ISO 27001 for managed service providers: scope, controls, proof

How UK MSPs certify to ISO 27001: what belongs in scope when you hold privileged access to client estates, the Annex A controls auditors focus on, and how CE+, ISO 27001 and SOC 2 fit together.

The short answer: ISO 27001 for managed service providers is the certification your clients' procurement teams treat as the baseline, because you hold privileged access into their tenants and your RMM tooling reaches hundreds of estates at once. Certifying proves that access, logging, incident response and supplier risk are managed under an audited system instead of tribal knowledge and one very good senior engineer. Most MSPs get audit-ready in around two to three months once evidence lives in one place rather than across ticket notes, shared drives and someone's laptop.

MSPs sit in an uncomfortable position. You are a small business by headcount and an enterprise by blast radius. A single compromised RMM console, jump host or shared admin credential does not affect one company, it affects every client that trusts you with domain admin. Attackers worked this out years ago, and so did the people writing supplier due-diligence questionnaires. UK buyers now ask for evidence before they ask for a quote, and public sector frameworks and insurers ask harder questions again. ISO 27001 is the answer that closes the fewest doors.

{{snapshot}}

ISO 27001 for MSPs at a glance

  • Your scope is other people's data. Certification has to cover the tooling and access paths that reach client estates, not just your own office network.
  • Privileged access is the audit centre of gravity. Annex A 8.2 and the access control clauses get more scrutiny for MSPs than for almost any other sector.
  • Cyber Essentials Plus is a floor, not a substitute. Many UK contracts require CE+ and ISO 27001, and they prove different things.
  • Offboarding runs on two clocks. Engineers leave you, clients leave you, and both have to strip access on a schedule you can evidence.
  • One control set can serve several frameworks. What you build for ISO 27001 carries most of the way into SOC 2 if you sell into the US.

{{/snapshot}}

Why your clients ask you for ISO 27001 before they get it themselves

Supply chain security stopped being a theoretical concern the moment a handful of high-profile intrusions arrived through trusted IT suppliers rather than the front door. The NCSC publishes guidance on supply chain security that pushes buyers to assess and monitor their suppliers rather than take assurances on trust. Your clients read it, or their auditors and insurers read it for them, and the questionnaire lands in your inbox.

What arrives is rarely a polite enquiry. It is forty pages asking how you segregate client environments, who can approve privileged access, how quickly you would tell them about a breach, and what happens to their backups if you go under. Answering that in prose, per client, per renewal, is a slow way to lose a delivery team. A certificate plus a controlled set of evidence answers most of it once.

Regulated clients raise the bar further. Financial services firms, healthcare providers and public sector buyers are all accountable for their suppliers, so they push their obligations down the chain into your contract. If you serve any of them, the question is not whether you will be assessed, only whether the assessment goes well.

What actually goes in scope when you hold the keys to everyone else's estate

The most common MSP mistake is scoping the ISMS around the office. Certifying "our corporate IT and head office" produces a certificate that a decent procurement analyst will reject in about ninety seconds, because it excludes the thing they care about: the service you sell.

Scope that stands up covers the delivery machinery. In practice that means:

  • Multi-tenant access paths into client tenants, hypervisors and firewalls, including delegated admin relationships and any standing global admin you have quietly accumulated.
  • RMM, PSA and monitoring platforms, plus the scripts and automations that run through them. These are code execution on client machines and auditors treat them that way.
  • Privileged access management and credential vaults, including how break-glass accounts are stored, approved and reviewed.
  • The service desk record, because ticket bodies and attachments hold client data whether or not anyone planned for that.
  • Backup and DR services you operate on clients' behalf, including immutability, restore testing and who can delete a backup set.
  • Subcontractors and vendor tooling, from offshore NOC partners to the one-person specialist you call for firewall migrations.

Offboarding deserves its own attention because it runs on two clocks. An engineer resigns and their access has to be pulled everywhere, across every client tenant and every tool, not just your own directory. A client leaves and your access has to be removed and proved removed, which is the point at which most MSPs discover they still hold admin in three former accounts. Auditors love that question. Answer it before they ask.

The Annex A controls auditors push hardest on for MSPs

ISO 27001:2022 has 93 Annex A controls across four themes, and every organisation justifies inclusion or exclusion in its Statement of Applicability. Sector shapes emphasis, and for MSPs the emphasis is heavily on access and evidence of what was done with it.

Expect real scrutiny on 8.2 privileged access rights, which is where the multi-tenant model either holds up or falls apart. Named accounts rather than shared ones, time-bound elevation, approval that is recorded somewhere other than a Teams message. Alongside that, 5.15, 5.16 and 5.18 cover access control, identity and access rights, and they are the controls that catch dormant accounts from a client you offboarded two years ago.

Logging and monitoring under 8.15 and 8.16 matter more for MSPs than most, because you need to show activity across client estates as well as your own, and show that someone actually looks at it. Supplier relationships under 5.19 to 5.22 apply to you twice over: you are a supplier being assessed, and you have your own suppliers to manage. Incident management under 5.24 to 5.27 has an MSP twist, which is client communication. Your incident plan needs a defined path for telling affected clients, within contractual and UK GDPR timeframes, and you should have tested it.

Then 8.13 backup and 5.30 ICT readiness for business continuity. If you sell backup and DR as a service, these controls are your product being audited. Restore testing that exists as a diary reminder rather than a record is a finding waiting to happen. Underneath all of it sits the risk assessment that justifies your choices, which is why a centralised risk register that auto-populates from your assets beats a spreadsheet that was accurate last March.

Cyber Essentials Plus, ISO 27001 or SOC 2: which one do you actually need?

Most UK MSPs end up holding more than one, and the sequencing matters more than the choice. Cyber Essentials Plus is fast, cheap and technically verified, and it is mandatory for some public sector work. It does not describe how you manage risk, suppliers or incidents, which is what enterprise buyers want to see. Our comparison of Cyber Essentials and ISO 27001 goes deeper, but the short version is below.

FrameworkWho asks for itWhat it provesEffort
Cyber Essentials PlusUK public sector, MOD supply chain, smaller commercial clients, some insurersFive technical controls verified by hands-on testing at a point in timeWeeks; annual reassessment
ISO 27001UK and EU enterprise, regulated clients, framework buyers, larger renewalsA managed system covering risk, access, suppliers, incidents and continuityTypically two to three months to audit-ready; three-year cycle with surveillance
SOC 2US buyers, US-headquartered clients and their procurement teamsAuditor opinion on control design and, for Type II, operating effectiveness over a periodSimilar build, plus an observation window for Type II

If you sell into the US as well as the UK, build once. The access reviews, logging evidence and vendor assessments that satisfy Annex A carry most of the way into the Trust Services Criteria, which is the argument set out on our page on SOC 2 compliance for managed service providers. Running two separate programmes because two different sales conversations demanded them is how compliance eats a quarter.

How to certify without stalling delivery

The reason MSPs stall is not the standard. It is that the people who would run the ISMS are the same people running major incidents on a Tuesday afternoon. Anything that depends on continuous manual effort loses to billable work, every time.

Three things change the maths. Policy and procedure templates already mapped to controls remove the blank-page problem. Evidence collection that pulls from your systems on a schedule removes the pre-audit scramble, which is where the real cost hides. And a single control set feeding several frameworks means the second certification costs a fraction of the first.

Net-Defence, a UK cyber-resilience and IT MSP, moved off spreadsheets onto Hicomply and reported compliance work running around 50% faster, with their MD saying it "far exceeded what we originally thought we would get from it". Advantex, an IT and communications integrator that already held ISO 9001 and Cyber Essentials Plus, added ISO 27001 and cut audit preparation time by 30 to 40%. Both were already competent at security. What they bought back was the week before the audit.

Turning your own certificate into a service line

The certificate is a sales asset, and MSPs are unusually well placed to use it twice. First on your own website and in your own bids, where a Security Report you can share with a prospect answers the questionnaire before it is sent. Second in your client conversations, because the SMEs and consultancies you support are being asked for the same evidence you were.

Plenty of MSPs now run compliance as a managed service alongside security operations. If that appeals, our partner programme exists for exactly that, and the sector pages on ISO 27001 for small businesses and ISO 27001 for consulting firms are a reasonable starting point for the conversations you will have. If you have started reselling or building AI tooling, AI risk management under ISO 42001 is the next question your regulated clients will raise, and it is better to have an answer ready.

{{snapshot}}

Hicomply's take

We have watched too many MSPs scope their ISMS around head office because it was the easiest thing to certify, then spend the following year explaining to procurement why the certificate does not cover the service. Scope the delivery platform from the start, even though it is harder. The other pattern we see: privileged access that is technically fine but evidentially invisible, because approvals happen in chat. Move approvals somewhere they leave a record, get access reviews on a calendar, and the audit stops being an archaeology exercise. The MSPs who certify quickly are rarely the most secure. They are the ones who can prove it.

{{/snapshot}}

Get your MSP audit-ready without pulling engineers off client work

You already run change control, monitoring and access reviews for other people. ISO 27001 mostly asks you to do it for yourself, write it down once, and keep the record current. The gap is almost never capability. It is the administrative weight of proving it across dozens of client environments while the service desk keeps ringing.

Start with the free ISO 27001 readiness assessment to see where your controls already stand, then book a demo and we will walk through what an MSP scope looks like in practice, including how privileged access, logging and supplier evidence get collected without a fortnight of chasing.

Ready to Take Control of Your Privacy Compliance?

Hicomply’s platform provides an all-in-one solution to streamline, automate, and centralise your compliance activities, ensuring complete control and efficiency.

Book a demo
Last updated
August 17, 2026
Category
ISO 27001 by Industry
Topics
No items found.
Lucy Murphy
Head of Customer Success

Lucy works closely with customers to help them get the most out of the Hicomply platform, from onboarding to audit success. She brings a user-focused mindset to everything she does, making her well-placed to write about day-to-day challenges, shortcuts, and success strategies. Her content is grounded in what real InfoSec and compliance teams need to know — and how to get there faster.Expect helpful walkthroughs, product tips, and practical insights.

Popular ISO 27001 for Managed Service Providers queries, answered!

Do managed service providers need ISO 27001?

There is no legal requirement, but in practice UK clients make it one. Because MSPs hold privileged access into client tenants, buyers, insurers and public sector frameworks increasingly ask for certified assurance before signing. If you sell to enterprise or regulated organisations, ISO 27001 is usually the difference between being shortlisted and being screened out at the questionnaire stage.

What should an MSP include in its ISO 27001 scope?

The service, not just the office. Include the RMM and PSA platforms, delegated admin and multi-tenant access paths, credential vaults and break-glass accounts, the service desk record, any backup or DR services you operate for clients, and subcontractors. A scope limited to corporate IT will not satisfy procurement teams assessing you as a supplier.

Is Cyber Essentials Plus enough instead of ISO 27001?

For some contracts, yes. Cyber Essentials Plus verifies five technical controls through hands-on testing and is mandatory for parts of UK public sector work. It says nothing about how you manage risk, suppliers, incidents or continuity. Most MSPs hold Cyber Essentials Plus as a floor and add ISO 27001 for enterprise and regulated buyers.

How long does ISO 27001 certification take for an MSP?

Typically two to three months to reach audit-ready if evidence is centralised and policies come from templates already mapped to controls, then a Stage 1 and Stage 2 audit with your certification body. Timelines stretch when access records, review logs and supplier assessments have to be reconstructed from tickets and shared drives before the auditor arrives.

Can we use ISO 27001 to win work and to help our clients certify?

Yes, and MSPs are well placed to do both. Your own certificate answers supplier questionnaires and supports bids. Many MSPs then run compliance as a managed service for the SMEs and consultancies they support, using one platform to hold each client's ISMS documents, policies and evidence in a separate, auditable repository.

Unlock Your Path to ISO 27001 Success

Download our Ultimate ISO 27001 Compliance Checklist for clear, step-by-step guidance to fast-track your certification.

End to end ISO 27001 compliance documentation

Your hub for the fundamentals of ISO 27001 compliance, curated best practices, and resources for GRC professionals.

ISO 27001 Overview

Achieve ISO 27001 Certification

ISO 27001 is the globally recognised standard for building a structured Information Security Management System (ISMS) that protects the confidentiality, integrity and availability of information. This article explains what ISO 27001 is, how it works, the core principles behind it, and what organisations must do to achieve certification. You’ll learn the standard’s structure, its key requirements, how the certification process unfolds, and the practical steps needed to implement an ISMS that is both compliant and effective.

Learn more about Achieve ISO 27001 Certification

Benefits Of ISO 27001 For Businesses

ISO 27001 certification is one of the most credible ways for businesses to prove they protect sensitive information with structure, consistency, and internationally recognised best practice. This guide explains what ISO 27001 certification is, why companies pursue it, the core business benefits, the costs involved, and how organisations of any size can achieve and maintain certification. Whether you're preparing for your first audit or strengthening your security posture, this article gives you the clarity, detail, and practical steps to move forward with confidence.

Learn more about Benefits Of ISO 27001 For Businesses

History And Evolution Of ISO 27001

ISO 27001 is now recognised as the world’s leading standard for managing information security, but its journey spans decades of technological change, emerging cyber threats, and global collaboration. This article traces the origins of ISO 27001, from its earliest foundations to the modern 2022 revision. You’ll learn how the framework developed, why it became globally adopted, how ISO 27002 fits into the picture, and how ISO standards evolved more broadly over time.

Learn more about History And Evolution Of ISO 27001
ISO 27001:2022 Requirements

Actions To Address Risks And Opportunities | Clause 6.1

Clause 6.1 of ISO 27001 defines how organisations must identify, assess, and treat information security risks — and how they must uncover opportunities to strengthen their Information Security Management System (ISMS). This clause acts as the engine of the ISO framework: it drives risk-based thinking, aligns controls to real-world threats, and ensures continual improvement. In this guide, we break down Clause 6.1 line by line, explain its relationship with Annex A, show you what documentation is required, and provide examples and best practices to help you implement it correctly and confidently.

Learn more about Actions To Address Risks And Opportunities | Clause 6.1

ISO 27001 Awareness | Clause 7.3

In this article, we explore everything you need to know about ISO 27001 Clause 7.3—its purpose, what the standard requires, how awareness strengthens your ISMS, and how to build a practical, auditor-ready awareness program that supports continuous security improvement.

Learn more about ISO 27001 Awareness | Clause 7.3

ISO 27001 Communication | Clause 7.4

In this guide, we break down exactly what ISO 27001 Clause 7.4 requires, why structured communication is essential to an effective ISMS, and how organisations can build a clear, compliant communication process supported by practical, real-world examples.

Learn more about ISO 27001 Communication | Clause 7.4

Internal Audit | Clause 9.2

Understanding the intricacies of ISO 27001:2022 is crucial for organisations aiming to enhance their information security management systems. Clause 9.2, which focuses on internal audits, plays a pivotal role in this context.

Learn more about Internal Audit | Clause 9.2
Information Security Management System (ISMS)

ISO 27001 ISMS Audit And Review Process

The audit and review process is one of the most important pillars of ISO 27001. It ensures your Information Security Management System (ISMS) is working as intended, risks are managed effectively, controls are operating correctly, and continual improvement is actively taking place. This guide explains every component of the ISO 27001 audit lifecycle — internal audits, external audits, certification audits, surveillance audits, and management reviews — and shows you how to prepare, what evidence auditors expect, and how to maintain long-term compliance.

Learn more about ISO 27001 ISMS Audit And Review Process

ISO 27001 ISMS Continuous Improvement Cycle

In this end-to-end guide, you’ll learn how continual improvement works in ISO 27001, why it’s essential for long-term security maturity, how the PDCA cycle operates inside an ISMS, and what processes, documentation, and actions are required to maintain compliance year after year.

Learn more about ISO 27001 ISMS Continuous Improvement Cycle
Annex A Controls — Organizational

Acceptable Use Of Assets | Annex A 5.10

Information security policies serve as the foundation of any robust cybersecurity program. Without clearly defined rules for acceptable use of information assets, organizations face increased vulnerability to data breaches, compliance violations, and operational disruptions. Control 5.10 of ISO 27001:2022 specifically addresses this critical aspect of information security management, requiring organizations to establish formal guidelines for how information and associated assets should be handled.

Learn more about Acceptable Use Of Assets | Annex A 5.10

Access Control Policies | Annex A 5.14

Information rarely stays still. Every organisation transfers data daily—between teams, systems, partners, customers, cloud platforms, and suppliers. Emails are sent, files are shared, storage media is moved, meetings are held, and conversations take place across calls and video conferences. Each transfer represents a moment of heightened risk.

Learn more about Access Control Policies | Annex A 5.14

Access Rights Management | Annex A 5.16

ISO 27001 Annex A 5.16 focuses on how organisations manage access rights by governing the full lifecycle of identities. This control ensures that only authorised users, systems, and services can access information assets, and that access is removed when no longer required.

Learn more about Access Rights Management | Annex A 5.16
Annex A Controls — People

Confidentiality And NDA Management | Annex A 6.6

Confidentiality obligations sit at the very core of information security. Without enforceable confidentiality controls, even the strongest technical safeguards can be rendered ineffective by human behaviour, contractual gaps, or unclear responsibilities. ISO 27001:2022 Annex A 6.6 formalises this reality by requiring organisations to define, implement, communicate, and enforce confidentiality and non-disclosure obligations across employees, contractors, suppliers, and other relevant parties.

Learn more about Confidentiality And NDA Management | Annex A 6.6

Disciplinary Process And Enforcement | Annex A 6.4

Establishing a fair disciplinary process is essential for organizations that want to effectively manage security violations while maintaining employee trust. When security breaches occur, organizations often struggle to respond consistently, which can lead to resentment, legal complications, or ineffective deterrence. Consequently, ISO 27001 includes specific requirements under Annex A 6.4 to ensure disciplinary processes are both fair and effective.

Learn more about Disciplinary Process And Enforcement | Annex A 6.4

Employee Screening And Background Checks | Annex A 6.1

In this guide, we explain everything organisations need to know about ISO 27001:2022 Annex A 6.1 — Employee Screening and Background Checks. You’ll learn what the control requires, why it exists, how auditors assess compliance, what evidence is expected, and how to design a screening process that is legally compliant, proportionate, and effective across different roles and risk levels.

Learn more about Employee Screening And Background Checks | Annex A 6.1
Annex A Controls — Physical

Access Control To Premises | Annex A 7.2

Physical security remains one of the most underestimated components of information security. While organisations invest heavily in cybersecurity tools, a single uncontrolled door, shared workspace, or unlogged visitor can undermine even the most mature digital controls. ISO 27001 Annex A 7.2 exists to address this exact risk by requiring organisations to establish and maintain effective access control to premises where information and information-processing facilities are located.

Learn more about Access Control To Premises | Annex A 7.2

Cabling And Electrical Security | Annex A 7.12

Modern technologies rely heavily on fiber, network, and power cables to function correctly. When we focus on ISO cyber security, we often overlook these critical components' physical vulnerabilities. Power and information cables face risks of damage and interception. Cyber criminals who gain access to fiber cables can disrupt all network traffic with simple techniques like 'bending the fiber.' This makes data and information unavailable.

Learn more about Cabling And Electrical Security | Annex A 7.12
ISO 27001 by Industry

ISO 27001 for Small Businesses

A practical guide to ISO 27001 for small businesses in the UK: how to scope the ISMS small, what certification really costs, how long it takes, the four mistakes small firms make, and when Cyber Essentials is enough instead.

Learn more about ISO 27001 for Small Businesses

ISO 27001 for Healthcare Companies

How UK health-tech firms, care providers and NHS suppliers use ISO 27001 to answer procurement security questions, and how it sits alongside the NHS DSPT, DTAC and Cyber Essentials Plus without duplicating the work.

Learn more about ISO 27001 for Healthcare Companies

ISO 27001 for Consulting Firms

How consultancies get ISO 27001 certified when their assets are people, laptops and client system access. Scoping by service line, the people and supplier controls auditors sample, and whether you need a consultant.

Learn more about ISO 27001 for Consulting Firms

ISO 27001 for Managed Service Providers

How UK MSPs certify to ISO 27001: what belongs in scope when you hold privileged access to client estates, the Annex A controls auditors focus on, and how CE+, ISO 27001 and SOC 2 fit together.

Learn more about ISO 27001 for Managed Service Providers

Your ISO 27001 Compliance Newsletter

Stay ahead with the latest expert insights, news, and updates on compliance.
Decorative