How MSPs Can Vet Outsourced Technical Support Providers for ISO 27001, SOC 2 and Client Access

S

sarahevans

Guest
Verizon's 2026 Data Breach Investigations Report found that third parties played a role in 48% of breaches, up from 30% the year before. ISO 27001 requires certified companies to manage that risk through their suppliers, and guidance for its Annex A 5.21 control carries those security requirements past a company's vendors to their subcontractors. When an MSP outsources support, the outside engineers who log into a client's systems join that chain. The client has no contract with the outsourcing firm, so it asks the MSP to prove the firm meets its security terms.


LTVplus, a managed technical support partner that recruits, trains and manages dedicated Tier 0-3 engineers for MSPs, handles that request in its sales process. "Our engineers work under the MSP's name. The client experiences one provider, and we're built to keep it that way," said David Henzel, Co-Founder of LTVplus. The audit works from the access list, and the access list shows who employs each engineer. The single-provider experience ends there.


Under ISO 27001 Annex A 5.21, security obligations follow the work down to the outsourced engineer.



Why do ISO 27001 supplier controls reach an MSP's outsourced engineers?​



A flow-down clause carries security requirements down the supply chain. It binds a subcontractor to the same obligations the MSP accepted in its client contract, and those obligations reach the engineer working the ticket. A provider's own ISO 27001 certificate covers only the sites named in its scope, which gives an MSP a list to compare with where the provider's engineers actually work.


What do ISO 27001 and SOC 2 cover?​



An accredited certification body issues ISO 27001 certificates. A CPA firm issues SOC 2 attestation reports under AICPA standards. Each document defines what it covers and how closely the auditor looked.


A SOC 2 report lists the services it covers in a section called the system description. A Type I report checks whether controls were designed well on a single date, and a Type II report checks whether they operated over 3 to 12 months. An ISO 27001 certificate lists what it covers in a scope statement, and a separate document, the Statement of Applicability, lists the controls the company uses.


Neither document shows which client environments one engineer can open at the same time. The provider controls access, so the MSP has to get that answer from the provider.


What ISO 27001 certificates and SOC 2 reports cover, and the access question neither answers



How does the cybersecurity skills gap shape outsourced security work?​



ISC2's 2025 Cybersecurity Workforce Study found that 88% of respondents had experienced at least one significant cybersecurity consequence from a skills gap, including oversights in security processes and parts of the organization left under-secured. About a quarter reported putting underqualified or inexperienced staff into roles.


An MSP hiring a security analyst competes for the same people as larger employers, including its own clients. When security work has no assigned owner, it moves to whoever is already on the desk, and a Tier 2 engineer without detection experience can end up triaging alerts.


"A layer resting on one or two people disappears the moment they leave, along with their knowledge of every client environment," Henzel said.


Five checks before an MSP signs an outsourced support provider​



Security review is one part of how MSPs evaluate managed support partners. Five checks show whether a provider's engineers work inside the scope its reports describe.


 Five checks to run before an MSP signs an outsourced support provider.



  1. Scope before certification. The ISO 27001 scope statement should name the legal entities and delivery sites working the account, and the SOC 2 system description should cover the service the MSP is buying.
  2. Per-client access control. The provider should be able to explain how it separates credentials across tenants, who approves an access grant and how long approval takes. An engineer who opens a ticket for one client may carry standing access to another, so the question for the provider is what that engineer can see.
  3. Security as a defined role. Security analysts should hold named positions with a job description, on-call rotation, reporting line and escalation authority. On some desks, alert handling falls to Tier 2 engineers who already carry a queue. A provider should be able to state who owns incident response when outsourced engineers work an MSP's accounts and name who handles each alert.
  4. An escalation path with an owner. The provider's severity-1 procedure should name the role on call at any hour, the notification clock, the handoff point back to the MSP and what gets logged afterward.
  5. Offboarding speed. The provider should be able to say how quickly it revokes an engineer's access to the MSP's client environments after the engineer rolls off the account, and where that revocation is logged. Access removal is a standard joiner-mover-leaver control in ISO 27001 and SOC 2 audits.


For an MSP, outsourcing a tier is a capacity decision with security consequences. The outside engineers work in client environments the MSP has promised to protect, which makes their desk part of the MSP's security program and part of what the client's auditor will ask about.



What This Article Covers


  • How ISO 27001 Annex A 5.21 extends supplier security requirements to an MSP's outsourced engineers
  • What Verizon's 2026 Data Breach Investigations Report found about third-party involvement in breaches
  • What an ISO 27001 certificate, Statement of Applicability and SOC 2 Type I and Type II report each cover
  • Why neither report shows which client environments one outsourced engineer can access
  • How the cybersecurity skills gap pushes security work onto support tiers
  • Five checks for evaluating an outsourced support or SOC provider
 

Thread statistics

Created
sarahevans,
Replies
0
Views
3
Back
Top