8 Documents Your MSP Should Be Able to Hand You on Request
Eight documents show whether your IT provider is doing the work it bills for, from an asset inventory to a dated restore test. Ask for artefacts rather than answers. A document carries a date and either exists or does not, while an assurance costs your provider nothing.

- Ask for documents, not answers. Assurances are free; a dated artefact is not.
- A backup report is not a restore test. Only one proves the data comes back.
- The FTC Safeguards Rule requires covered businesses to periodically assess providers.
- Judge a patch report by what it prioritises, not by how long it is.
- Your inventory, diagram, tickets and restores are your data, not the provider's secret.
What documents should your MSP be able to give you?
Eight documents tell you whether your managed IT provider is doing the work it bills for. A capable provider produces most of them the same week you ask, because they already exist as part of running your estate. A provider that has to build them from scratch is telling you they were never built.
Asking for artefacts beats asking questions. A question invites an assurance, and assurances are free. A document has a date on it, names systems, and either exists or does not. That is why this audit is a request list rather than an interview.

The list below draws on CISA's published risk framework for MSP customers, which sets out what a customer should obtain from a provider. Each entry names the document, what a real one contains, and the answer that should worry you.
- Asset inventory. Every device, server, licence and cloud tenant, with owners.
- Network diagram. Current, dated, and showing where your network meets your provider's.
- Restore test report. A restore that was actually performed, with a date and a duration.
- Ticket and response record. Your own history, measured against the service levels you pay for.
- Incident response plan. Naming your people, not just the provider's process.
- Patch and vulnerability status. What is unpatched today, and the reason for each exception.
- Subcontractor and data-location disclosure. Who else touches your systems, and where your data sits.
- The provider's own security evidence. Attestations, insurance, and how client data is separated.
Why does asking for documents work better than asking questions?
Because documents carry dates and questions carry opinions. There is also a legal edge to it for many businesses. The FTC Safeguards Rule requires covered businesses to select service providers capable of maintaining appropriate safeguards, require those safeguards by contract, and periodically assess them. Periodic assessment is the phrase that matters, and an assessment without evidence is a conversation.
CISA reaches the same place from the security side, telling customers to secure the ability to examine the systems that directly and indirectly support the contracted service on demand. The stakes are ordinary rather than exotic. Verizon found vulnerability exploitation is the top initial access vector, at 31 percent of breaches, and IBM put the global average cost of a data breach at 4.99 million dollars. Both of those are governed by paperwork somebody was supposed to keep.
Document 1. Do you have a current asset inventory?
Ask for the list of what you own, and check the date on it. A real inventory names every workstation, server, network device, software licence and cloud tenant, and says who owns each one. CISA treats this as foundational, advising that risk management plans include an inventory of organizational assets and the degree to which each type of asset is exposed to risk.
The test is not whether a list appears. It is whether the list matches reality. Pick five things you know exist, a laptop issued last month, a server you decommissioned, a SaaS tool a department bought directly, and look for them. Inventories fail at the edges, and the edges are where unmanaged devices live.
Document 2. Is there a dated network diagram?
Ask for the diagram and look for two things: a date, and the boundary. A diagram without a date is a drawing from an onboarding project nobody has touched since. The boundary matters because it is where your provider's systems meet yours, and the advisory singles it out, telling organisations to audit their network infrastructure paying particular attention to systems on the MSP-customer boundary, to identify and disable unused systems and services.
A good diagram shows segmentation, the internet-facing services, and how remote access enters. If your provider cannot draw your network, it is operating it from memory.
Document 3. When was your last restore actually tested?
Ask for a restore test report, and refuse a backup report in its place. They are different claims. A backup report says a job ran. A restore report says the data came back, and records how long it took.

The guidance asks for the test, not the job. Organisations should regularly update and test backups, including gold images of critical systems in the event these need to be rebuilt. A gold image is the part most providers skip, because rebuilding a domain controller is harder than restoring a file.
Two numbers make the report real. The date of the last successful restore, and the elapsed time it took. If the answer is that restores are tested automatically, ask which system was restored, and when.
Document 4. What do your own ticket records show?
Ask for your ticket history with response and resolution times, measured against the service levels in your agreement. This is the one document you are entitled to without argument, because it is a record of your own requests.
CISA advises customers to obtain specific performance-related service level agreements, including a clear delineation of operational IT services and security services. That delineation is what to test against the data. Providers frequently meet a response target and miss a resolution target, and only the second one describes your Tuesday.
Look at the tail rather than the average. A median response of nine minutes alongside a handful of tickets open for three weeks is a different service from a steady two hours.
Document 5. Does the incident response plan name your people?
Ask to see the plan, then look for your own names in it. A provider's generic incident process is not the same as a plan for your business. The advisory expects the plan to include roles and responsibilities for all organizational stakeholders, including executives, technical leads and procurement officers.
Two further details separate a real plan from a template. It should have been rehearsed, because customers should ensure such plans are tested at regular intervals. And it should exist on paper, since organisations should maintain up-to-date hard copies so responders can access them if the network is inaccessible. A recovery plan stored only on the network you are recovering is not available on the day you need it.
Ask when the plan was last exercised, and what changed as a result.
Document 6. What is unpatched right now?
Ask for the current vulnerability and patch status, including the exceptions and the reason for each. Every estate has exceptions. A provider that reports none is not looking.

Judge the report on what it prioritises. CISA advises prioritising vulnerabilities listed in its catalogue of known exploited vulnerabilities rather than only those with high CVSS scores that may never be exploited. A report sorted purely by severity score is a report that has not been thought about.

Ask what the standing arrangement is, too. Customers should understand their provider's policy on software updates and request that comprehensive and timely updates are delivered as an ongoing service, which means patching is a contracted service rather than a favour done when someone remembers.
Document 7. Who else touches your systems, and where does the data sit?
Ask for the subcontractor list and the data locations in one request, because they answer the same worry. Your provider may not be the only party with access.

CISA tells customers to obtain notification of any sub-contracts and independent consultants that would potentially expose the organization's data to another external party, and separately to obtain documentation of vetting of employees, including subcontractors and independent consultants. The second request is the one providers rarely expect.
Then ask how you are kept apart from the provider's other clients. Customers should obtain a statement from the MSP on how data from different clients will be segmented or separated on the MSP's networks. A provider that has genuinely thought about this answers in specifics about tenancy and credentials.
Document 8. Can your provider evidence its own security?
Ask your provider to document its own posture, not just yours. The request is reasonable, since a compromise of your provider becomes a compromise of you.
Three artefacts do most of the work. An attestation or audit report covering how the provider runs its own environment. A current certificate of cyber liability insurance. And CISA's blunter one, documentation of the MSP's financial health, performance record for other clients, and disclosure of any previous legal issues, which reads oddly until you remember that a provider in difficulty is a provider about to have a service disruption.
Ask also for remediation acceptance criteria that define the steps the MSP will take to mitigate known risks. It converts we will look into it into a defined action with an end state.
What should you do with a document your provider cannot produce?
Set a date for it rather than treating the gap as a verdict. Several of these documents are ordinary to assemble in a fortnight, and a provider that produces six of eight quickly and commits to the other two in writing has behaved well.
Weight the gaps by consequence. A missing asset inventory or an untested restore is a live operational risk, because both describe work that is not happening. A missing subcontractor disclosure is a governance gap you can close with a clause. Fix the first kind now and the second at renewal.
Keep whatever arrives in a folder you control, dated. That folder becomes the periodic assessment the FTC Safeguards Rule asks covered businesses to perform, and it is the evidence you will want if you ever have to show that you exercised oversight.
The access side of this audit is separate and worth running alongside, since documents describe the work and credentials describe the reach.
FAQ
What documents should your MSP provide?
Eight cover the ground: an asset inventory, a dated network diagram, a restore test report, your ticket and response record, an incident response plan naming your staff, current patch and vulnerability status, a subcontractor and data-location disclosure, and evidence of the provider's own security posture. CISA's risk framework for MSP customers sets out most of these as things a customer should obtain from a provider.
Is a backup report the same as a restore test?
No. A backup report confirms a job ran and data was copied. A restore test confirms the data came back, and records how long it took to return. Only the second answers the question you care about on the day something fails. Ask for the date of the last successful restore and the elapsed time, and ask specifically whether a full system rebuild from a gold image has ever been tested rather than just individual file recovery.
Are you entitled to your own ticket history?
Yes in practice, because it is a record of requests your business made. Ask for response and resolution times against the service levels in your agreement, and read the tail rather than the average. Providers commonly hit a response target and miss a resolution target, and resolution is the number that describes how long your staff were actually unable to work.
How often should you ask for these documents?
Annually for the full set, and immediately after any incident. Businesses covered by the FTC Safeguards Rule have a firmer reason: the rule requires them to select service providers capable of maintaining appropriate safeguards, require those safeguards by contract, and periodically assess them. A dated folder of provider documentation is what that periodic assessment looks like in practice.
What if your provider says these documents are confidential?
Distinguish between the two kinds. Documents describing your own estate, your inventory, your diagram, your tickets, your restores, are yours and confidentiality does not apply. Documents about the provider's internal operations may genuinely be restricted, in which case an attestation, a summary report or a redacted version is the normal answer. A blanket refusal covering your own data is not a confidentiality position.
Sources
- CISA Insights, Risk Considerations for Managed Service Provider Customers (2 September 2021)
- CISA, NSA, FBI, NCSC-UK, ACSC, CCCS and NZ NCSC, Joint Cybersecurity Advisory AA22-131A, Protecting Against Cyber Threats to Managed Service Providers and their Customers (11 May 2022)
- Cornell Law School Legal Information Institute, 16 CFR 314.4, FTC Safeguards Rule, elements of an information security program
- Verizon, 2026 Data Breach Investigations Report, 19th edition (news release, 19 May 2026)
- IBM, Cost of a Data Breach Report 2026 (news release, 29 July 2026)
Best IT MSP is an independent directory of managed IT providers across the US and Canada. We rank on verified rating and firmographic data, we label paid placement, and we do not sell IT services.