The MSPs for the Protection of Critical Infrastructure (MSP Collective) has announced the launch of a directory of External Service Providers (ESPs) certified under the Cybersecurity Maturity Model Certification (CMMC) Level 2 Assessment. This directory, available at MSPCollective.org, aims to support organizations seeking certification (OSCs) by connecting them with certified service providers to help meet National Institute of Standards and Technology (NIST) 800-171 requirements.

Executive Director Scott Edwards stated, “When the MSP Collective learned that Cyber AB would not be hosting a directory, we immediately began discussing how our organization could fulfill this need in our community. The mission of the MSP Collective is to inform the US Government and Critical Infrastructure industries on topics related to Managed Service Providers and Managed Security Service Providers.” He emphasized that creating the ESP Directory represents a proactive approach to address this gap.

Companies that have attained their CMMC L2 Assessment Certification can apply for inclusion in the directory through an online form. The application process includes validation of the information by the Certified Third-Party Assessment Organization (C3PAO) that granted the certification, ensuring the directory remains a trusted resource—all at no cost to the service providers. The directory will expand as additional companies achieve certification, with members of the MSP Collective distinguished by a torch logo adjacent to their names.

The MSP Collective's overarching goal is to enhance information dissemination regarding Managed Service Providers and Managed Security Service Providers, while contributing to the national security initiative of maintaining resilient and secure critical infrastructure.