If you run a managed IT shop in South or Central Florida, you have probably seen a new question show up in client renewals. A personal injury firm in Fort Lauderdale sends over a vendor questionnaire. A multi-location dermatology group in Tampa asks for your security documentation before signing a new business associate agreement. A wealth management office in Palm Beach says their compliance consultant wants your SOC 2 report on file. A year ago most of these clients took your word for it. Now they want something in writing from a CPA firm.
There is a reason for that. Your clients are being pushed by their own rules to check on the vendors who hold the keys to their systems, and an MSP holds more keys than almost anyone.
Each of the big client groups in Florida has its own pressure point. Financial firms covered by the FTC Safeguards Rule, which includes tax preparers, CPA firms, mortgage brokers and many investment advisers outside SEC registration, have to select service providers that can maintain appropriate safeguards, require those safeguards by contract, and periodically assess those providers based on the risk they present. That last part is where your SOC 2 request usually comes from.
Medical practices sign business associate agreements with their IT vendors under HIPAA. HHS proposed changes to the HIPAA Security Rule in January 2025 that would have business associates confirm their safeguards in writing on a regular basis. That rule is still a proposal, and the target date for a final version has slipped into 2027, but many practices and their attorneys are already writing similar language into new agreements. Healthcare clients working toward HIPAA/HITRUST certification face the same kind of vendor review from their assessors.
Law firms have Florida Bar guidance to point to. Ethics Opinion 12-3 says lawyers can use cloud and outside technology providers, but they have to do reasonable due diligence on those providers first. A SOC 2 report is one of the easiest ways for a firm to show it did that homework.
Put together, the client is not asking because a salesperson told them to. They are asking because someone above them will eventually ask what they did to check on you.
A SOC 2 report is issued by a licensed CPA firm under AICPA standards and measures your controls against the Trust Services Criteria. Security is required in every report. Most MSPs also add Availability if they promise uptime or recovery times, and Confidentiality if they handle sensitive client data, which nearly all of them do.
For an MSP, the audited system is not every client network you touch. It is your own control plane: the RMM platform, the PSA and ticketing system, backup and recovery tools, your security stack, the identity provider your technicians log in through, and the people and processes around all of it. Getting that scope right early saves a lot of time and money.
Once the scope is set, the auditor will spend most of their time on a few areas where MSPs tend to get written up:
Technician access. Who has admin rights into client tenants, whether those accounts use phishing resistant MFA, and whether someone actually reviews that access on a schedule and keeps proof that they did.
Offboarding. When a tech leaves, how fast their RMM, PSA, password vault and client tenant access gets shut off, and whether a ticket shows it.
Change management. Whether script pushes, patch policies and firewall changes go through a ticket with some kind of approval, or whether they happen on a Friday night with no record.
Vendors you depend on. Your RMM, backup and cloud providers are subservice organizations. You will need their SOC reports on file and a record that you reviewed them, because your clients are relying on that chain.
A Type 1 report looks at whether your controls are designed properly at a single point in time. A Type 2 report tests whether those controls actually worked over an observation period, usually somewhere between three and twelve months. Regulated clients and their auditors generally want Type 2. Some MSPs start with a Type 1 to lock in scope and give clients something now, then roll straight into a Type 2 period.
The order we suggest for most Florida MSPs is to do a readiness assessment against the criteria first, fix the gaps in access reviews, offboarding and change tickets, then start the observation window only once those controls are running every week. Starting the clock before the controls are steady is the most common way a first Type 2 report ends up with exceptions in it.
It also helps to be clear with clients about the timeline. Telling a client "our Type 2 period started in October and the report will be ready next year" is a perfectly good answer for most renewals, as long as you can back it up.
CMBNetworks helps South and Central Florida MSPs and IT providers with SOC 2 readiness, from drawing the right scope around your tools to getting controls running before the auditor starts the clock. The practice is led by a former SOC auditor and former HITRUST Lead Assessor, so we know what the testing will look like before it happens. Start a conversation.