Hello Jay Deena,
Thank you for reaching out, You're looking for the Azure Commercial Cloud NIST SP 800-171 Customer Responsibility Matrix (CRM). It is referenced in the Azure – Commercial – System Security Plan (2025) under Appendix J, but you're unable to locate the workbook on the Service Trust Portal (STP).
There are actually two distinct CRM artifacts, which is the source of the confusion:
Appendix J – CIS / Customer Responsibilities Matrix (referenced in the SSP)[NIST 800-53 (FedRAMP High baseline)]: Delivered inside the Azure Commercial FedRAMP authorization package > STP Audit Reports > FedRAMP Reports (access-controlled)
Standalone NIST SP 800-171 CRM[NIST 800-171]: STP > Azure Security and Compliance Blueprint section (last updated 23 Oct 2025)
Direct link to the standalone 800-171 CRM: https://servicetrust.microsoft.com/DocumentPage/278a71c1-0438-4330-abb3-ad475f982f1e
To access the document:
- Sign in to the Service Trust Portal (https://servicetrust.microsoft.com) using your organization's Azure AD (Entra ID) account — sign-in is required to download.
- Use the direct link above, or search for "NIST SP 800-171 Customer Responsibility Matrix."
- Alternatively, browse to the Azure Security and Compliance Blueprint grouping (not the FedRAMP SSP package).
- If you specifically need the Appendix J CIS/CRM (800-53), go to Audit Reports → FedRAMP Reports — note this requires the appropriate STP entitlement/NDA access.
- If the file still doesn't appear after sign-in, this is typically an STP access/entitlement issue rather than a missing document.
Reference:
Hope this helps, If you have any question, please do let us know, Thank you