Multi-tenant compliance for MSPs: one ISMS, many clients

MSPs live at the intersection of one internal ISMS and dozens of client environments each with their own regulatory obligations. Here is the operating model that keeps one certifiable ISMS while genuinely serving very different client compliance regimes.

Michael McCarroll 15 min read Updated June 2026

Why multi-tenant compliance matters for managed service providers

For a 20–200 person managed service provider turning over £2m–£20m, multi-tenant compliance has moved from a nice-to-have to a deal-shaping requirement. Mid-market cios, regulated clients and framework buyers now ask for it by name in RFPs, and the absence of a credible answer is enough to lose the deal before a technical conversation ever happens.

The ICP this guide is written for: a 20–200 person B2B tech business turning over £2m–£20m, pursuing multi-tenant compliance (often alongside one or more of ISO 27001, ISO 20000-1, ISO 9001 and ISO 42001) without a dedicated full-time compliance manager. The founder, CTO, COO or Head of Ops usually owns it in practice.

  • You are past the stage where 'we take security seriously' answers a questionnaire
  • Your average enterprise sales cycle now includes an infosec assurance step
  • You cannot justify a £120k head to own compliance — but the work is real

Where firms in this sector typically start

Most MSP firms we speak to are somewhere between two familiar states: an experienced team who genuinely do the right things but cannot prove it to a buyer, and a team with a folder of policies written by someone external three years ago that no one has opened since.

Neither passes a modern audit or a modern buyer review. The starting point isn't 'implement everything' — it's a short, honest gap analysis against the standard, mapped to what already exists.

  • A 60–90 minute internal walkthrough of what already exists
  • A gap register scoped to the standard's mandatory clauses first, then Annex controls
  • An owner and a target certification window — 4–6 months is realistic for this sector

The minimum viable programme

Without a full-time compliance manager, the trap is trying to do everything. A minimum viable multi-tenant compliance programme for a 20–200 person managed service provider turning over £2m–£20m is scoped, owned, and evidenced — not exhaustive.

The essential ingredients are the same across sectors: a defined scope, a leadership team that has signed off, a live risk register, the controls the standard requires, policies people actually read, and evidence produced as a by-product of doing the work rather than a separate reporting task.

  • Scope statement (single page, signed by the CEO)
  • Risk register with owners, treatment plans and review dates
  • Controls / Annex mapping showing what applies, what doesn't, and why
  • Policies drafted for adoption, not for a shelf
  • Evidence store linked directly to controls and audits
  • A calendar of internal audit, management review and improvement actions

Sector-specific pitfalls in MSP firms

MSPs typically confuse client environments with their own ISMS. Your ISMS covers how you deliver managed services; individual client tenants are in scope for supplier assurance to those clients, not for your own certificate. Getting this boundary right cuts the programme in half.

The second pattern to avoid is treating the standard like a shopping list. The clauses that talk about leadership, planning, evaluation and improvement matter more than the controls themselves — those are what auditors actually test for maturity.

How ISO-STANDARD.app changes the economics

The reason a 20–200 person managed service provider turning over £2m–£20m without a compliance manager historically failed to certify wasn't will — it was cost. A traditional consultancy-plus-spreadsheet programme runs £30k–£45k in year one. Most of that pays for policy drafting, spreadsheet maintenance and evidence chasing that a modern platform simply removes.

ISO-STANDARD.app ships a ready-to-adopt multi-tenant compliance workspace with the risk register, controls catalogue, policies, evidence store, internal audit programme and audit-ready exports already wired together. What remains is your organisation's genuinely unique work — scope, risk decisions, and evidence — which is where a founder or ops leader's time actually adds value.

  • Consultancy-led baseline: ~£30k–£45k in year one
  • Templates + spreadsheets baseline: ~£20k–£25k with heavy internal hours
  • ISO-STANDARD.app: from £39/month plus focused internal effort

A 90-day path to readiness

For a 20–200 person managed service provider turning over £2m–£20m, a credible 90-day readiness path exists and is well-worn. Certification itself lands in months 4–6 depending on registrar availability.

  • Days 1–14 · Scope, leadership sign-off, gap analysis, register the workspace
  • Days 15–45 · Populate the risk register, adopt policies, assign control owners, close top-priority gaps
  • Days 46–75 · Collect evidence for each control, run the first internal audit, remediate findings
  • Days 76–90 · Management review, Stage 1 documentation submission, book Stage 2

Frequently asked questions

Do we really need multi-tenant compliance to sell into enterprise?
For a 20–200 person managed service provider turning over £2m–£20m, yes — increasingly so. It's the fastest way to get through the infosec section of an RFP or vendor onboarding without a bespoke justification. Firms that don't have it either lose deals or spend disproportionate founder time answering questionnaires that a certificate would answer once.
Can we certify multi-tenant compliance without hiring a compliance manager?
Yes, and most firms in this ICP do exactly that. What you need is a nominated owner (typically the COO, CTO or Head of Ops) with 4–6 hours a week for the programme, an executive sponsor, and a platform that removes the spreadsheet and drafting work. A part-time fractional practitioner for 4–8 days total is often enough.
How long does it realistically take?
For a 20–200 person B2B tech firm with a tight scope and an integrated platform: 90 days to readiness, 4–6 months to certificate (governed by UKAS registrar availability). Longer programmes almost always suffer from over-scoping, not from complexity of the standard.
How much will it cost in year one?
All-in with ISO-STANDARD.app: roughly £8k–£15k for a small scope (registrar + platform + focused internal time). Traditional consultancy-plus-spreadsheet programmes for the same scope typically run £30k–£45k. Recertification and surveillance run £4k–£8k a year afterwards.
How does multi-tenant compliance fit if we're also pursuing ISO 27001 / ISO 9001 / ISO 42001?
Well, if you use one integrated management system. The clauses on leadership, planning, support, operation, evaluation and improvement are near-identical across ISO management system standards. Duplicated risk registers, audit programmes and policies are the biggest source of wasted effort — an integrated workspace collapses them into one.

Ship multi-tenant compliance without a full-time compliance manager

ISO-STANDARD.app packages the whole multi-tenant compliance programme — risk register, controls, policies, evidence, audits — into one workspace priced for a 20–200 person managed service provider turning over £2m–£20m.

ISO-STANDARD.app ships a ready-to-adopt multi-tenant compliance workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.

Free downloads for this topic

Prefer a conversation? Email hello@iso-standard.app — a real human responds within one business day.

Related guides
Trust & security
ISO 27001 aligned
Controls mapped to Annex A
Encryption in transit & at rest
TLS 1.3 · AES-256
MFA enforced
TOTP required for all admins
GDPR & UK GDPR
DPA on request · EU/UK data
SOC 2 ready posture
Audit-grade logging
RLS-isolated tenants
Row-level data separation
← All guidesHome →