top of page
Search

Your MSP Has a SOC 2. Does It Even Mention the AI?

Aug 8
2 min read

Somebody asked me this week how many MSPs are actually SOC 2 Type II attested, and the honest answer is that nobody knows. There is no registry. Unlike ISO certification or CMMC status in SPRS, a SOC 2 report is an AICPA attestation delivered under NDA, so no one publishes a list and every percentage you see quoted is a vendor estimate rather than a census. What we can reason from is cost. A Type II runs thirty to a hundred fifty thousand dollars (depending on size and complexity) plus the internal lift and a six to twelve month observation window (I like the term baking period), and the large majority of MSPs in this country are shops of under twenty people.


But the number is not the real problem. The real problem is that most firms asking the question stop at yes or no (Do you have a SOC). They collect the report, note that it exists, file it, and move on. Almost nobody reads it. And if you actually open the thing, the first question to ask right now is whether it says anything at all about AI (which at this stage almost none do).


A Type II attests to control operating effectiveness over a window that has already closed. Most MSPs bolted AI tooling into their stack far faster than their audit cycle turned over. That means a report can be completely accurate and still describe an environment that no longer exists. So check the observation period against when the AI tooling went live. Check the system description and see whether the copilot ingesting your ticket data sits inside the described boundary or outside it. Check the subservice organizations and whether they were treated carve out or inclusive, because carve out is standard and it means the model provider’s controls were never tested, which just moves your question one vendor down the chain. Read section four for exceptions. Read the complementary user entity controls, because that is where obligations get quietly handed back to you. Ask for a bridge letter covering the gap between period end and today.


None of this is exotic. It is thirty minutes with a PDF. But I keep seeing organizations treat an attestation like a certificate on a wall rather than a document with dates, scope, and boundaries that either include your risk or do not. Most firms saving grace is the auditor does not bother to look at the SOC either:) 


The better question is not whether your provider has a SOC 2. It is whether the report describes the environment they are running your data through today.


Have you read your provider’s report, or just confirmed it exists? Remember failing your audit is by far not the worst thing that can happen anymore, a good breach and your out of business. 

 
 

Recent Posts

See All
Reconnaissance Is Not an Incident

Every statement out of the water sector this week says the same thing. Contained. Water is safe. Operators handled it. That is an after action report written by the wrong side. Twelve states now. More

 
 

Timcke Risk Management, LLC

660 Massachusetts Ave

6th Floor, Boston, MA 02118

 

© 2025 by Timcke Risk Management, LLC

 

bottom of page