Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

SOC 2 · SaaS & technology

SOC 2 Readiness for MSPs & IT Consultancies

SOC 2 readiness for an MSP or IT consultancy scopes the audit around service delivery itself, the RMM console, GDAP roles and remote-access tools that reach every client, not a single product. The trigger is usually a client saying they won't renew without a report, a plan to win larger accounts by leading with the audit instead of answering a questionnaire every time, or a decision to get ahead of what SOC 2 as sales collateral now requires. We scope the system, close the gaps, and prepare the firm for the auditor.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

What SOC 2 scrutiny covers when the "system" is managed services delivery

For an MSP, the audited system isn't one product. It's the combination of tools and access the firm uses to deliver service to every client at once.

The RMM and PSA platforms

How access to ConnectWise, Kaseya, NinjaOne or similar platforms is controlled, logged and reviewed, since these tools are effectively the production environment being audited.

GDAP and CSP tenant access

Which technicians hold delegated roles into which client tenants, how those roles are granted and revoked, and whether that process is evidenced consistently enough to survive testing.

Remote-access session controls

ScreenConnect, Splashtop or TeamViewer configuration, session logging and authentication, reviewed as core infrastructure rather than a support convenience.

Backup and business continuity

Veeam, Cove or Datto backup jobs and the firm's own continuity planning, since availability criteria treat an MSP's uptime as directly tied to every client's own operations.

Change management across the technician team

How configuration changes to client systems are requested, approved and logged, given that a single unreviewed change can touch dozens of environments at once.

Regulatory map

Why SOC 2 has become table stakes for winning MSP business

No regulator requires SOC 2 of an MSP. Clients increasingly do, because it replaces trusting the sales pitch.

The AICPA Trust Services Criteria

SOC 2 is an attestation against the AICPA's 2017 criteria, revised 2022, issued by a licensed CPA firm, the actual framework the firm's controls get measured against, not a marketing checklist.

Primary source →

Clients tired of custom questionnaires

A current SOC 2 report answers much of what a SIG or CAIQ questionnaire is really asking, which is why clients increasingly ask for the report first and reserve the full questionnaire for what the report doesn't cover.

Primary source →

OSFI B-10 for bank and insurer clients

A federally regulated client's third-party risk guideline expects ongoing oversight and incident notification, and a current SOC 2 report goes a long way toward satisfying that expectation without a bespoke audit.

Primary source →

PIPEDA's safeguards duty sitting underneath

The security criterion overlaps with the safeguards PIPEDA already requires for client personal information moving through the firm's systems, so readiness work discharges a statutory duty at the same time it produces audit evidence.

Read our guide →

What goes wrong

What SOC 2 preparation forces an MSP to find before an auditor does

Readiness surfaces the exact weaknesses that produced this sector's defining incidents, before a report ships with the firm's name on it.

  • RMM access without MFA or logging

    The 2024 Snowflake-linked campaign ran on stolen credentials against accounts without multi-factor authentication, precisely the access-control gap a SOC 2 gap review is built to catch on RMM and PSA logins before it reaches production.

    Source →

  • A remote-access tool nobody had tested

    CVE-2024-1709 turned an unpatched ScreenConnect instance into a mass-exploitation event within days, and readiness work checks patch cadence on exactly this class of tool before an auditor asks about it.

    Source →

  • GDAP roles nobody was reviewing

    Delegated administration accumulated over years without a formal review cycle is a common readiness finding, and one auditors test directly once they understand how GDAP actually works.

  • A support tool trusted without scrutiny

    Okta's 2023 support-system breach is a reminder that vendor-facing support tools sit inside the audit boundary even when they feel peripheral to the firm's core RMM stack.

    Source →

Our soc 2 for msps & it consultancies

What our SOC 2 preparation covers for an MSP

Gap review, documentation, control build-out and audit support, scoped around service delivery across client tenants rather than a single product.

Office, night and businessman with computer for research, online information and solution for startup. Screen, male employee or digital marketing specialist with laptop for seo, ke
  1. System description and criteria selection

    We define the service boundary, RMM, PSA, remote access and GDAP paths included, and decide which Trust Services Criteria beyond security actually apply.

  2. High-level gap review

    A structured comparison of current practice against the selected criteria, producing a remediation list ordered by what a client's audit or an insurer would actually flag first.

  3. Documentation guidance

    Policies, control descriptions and the system description itself, written to reflect how a managed services team actually operates day to day.

  4. Control build-out support

    Guidance on access, change-management and vendor-management controls specific to the RMM/PSA stack, implemented without freezing service delivery.

  5. Internal review before the auditor arrives

    A pre-audit check of the evidence trail and a readiness conversation with the technicians and leadership who will sit across from the CPA firm's testing team.

  6. Ongoing support through the audit window

    Light-touch guidance while the observation period runs, so a control that drifts mid-cycle gets caught internally, not flagged as an exception in the final report.

How the engagement runs

How SOC 2 readiness runs against a live client book

Sequenced so service delivery keeps running while the evidence trail builds underneath it.

  1. Step 1

    Scope the system and the deal

    We confirm which client or renewal is driving the timeline, which criteria their contract actually requires, and set a realistic date.

  2. Step 2

    Gap review and remediation plan

    RMM, PSA, GDAP and backup controls are compared against the criteria, and the resulting plan is ordered so the highest-risk gaps close first.

  3. Step 3

    Remediate with evidence built in

    Controls are implemented alongside a capture routine, access logs, ticket approvals, sign-offs, so the audit trail exists from the day each control goes live.

  4. Step 4

    Type I now, Type II on schedule

    Many firms take a Type I to answer an immediate client deadline, then run the observation period straight into a Type II so the next renewal needs no scramble.

  5. Step 5

    Auditor selection and support

    We help select a CPA firm experienced with managed services engagements and stay engaged through fieldwork so questions get routed to the right technician quickly.

What it costs

What drives SOC 2 readiness cost for an MSP

Cost tracks distance from ready, not headcount. A firm with disciplined GDAP reviews and logged access changes closes gaps faster than one running on tribal knowledge and ticket-note passwords. The number of criteria in scope, how many RMM and PSA platforms are involved, and whether availability criteria join security all move the estimate.

Readiness and remediation are billed separately from the independent CPA firm's attestation fee, since Privacy Horizon prepares the firm but does not issue the report itself. We quote readiness after a scoping review of the firm's stack and the client deadline driving it, and can introduce auditors experienced with managed services engagements.

MSPs & IT Consultancies: SOC 2 questions, answered

It depends on whether clients are asking, and increasingly they are: a current SOC 2 report replaces answering the same custom questionnaire repeatedly and signals the firm holds itself to the standard it sells. For a firm still winning business on relationships alone, it may not be urgent yet, but the moment a client's renewal or a target account's procurement process requires it, the runway to get one done matters more than the decision itself.

It means defining the boundary as the tools and access used to deliver the service, RMM console, PSA platform, remote-access tools and GDAP-delegated paths into client tenants, rather than a single application. That's a different scoping exercise than a SaaS company faces, and getting the boundary right up front avoids testing systems that don't actually matter to what clients are asking about.

A Type I, which attests controls are designed correctly at a single point in time, can often be produced faster and buys time while a Type II observation period runs in the background. A Type II needs that observation period to complete, commonly a period of several months to a year, before the report can be issued, so the honest answer depends on how close current practice already is to the criteria.

It covers the controls the firm applies to that access, how GDAP roles are granted, reviewed and revoked, and how sessions into client tenants are logged, rather than auditing the client's own environment directly. The client tenant itself stays outside the boundary; the firm's governance of its access into that tenant is squarely inside it.

It shifts the conversation from asserting security practices to producing independent evidence of them, which shortens procurement cycles with clients who would otherwise send a lengthy custom questionnaire. Firms that lead with a current report, rather than promising to answer questions later, tend to close larger accounts faster.

Yes. Any subcontractor with access to the systems or client data inside the audit boundary needs to be accounted for in the system description and, depending on the arrangement, may need its own controls tested or a carve-out clearly documented. This is exactly the kind of detail that surfaces during the gap review rather than being obvious upfront.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.