The Attestation Letter Your MSP Should Be Willing to Sign

Share this post on:

Cyber insurance carriers have spent two years tightening their requirements, and a documented trend in 2025 and 2026 underwriting is the demand that a business’s IT provider attest, in writing, that named security controls are actually in place. Coalition’s 2026 Cyber Claims Report shows misconfigured or unverified controls are among the leading causes of denied or reduced payouts. An MSP that receives that attestation request from a client’s broker has two paths.

The MSP had two paths. Sign, and take on legal exposure for the accuracy of every line on the application. Refuse, and hand the client back a form they now had to fill out themselves without the person who actually deployed the controls being on record.

The MSP attestation letter is not going away. Carriers are moving toward it because the industry finally learned that a business owner attesting to their own security posture is not the same as evidence. And every MSP that intends to survive the next decade has to have a defensible answer for what they are, and are not, willing to sign.

Why the MSP Attestation Letter Exists Now

The rise of the attestation letter is a direct consequence of the last three years of denied claims. Coalition’s 2024 Cyber Claims Report found that 82 percent of denied claims involved organizations without properly implemented MFA across their environment.1 The precedent set in Travelers v. International Control Services in 2022 established that a carrier can rescind a policy over material misrepresentation on the application regardless of intent. Underwriters looked at those two data points and decided the client’s word alone was not enough.

The attestation letter closes the gap. If the client is going to sign the application, and the MSP is the one who deployed the controls, the carrier wants both signatures. The client attests to the business context. The MSP attests to the technical implementation. If the two conflict at claim time, the carrier has a specific person to point at.

The MSP attestation letter is not a paperwork chore. It is a legal document. Treating it like a favor for the client will get an MSP into more trouble than it saves.

What the Attestation Letter Actually Covers

Different carriers ask for different scopes, but a modern MSP attestation letter typically confirms the following in specific, verifiable terms:

  • Multi-factor authentication is enforced on every account listed on the application, with the form of MFA named (authenticator app, hardware key, or SMS, the last of which is increasingly disqualifying on its own).
  • Endpoint detection and response is deployed on every endpoint and every server, with the product named and monitored by a specific SOC or MDR provider on a 24/7 schedule.
  • Backups are immutable, isolated from production credentials, and restore-tested with a documented date within the required interval.
  • Email authentication is deployed with SPF, DKIM, and DMARC configured, and DMARC policy is at reject rather than monitor.
  • Security awareness training is delivered on a documented schedule with tracked completion.
  • Patch management operates against a defined SLA, with critical patches deployed within a stated timeframe.
  • An incident response plan exists and has been tested within a stated period.

Every item on that list is either provable with an export, a log, or a document, or it is not. What the letter does is force the MSP to be on record about which of those they can prove.

What Your MSP Should Be Willing to Sign

If an MSP intends to be in business in five years, the honest answer to “will you sign this” is not always yes. It is not always no either. It is a defensible framework that separates what the MSP can attest to from what the MSP cannot.

Sign what you deployed and can prove. If MFA is enforced across every account with phishing-resistant methods, and the export from Entra shows it, sign that line. If EDR is on every endpoint and every server, and the RMM inventory reflects it, sign that line. Anything with a provable configuration and an evidence artifact is signable.

Do not sign what the client controls. If the client’s staff go around the security awareness training, that is not the MSP’s material representation. If the client insists on keeping an unmanaged BYOD device outside the RMM inventory, that device is outside the attestation. Draw the line in writing, in the letter, and make the exclusions explicit.

Attest only for the date the letter is signed. Cyber controls drift. New endpoints join the environment. New service accounts get created without MFA. New OAuth apps get consented to. An attestation letter is a snapshot. Say so on the letter. Recommend a follow-up attestation cadence tied to renewal.

Refuse to attest to controls you did not verify recently. If the MSP is asked to sign for the client’s identity provider configuration and has not audited it in the last 90 days, saying “yes” is a legal representation the MSP cannot defend. Fix the audit gap or write the exclusion into the letter.

The Operational Side of the Letter

The attestation letter is not a document that gets drafted at renewal time. It is the output of a system that has to run all year, or the MSP will not have the evidence to write it honestly.

A control matrix per client. The list of policy questions the carrier will ask, mapped to the specific deployment in the client’s environment, with a link or reference to the evidence. Ninety percent of the letter is already written the day the matrix is up to date.

Quarterly control audits. Not a full pen test. A structured internal review of the controls the attestation letter covers, with findings and remediation. This is the audit trail that lets the MSP sign the letter without hedging.

Errors and omissions coverage that anticipates attestation. The MSP’s own insurance needs to cover the exposure the attestation letter creates. Read the E&O policy with this scenario in mind. Do it before signing anything, not after.

A client conversation before the renewal. If the client’s environment is 80 percent of what the carrier is asking for, that gap is the last agenda item on the pre-renewal call, not the first surprise on the day the application is due.

The Strategic Value of Being Willing to Sign

An MSP that can produce a defensible MSP attestation letter has done something most of the competition cannot. They have built the operational discipline that makes the letter possible in the first place. The letter is downstream of the work. What upstream discipline created it is what a serious client is really paying for.

The MSPs that refuse to sign anything are protecting themselves from a specific legal exposure and creating a different one, the exposure of losing every client whose cyber policy application asks for a signature they cannot provide. The MSPs that sign everything, indiscriminately, are trading a short-term client win for the specific liability the Travelers v. ICS ruling made real. The right position is in the middle. Sign what you can prove. Exclude what you cannot. Do it in writing.

Where This Leaves You

The MSP attestation letter is a legal document, an operational scorecard, and a strategic differentiator all at once. It is also, if handled poorly, a set of legal exposures a professional operator does not want.

The MSPs that treat the MSP attestation letter as a discipline rather than a chore will keep more clients, close more high-value engagements, and stay out of the courtroom stories the industry is going to write about the next five years of cyber insurance litigation. The MSPs that keep dodging the question will find out at renewal time which of their clients had already decided to leave.

Draft the letter. Review the exclusions. Set the audit cadence. Make it a service, not a favor.

Sources

1 Coalition, “The State of Active Insurance: 2024 Cyber Claims Report,” coalitioninc.com.

About Brent Lacy: Brent Lacy has been in the IT industry since 1997. He moved into the managed services world around 2015 and was doing vCIO work before the title even existed. He writes about the operational discipline, trust-based relationships, and strategic thinking that separate MSPs built to last from those built to bill. He is the author of Rewired MSP: Mastery, Scalability and Performance, vCIO Rewired: Virtually Conquering IT Obstacles, and Near Miss: Preventable IT Failures Threatening Your Business Security.

Leave a Reply