8 reasons why IT providers struggle with compliance.

Achieving ISO certification is tough. It demands specialist knowledge, sustained effort, and somebody who owns it long-term, not just in name.

It’s not for the faint-hearted or time-poor.

But many MSPs still underestimate exactly how challenging and time-consuming the certification process is. As ISO certification specialists, we hear the same eight reasons why the MSP community so often struggles with DIY implementation.

We suspect most of them will be familiar.

1. "Yes, we know the requirements"

Reality check: You likely only know about a third of the Annex – and that doesn’t even touch the ISO Management Clauses 4 – 10.

The technological controls you know so well are listed in Annex A (ISO/IEC 27001:2022). But they represent only 34 controls out of 93, and often fewer in practice.

The other 59? They cover organisational, people, and physical controls. The organisational theme alone consists of 37 controls, more than the entire technological set.

Then there are the mandatory management clauses. Most IT providers struggle to conceive the deliverables, let alone articulate them. Knowing how to harden a tenancy doesn’t equip you to produce context, scope, a risk methodology, a Statement of Applicability, an internal audit programme, corrective actions or management reviews.

Overconfidence has a cost: it often delays discovering what you’re missing until the gap analysis, or worse, until your Stage 1 audit.

2. "But we have templates, we’ll be fine!"

Reality check: Relying on templates is problematic.

A toolkit that describes someone else’s organisation still requires someone to make it true. Templates written for a 500-person enterprise don’t fit a 15-person MSP.

As one of our clients put it, the difference in engaging us was that "rather than providing generic templates, ISO365 worked alongside us to build a management system that fits our business."

3. "One person got lumped with the job (but it needed a team)."

Reality check: When responsibility lands on the wrong seat, it consumes two or more other resources in its wake.

Typically, your Operations Manager or Senior Engineer draws the short straw and is tasked with getting the business over the ISO line. They’re handed 93 controls in a standard they’ve never seen before, including management clauses they aren't trained to implement.

So, like a black hole, they pull in people in their orbit to help get this over the line.

Now two or more of your senior people are on the implementation. Neither has a project plan. Neither has a strategy for this. They’re largely winging it. The upshot? Time and resources come directly out of the business, and your two senior managers take their eyes off the business-as-usual ball.

Make no mistake, people don’t like to fail – so they will drop their day job to make sure this project they’ve been handed doesn’t make them look bad. This means their day job goes out the window, indefinitely.

And getting certified is only the beginning. The maintenance of a management system post-certification means your internal team continues to own and spend time on it, something they never signed up for (or enjoyed). What’s worse, when they inevitably leave or retire, the system stops.

Case in point: one of our clients commented on the effort required to keep their ISO 9001 and 27001 running “especially after our internal quality manager retired.”

4. "Chargeable hours come before compliance."

Reality check: Internal work typically loses out to billable work.

Every hour on your own management system is an hour not billed to a client. In a services business, that results in one outcome – and it’s not a discipline or motivation problem.

As one client put it: without someone keeping them accountable internally, compliance always loses out to billable work.

In short, any plan that relies on your senior staff finding time for compliance efforts between client escalations has already failed.

5. "We’ll stick our most competent people on it; they’ll nail it in no time."

Reality check: Capable people are slow at governance work.

One MSP principal, after sitting through a monthly governance meeting, said to us: "What we did in one hour in our meeting the other day, I could only dream of for us. If that were one of my Account Managers, we would have been there for four hours."

Now, that’s not a comment about competence. Even the most capable people in your business are slower than normal when faced with unfamiliar work – wanting to absorb the details and implications and making sure they understand everything fully. That’s who they are, and what makes them good at what they do.

It just doesn’t necessarily make them the right people for unfamiliar work.

6. "We just need to find someone internally to take it on. Then, job done."

Reality check: Nobody actually wants the job. (They may just not want to say it to your face.)

One client was honest enough to tell us: "The ISO365 team is great to work with, and I don't want to do this work myself."

And why would they?

Audits, minutes, register hygiene, evidence filing, and version control are no one's idea of fun (unless you’re us). Nobody started an IT business to do this. Assigning it internally produces a system that looks staffed. It rarely is.

7. "We're on the journey."

Reality check: Write it once in a tender, and it buys time. Twice, and it burns credibility.

Saying ‘we’re on the journey’ for two years can cost you the thing you most want to protect: your credibility when it comes to your ability to deliver on time, in scope, and to budget.

It’s a phrase designed to defer a question rather than answer it honestly. The longer “we’re on the journey” remains the answer, the harder it becomes to account for your lack of progress.

And in a relationship-driven business, credibility is not easily recovered.

8. "No, we’re not certified. But we will be soon."

Reality check: The moment the question is asked, you’re already six months behind.

If you haven’t been asked the question yet, it may not have even occurred to you to worry about it. But that’s a trap.

When the inevitable happens, and a client, a tender, or an insurer asks you ‘that question,’ you’re already running late. And you’re not starting from zero, but at least six to twelve months late.

That’s because it takes that long to build and operate a management system to the point of certification. It’s time that can’t be compressed – there are no shortcuts. And so, when asked if you’re certified, your answer is ‘not yet’. And it stays that way for month after month, while everything else moves forward without you.

That ‘no, not yet’ has consequences beyond the certificate.

It dictates which tenders you can enter and those you must decline. It shapes which clients choose you and even which vendors will partner with you. Meanwhile, competitors who achieved certification 18 months ago are moving ahead.

This is when compliance stops being a decision and becomes a constraint on business strategy. It’s a constraint you can avoid, but only if certification starts well before the requirement arrives.

Knowledge isn’t the problem.

Most MSPs already have the technical capability required for ISO/IEC 27001:2022.

But what’s typically in short supply is time, the governance expertise to do it properly, and someone who will own it beyond the implementation phase. That’s why successful certification projects address more than controls. They address the operational realities that often prevent compliance efforts from gaining traction.

Producing a system that’s both effective and sustainable requires monthly reviews, risk guidance, internal audits and ongoing support.

Ask us how we can get you ISO certified within six months – and then keep you certified. 

Next
Next

ISO 9001:2026 is here.