The short answer: ISO 27001 for managed service providers is the certification your clients' procurement teams treat as the baseline, because you hold privileged access into their tenants and your RMM tooling reaches hundreds of estates at once. Certifying proves that access, logging, incident response and supplier risk are managed under an audited system instead of tribal knowledge and one very good senior engineer. Most MSPs get audit-ready in around two to three months once evidence lives in one place rather than across ticket notes, shared drives and someone's laptop.
MSPs sit in an uncomfortable position. You are a small business by headcount and an enterprise by blast radius. A single compromised RMM console, jump host or shared admin credential does not affect one company, it affects every client that trusts you with domain admin. Attackers worked this out years ago, and so did the people writing supplier due-diligence questionnaires. UK buyers now ask for evidence before they ask for a quote, and public sector frameworks and insurers ask harder questions again. ISO 27001 is the answer that closes the fewest doors.
{{snapshot}}
ISO 27001 for MSPs at a glance
- Your scope is other people's data. Certification has to cover the tooling and access paths that reach client estates, not just your own office network.
- Privileged access is the audit centre of gravity. Annex A 8.2 and the access control clauses get more scrutiny for MSPs than for almost any other sector.
- Cyber Essentials Plus is a floor, not a substitute. Many UK contracts require CE+ and ISO 27001, and they prove different things.
- Offboarding runs on two clocks. Engineers leave you, clients leave you, and both have to strip access on a schedule you can evidence.
- One control set can serve several frameworks. What you build for ISO 27001 carries most of the way into SOC 2 if you sell into the US.
{{/snapshot}}
Why your clients ask you for ISO 27001 before they get it themselves
Supply chain security stopped being a theoretical concern the moment a handful of high-profile intrusions arrived through trusted IT suppliers rather than the front door. The NCSC publishes guidance on supply chain security that pushes buyers to assess and monitor their suppliers rather than take assurances on trust. Your clients read it, or their auditors and insurers read it for them, and the questionnaire lands in your inbox.
What arrives is rarely a polite enquiry. It is forty pages asking how you segregate client environments, who can approve privileged access, how quickly you would tell them about a breach, and what happens to their backups if you go under. Answering that in prose, per client, per renewal, is a slow way to lose a delivery team. A certificate plus a controlled set of evidence answers most of it once.
Regulated clients raise the bar further. Financial services firms, healthcare providers and public sector buyers are all accountable for their suppliers, so they push their obligations down the chain into your contract. If you serve any of them, the question is not whether you will be assessed, only whether the assessment goes well.
What actually goes in scope when you hold the keys to everyone else's estate
The most common MSP mistake is scoping the ISMS around the office. Certifying "our corporate IT and head office" produces a certificate that a decent procurement analyst will reject in about ninety seconds, because it excludes the thing they care about: the service you sell.
Scope that stands up covers the delivery machinery. In practice that means:
- Multi-tenant access paths into client tenants, hypervisors and firewalls, including delegated admin relationships and any standing global admin you have quietly accumulated.
- RMM, PSA and monitoring platforms, plus the scripts and automations that run through them. These are code execution on client machines and auditors treat them that way.
- Privileged access management and credential vaults, including how break-glass accounts are stored, approved and reviewed.
- The service desk record, because ticket bodies and attachments hold client data whether or not anyone planned for that.
- Backup and DR services you operate on clients' behalf, including immutability, restore testing and who can delete a backup set.
- Subcontractors and vendor tooling, from offshore NOC partners to the one-person specialist you call for firewall migrations.
Offboarding deserves its own attention because it runs on two clocks. An engineer resigns and their access has to be pulled everywhere, across every client tenant and every tool, not just your own directory. A client leaves and your access has to be removed and proved removed, which is the point at which most MSPs discover they still hold admin in three former accounts. Auditors love that question. Answer it before they ask.
The Annex A controls auditors push hardest on for MSPs
ISO 27001:2022 has 93 Annex A controls across four themes, and every organisation justifies inclusion or exclusion in its Statement of Applicability. Sector shapes emphasis, and for MSPs the emphasis is heavily on access and evidence of what was done with it.
Expect real scrutiny on 8.2 privileged access rights, which is where the multi-tenant model either holds up or falls apart. Named accounts rather than shared ones, time-bound elevation, approval that is recorded somewhere other than a Teams message. Alongside that, 5.15, 5.16 and 5.18 cover access control, identity and access rights, and they are the controls that catch dormant accounts from a client you offboarded two years ago.
Logging and monitoring under 8.15 and 8.16 matter more for MSPs than most, because you need to show activity across client estates as well as your own, and show that someone actually looks at it. Supplier relationships under 5.19 to 5.22 apply to you twice over: you are a supplier being assessed, and you have your own suppliers to manage. Incident management under 5.24 to 5.27 has an MSP twist, which is client communication. Your incident plan needs a defined path for telling affected clients, within contractual and UK GDPR timeframes, and you should have tested it.
Then 8.13 backup and 5.30 ICT readiness for business continuity. If you sell backup and DR as a service, these controls are your product being audited. Restore testing that exists as a diary reminder rather than a record is a finding waiting to happen. Underneath all of it sits the risk assessment that justifies your choices, which is why a centralised risk register that auto-populates from your assets beats a spreadsheet that was accurate last March.
Cyber Essentials Plus, ISO 27001 or SOC 2: which one do you actually need?
Most UK MSPs end up holding more than one, and the sequencing matters more than the choice. Cyber Essentials Plus is fast, cheap and technically verified, and it is mandatory for some public sector work. It does not describe how you manage risk, suppliers or incidents, which is what enterprise buyers want to see. Our comparison of Cyber Essentials and ISO 27001 goes deeper, but the short version is below.
| Framework | Who asks for it | What it proves | Effort |
|---|---|---|---|
| Cyber Essentials Plus | UK public sector, MOD supply chain, smaller commercial clients, some insurers | Five technical controls verified by hands-on testing at a point in time | Weeks; annual reassessment |
| ISO 27001 | UK and EU enterprise, regulated clients, framework buyers, larger renewals | A managed system covering risk, access, suppliers, incidents and continuity | Typically two to three months to audit-ready; three-year cycle with surveillance |
| SOC 2 | US buyers, US-headquartered clients and their procurement teams | Auditor opinion on control design and, for Type II, operating effectiveness over a period | Similar build, plus an observation window for Type II |
If you sell into the US as well as the UK, build once. The access reviews, logging evidence and vendor assessments that satisfy Annex A carry most of the way into the Trust Services Criteria, which is the argument set out on our page on SOC 2 compliance for managed service providers. Running two separate programmes because two different sales conversations demanded them is how compliance eats a quarter.
How to certify without stalling delivery
The reason MSPs stall is not the standard. It is that the people who would run the ISMS are the same people running major incidents on a Tuesday afternoon. Anything that depends on continuous manual effort loses to billable work, every time.
Three things change the maths. Policy and procedure templates already mapped to controls remove the blank-page problem. Evidence collection that pulls from your systems on a schedule removes the pre-audit scramble, which is where the real cost hides. And a single control set feeding several frameworks means the second certification costs a fraction of the first.
Net-Defence, a UK cyber-resilience and IT MSP, moved off spreadsheets onto Hicomply and reported compliance work running around 50% faster, with their MD saying it "far exceeded what we originally thought we would get from it". Advantex, an IT and communications integrator that already held ISO 9001 and Cyber Essentials Plus, added ISO 27001 and cut audit preparation time by 30 to 40%. Both were already competent at security. What they bought back was the week before the audit.
Turning your own certificate into a service line
The certificate is a sales asset, and MSPs are unusually well placed to use it twice. First on your own website and in your own bids, where a Security Report you can share with a prospect answers the questionnaire before it is sent. Second in your client conversations, because the SMEs and consultancies you support are being asked for the same evidence you were.
Plenty of MSPs now run compliance as a managed service alongside security operations. If that appeals, our partner programme exists for exactly that, and the sector pages on ISO 27001 for small businesses and ISO 27001 for consulting firms are a reasonable starting point for the conversations you will have. If you have started reselling or building AI tooling, AI risk management under ISO 42001 is the next question your regulated clients will raise, and it is better to have an answer ready.
{{snapshot}}
Hicomply's take
We have watched too many MSPs scope their ISMS around head office because it was the easiest thing to certify, then spend the following year explaining to procurement why the certificate does not cover the service. Scope the delivery platform from the start, even though it is harder. The other pattern we see: privileged access that is technically fine but evidentially invisible, because approvals happen in chat. Move approvals somewhere they leave a record, get access reviews on a calendar, and the audit stops being an archaeology exercise. The MSPs who certify quickly are rarely the most secure. They are the ones who can prove it.
{{/snapshot}}
Get your MSP audit-ready without pulling engineers off client work
You already run change control, monitoring and access reviews for other people. ISO 27001 mostly asks you to do it for yourself, write it down once, and keep the record current. The gap is almost never capability. It is the administrative weight of proving it across dozens of client environments while the service desk keeps ringing.
Start with the free ISO 27001 readiness assessment to see where your controls already stand, then book a demo and we will walk through what an MSP scope looks like in practice, including how privileged access, logging and supplier evidence get collected without a fortnight of chasing.


.avif)























