Customer Responsibility Matrix
A Customer Responsibility Matrix is a document that spells out which security controls a cloud service provider handles and which ones the customer using the service must handle themselves. It exists because in cloud environments the work of protecting a system is split between the provider and the customer, and each side needs to know exactly what they are accountable for. Without a clear division, controls can fall through the gaps because each party assumes the other is covering them.
A Customer Responsibility Matrix is a control-by-control mapping that allocates responsibility for implementing, operating, and maintaining security controls between a cloud service provider (CSP) and the customer (consuming organization) in a shared-responsibility model. It typically identifies each applicable control and designates it as provider-responsible, customer-responsible, or shared/hybrid, and often describes the specific customer-implemented (or customer-configured) portion the consuming organization must satisfy within its own boundary. In an authorization context, the CRM helps the customer determine which inherited controls are covered by the provider's authorization and which controls remain the customer's obligation to implement and assess for its own system. Practitioners should note that specific control identifiers, baselines, and the precise scope of allocation depend on the applicable framework, revision, and the individual service offering; the actual contents, format, and binding effect of a given CRM should be verified against the provider's documentation and the governing authorization or contractual requirements. A CRM allocates responsibility but does not by itself demonstrate that customer-responsible controls have been implemented or assessed; the customer must still implement and validate those controls, and reliance on a CRM does not transfer accountability for controls designated as the customer's.
Why it matters
In a shared-responsibility model, security failures most often occur not in the controls one party actively manages, but in the ambiguous space between provider and customer. A Customer Responsibility Matrix exists to eliminate that ambiguity by documenting, control by control, who is accountable for what. When this division is unclear or unread, controls can fall through the gaps because each party assumes the other is covering them, a customer may assume the cloud provider is encrypting data or managing access logs when, in fact, that configuration is the customer's obligation. The CRM is the reference document that prevents these assumptions from becoming exposures.
A critical point that practitioners frequently misunderstand is that a CRM allocates responsibility but does not demonstrate compliance. The existence of a matrix stating that a control is customer-responsible does nothing to prove that the customer has actually implemented, configured, or assessed that control. Similarly, inheriting a control from a provider's authorization does not relieve the customer of the obligation to confirm the inheritance is valid for its own system boundary and use case. Reliance on a CRM does not transfer accountability for controls designated as the customer's; accountability for a customer-responsible control remains with the customer regardless of what the matrix says.
For organizations operating in authorization contexts, whether pursuing an Authority to Operate for a federal system or documenting a security posture for CUI, the CRM is generally central to distinguishing inherited controls from those that must be independently implemented and assessed. Because the specific control identifiers, baselines, and scope of allocation depend on the applicable framework, revision, and the individual service offering, the CRM should always be read against the current provider documentation and the governing authorization or contractual requirements rather than treated as a static or interchangeable artifact.
Who it's relevant to
Inside CRM
Common questions
Answers to the questions practitioners most commonly ask about CRM.