Supervising the IT Provider You Already Have
Almost everything written about managed IT providers is about choosing one. The frameworks treat the relationship as a lifecycle with a distinct monitoring stage, CISA added a goal for it in December 2025, and 15% of businesses have ever reviewed the suppliers they already use.

- NIST sequences the relationship as before, during and after entering it.
- The FTC's annual penetration test is a fallback, not the primary rule.
- CISA added an MSP supervision goal in December 2025 that did not exist before.
- 15% of UK businesses have ever formally reviewed their suppliers' cyber risk.
- No authority will name a review interval; the ones that do sell the software.
Why does choosing a provider get all the attention?
Choosing gets the attention because choosing is the part with a deadline. Selection has a decision date, a shortlist and a signature. Supervision has none of those, so it becomes the thing that happens if someone remembers. This article is about the part with no deadline.

The frameworks do not share that bias. NIST's Cybersecurity Framework 2.0 sequences the supplier relationship explicitly in time. One subcategory covers the work done before entering into formal supplier or other third-party relationships. A second covers risks monitored over the course of the relationship. A third covers activities that occur after the conclusion of a partnership or service agreement.
Three stages, and almost everything written for buyers concerns the first. The nine articles before this one were about the second, and the last of them was about the third.
What does monitoring a provider actually involve?
It involves four things, and NIST names them concretely rather than in the abstract. Evaluate the provider's evidence of compliance with contractual cybersecurity requirements, such as self-attestations, warranties, certifications, and other artifacts. Monitor them using inspections, audits, tests, or other forms of evaluation. Watch for changes to their risk profile. And verify that supplier access to organization resources is deactivated promptly when it is no longer needed.
Notice what the first of those means in practice. Evidence gets <strong>evaluated</strong>, not collected. A certificate in a folder is not the control. Reading it, and knowing what it covers, is the control.
Start by deciding which providers this applies to. NIST's framing is that suppliers are known and prioritized by criticality, which for most businesses is a short exercise. The firm holding privileged access to every system you own is the critical one.
The obligation is also meant to be written into the agreement rather than left to goodwill. NIST's own quick-start guidance advises defining security requirements in service level agreements for monitoring suppliers for acceptable security performance throughout the supplier relationship lifecycle.
How often should you review your IT provider?
No authority will tell you, and that is deliberate rather than an oversight. Four were asked for this article and four decline to name an interval.

The HIPAA Security Rule requires a periodic technical and nontechnical evaluation establishing the extent to which security policies and procedures meet the rule's requirements. The word is periodic and there is nothing after it. HHS then makes the trigger explicitly change-based, advising you to assess the need for a new evaluation based on changes to the security environment since the last evaluation.
NIST takes the same position from a different angle, advising that you adjust assessment formats and frequencies based on the third party's reputation and the criticality of the products or services they provide. Frequency is an output of how much the provider matters, not an input.
The UK NCSC gives the most practical answer available, which is to attach the review to a date that already exists: require contracts to be renewed at appropriate intervals, and require reassessment of associated risks at the same time. Your renewal date is already in the calendar. Put the review there.
Treat published cadences with suspicion. Every source we found offering a specific interval, such as critical vendors every three to six months, sells third-party risk management software, and none published a survey, a methodology or a sample size behind the number.
Why is annual testing the fallback rather than the rule?
Because the regulation prefers continuous monitoring and treats the calendar as what you owe when you do not have it. This is the most commonly misread provision in the whole area, and it is worth reading slowly.
The FTC Safeguards Rule requires that monitoring and testing include continuous monitoring or periodic penetration testing and vulnerability assessments, with annual penetration testing required only absent effective continuous monitoring. The annual test is the substitute. Where there is no continuous monitoring, the rule then requires vulnerability assessments at least every six months and whenever there are material changes to operations or business arrangements.
The same rule closes the loop, requiring you to evaluate and adjust the information security program in light of testing results, material changes to operations or business arrangements, and risk assessment results. Monitoring that changes nothing is not monitoring. It is record-keeping.
It also puts providers on the agenda at the top. The rule requires a written report to the board or governing body regularly and at least annually, and names <strong>service provider arrangements</strong> among the matters that report must address. Provider oversight is treated as governance, not procurement.
One carve-out matters for smaller readers, and skipping it would misstate the law. The annual penetration test, the semi-annual vulnerability assessment and the annual board report do not apply to financial institutions maintaining customer information concerning fewer than five thousand consumers. What still applies to everyone covered is the periodic risk reassessment, the periodic review of access controls, regular testing, periodic assessment of service providers, and the duty to evaluate and adjust.
What changed in December 2025?
CISA added a goal about supervising managed service providers, and it had not been there before. The Cybersecurity Performance Goals 2.0, published on 11 December 2025, set the outcome that the risks posed by a managed service provider are identified, recorded, assessed, prioritized, monitored, and updated over the course of the relationship.

The previous baseline had nothing equivalent. The superseded v1.0.1 goals contained no managed service provider goal, and their three third-party goals covered incident reporting, vulnerability disclosure and procurement requirements. Every one of those is about buying something or about being told something. None is about supervising a firm that already runs your systems.
CISA is direct about why it changed, stating that new goals were added to address emerging threats including cybersecurity oversight and risks associated with managed service providers. A national cyber defence agency reviewed its own baseline, found a gap, and the gap was this one.
The recommended action is close to a summary of this whole series: develop and maintain an understanding of the services provided by MSPs, understand contractual agreements, and proactively address security gaps that fall outside the scope of the contract. Note the last clause. The gaps that matter are the ones the contract does not cover.
CISA also rates the goal Moderate cost, Moderate impact and Complex to implement. That honesty is worth matching. This is not a quick win, and anyone selling it as one is selling something.
One naming caution, because it will trip you up. Cite this as CPG 2.0 goal 1.E. In the older v1.0.1 numbering, 1.E is a completely different goal about known vulnerabilities, and both documents are still live.
How many businesses actually do this?
Very few, and the best measurement of it is a government statistic rather than a vendor survey. The UK Cyber Security Breaches Survey found that 15% of businesses had carried out work to formally review the cyber risks posed by their immediate suppliers, and 6% had reviewed their wider supply chain.

Read that number precisely, because the precise version is worse. The survey asks whether an organisation has <strong>ever</strong> done this, not how often. So it does not describe a cadence problem. Roughly six in seven businesses have never formally reviewed the cyber risk of suppliers they already use. It is also a question about all suppliers rather than IT providers specifically.
Size predicts it strongly. 48% of large businesses reviewed the risks posed by immediate suppliers, against 22% of small businesses and 12% of micro businesses, which is the pattern you would expect when the work depends on having someone whose job it is.

It is not improving. The question has been asked since the 2019/2020 study and remains relatively stable at the overall level. Six years, no movement. The related finding is just as flat: only 11% of businesses required suppliers to hold any standards or accreditations, and 3% required Cyber Essentials specifically.
The figures are worth trusting because of how they were produced. This is an Official Statistic built on a strict random probability telephone survey of 2,112 businesses and 1,085 charities, with fieldwork from August to December 2025, published by a government department rather than by anyone selling a remedy.
The UK's national cyber authority reaches the same conclusion in its own current guidance, stating plainly that many companies lose sight of their supply chains.
What is the right to audit worth if you never use it?
Nothing, and the NCSC says so in the same breath as recommending it. Its guidance advises you to build the right to audit into all contracts and exercise it, and require your suppliers to do the same for contracts relating to your own.
Those last three words carry the argument of this entire series. A national cyber authority writing guidance for organisations anticipated the failure mode and named it inside the recommendation. The clause gets negotiated, signed and never invoked.
The same guidance treats access as recurring rather than settled, advising that accesses provided to a supplier's people and systems be reviewed periodically and removed when no longer required. That is the first article in this series restated as a standing obligation, which is exactly the point.
Regulators may soon put a number on one piece of this. A proposed HIPAA rule published in January 2025 would require written verification from a business associate at least once every 12 months that it has deployed the required technical safeguards, supported by a written analysis by a person with appropriate knowledge and experience, plus a written certification by a person with authority to act for the business associate. Treat that as proposed rather than current: it remains a proposed rule and has not been finalised.
The standards bodies point the same way. ISO/IEC 27001:2022 contains an Annex A control numbered 5.22, titled Monitoring, review and change management of supplier services, separate from the controls covering selection and contracting. The control's text sits behind a paywall, so the title is all we cite, and the title alone makes the point: monitoring supplier services earned its own control.
What should you actually put on the calendar?
Put the nine checks from this series on your contract renewal date, and treat that date as the review rather than a paperwork deadline. Each one produces an artefact or a written answer, so the meeting has an output.

- Access. Who at the provider can reach what, and whether anyone who left still can.
- Documentation. Whether what you hold still matches what is running, and the date it was last refreshed.
- Incident response. The last test, with a date, and what it found.
- Scope. What the contract covers, and the written list of what it does not.
- Subcontractors. Who else touches your systems, and under what terms.
- Detection. What is actually monitored, and whether you would be told.
- Licences and billing. What you pay for against what you use.
- Their own security. The provider's posture, and what its certificates really scope.
- Exit readiness. Whether you could leave, tested rather than assumed.
None of this presumes your provider is failing. Most are not. The discipline exists because the alternative is finding out during an incident, which is the most expensive moment to learn anything.
Keep the effort proportionate to what the provider holds. If they have privileged access to everything you own, they are the critical supplier, and the framework language about criticality is telling you where to spend the afternoon.
And set the bar at the artefact rather than the assurance. Every check above is written to produce something you can read: a date, a list, a report, a name. A provider that answers all nine well has earned the trust you were extending anyway. One that cannot answer any of them has just told you something you needed to know.
FAQ
How often should a business review its managed IT provider?
No authority names an interval, and that appears to be deliberate. HIPAA requires a periodic evaluation and stops there. HHS advises assessing the need for a new evaluation based on what has changed since the last one. NIST advises adjusting frequency based on the criticality of the products or services the third party provides. The most practical answer comes from the UK NCSC, which advises requiring contracts to be renewed at appropriate intervals and requiring reassessment of the associated risks at the same time. Every source we found offering a specific number of months sells third-party risk management software and published no methodology behind it.
Does the FTC Safeguards Rule require annual penetration testing?
Only as a fallback. The rule requires continuous monitoring or periodic penetration testing and vulnerability assessments, and the annual penetration test plus semi-annual vulnerability assessment apply absent effective continuous monitoring. The rule's preference is ongoing monitoring, with the calendar as the substitute. Those provisions, along with the annual board report, also do not apply to financial institutions maintaining customer information concerning fewer than five thousand consumers.
What did CISA change about managed service providers in 2025?
It added a goal that had not existed before. Cybersecurity Performance Goals 2.0, published 11 December 2025, includes goal 1.E, setting the outcome that risks posed by a managed service provider are identified, recorded, assessed, prioritized, monitored, and updated over the course of the relationship. The superseded v1.0.1 baseline had no MSP goal at all; its three third-party goals covered incident reporting, vulnerability disclosure and procurement. Cite it as CPG 2.0 goal 1.E, because 1.E in the older numbering is a different goal about known vulnerabilities.
How many businesses formally review their suppliers' cyber risk?
15% of UK businesses have carried out any formal review of the risks posed by their immediate suppliers, and 6% have reviewed their wider supply chain, according to the Cyber Security Breaches Survey, an Official Statistic based on a random probability survey of 2,112 businesses. The question asks whether it has ever been done rather than how often, so the finding is that roughly six in seven businesses have never done it. It also covers all suppliers rather than IT providers specifically.
Is my IT provider required to prove its security every year?
Not at present, in most cases. A proposed HIPAA Security Rule published in January 2025 would require written verification from a business associate at least once every 12 months that it has deployed the required technical safeguards, with a written analysis and a certification signed by someone authorised to act for the provider. That remains a proposed rule rather than law. Outside it, recurring proof is a matter of what your contract requires, which is why the NCSC advises building a right to audit into contracts and actually exercising it.
Where should provider oversight sit inside a business?
With whoever owns risk, not with whoever owns the relationship. The FTC Safeguards Rule requires a written report to the board or equivalent governing body regularly and at least annually, and names service provider arrangements among the matters that report must address. That places provider oversight in governance rather than procurement. For a smaller business without a board, the equivalent is a named senior person who reads the answers and can act on them.
Sources
- NIST, The NIST Cybersecurity Framework (CSF) 2.0, NIST.CSWP.29 (26 February 2024)
- NIST, Cybersecurity Framework 2.0 Reference Tool, Core with Implementation Examples
- NIST Special Publication 1305, CSF 2.0 Quick-Start Guide for Cybersecurity Supply Chain Risk Management (October 2024)
- Electronic Code of Federal Regulations, 16 CFR 314.4, Elements (FTC Safeguards Rule)
- Electronic Code of Federal Regulations, 16 CFR 314.6, Exceptions (FTC Safeguards Rule)
- Electronic Code of Federal Regulations, 45 CFR 164.308(a)(8), Evaluation (HIPAA Security Rule)
- US Department of Health and Human Services, Summary of the HIPAA Security Rule
- Federal Register, HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information, proposed rule, RIN 0945-AA22 (6 January 2025)
- CISA, Cybersecurity Performance Goals 2.0 (11 December 2025), goal 1.E
- CISA, Cross-Sector Cybersecurity Performance Goals v1.0.1, the superseded baseline
- UK National Cyber Security Centre, Supply chain security guidance, the 12 principles (reviewed 22 October 2025)
- Department for Science, Innovation and Technology and Ipsos, Cyber Security Breaches Survey 2025/2026 (published 30 April 2026)
- Department for Science, Innovation and Technology and Ipsos, Cyber Security Breaches Survey 2025/2026: technical report
- ISO, ISO/IEC 27001:2022, catalogue record and Online Browsing Platform
Best IT MSP is an independent directory of managed IT providers across the US and Canada. We rank on verified rating and firmographic data, we label paid placement, and we do not sell IT services.