Why regulated clients ask harder security questions

Regulated clients are asking UK MSPs harder security questions, pushed by DORA, NIS2 and the FCA. The MSPs that win are the ones who can prove it on the spot.

A financial services client just sent your team a 40-tab security questionnaire, and half the questions weren't there last year. Their regulator is reaching through them, into you. The MSPs that win the account are the ones who can answer on the spot, with evidence.

Why are regulated clients asking so many security questions?

Because their own rulebooks changed. An FCA-regulated firm, an insurer, an NHS trust, a law firm holding client money: each one carries a duty to manage the risk sitting in its suppliers. You are a supplier. When their auditor asks how they control third-party risk, your MSP contract is one of the answers they have to give.

So the questionnaire lands on you. Access controls, backup testing, incident response times, joiner-mover-leaver process, evidence of the last time you actually restored from backup. The questions got sharper because the people asking them are now personally accountable for the answers.

What's actually driving the acceleration?

Two regulations from across the Channel are doing a lot of the work, even for UK firms.

DORA (the Digital Operational Resilience Act) has been in force since January 2025. It's an EU regulation covering financial entities and the critical ICT third-party providers they depend on. NIS2 is the EU directive that widens the old NIS scope to pull supply chains into the frame.

Neither one automatically binds every UK MSP. But plenty of your clients are caught, or they serve someone who is, or their group has an EU entity. The UK has its own regime pushing in the same direction. The effect on the ground is the same: your clients are being told to prove their suppliers are safe, and they can only prove it by asking you.

If a client is regulated, or sells to someone who is, third-party risk rolls downhill until it reaches the smallest supplier who can't push back. That's usually the MSP.

This trend rewards MSPs who can prove it

Here's why the harder questions are good news for a good MSP. They work as a filter.

For years, every MSP in the room could say "yes, we take security seriously." The words were free. Now the client wants the receipt. Show me the policy. Show me the last restore test. Show me who has admin and when you last reviewed it.

An MSP that runs a tight shop loves that question, because it separates them from the one down the road who's winging it on price. The bluff stops working. The proof starts winning deals.

We built our whole business on that shift, so we're not neutral about it.

What do regulated buyers actually want to see?

They want evidence, dated and independent. A confident answer in a sales meeting doesn't survive contact with a procurement team that's been burned before.

Three things move the needle:

That last point is where most certificates fall down. A point-in-time certificate shows the day it was checked; Assurix proves it's still being maintained today.

How does an MSP answer with proof instead of promises?

This is why we built the Assurix Trustmark.

It's an independent, evidence-based certification for UK MSPs. Sixty-four controls, mapped to the NCSC Cyber Assessment Framework (CAF v4). All 64 have to pass. If something slips, you get 30 days to fix it, and if it's still failing after that, the Trustmark is publicly suspended. Reassessment runs annually, with continuous monitoring in between.

The scope is the MSP itself. So when a regulated client asks "can we trust the firm running our IT," the badge answers about your own business, front to back.

Proof, not promises.

When a client's questionnaire asks whether your security is independently verified, "yes, here's the Trustmark, and here's the live status page" is a very short conversation. That's the point.

What happens to the MSPs who can't answer?

They stall. The client asks for evidence, the MSP can't produce it fast enough, and silence reads as risk.

We've watched deals sit for weeks while an MSP tried to assemble paperwork they should have had ready. Meanwhile a competitor who'd done the work up front walked in, answered the questions in one meeting, and signed. Same service, same price bracket. The difference was proof on the table.

Worth saying plainly: the firms losing these deals often have decent security. They just can't show it on demand.

Start by finding your gaps

Find out how you'd score before a client does. Our free scorecard walks you through the questions regulated buyers are already asking, and tells you where the gaps are.

Check your readiness with the free scorecard.

Take the Proof Gap Scorecard

If you want the full breakdown of how to win work in financial services, healthcare, and legal, see the full playbook: how to win MSP deals in regulated sectors.

The harder questions aren't going away. Good. Let them do the sorting.

Related reading