MSP Field Guide

Should a managed service provider get SOC 2?

October 10, 2026

Short answer

Probably yes if an MSP’s clients are regulated or the owner plans to sell, and probably later if neither is true. SOC 2 is useful to an MSP for two separate reasons: clients in financial services and similar fields ask for it, and an outside audit of the MSP’s own processes is something a strategic buyer values. It is not free in time or attention, so the honest test is whether a specific client, a specific deal, or a specific exit plan is waiting on it. Bright Bear Technology Solutions held its own SOC 2 while serving financial services firms, and Nathan Phinney has led 17 SOC 2 initiatives across six companies.

What Phinney learned doing it

Bright Bear focused on financial services, especially escrow firms, and held its own SOC 2 report; CRN called it a certification. CRN reported in July 2020 that Phinney called that unusual for a company of Bright Bear’s size. On the acquisition, Phinney told CRN:

“We both had an emphasis on security,” he said. “Datapath had more of a focus in government and education. It made sense to put the two together. We’re big in some competencies they didn’t focus on before, and vice versa.”

After Bright Bear, Phinney led SOC 2 compliance work at Datapath, directed a SOC 2 program at Innovation Refunds that closed with no exceptions, and led a SOC 2 audit at AllSafe IT, where he is COO, that also closed with no exceptions. Across all of it, his profile counts 17 SOC 2 initiatives across six companies, never an exception on an effort he led. A Bigleaf Networks case study on Innovation Refunds noted that the company had recently earned its AICPA SOC 2 attestation, “allowing Innovation Refunds to work directly with banks and other financial service providers.”

When CRN covered Convilo at XChange NexGen 2024, Phinney described why he pushes SOC 2 on the MSPs he works with:

“A lot of is having your processes in order, which is something that SOC 2 can help with, because you’re bringing in someone outside the organization to audit them and validate that they’re doing all the things they’re supposed to be doing. That’s valuable to a strategic buyer. And it’s a pleasure getting to be on the other side of it and to get to talk with people about how to get where they want to go with what they’ve been doing.”

The work is not light. In Chapter 1 of CTRL ALT SURVIVE, Phinney lists what he was carrying in 2020, and SOC 2 Type II reports with hundreds of documentation requests sit on that list beside payroll, sales targets, a relentless ticket queue, and the diligence for selling the company.

How the escrow vertical grew

Chapter 7 of the book, Focus, tells how the escrow specialty began. The first escrow company Bright Bear worked with found it through a Google search, which Phinney says was one of the only times organic search ever produced a client. Within a few months Bright Bear was working with that client on SOC 1 and SOC 2 compliance, the AICPA reporting frameworks for service organizations (the book describes them as designed for financial institutions and their service providers), and Phinney writes that learning to do it proved important later.

Separately, that client’s CFO moved to another escrow company that also needed IT help; because escrow officers change firms often, others followed, and before long Phinney was speaking to escrow officers at conferences about IT security. Escrow firms began seeking Bright Bear out. Each new one made the firm more valuable to the next, because these accounts came with real security, compliance, and business problems that required specialized knowledge. By the time of the sale, the book says (Chapter 11), Bright Bear served two of the largest escrow companies in Southern California and many of the smaller ones.

The standard carried down to the smallest clients. Bright Bear’s firewall configuration passed an annual penetration test by a certified ethical hacker and protected billions of dollars of transactions on public and private networks, in the book’s words, and small clients got the same firewall whether or not they knew any of that.

The vertical also brought emergencies. Chapter 7 includes a morning when an escrow company’s executives and a regional bank’s security team called Phinney together, demanding that the client’s email be shut down and audited after a fraudulent wire request. How he ended the call, and the rule he set for every email that client sent the bank from then on, is one of the more useful stories in the book for an MSP that serves financial services. In Chapter 7, Phinney sums up what the escrow work did for him: “I was becoming perceived as an expert, because I had learned to be specific.”

What a SOC 2 report is, and why buyers read it

This section is general background on SOC 2 reports, not Phinney’s account. An auditor does not grade an MSP’s tools. A SOC 2 report is an attestation from an independent CPA firm about whether the company’s controls meet the AICPA Trust Services Criteria it chose to include, which always cover security and may add availability, confidentiality, processing integrity, and privacy. A Type I report covers the design of the controls at a point in time. A Type II report covers whether they operated over a review period, and it is commonly the one clients and buyers ask for.

In practice an auditor asks for evidence that what the written policies say is what the people do: access that is granted and removed on a schedule, changes that are reviewed before they are made, vendors that are assessed, incidents that are logged and followed up, and training that is recorded. For an MSP that also means showing how it protects access to its clients’ systems, since it holds the keys to them.

A buyer reads the same report as a shortcut. It tells the buyer that an outsider has already examined the processes, which is the point Phinney made to CRN.

In the book

Chapter 7, Focus, covers how Bright Bear’s SOC 1 and SOC 2 work with its first escrow client grew into a specialty in escrow companies, and the wire-fraud scare that tested it. Chapter 1, The Bear Who Wanted To Be A Bear, mentions the SOC 2 Type II documentation load Phinney carried in 2020 while selling the company. The book does not walk through running an audit; the section on what a SOC 2 report is is general background, not Phinney’s account.

Sources

Frequently asked questions

Should a managed service provider get SOC 2?

If the MSP serves regulated clients or expects to sell the business, it is worth serious consideration. Bright Bear served financial services firms, especially escrow companies, and held its own SOC 2, and Nathan Phinney told CRN it helps because an outside auditor validates the processes, which is valuable to a strategic buyer.

What is a SOC 2 report?

It is an attestation report from an independent CPA firm on how a company's controls meet the AICPA Trust Services Criteria. A Type I report covers the design of controls at a point in time; a Type II report covers whether they operated over a period.

Did SOC work play a part in Bright Bear's escrow specialty?

Phinney says Bright Bear began SOC 1 and SOC 2 work with its first escrow client within months, and that learning it 'proved to be important later.' The book credits the specialty to referrals as escrow officers changed firms and to his talks at escrow conferences.

How many SOC 2 efforts has Nathan Phinney led?

His profile lists 17 SOC 2 initiatives across six companies, with no exception on any effort he led.

All guides