How to Verify an MSP's Certifications, Reviews and Security Claims
A practical due-diligence checklist for Australian businesses evaluating managed IT providers. Don't take claims at face value — here's how to verify them.
In brief: Before signing with an MSP, independently verify every certification, review, and security claim. Check the legal entity on certificates, distinguish the MSP's own certifications from their cloud provider's, evaluate online reviews for authenticity, request evidence of cyber insurance and incident response plans, and speak directly to client references. This guide provides a checklist for each step.
In This Guide
Verifying Certifications
Certifications are among the most commonly referenced trust signals on an MSP's website. However, the existence of a logo on a webpage does not mean the MSP holds the certification — or that the certification covers the services you need. Here's how to verify each one.
ISO 27001
ISO/IEC 27001 — Information Security Management System
What to Verify
- The legal entity on the certificate matches the MSP's contracting entity (not a parent company, subsidiary, or different trading name)
- The Statement of Applicability (SoA) scope covers the specific services you are purchasing
- The certificate has not expired — ISO 27001 certificates are valid for three years with annual surveillance audits
- The certification body is accredited by a recognised accreditation body (e.g. JAS-ANZ in Australia, UKAS in the UK)
- Search the JAS-ANZ directory (jas-anz.org) or the IAF CertSearch database to confirm the certification body's accreditation
Common Misrepresentations
- Claiming certification when only "aligned" or "working towards" it
- Showing a certificate held by a parent company that does not cover the MSP entity
- Certificate scope excludes the services you actually need (e.g. certified for data centre operations but not managed services)
SOC 2
SOC 2 — Service Organisation Control Report (Trust Services Criteria)
What to Verify
- Ask whether it is a Type I (point-in-time design) or Type II (effectiveness over a period, typically 6–12 months) — Type II is significantly more valuable
- Check the report period dates to ensure it is current
- Review which Trust Services Criteria are covered: Security is the baseline; Availability, Processing Integrity, Confidentiality, and Privacy are optional
- The report is issued by a licensed CPA firm — SOC reports can only be issued by qualified auditors
- Ask for the management assertion and the auditor's opinion (a clean/unqualified opinion vs. qualified opinion with exceptions)
Common Misrepresentations
- Claiming SOC 2 when they only have SOC 1 (which covers financial reporting controls, not security)
- Referencing an old SOC 2 report that is no longer current
- Having SOC 2 Type I only but implying ongoing compliance
- Not disclosing qualified opinions or exceptions noted in the report
Essential Eight Assessments
Essential Eight Maturity Model — Australian Cyber Security Centre (ACSC)
What to Verify
- Ask what maturity level they claim for each of the eight mitigation strategies (Maturity Level 0–3)
- Determine whether the assessment was self-assessed or independently assessed by a qualified assessor
- Independent assessments carry substantially more weight than self-assessments
- Check the assessment date — the Essential Eight model is updated periodically, and older assessments may not reflect current requirements
- Understand whether the assessment covers the MSP's own environment, their managed client environments, or both
Common Misrepresentations
- Claiming a maturity level without specifying which strategies it applies to
- Self-assessing and presenting it as an independent assessment
- Claiming a maturity level across all eight strategies when only some have been assessed
- Confusing Essential Eight compliance for client environments with the MSP's own internal compliance
Their Certification vs. Their Cloud Provider's
This Is One of the Most Common Misunderstandings
Many MSPs state claims like "We're ISO 27001 certified" or "Our infrastructure is SOC 2 compliant" when, in reality, it is their hosting or cloud provider (e.g. Microsoft Azure, Amazon Web Services, Google Cloud) that holds the certification — not the MSP itself. This is a critical distinction that many buyers miss.
MSP Holds the Certification
This means the MSP's own operations, processes, staff, and management systems have been audited and certified. It covers:
- ✓ How they manage access to your systems
- ✓ Their staff vetting and training processes
- ✓ Their incident detection and response procedures
- ✓ Their internal security policies and controls
- ✓ Their change management and risk assessment
Cloud Provider Holds the Certification
This only covers the cloud platform's infrastructure and operations. It does not cover:
- ✗ How the MSP configures your cloud environment
- ✗ The MSP's internal processes or staff
- ✗ How the MSP manages access controls for your tenant
- ✗ The MSP's incident response or breach notification process
- ✗ Your specific data handling and security configuration
The Key Question to Ask
"Is it your company that holds this certification, or your cloud/hosting provider? Can I see the certificate with your company's legal name on it?"
An MSP hosting client environments on a certified platform is a reasonable baseline — but it is not a substitute for the MSP having its own certified security management practices. Both are valuable; conflating them is misleading.
Evaluating Online Reviews
Online reviews are useful but imperfect. Understanding the strengths and limitations of each platform — and how to spot suspicious patterns — helps you form a more accurate picture.
Google Business Profile
What to Check
- Total number of reviews (a handful of reviews may not be statistically meaningful)
- Distribution of ratings — a natural profile usually has mostly positive with some lower ratings
- Recency — recent reviews are more relevant than those from several years ago
- Whether the MSP responds to negative reviews professionally (this reveals their attitude to feedback)
- Check if reviewers have other review activity (single-review accounts are less reliable)
Clutch.co
What to Check
- The number of verified reviews (Clutch conducts phone interviews to verify)
- Project details including budget range, timeline, and services purchased
- Whether reviews cover the specific services you need
- The company's Clutch ranking within their service category and location
- Read the detailed review narratives, not just the star ratings
Industry Awards and Rankings
What to Check
- Research the awarding body — is it a recognised industry association or a commercial operation?
- Check the judging criteria — are awards based on measurable outcomes or subjective nomination?
- Look at whether the MSP won in a relevant category (not just "best website" or "fastest growing")
- Consider how recent the award is — an award from five years ago may not reflect current service quality
- Be cautious of "badges" or "certifications" that are simply purchased listings on a directory
Signs of Genuine Reviews
- • Mention specific services, projects, or staff interactions
- • Include both positives and constructive feedback
- • Varied writing styles and levels of detail
- • Reviewer has other review activity on their profile
- • Reviews posted over an extended period, not all at once
- • Rating distribution is realistic (not all 5 stars)
Signs of Suspicious Reviews
- • Generic praise with no specific details ("Great company, highly recommend!")
- • Cluster of reviews posted within a short period
- • Near-identical wording or structure across multiple reviews
- • Reviewer profiles with zero or one other review
- • Perfect 5.0 average with a small total review count
- • Reviews that read like marketing copy or include sales language
Verifying Security Claims
Security is often the most heavily marketed — and the hardest to evaluate — aspect of an MSP's offering. Here's what to request and what to look for in each area.
Cyber Insurance
What to request: A Certificate of Currency for their professional indemnity and cyber liability insurance
What to Check
- The policy is current (check start and end dates)
- Coverage amounts are appropriate (discuss with your own insurance broker what level of cover is reasonable for your contract value)
- The insured entity name matches the MSP's contracting entity
- The policy covers third-party liabilities (i.e. if a breach at the MSP affects your data)
Incident Response Capability
What to request: A redacted copy of their Incident Response Plan, or at minimum the table of contents and last review date
What to Check
- The plan exists and has been reviewed or updated within the last 12 months
- It defines roles and responsibilities, escalation procedures, and communication protocols
- The MSP conducts tabletop exercises or simulations (ask when the last one was and what was learned)
- There is a defined process for notifying affected clients in the event of a breach
Security Operations
What to request: Details of their security monitoring and management capabilities
What to Check
- Whether their SOC is in-house, outsourced, or a hybrid — and if outsourced, to whom
- What SIEM (Security Information and Event Management) platform they use
- Average time to detect and respond to alerts (ask for metrics, not just claims)
- Staff certifications in security (e.g. CISSP, CISM, CompTIA Security+, GIAC certifications)
- Whether they conduct regular penetration testing or vulnerability assessments on their own infrastructure
Data Handling and Privacy
What to request: Their data handling policy and evidence of compliance with the Australian Privacy Act
What to Check
- Where your data will be stored (geographic location of data centres)
- Whether data is encrypted at rest and in transit, and using what standards
- Their data retention and disposal policies
- How they manage access controls for their staff accessing your systems
- Whether they have a Privacy Impact Assessment process for new services
Evaluating Client References
Client references are one of the most valuable due-diligence steps — but only if you use them effectively. The goal is not to hear a rehearsed endorsement, but to understand the real working relationship.
Best Practice: Contact References Independently
Request contact details and reach out directly rather than participating in a three-way call arranged by the MSP. This gives the reference more freedom to speak candidly.
Relationship and Tenure
- → How long have you been a client of this MSP?
- → How many users/endpoints do they manage for you?
- → Have you renewed your contract at least once?
Service Delivery
- → Does the MSP consistently meet their SLA response times?
- → How would you rate their communication during outages or incidents?
- → Have you experienced any unexpected costs or charges beyond the agreed contract?
Security and Incidents
- → Have you experienced a security incident while under this MSP's management? If so, how was it handled?
- → How proactive is the MSP in identifying and addressing security risks?
- → Do they provide regular security reporting?
Honest Assessment
- → What is one area where the MSP could improve?
- → Have you ever considered switching providers? If so, why?
- → Would you recommend them to a business similar to yours?
Red Flags: Common Exaggerations and Misrepresentations
These are patterns we see frequently in MSP marketing. None of these are necessarily deal-breakers on their own, but each warrants further investigation. The "What to Ask" prompts give you a way to address each one directly.
"We're ISO 27001 Certified" — but the certificate is their cloud provider's
The MSP is relying on their hosting or cloud platform's certification (e.g. Azure, AWS) and presenting it as their own. The cloud provider's certification covers their infrastructure, not how the MSP operates within it.
What to Ask
Can you show me the ISO 27001 certificate with your company's legal name on it? What is the scope of your certification?
"We've never had a security breach"
This claim is essentially unverifiable and often unrealistic. Many organisations experience attempted or minor breaches. A more honest answer acknowledges that incidents occur and focuses on detection and response capabilities.
What to Ask
How do you detect and respond to security incidents? Can you walk me through your incident response process? What was the last incident you managed and what was the outcome?
"We monitor your systems 24/7/365" — but can't explain the staffing
Genuine 24/7 monitoring requires multiple shifts of qualified staff or a contracted Security Operations Centre (SOC). Automated alerting tools that send emails overnight is not the same as staffed 24/7 monitoring.
What to Ask
How many staff are on shift during overnight and weekend hours? Is your SOC in-house or contracted to a third party? What is your average time to acknowledge an alert outside business hours?
Perfect 5.0 rating with a small number of reviews
A perfect score with few reviews is statistically unreliable and may indicate that only selected clients were asked to review. A larger number of reviews with a high (but not perfect) average is generally more trustworthy.
What to Ask
Can you provide references beyond what's on your review profiles? How do you collect client feedback?
"Certified" or "Compliant" without specifying the standard
Vague compliance claims without naming the specific standard, scope, and certifying body are a red flag. Legitimate certifications come with specific, verifiable details.
What to Ask
Which specific standard are you certified against? Who was the certifying or auditing body? Can I see the certificate or a summary of the audit report?
No willingness to provide client references
While confidentiality is a valid concern for some clients, an MSP should be able to provide at least a few references from clients who have agreed to participate. A complete refusal may indicate a lack of satisfied, long-term clients.
What to Ask
Can you provide two or three references from businesses similar to ours in size or industry? If client confidentiality is a concern, can we speak to a reference anonymously?
Claims of "military-grade encryption" or similar marketing language
This phrase has no standard technical meaning. Legitimate security providers describe their encryption in specific terms (e.g. AES-256, TLS 1.3) rather than using marketing superlatives.
What to Ask
What specific encryption standards and protocols do you use for data at rest and in transit?
MSP Verification Checklist
Use this checklist when evaluating any MSP. You can print this page or copy the checklist into your own evaluation document.
Tip: Use your browser's Print function (Ctrl+P / Cmd+P) to save this page as a PDF for offline use.
Certification Verification
- Requested copies of all claimed certifications
- Confirmed the legal entity on each certificate matches the contracting MSP
- Verified certification scope covers the services I am purchasing
- Checked expiry dates — all certificates are current
- Confirmed the certification body is accredited (checked JAS-ANZ or equivalent)
- Distinguished between the MSP's own certifications and their cloud/hosting provider's certifications
- For SOC 2: confirmed it is Type II (not just Type I) and reviewed the report period
- For Essential Eight: confirmed whether the assessment was independent or self-assessed
Online Reviews and Reputation
- Checked Google Business Profile — reviewed total count, rating distribution, and recency
- Reviewed Clutch.co profile (if applicable) — read detailed verified reviews
- Assessed whether reviews appear genuine (specific details, varied language, reviewer history)
- Checked how the MSP responds to negative reviews
- Investigated any industry awards — verified the awarding body's credibility
- Searched for any public complaints, legal disputes, or data breach notifications
Security Claims Verification
- Requested a Certificate of Currency for cyber insurance
- Confirmed insurance covers third-party liability and the coverage amount is reasonable
- Requested evidence of an Incident Response Plan (redacted copy or table of contents)
- Asked when the plan was last reviewed and when the last tabletop exercise was conducted
- Clarified whether 24/7 monitoring means staffed SOC or automated alerting only
- Asked about specific security tools and platforms (SIEM, EDR, etc.)
- Requested details on staff security certifications
- Asked about penetration testing and vulnerability assessment practices
Client References
- Requested at least two references from businesses of similar size and industry
- Contacted references independently (not via a conference call arranged by the MSP)
- Asked references about SLA adherence, communication quality, and incident handling
- Asked references about areas where the MSP could improve
- Asked references whether they have renewed their contract and why (or why not)
Data and Privacy
- Confirmed where data will be stored geographically
- Reviewed the MSP's data handling and privacy policies
- Confirmed encryption standards for data at rest and in transit
- Reviewed data retention and disposal policies
- Confirmed the MSP's staff access control procedures for your systems
Need Help Evaluating MSPs?
If you'd like assistance comparing managed IT providers or want to discuss your specific requirements, we're happy to help — no obligation.
Get in Touch