Skip to content
Capability/Technology

Managed Service Providers

Multi-tenant compliance orchestration

01 / Overview

Managed Service Providers serve multiple clients with varying compliance requirements from a shared platform. Thalorin enables MSPs to efficiently manage compliance across their client base while maintaining security controls appropriate for privileged access to client environments.

Managed service providers are being written into statute rather than governed through their customers' contracts. The Cyber Security and Resilience (Network and Information Systems) Bill was introduced in the Commons on 12 November 2025, cleared third reading there on 16 June 2026, had its Lords second reading on 14 July 2026 and enters Lords committee stage on 1 September 2026. It is not law as of August 2026, and most of its operative detail is left to secondary legislation. The direction is already settled: the provider becomes a duty holder.

In the United States the pressure runs the other way — obligation without a certificate. Under 32 CFR 170.19 an external service provider that is not a cloud service provider and handles Controlled Unclassified Information needs no CMMC certification of its own. Its services instead sit inside the client's assessment scope, are assessed as part of the client's Level 2 assessment, are documented in the client's System Security Plan and are described in the provider's service description and customer responsibility matrix. The same platform is examined repeatedly, by a different C3PAO each time.

What gets underestimated is that the administrative plane is the product. Monitoring, ticketing, backup and identity tooling exist to reach into every client at once, which is why joint advisory AA22-131A — issued on 11 May 2022 by CISA, the NSA and the FBI alongside the NCSC in the United Kingdom, the ACSC, the CCCS and the NCSC in New Zealand — is written about the provider-customer trust relationship rather than about any single vulnerability. Far fewer providers can evidence standing privilege inside client tenants than can evidence their own corporate estate.

Keeping those states apart is the architectural problem. Every client carries its own control state and its own obligations, held against the contract or award that imposed them, while the controls the provider genuinely operates once — identity, change management, the management platform itself — are declared once and inherited, with the inheritance recorded rather than implied. Change a shared control and every client control resting on it is raised in the same moment.

02 / Challenges

Technology companies must prove their security

Assessed in every client's scope, certified in none

A non-cloud external service provider handling CUI is examined inside each client's CMMC Level 2 assessment rather than holding a certificate. The same services are re-examined per client, against boundaries the provider did not define.

The cloud service provider definition triggers FedRAMP

A provider meeting CMMC's definition of a cloud service provider and handling CUI must satisfy the FedRAMP requirements referenced by DFARS 252.204-7012. Crossing that line is a change of regime, not a change of paperwork, and the client's assessment cannot absorb it.

One administrative path into every client

Monitoring, backup and identity tooling reaches into every tenant by design, so one compromised administrative credential is a customer incident many times over. AA22-131A addresses the provider and the customer separately because neither controls the exposure alone.

One shared plane, several strictest tenants

A single management, ticketing and identity plane can serve a business associate obligation under 45 CFR 160.103, a PCI DSS v4.0.1 service provider scope and a CMMC Level 2 client simultaneously. A per-client exception in a shared plane is rarely per-client.

03 / Capabilities

How Thalorin helps

SOC 2ISO 27001MSP-specific frameworks

Multi-tenant compliance management

Each client holds a separate control state with its own scope, evidence and clocks, while controls the provider operates once are declared once and inherited as a recorded relationship rather than an assumption.

Client-specific control mapping

One platform control projects into whichever framework the client is judged against — HIPAA Security Rule safeguards at 45 CFR 164.308, PCI DSS v4.0.1 requirements, CMMC Level 2 practices — without being re-implemented per client.

Inherited control documentation

Complementary user entity controls are published to the clients that must operate them, so an unconfirmed control appears as an open dependency rather than a page nobody read in an attached report.

MSP security program

The provider's own posture is a control state in its own right — privileged access into client tenants, service accounts, jump hosts, platform change control — against the actions AA22-131A sets out for providers.

Client reporting automation

Evidence packs are generated per client from live state and scoped to that tenancy, so a report issued to one client cannot carry another client's asset names, findings or personnel.

Vendor risk for MSP clients

The provider's own suppliers become each client's fourth parties, so a monitoring, backup or identity vendor incident resolves to the client contracts it touches rather than being triaged apart from them.

Questions

Managed Service Providers: common questions

Does my MSP need its own CMMC certification?

Not unless it meets CMMC's definition of a cloud service provider. 32 CFR 170.19 places an external service provider's CUI-handling services inside the client's assessment scope, assessed within the client's Level 2 assessment, documented in the client's System Security Plan and described in the provider's service description and customer responsibility matrix. A provider may undergo a CMMC assessment voluntarily to reduce work its clients otherwise repeat, and the minimum assessment type follows the client's DoD contract requirement.

When does a managed service provider have to meet FedRAMP?

When it meets CMMC's definition of a cloud service provider and processes, stores or transmits CUI. The requirement traces to DFARS 252.204-7012, which points at the FedRAMP Moderate baseline. The DoD CIO memorandum of 21 December 2023 sets the equivalency route: assessment by a FedRAMP-recognised 3PAO against the full Moderate baseline with a supporting body of evidence, and no self-attestation. Equivalency is not a FedRAMP authorisation, and the duty to hold that evidence sits with the defense contractor buying the service, not with the FedRAMP programme.

Are managed service providers in scope of NIS2?

Yes. Annex I of Directive (EU) 2022/2555 covers ICT service management on a business-to-business basis, naming managed service providers and managed security service providers, and Commission Implementing Regulation (EU) 2024/2690 sets their technical requirements. Size decides classification: a large enterprise is essential, a medium one important, which changes whether supervision is proactive or after the fact. Article 23 applies either way — early warning within 24 hours, notification within 72, final report within one month.

Does our SOC 2 report cover our clients' environments?

No, and letting a client believe otherwise creates a problem later. The report covers the system described in its scope section and nothing beyond it. Whatever the client must do for the provider's service commitments to hold appears as a complementary user entity control, tested by the client's own auditor in the client's own report. A client that treated the provider's report as coverage discovers the gap during its own fieldwork.

Will the UK Cyber Security and Resilience Bill apply to my business?

Probably, if you supply managed services into the United Kingdom, though the detail is unsettled. Introduced on 12 November 2025, the bill cleared the Commons on 16 June 2026, had its Lords second reading on 14 July 2026 and enters Lords committee stage on 1 September 2026, so it is not law as of August 2026. It reforms and extends the regime created by the Network and Information Systems Regulations 2018, leaving designation criteria, duties and reporting detail largely to secondary legislation.

Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.

05 / Get Started

Talk to us about Managed Service Providers.

See how one evidence artifact satisfies Managed Service Providers requirements alongside every other framework you carry.