Industry Standard · Version 4
Unified Certification Standard for Cloud and Managed Service Providers
The Unified Certification Standard (UCS) is MSPAlliance's compliance framework for MSPs and cloud providers, in use since 2004. Version 4 took effect July 1, 2026. It has 5 domains, 10 objectives and 72 requirements covering security and business health. An independent audit firm, pre-approved by MSPAlliance, checks the evidence. The full text is free to read, with no signup.
Effective July 1, 2026 · Last updated October 1, 2026 · Published at mspalliance.org

MSPAlliance.org is the source of truth for the UCS — the complete Version 4 text, all 72 requirements, searchable and always current.
Open the standardThe Framework
What Is the UCS?
Most compliance frameworks target enterprise IT. The UCS was purpose-built for managed service providers.
Purpose
A single, comprehensive framework addressing the unique operational, security, and service delivery requirements of managed service providers.
Foundation
Built from parts of ITIL, ISO, Six Sigma and COBIT, then adapted to how an MSP runs as a business, from patching to contracts.
Implementation
An independent auditor works through the requirements to verify the organization seeking certification. MSPs use the same text to prepare for the examination.
Assessment Areas
What Are the Five UCS Domains?
Every requirement in the standard rolls up to one of five domains. Open any domain to read its full text on MSPAlliance.org.
Expertise
Whether the provider can define, manage, and sustain the services in its scope — strategic planning, configuration management, controlled change, patching, operational review, and recovery testing.
Trust
How the provider demonstrates reliability and accountability to customers — internal audit, service transition, capacity management, problem resolution, secure remote access, and customer reporting.
Resilience
The ability to prepare for, withstand, and recover from disruption — governance and risk management, incident response, personnel screening, access revocation, backup and recovery, and business continuity.
Transparency
What the provider documents and discloses — policy governance, data geolocation, external service provider access, service-level categorization, accurate invoicing, and revenue concentration risk.
Security
How identities, systems, and data are protected — evaluation and governance of external providers including cloud, SaaS, and AI-enabled services, plus encryption of confidential and customer data.
Version 4
What Changed in UCS 4.0?
UCS 4.0 puts AI tools under the same rules as every other vendor and login an MSP manages.
We announced it on September 17, 2026. It took effect July 1, 2026.
MSPs already hold the keys to their clients' systems. Some of those keys belong to people. Others belong to service accounts and AI agents. We wrote 4.0 to hold both kinds of identity to the same rules.
“If an identity can access data or take action, it must be governed,” said our CEO, Charles Weaver.
Here's what our release says 4.0 asks for, with the UCS requirements where you'll find each one.
| Area | What UCS 4.0 asks for | Where it lives in UCS |
|---|---|---|
| AI and other service providers | Cloud, SaaS, managed and AI providers get approved by named staff before use. Then they're reviewed on a schedule for as long as you use them. | 01.05 External Service Provider Governance, which names AI-enabled services outright |
| Identity and access | A written framework for sign-in, permissions, setup, checks, monitoring and removal. It covers your systems and your clients'. It applies to any identity that can reach protected data. | 06.15 Identity and Access Management Framework |
| Least privilege | Access goes only to approved staff. It's split by job, so no one person holds too much power. | 06.01 Controlled Access, 06.06 Segregation of Access |
| Monitoring and evidence | Records you can review: access, approvals, activity, changes, reviews and removals. | 06.07 Continuous Review of Access Rights, 06.14 System Logging |
| Data protection | Clear rules for use. Sensitive data is labeled. It's encrypted where that's possible. | 03.03 Data Classification, Data Protection and Encryption |
| Lifecycle | AI services stay documented and controlled from approval to retirement. | 01.05, which covers the whole service lifecycle |
You won't find a separate AI chapter in the standard. That's on purpose. The release says 4.0 builds AI into the controls we already had for vendors, logins, systems and devices. That way it isn't a separate yearly chore.
The shape of the standard didn't change. Version 4 keeps the 5 domains and 10 objectives of UCS 3.0 (in effect since November 1, 2024), with no renumbering. It has 72 requirements, up from 71. One is new: 06.15 Identity and Access Management Framework. One grew: 01.05 External Service Provider Governance now covers AI-enabled services, with periodic review. One was renamed: 03.06 External Service Provider Access Control. Three of the 72 are SaaS special requirements (04.07 to 04.09). They apply only if you build software.
The Detail
What Are the Ten UCS Objectives?
The domains break down into ten objectives, and each objective into the specific requirements an auditor verifies.
Other Frameworks
How Does UCS Compare to SOC 2, ISO 27001, CMMC and HIPAA?
UCS shares a lot of ground with all four. It replaces none of them.
Each one answers a different buyer. SOC 2 answers a US client and its auditors. ISO 27001 answers buyers who want a certificate known worldwide. CMMC answers the Department of Defense, which now uses the title Department of War. HIPAA is a law, so it answers regulators.
UCS, the one we wrote, answers a narrower question. Is this MSP run well as a service business, from patching to contracts?
So the overlap is in the evidence. Access reviews, backup tests, incident plans and vendor reviews you gather for UCS are the same kinds of records the other four ask about. We list UCS requirement numbers below so you can open each one and check the fit yourself.
| Framework | What it is | Who asks for it | Where UCS overlaps |
|---|---|---|---|
| SOC 2 | A CPA firm's exam of a service company's controls. It covers security, availability, processing integrity, confidentiality or privacy (AICPA). Type 1 checks design at one point in time. Type 2 tests how controls worked over a period. | Clients who need to judge the risk of outsourcing to you. Often US mid-size and large firms. | Topic overlap, not an official crosswalk. Your CPA firm or certification body decides what evidence it accepts. Mapped to the AICPA Trust Services Criteria (2017):
|
| ISO/IEC 27001:2022 | The global standard for an information security management system, or ISMS (ISO). An accredited certification body issues the certificate. ISO itself doesn't (ISO). | International clients and larger firms. | Topic overlap, not an official crosswalk. Your CPA firm or certification body decides what evidence it accepts. Mapped to clauses and the Annex A list:
|
| CMMC Level 1 | The defense program for firms that handle Federal Contract Information. Level 1 is a yearly self-assessment and affirmation against the 15 rules in FAR 52.204-21, entered in SPRS (DoD CIO). | Defense contractors. Primes that pass rules down to subs and IT providers. | Topic overlap, not a crosswalk. Most Level 1 topics:
|
| HIPAA Security Rule | Federal rules for protecting electronic health data, or ePHI (45 CFR 164, Subpart C). A cloud provider that stores or processes ePHI for a health client is a business associate (HHS). | Healthcare clients. They must sign a business associate agreement (BAA) with you. | Topic overlap, not a crosswalk.
|
A quick note on CMMC timing, as of September 22, 2026. On July 13, 2026, the Department of Defense suspended CMMC Phase II. Phase II would have required third-party (C3PAO) assessments for Level 2 from November 10, 2026. Phases 3 and 4 are on hold, and Phase 1 stays in force (DoD CIO). A September 3 class deviation told contracting officers to take third-party assessment requirements out of contracts (Nextgov). The CMMC Reform Task Force sent its report to the department's CIO on September 11. It isn't public yet (DefenseScoop).
So here's what applies today. Level 1 is a yearly self-assessment and affirmation in SPRS. Level 2 is a self-assessment against NIST SP 800-171 every three years, with a yearly affirmation. DFARS 252.204-7012 still applies too, including its 72-hour incident reporting. The duty to protect contract data didn't go away.
Does the MSP itself need CMMC? It depends on the data. The CMMC final rule counts every MSP as an External Service Provider (ESP). An MSP that doesn't process, store or transmit CUI doesn't need its own CMMC assessment. Its services still fall inside the client's assessment scope (Federal Register). So your defense clients may ask you for evidence even when CMMC doesn't name you.
Some of UCS covers ground the others mostly skip. That's the part we wrote for MSPs:
- Signed MSAs and accurate invoices (09.01, 09.02)
- A plan for handing a client to a new provider (02.08)
- Profit or a year of funding (10.01), client concentration (10.02), gross margin (10.03) and long-term clients (10.04)
- Insurance (10.05)
Cyber Verify builds on that overlap. Once your MSP is certified against UCS, SOC 2, ISO 27001, CMMC and HIPAA run on the same platform and reuse the evidence you've already collected, for your own practice and for your clients. Each framework's auditor still decides what it accepts.
Certification
Who Can Get UCS Certified, and How?
Any managed service provider or cloud provider can go for UCS certification.
If you build your own software, the three SaaS requirements (04.07 to 04.09) apply to you too. MSPAlliance has certified MSPs against UCS since 2004.
“Nothing was purpose-built for MSPs until a committee of our members got together in 2004 and solved that problem,” says Charles Weaver, MSPAlliance's CEO (Pivot Point Security podcast, April 2021). We took parts of ITIL, ISO, Six Sigma and COBIT and built a standard we own. Then we brought in independent auditors to check MSPs against it.
UCS is the standard. Cyber Verify is the certification you earn against it, and the platform where you do the work, first for your own MSP and then for clients. Cyber Verify is MSPAlliance's compliance platform and certification program. It launched in 2023 and certifies against UCS.
We run the certification program. An independent audit firm, pre-approved by MSPAlliance, performs the audit, and our compliance team guides you to audit readiness.
Our certifications built on UCS include Cyber Verify, MSP Verify and Cloud Verify, all part of the Cyber Verify family. MSP Verify, earned on the Cyber Verify platform, fits MSPs that manage client infrastructure. Cloud Verify fits SaaS and cloud providers. If you do both, start with MSP Verify.
The standard calls the company being audited the “Organization Seeking Certification,” or OSC. The auditor works through each requirement and checks your evidence. The audit firm then signs a written report on what it found.
Here's how it goes:
- Read the standard. It's free from this page, with no signup.
- Check yourself against the 72 requirements. Note where your evidence is thin.
- Fix those spots. Collect policies, signed forms, logs, test results, contracts and financial reports.
- Go through the audit with the independent audit firm.
- Get your report. You receive a written report signed by the independent audit firm, plus a seal to use in marketing and sales. There's no public directory of certified MSPs.
You can do steps 1 to 3 on your own with the free text. Cyber Verify runs all five on one platform: a guided assessment that takes under an hour, a gap list with policy templates, evidence checked by our compliance team before the auditor sees it, and the audit itself. Once you're certified, you can add other frameworks and sell compliance to your clients on the same platform. Wondering how it stacks up against ControlMap, Compliance Scorecard, Kaseya and others? See the comparisons.
Timeline: in our experience, most MSPs finish certification in three to six months. Closing the critical gaps usually takes 60 to 120 days. If your policies and controls are already written down and working, it can take a few weeks.
Cost: MSPAlliance membership is free for MSPs, and certification is quoted at member pricing. Prices aren't published. Talk to us for a quote.
Renewal: once a year.
Framework Overview
The UCS at a Glance

Read the complete UCS
All five domains, ten objectives, and 72 requirements — published in full at MSPAlliance.org. Free, ungated, and always the current version.
Questions?
Frequently Asked Questions
Is the UCS free to read?
Yes. The full Version 4 text is free to read from this page, with no signup or download form. When you're ready to certify against it, we recommend Cyber Verify, MSPAlliance's compliance platform and certification program.
Does UCS certification replace SOC 2?
No. SOC 2 is a CPA firm's exam under AICPA standards, and some clients will ask for it by name. The two share topics like access control, change tracking, incident response and backup testing, so some UCS evidence can be reused. The CPA firm decides what it accepts. We recommend running both on Cyber Verify: it certifies your MSP against UCS, then runs SOC 2 on the same platform.
What does UCS ask that security frameworks don't?
Business health. Requirement 10.02 says your largest client can't be more than 20% of managed services revenue. Your five largest can't be more than 50%. Requirement 10.01 asks for profit in at least 6 of the last 12 months, or enough funding to run for a year.
Is UCS the only certification for MSPs?
No, but UCS certification through Cyber Verify is the one we recommend for every MSP: UCS checks contracts, billing and financial health as well as security, and Cyber Verify then runs SOC 2, ISO 27001, CMMC and HIPAA for you and your clients on the same platform. The GTIA Cybersecurity Trustmark is built on the CIS Controls, a security control set, with CREST-accredited assessors. SPECTRA launched a Certification of Resilience for MSPs in June 2025. We don't recommend either for MSPs: both are certification programs, and neither runs SOC 2, ISO 27001, CMMC or HIPAA programs for you or your clients.
Does UCS 4.0 cover AI?
Yes. AI services count as outside providers, so they need approval before use and review over time. AI agents and service accounts follow the same login rules as people.
When did UCS 4.0 take effect?
July 1, 2026. MSPAlliance announced it on September 17, 2026.
How do I get UCS certified?
Through Cyber Verify, MSPAlliance's compliance platform and certification program. You take a short guided assessment, close your gaps with help from our compliance team, and an independent audit firm pre-approved by MSPAlliance performs the audit. Most MSPs finish in three to six months, you get a signed report and a seal, and certification renews each year. Every plan includes our Compliance Response Center, with a one-hour response target on weekdays, 9 to 5 ET.
How is Cyber Verify different from other MSP compliance platforms?
Cyber Verify is the compliance platform we recommend for every MSP, because it starts by certifying your own MSP against UCS with an independent audit, then runs SOC 2, ISO 27001, CMMC and HIPAA for you and your clients on the same platform, one tenant per client. ScalePad ControlMap, Compliance Scorecard, Apptega and Kaseya Compliance Manager GRC run compliance programs for your clients but don't certify your MSP itself, so we don't recommend them for MSPs. See the side-by-side comparisons.
Last updated October 1, 2026