MSP & MSSP Assessment Kit
Your MSP is your administrative plane. Assess what they hold, how they reach you, what they can evidence, what the contract says and whether you could leave — with a scenario that proves you can act the night they are breached.
What this actually gives you
- Your MSP is not a vendor, it is your administrative plane — RMM on every endpoint, delegated admin, the credential vault, the backups, the network gear, often the registrar. A vendor questionnaire treats that as one row.
- 75% of MSPs were breached in the past year and 54% more than once (2026 survey of 350 providers); Verizon’s 2026 DBIR puts third-party involvement in 48% of breaches, up 60% year on year.
- The custody cliff: most mid-market firms cannot log into their own firewall, restore their own backups or recover their domain without the provider. The assessment names how many holdings sit past it and prices pulling each one back.
- Refusal to evidence a control is itself the finding. A provider who will not show MFA enforcement, backup immutability or their own IR plan has answered the question.
- Regulators now name the relationship specifically — the DFS third-party service provider letter (Oct 2025) on MFA for provider access, HIPAA’s annual BA verification, the UK Act’s RMSP duties, DORA’s critical ICT third parties, NIS2 Article 21(2)(d).
Your MSP is not a vendor. It is your administrative plane. It holds the RMM agent on every endpoint, delegated admin in your tenant, the credential vault, the backups, the network gear, the security stack, the documentation, and often the domain registrar. A vendor questionnaire treats that as one row. This kit treats it as what it is.
The numbers say this is now the likeliest way you get breached. A 2026 survey of 350 MSPs found 75% were breached in the past year and 54% more than once. Verizon's 2026 DBIR puts third-party involvement in 48% of breaches, up 60% year on year. One provider compromise is many victims — Kaseya in 2021 was roughly 60 MSPs and 1,500 businesses downstream.
Regulators have stopped treating it as generic third-party risk and started naming the relationship. New York DFS issued a third-party service provider industry letter in October 2025 specifically about MFA on provider access. HIPAA's proposed rule requires annual business-associate verification. The UK Bill imposes duties on relevant managed service providers directly. DORA governs critical ICT third parties; NIS2 Article 21(2)(d) covers supply chain.
The custody cliff. Most mid-market organisations cannot log into their own firewall, restore their own backups, or recover their own domain without their provider. That is not a control gap, it is a custody gap, and it decides what your options are on the worst night. File 01 names how many holdings sit past the cliff; file 05 prices what it costs to pull each one back.
Refusal to evidence a control is itself the finding. File 03 is built on that rule. It is not a trust exercise — a provider who will not show you their MFA enforcement, their backup immutability or their own IR plan has answered the question.
What you get
01 MSP Dependency Map (XLSX) — every holding, from RMM and delegated admin through credentials, backups, network, security stack, documentation, PSA, registrar and cloud subscriptions, each scored for custody, reach and recoverability, resolving to a blast radius and the custody-cliff verdict.
02 Access-Path Audit (XLSX) — every path the provider uses into your estate with account type, whether MFA is enforced on their side, approval, your log visibility, scope, custody and the leaver process, returning HIGH / MEDIUM / LOW with the fix.
03 MSP Control Assessment (XLSX) — 40 controls the provider must evidence, across identity, RMM, backups, detection, network, supply chain, incident response, governance, people, data, change, vulnerabilities, resilience, exit and concentration, mapped to CIS and the CAF and to the regimes that ask for them, weighted and scored. Ships with a send-out questionnaire tab so the provider answers in your format rather than their marketing one.
04 Contract Audit (XLSX) — 20 clauses against UK, DFS, HIPAA, DORA and NIS2 expectations, marked present, weak or absent, prioritised P1 to P3, ending in an addendum verdict.
05 Concentration & Exit Analysis (XLSX) — per critical holding: could you operate without them, could you regain control, in how many hours, what should you hold yourself, and what does that cost. Then the exit plan, both planned and stressed.
06 "MSP Breached Tonight" — Scenario & Playbook (DOCX) — the first hour without your provider, hours 1 to 24, days 2 to 30, and a 60-minute drill with pass criteria. This is the deliverable that converts the assessment into something you know rather than something you filed.
07 Findings Report + Board Slide (DOCX + PPTX) — the scorecard assembled from the workbooks, the findings, the decision, the addendum clauses, a ninety-day plan, and one slide for the board.
08 Practitioner Guide (PDF) — why this is regulated now, why one vendor row is not enough, each assessment in turn, the regulatory pull by regime, how to run it (including as a vCISO service line), ninety days, failure patterns and an FAQ.
msp01.json — the holdings taxonomy, path types, control ids, clause ids and scoring rules.
This is the buyer's side. It is written for the organisation being served — an IT lead, CISO, CFO or general counsel — and for vCISOs assessing a client's provider. The Vendor Risk Operations Kit runs the whole vendor programme and this feeds one deep row into it; the TPRM Program Kit holds the clause library file 04 draws on. If you are the MSP, the UK Cyber Security & Resilience Act Kit is the provider-side duty, and this kit is worth reading anyway — it is the checklist your customers are about to run on you.
Pairs with the Executive Tabletop Kit whose scenario 2 is the drill, I've Been Breached if it becomes your incident, the HIPAA Security Rule 2027 Readiness Kit for business-associate verification, the NYDFS Part 500 Kit for §500.11, and the Cyber Insurance Application Readiness Kit for the baseline an underwriter expects.
A practitioner's toolset, not legal advice. UK duties are bill-stage and the HIPAA verification content is from the proposed rule — both are marked "verify final" in the files.
Also available in 5 bundles
This product is sold on its own and as part of a set. If you need more than this one, the set is cheaper than buying the parts.
Infrastructure Providers Pack
The two parties that run your estate for you — the MSP with delegated admin, and the facility where the data physically sits. Same assessment discipline applied to both. 15% off buying separately.
Provider Risk Pack
The vendor programme, and a deep assessment of the vendor that holds your admin rights. Run every supplier properly, then run your MSP properly — because one row in a register does not cover the party with delegated admin on your tenant. 14% off buying separately.
Healthcare Provider Risk
The billing company holds your cardholder data and your PHI, and the MSP holds the admin rights over both. Assess the payment side and the provider that runs it. 15% off buying separately.
Both Sides of the MSP
The duties a UK managed service provider owes, and the assessment its customers are about to run on it. Read your own regime and your customers’ checklist in one purchase. 14% off buying separately.
Defense Supplier Pack
The CMMC self-assessment and SPRS score you are certifying to, the provider holding your admin rights, and the federal incident clock underneath both. What a DIB contractor is actually accountable for while Phase 2 is suspended. 19% off buying separately.
What's included
- Complete Library (.zip) — all formats included — fully editable
- Instant download after purchase
- Free updates — re-download when we release new versions
- Practitioner License: unlimited client use (vCISO / MSP)
More from the CISO Marketplace ecosystem
Choose your license:
- Secure checkout via Stripe
- All major cards accepted
- 30-day satisfaction guarantee