Screenata

Beyond SOC 2

What is a CSP vs MSP?

August 22, 20263 min read

What is a CSP vs MSP?

A CSP (cloud service provider) sells cloud infrastructure and platforms that you operate yourself; AWS, Microsoft Azure, and Google Cloud are the three largest. An MSP (managed service provider) operates IT on your behalf, often building on or reselling a CSP's services. In short: a CSP gives you the environment, an MSP runs an environment for you. The next term you will hit is MSSP, a managed security service provider, which is an MSP specialized in security operations.

The three terms side by side

CSPMSPMSSP
What they sellCloud infrastructure and platform services (compute, storage, databases)Operation of your IT: cloud management, help desk, patching, backupsSecurity operations: monitoring, detection and response, SIEM, often a 24/7 SOC
ExamplesAWS, Microsoft Azure, Google CloudRegional IT firms, cloud consultancies, AWS and Azure partner MSPsArctic Wolf, Secureworks, security arms of large MSPs
Your compliance relationshipYou inherit controls; their SOC 2 or ISO 27001 covers the infrastructure layer under shared responsibilityVendor and usually subprocessor; belongs in your vendor register and TPRM reviewsVendor with privileged security access; highest-scrutiny tier of vendor review

The lines blur in practice. Many MSPs resell CSP capacity, hold administrative access to your CSP accounts, and bundle MSSP-style monitoring. What stays fixed is the relationship: the CSP is a platform you build on, while MSPs and MSSPs are companies acting inside your environment on your behalf.

The Microsoft "CSP" confusion

In Microsoft's ecosystem, CSP also stands for Cloud Solution Provider, Microsoft's reseller program. A company enrolled in it resells Microsoft 365 and Azure subscriptions, usually bundled with management services. So a Microsoft "CSP partner" is, in the generic vocabulary, an MSP reselling a CSP. If a vendor introduces itself as "a CSP," ask whether it means it operates a cloud platform or resells Microsoft licensing; the compliance treatment differs completely, because one is an infrastructure provider you inherit controls from and the other is a service vendor you must assess.

Why the distinction matters for compliance

Under the shared responsibility model, a CSP is responsible for security of the cloud (physical data centers, hardware, the hypervisor) and you are responsible for security in the cloud (your configurations, access, data). In a SOC 2 or ISO 27001 audit, you inherit the CSP's infrastructure-layer controls by relying on its own audit reports; the major CSPs publish SOC 2 reports for exactly this purpose. You do not audit AWS; you collect its report and carry your side of the responsibility split.

An MSP sits on the other side of the line. It works inside your responsibility zone, often with administrator access, which makes it a vendor and usually a subprocessor of your customer data. That places it in your vendor register, subject to your third-party risk management process: collect its SOC 2 or equivalent, review it at least once a year, and bind it with a contract and, where personal data is involved, a data processing agreement. Your own SOC 2 report will then treat the MSP as a subservice organization, disclosed under the carve-out or inclusive method.

The practical summary: a CSP reduces your control surface because you inherit the layers it operates, while an MSP expands your vendor risk surface because a third party now acts with your privileges. Both can be the right choice; they just land in different sections of your compliance program. For how the relationship looks from the MSP's side, see how an MSP should manage compliance evidence for multiple clients.

Connect and see

See your SOC 2 with your real systems.

Connect GitHub and cloud read-only. Vera shows your control matrix, policy gaps, and prioritized next actions before you commit to anything.