Why MSPs certify
Managed service providers hold the keys to their clients’ environments, which makes them a target and a supply chain risk. Clients, insurers, and regulators have noticed. ISO 27001 certification is now a routine requirement in MSP contracts and tenders, and a practical way to show that privileged access, remote management, and change control are governed rather than improvised.
What the audit focuses on
An MSP audit turns on how you keep client environments separate, how you control your own staff’s access to them, and how you would know if either had been compromised. We pay particular attention to:
- Remote monitoring and management tooling. Hardening, access control, and monitoring of the platforms that give you access to clients, which are themselves prime targets.
- Privileged access. Named accounts, MFA, approval and time-limiting of elevated access, and logging that ties actions to people.
- Segregation. Technical and procedural separation between client environments and between clients and your own corporate systems.
- Change and configuration. How changes to client systems are requested, approved, tested, and recorded, and how standard configurations are maintained.
- Detection and response. Monitoring coverage across your own and client environments, alert handling, and how incidents affecting clients are communicated.
- Continuity. Your ability to keep serving clients if your own systems, offices, or key suppliers are unavailable.
Evidence we typically examine
- RMM and PSA platform configuration, roles, and audit logs
- Privileged access requests and reviews for a sample of clients
- Change tickets from request to closure, including emergency changes
- Alert-to-ticket traces from the security monitoring platform
- Onboarding and offboarding of engineers, including credential rotation
- Supplier reviews for the software and services your operation depends on
Scope
MSP scopes usually cover service delivery, service desk, security operations if offered, and corporate functions, across all offices. Multi-site providers can be certified under one certificate with sites sampled across the cycle.