Beyond SOC 2
What is a CSP vs MSP?
What is a CSP vs MSP?
A CSP (cloud service provider) sells cloud infrastructure and platforms that you operate yourself; AWS, Microsoft Azure, and Google Cloud are the three largest. An MSP (managed service provider) operates IT on your behalf, often building on or reselling a CSP's services. In short: a CSP gives you the environment, an MSP runs an environment for you. The next term you will hit is MSSP, a managed security service provider, which is an MSP specialized in security operations.
The three terms side by side
| CSP | MSP | MSSP | |
|---|---|---|---|
| What they sell | Cloud infrastructure and platform services (compute, storage, databases) | Operation of your IT: cloud management, help desk, patching, backups | Security operations: monitoring, detection and response, SIEM, often a 24/7 SOC |
| Examples | AWS, Microsoft Azure, Google Cloud | Regional IT firms, cloud consultancies, AWS and Azure partner MSPs | Arctic Wolf, Secureworks, security arms of large MSPs |
| Your compliance relationship | You inherit controls; their SOC 2 or ISO 27001 covers the infrastructure layer under shared responsibility | Vendor and usually subprocessor; belongs in your vendor register and TPRM reviews | Vendor with privileged security access; highest-scrutiny tier of vendor review |
The lines blur in practice. Many MSPs resell CSP capacity, hold administrative access to your CSP accounts, and bundle MSSP-style monitoring. What stays fixed is the relationship: the CSP is a platform you build on, while MSPs and MSSPs are companies acting inside your environment on your behalf.
The Microsoft "CSP" confusion
In Microsoft's ecosystem, CSP also stands for Cloud Solution Provider, Microsoft's reseller program. A company enrolled in it resells Microsoft 365 and Azure subscriptions, usually bundled with management services. So a Microsoft "CSP partner" is, in the generic vocabulary, an MSP reselling a CSP. If a vendor introduces itself as "a CSP," ask whether it means it operates a cloud platform or resells Microsoft licensing; the compliance treatment differs completely, because one is an infrastructure provider you inherit controls from and the other is a service vendor you must assess.
Why the distinction matters for compliance
Under the shared responsibility model, a CSP is responsible for security of the cloud (physical data centers, hardware, the hypervisor) and you are responsible for security in the cloud (your configurations, access, data). In a SOC 2 or ISO 27001 audit, you inherit the CSP's infrastructure-layer controls by relying on its own audit reports; the major CSPs publish SOC 2 reports for exactly this purpose. You do not audit AWS; you collect its report and carry your side of the responsibility split.
An MSP sits on the other side of the line. It works inside your responsibility zone, often with administrator access, which makes it a vendor and usually a subprocessor of your customer data. That places it in your vendor register, subject to your third-party risk management process: collect its SOC 2 or equivalent, review it at least once a year, and bind it with a contract and, where personal data is involved, a data processing agreement. Your own SOC 2 report will then treat the MSP as a subservice organization, disclosed under the carve-out or inclusive method.
The practical summary: a CSP reduces your control surface because you inherit the layers it operates, while an MSP expands your vendor risk surface because a third party now acts with your privileges. Both can be the right choice; they just land in different sections of your compliance program. For how the relationship looks from the MSP's side, see how an MSP should manage compliance evidence for multiple clients.