One view across the client OSAs you support. Each client decides, per entity, whether you see its readiness state, and can withdraw at any time. Nothing is shared by default, and nothing is shared because you asked.
An MSP, MSSP or ESP supporting DIB contractors asks: “Can I demonstrate that the services and controls I’m responsible for are actually operating across my client base?”
For each client entity that granted, this view shows the readiness state the agents recorded in that client’s own workspace, as of its last measurement, with the date on the record; what that covers is listed below. It shows each client’s recorded state, not per-control evidence: the evidence stays in the client’s workspace. Clients that have not granted show as awaiting the client’s decision or as not shared, never as an estimate. The affirmation stays with each client’s Affirming Official.
You add a client by company name and email. We email the client its own link; you never receive it. Notices are limited per day, and your view is the same whether or not the company already works with us. The client grants or declines for each entity. Your view shows every client you added, and the state of only those that granted, with the count of how many have. You cannot change anything in a client’s workspace.
Requirement counts, open gaps and when each was last measured. At Level 1, also open evidence requests. At Level 2, also the responsibility-matrix rows the client allocated to you.
See a sample of the MSP / MSSP / ESP view, with fictional data →
Under 32 CFR 170.4 a provider is an External Service Provider in the CMMC Program only when CUI or Security Protection Data is processed, stored or transmitted on its assets. At Level 2, a non-cloud ESP that handles CUI, and any ESP that handles Security Protection Data, is in the OSA’s assessment scope; a cloud provider handling CUI must meet FedRAMP requirements under DFARS 252.204-7012 (32 CFR 170.19(c)(2), Table 4). Its use is documented in the OSA’s SSP and in the ESP’s service description and customer responsibility matrix. At Level 1, the OSA considers ESPs when it scopes (32 CFR 170.19(b)(3)).
“What you share may be Security Protection Data under 32 CFR 170.4; at Level 2, a provider that stores or processes it may be an External Service Provider in your assessment scope (32 CFR 170.19(c)(2)). Record it on your ESP list.”
It does not assess, certify or affirm. The OSA’s Affirming Official makes the affirmation decision; self-assessments are the OSA’s own, and certification assessments are conducted by independent Cyber AB-authorized C3PAOs or DCMA DIBCAC.
Enclave AI is priced by compliance function and agent workload, never by seat. Any price for the provider view is published here before it applies, and no fee of any kind is paid for a client you add. Your client’s own subscription pays for the agents’ work.
The dashboard link goes to the contact address after it is confirmed. A business email address is needed (free-mail addresses are refused), and each email domain holds one MSP, MSSP or ESP seat. For its first 14 days a new seat can send at most 3 client notices in any 24 hours. A seat whose link was lost can have it sent to its contact address again from the help page. No call is needed.
See the sample view → For C3PAO →