Mandatory Security Baselines: What MSPs Must Require of Their Clients
Mandatory Security Baselines: What MSPs Must Require of Their Clients
For years, managed service providers (MSPs) could treat security as a menu items:
- Firewalls here,
- Backups there,
- Multi-factor authentication (MFA) if the client was willing to pay for it.
Why isn’t this still a good plan?
Regulators, cyber insurers, and federal guidance are converging on a simple expectation: MSPs are responsible for setting a mandatory security floor beneath every client relationship, not an optional upsell.
I want to tell you why “optional” security no longer works for our clients.
MSPs sit at the center of the supply chain, with privileged access into dozens or hundreds of client networks. That concentration of access is exactly why threat actors target providers directly, a risk the Cybersecurity and Infrastructure Security Agency (CISA) formally warned about in its joint advisory on protecting MSPs and their customers (CISA AA22-131A).
A single compromised MSP credential can cascade into ransomware across every client tenant it touches, which is why regulators increasingly hold the provider, not just the client, accountable for baseline hygiene.
That accountability is showing up in contract language and audit requirements.
HIPAA’s proposed 2026 Security Rule updates would require business associates — including MSPs — to prove MFA, encryption, and semiannual vulnerability scanning are actually operating, not merely documented. PCI DSS 4.0.1, mandatory since March 2025, now demands quarterly scans and continuous change-detection evidence. CMMC 2.0 is extending third-party assessment requirements to defense-sector clients starting in November 2026. Add in the FTC Safeguards Rule and a growing patchwork of state privacy laws, and the message is consistent: policies alone no longer satisfy anyone.
What belongs in the baseline
Across these frameworks, a common floor of controls has emerged as the practical minimum an MSP should mandate, not recommend, for every client, regardless of contract tier:
- Phishing-resistant MFA on all administrative and remote-access accounts, moving beyond SMS or push-based approval.
- Endpoint detection and response (EDR) with 24/7 monitoring, rather than legacy signature-based antivirus alone.
- Centralized logging and SIEM coverage sufficient to reconstruct an incident timeline.
- Documented, tested backups with offline or immutable copies and a defined recovery time objective.
- Privileged access management, including just-in-time elevation instead of standing admin rights.
- A patch management cadence with defined SLAs for critical vulnerabilities.
- A written, exercised incident response plan — not a template that has never been tested.
CISA’s Cross-Sector Cybersecurity Performance Goals restate much of this same list as a voluntary baseline for critical infrastructure organizations, and it’s increasingly the yardstick auditors and cyber insurers reach for even outside regulated sectors.
Making the baseline actually mandatory
The hardest part isn’t defining the baseline — it’s enforcing it. Two mechanisms are becoming standard practice among mature MSPs. First, contracts should state plainly that these controls are conditions of service, not add-ons, with any client refusal captured in a signed risk-acceptance waiver that shifts liability back to the client. Second, evidence should be continuous rather than annual: MFA coverage reports, scan results, and backup test logs generated on a recurring schedule, not produced only when an auditor asks.
That shift — from attestation to continuous, evidence-backed operation — is the throughline across every framework touching MSPs right now. Providers that build it into their service delivery model, rather than bolting it on before an audit, will be the ones still standing when the next regulatory deadline or the next ransomware advisory lands.
Sources
Protecting Against Cyber Threats to Managed Service Providers and their Customers — CISA AA22-131A
MSP Compliance: The Complete Guide to Meeting Security and Regulatory Standards in 2026 — Huntress

