• Skip to primary navigation
  • Skip to main content
  • Skip to footer
ControlCase No Tag LOGO md

ControlCase

IT Certifications, Continuous Compliance and Cybersecurity Services Provider

  • Company
    • About Us
    • Careers
    • Locations
    • Team
  • Industries
    • Business Process Outsourcing
    • Cloud Service Providers
    • Retail
    • Telecom | Entertainment
    • Managed Service Providers
  • Certifications
    • PCI DSS Certification
    • CSA STAR Certification
    • GDPR Assessment
    • HIPAA Assessment
    • HITRUST® Certification
    • ISO 27001 Certification
    • FedRAMP 3PAO Services and NIST 800-53
    • CMMC Certification
    • MARS-E Assessment
    • PCI SSF
    • P2PE Certification
    • SOC2 Report
  • Solutions
    • Continuous Compliance Solution
    • One Audit
    • Card Data Discovery Software
    • Data Security Rating
  • Testing
    • Application Reviews
    • Application Security Training
    • Code Reviews
    • Card Data Discovery
    • External Vulnerability Scans
    • Firewall Security Reviews
    • Internal Vulnerability Scans
    • Log Monitoring
    • Penetration Testing
  • Resources
    • Events
    • News
    • Webinars
    • Courses
    • Blog
    • Tools
    • Become a Partner
  • Contact Us
  • English

Kaseya Publishes Customer Responsibility Matrices to Help Partners Meet Department of Defense Cybersecurity Requirements

You are here: Home / News / Kaseya Publishes Customer Responsibility Matrices to Help Partners Meet Department of Defense Cybersecurity Requirements

Miami, FL, August 19, 2025 – Kaseya, the leading global provider of AI-powered IT management and cybersecurity software, announced today that it has rolled out customer responsibility matrices (CRMs) for a set of critical products managed service providers (MSPs) use to ensure their customers meet Cybersecurity Maturity Model Certification (CMMC) requirements. A CRM document identifies the appropriate individual for implementing, managing and maintaining cybersecurity controls to prevent gaps in compliance.

“As a Lead Certified CMMC Assessor (CCA), the availability of a well-developed Customer Responsibility Matrix for cloud-based Security Protection Assets (SPAs)—like those provided by Kaseya—greatly streamlines the assessment process,” said Brian Hubbard, President, Evolved Cyber, LLC and Lead CCA. “When an OSC includes a CRM that clearly delineates responsibilities between the organization and the External Service Provider (ESP), it allows me to quickly verify which party is accountable for each relevant security requirement and whether appropriate evidence has been provided.”

Software vendors required to meet CMMC are mandated to create CRMs, and MSPs working with the Department of Defense (DoD) and other agencies, must demonstrate cybersecurity capabilities to safeguard sensitive information. As organizations of all sizes demand support to comply with evolving compliance frameworks, MSPs are increasingly adopting standardized security protocols, conducting regular audits, and implementing advanced monitoring tools to ensure adherence to federal cybersecurity requirements.

“In order to provide best-in-class support to our partners, Kaseya has begun publishing CMMC Customer Responsibility Matrices product by product,” said Jon DePerro, Vice President, FedRAMP and Compliance Solutions at Kaseya. “We understand the complexities around CMMC, and want to ensure our customers have the tools, and capabilities, necessary to meet compliance standards, not only for their businesses, but their customers too.”

Kaseya employed ControlCase, a leading CMMC C3PAO to document and validate the customer responsibility matrices. The first group of matrices released includes Datto RMM, VSAX, IT Glue, vPenTest, Vulscan, Network Detective Pro, and Compliance Manager GRC, with more planned to be published before the end of the year.

“Kaseya is taking ownership and is at the forefront of developing this body of work for the MSP community,” said Joshua Hoffman, Chief Revenue Officer, ControlCase. “This allows MSPs to show their value, and partner with their customers, and ensure compliance standards are being met.”

For more information, go here.


  • Facebook
  • LinkedIn
  • Twitter
  • YouTube

Footer

Connect

Corporate Headquarters
3975 FAIR RIDGE DR STE T25S-D
FAIRFAX, VA 22033

Send us a message

Call Us

Search

About Us

ControlCase is a United States based company, headquartered in Fairfax, Virginia with locations in North America, Europe, Latin America, Asia/Pacific, Australia and the Middle East to serve our clients globally.

Quick Links

  • Company
  • Careers
  • Locations
  • Covid-19 Notice

Certifications, Assessments and Reports

  • PCI DSS Certification
  • CSA STAR Certification
  • GDPR Assessment
  • HIPAA Assessment
  • HITRUST® Certification
  • ISO 27001 Certification
  • FedRAMP and 3PAO Services
  • MARS-E Assessment
  • PCI SSF
  • P2PE Certification
  • SOC2 Report

© ControlCase LLC 2025 | Privacy Policy | Impartiality Statement | Legal Notices

  • English
Manage your privacy

We use cookies to enhance your experience and show relevant ads. Consent allows us to process data like browsing behavior. Without consent, some features may not work. If you log in, all cookies are accepted by default. Learn more in our Privacy Policy & Cookies Policy.

Strictly Necessary Cookies Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Functional Cookies
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics Cookies
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing Cookies
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
Manage options
{title} {title} {title}