MSP / MSSP Responsibility Matrix
Brilliant at the Basics Resource Center · brilliantatthebasics.us · published by inDirectIT, Inc.
Independent educational material. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Does not establish compliance, certification, or contractual standing.
Purpose
Most disputes between a contractor and its service provider are not about capability — they are about an assumption nobody wrote down. This matrix exists to be filled in together and signed.
How to use it
Complete one row per practice with both parties present. 'Accountable' can only ever be the contractor: a service provider can be responsible for doing the work, but accountability for the outcome does not transfer with the task. Where a cell is genuinely shared, write down the split rather than leaving it blank.
How to split the work
| Column | What it means | Typical answer |
|---|---|---|
| Implement | Who performs the initial build or configuration. | Often the service provider. |
| Operate | Who runs it day to day and responds when it breaks. | Often the service provider. |
| Evidence | Who produces and retains the artifacts that prove it operates. | Frequently unassigned — this is the row that causes trouble. |
| Accountable | Who answers for the outcome to a customer, an assessor, or a regulator. | Always the contractor. |
A provider can implement and operate a control perfectly and still leave you with nothing to show for it. Agree who exports the configuration, who retains the reports, where they are stored, and for how long — before the engagement starts, not during an assessment.
Responsibility matrix
| Practice | Track | Implement | Operate | Evidence | Accountable |
|---|---|---|---|---|---|
| IT-01 — Phishing-resistant MFA | IT | ||||
| IT-02 — Asset inventory | IT | ||||
| IT-03 — Technical debt reduction | IT | ||||
| IT-04 — Flexible technology stack | IT | ||||
| IT-05 — Logical segmentation | IT | ||||
| IT-06 — Risk-based vulnerability management | IT | ||||
| IT-07 — Security in the development lifecycle | IT | ||||
| IT-08 — Secure AI adoption | IT | ||||
| IT-09 — Backup and disaster recovery | IT | ||||
| IT-10 — Technical workforce readiness | IT | ||||
| OT-01 — OT identity and access control | OT | ||||
| OT-02 — Validated OT asset inventory | OT | ||||
| OT-03 — OT network segmentation | OT | ||||
| OT-04 — OT incident response and recovery | OT | ||||
| OT-05 — OT vulnerability management | OT | ||||
| OT-06 — OT remote access pathways | OT | ||||
| OT-07 — OT continuous monitoring | OT | ||||
| OT-08 — OT system resiliency | OT | ||||
| OT-09 — OT supply chain security | OT | ||||
| OT-10 — OT change review | OT |
Agreed by
| Name | Organization | Role | Date |
|---|---|---|---|
Limitations
This is independent educational material. It supports planning and evidence collection; it does not establish compliance with NIST SP 800-171, DFARS 252.204-7012, CMMC, export-control obligations, or any contract requirement, and it is not an assessment. Tailor every item to your own technical, operational, contractual, regulatory, and safety requirements.
Printing produces a paginated document. Choose “Save as PDF” in the print dialog and name it batb-msp-responsibility-matrix to keep filenames consistent across your team.