
Updated standard recognizes MSPs as custodians of human and non-human identities protecting critical data, devices, and AI-enabled systems
LAS VEGAS, Sept. 17, 2026 /PRNewswire/ -- MSPAlliance, the world's largest vendor-neutral industry association and certification body for managed services and cloud computing professionals, today announced the availability of UCS 4.0, the latest version of the Unified Certification Standard for Cloud and Managed Service Providers. Effective July 1, 2026, the standard gives MSPs and cloud service providers a practical framework for governing AI-enabled services, privileged identities, and third-party providers while strengthening requirements for identity, access, external service providers, and management accountability.
MSPs are custodians of the human and non-human identities that connect people, devices, applications, service accounts, and AI agents to business systems. These identities often carry privileged access to customer data and infrastructure. When compromised or misused, they can provide a direct path to sensitive information, endpoints, cloud environments, and AI systems, enabling unauthorized access, data exposure, or harmful activity.
UCS 4.0 governs AI-enabled services through its established requirements for external service providers, identities, information systems, and devices. Providers of cloud, SaaS, managed, and AI-enabled services must be evaluated and approved by designated personnel before use, then reviewed periodically throughout the service lifecycle. Related requirements address controlled access, segregation of duties, continuing review of access rights, secure remote access, system logging, data protection, and management accountability.
"AI does not reduce the need for identity governance; it expands it," said Charles Weaver, CEO and co-founder of MSPAlliance. "MSPs already manage the credentials, permissions, devices, and platforms that determine who—or what—can reach customer systems. UCS 4.0 makes clear that AI agents and AI-enabled services must operate under the same expectations for approval, least privilege, monitoring, and accountability. If an identity can access data or take action, it must be governed."
UCS 4.0 AI Governance Requirements
- AI-enabled service provider governance: Providers of cloud, SaaS, managed, and AI-enabled services must be evaluated and approved by designated personnel before use, then periodically reviewed throughout the service lifecycle.
- Identity and access governance: The standard requires an identity and access management framework governing authentication, authorization, provisioning, verification, monitoring, and revocation across organizational and customer systems. These requirements apply to any identity or access mechanism used to reach protected data, systems, applications, or devices.
- Least privilege and segregation of duties: Access must be restricted to authorized personnel and separated by functional area to limit excessive authority, conflicts of responsibility, and misuse.
- Monitoring and evidence: Organizations must maintain documented, reviewable evidence of access controls, approvals, system activity, changes, periodic reviews, and revocations in accordance with applicable UCS requirements.
- Acceptable use and data protection: Organizations must define acceptable use, classify and protect sensitive information, apply encryption where available, and maintain safeguards that prevent unauthorized access or disclosure.
- Lifecycle accountability: Organizations must maintain accountability for AI-enabled services from approval through retirement. Access, changes, logging, data protection, and periodic reviews must remain documented and effective throughout the service lifecycle.
UCS 4.0 is organized into five Domains: Expertise, Trust, Security, Resilience, and Transparency. Together, these Domains group ten Objectives and 72 Requirements, including three SaaS special requirements, into a unified framework for evaluating how an MSP or cloud service provider governs its operations, protects organizational and customer information and identities, sustains service delivery, demonstrates accountability, and communicates material practices and performance. Each Domain contains defined Objectives and Requirements that an organization seeking certification must address and support with evidence during independent verification. Certification indicates that the organization has been independently evaluated against the applicable UCS requirements.
For MSP customers, UCS 4.0 provides a clearer basis for determining whether a provider can govern the identities, systems, and technology entrusted to it as AI becomes embedded in service delivery. For MSPs, the update integrates responsible AI adoption into an established control model rather than treating AI governance as a separate annual exercise. The result is a stronger shared-responsibility foundation for protecting users, data, devices, applications, and AI-enabled environments.
Availability
UCS 4.0 is now in effect and provides the requirements used in applicable MSPAlliance certification and independent verification activities. MSPs, cloud service providers, and their customers can view the full Unified Certification Standard Version 4 at MSPAlliance.org. Organizations can use the standard to assess operational maturity, organize evidence, strengthen customer assurance, and prepare for certification under the relevant MSPAlliance program.
About MSPAlliance
MSPAlliance is the world's largest vendor-neutral industry association and certification body for cloud computing and managed service professionals. Founded in 2000, the organization develops standards and certification frameworks for the managed services profession, including MSP Verify®, Cloud Verify®, and Cyber Verify®, and advances best practices in compliance, security, and operational maturity. MSPAlliance represents more than 30,000 members across dozens of countries and supports the profession through education, certification, advocacy, peer networking, and industry programs.
Media Contact
MSPAlliance
Celia Weaver, President
[email protected]
530-891-1340
SOURCE MSPAlliance
Share this article