

Failure mechanism: Teams collapse multiple contract paths into a single control narrative, then reuse certification evidence outside the scope in which it was produced. That can create unsupported claims, delayed notification, and uncontrolled access overlap between environments or business lines.

Impact: The contractor can face failed assessments, corrective-action pressure, contract performance disruption, and avoidable exposure if the wrong people or processes are treated as authoritative for the wrong work path.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5CA-2 — Control AssessmentsSeparate contract paths need distinct assessment scope and evidence.
AU-6 — Audit Record Review, Analysis, and ReportingNotification and review processes depend on timely review of scope-specific evidence.
AC-6 — Least PrivilegeCross-scope access should be limited so one contract path does not inherit another's authority.
Recommendation — Define the assessment boundary for each contract path and verify the evaluator's authority. Route audit and review evidence to the authority that owns each contract path. Limit access so personnel and systems only operate within the contract path they are authorized for.
ISO/IEC 27001:2022A.5.15 — Access controlScope separation and review authority are access-control problems in an ISMS.
Recommendation — Define access rules separately for each contract scope and enforce them consistently.
CIS Controls v8CIS-5 — Account ManagementContract-path separation depends on controlling accounts, sponsorship, and review lifecycle.
Recommendation — Review and constrain accounts so contractor access matches the correct engagement scope.

Practitioner Guidance

What to verify: Confirm, in writing, which authority owns review and notification for the GSA engagement, and whether the assessor or evidence set is accepted for that specific path. If the answer depends on “we usually do,” the scope is not controlled enough yet.

Decision rule: If the GSA work is not explicitly inside the certification boundary, run a separate evidence file, separate reviewer chain, and separate exception log. Do not wait for reciprocity before operating the contract.

Practitioner takeaway: Treat certification as proof for a defined scope, not as a portable excuse to skip contract-specific governance.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org