Industry Standard · Version 4
Unified Certification Standard for Cloud and Managed Service Providers
The first compliance framework purpose-built for managed service providers. Five domains, ten objectives, 72 requirements — published in full, free to read, no signup.
Effective July 1, 2026 · Published at mspalliance.org

MSPAlliance.org is the source of truth for the UCS — the complete Version 4 text, all 72 requirements, searchable and always current.
Open the standardThe Framework
What Is the UCS?
Most compliance frameworks target enterprise IT. The UCS was purpose-built for managed service providers.
Purpose
A single, comprehensive framework addressing the unique operational, security, and service delivery requirements of managed service providers.
Foundation
Built on globally recognized standards including ISO, NIST, and SOC frameworks — adapted specifically for the MSP business model.
Implementation
An independent auditor works through the requirements to verify the organization seeking certification. MSPs use the same text to prepare for the examination.
Assessment Areas
The Five UCS Domains
Every requirement in the standard rolls up to one of five domains. Open any domain to read its full text on MSPAlliance.org.
Expertise
Whether the provider can define, manage, and sustain the services in its scope — strategic planning, configuration management, controlled change, patching, operational review, and recovery testing.
Trust
How the provider demonstrates reliability and accountability to customers — internal audit, service transition, capacity management, problem resolution, secure remote access, and customer reporting.
Resilience
The ability to prepare for, withstand, and recover from disruption — governance and risk management, incident response, personnel screening, access revocation, backup and recovery, and business continuity.
Transparency
What the provider documents and discloses — policy governance, data geolocation, external service provider access, service-level categorization, accurate invoicing, and revenue concentration risk.
Security
How identities, systems, and data are protected — evaluation and governance of external providers including cloud, SaaS, and AI-enabled services, plus encryption of confidential and customer data.
The Detail
Ten Objectives, 72 Requirements
The domains break down into ten objectives, and each objective into the specific requirements an auditor verifies.
Framework Overview
The UCS at a Glance

Read the complete UCS
All five domains, ten objectives, and 72 requirements — published in full at MSPAlliance.org. Free, ungated, and always the current version.