Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
MATRIX · IT / OTv1.0 · REVIEWED 2026-07-28

MSP / MSSP Responsibility Matrix

Brilliant at the Basics Resource Center · brilliantatthebasics.us · published by inDirectIT, Inc.

Independent educational material. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Does not establish compliance, certification, or contractual standing.

Purpose

Most disputes between a contractor and its service provider are not about capability — they are about an assumption nobody wrote down. This matrix exists to be filled in together and signed.

How to use it

Complete one row per practice with both parties present. 'Accountable' can only ever be the contractor: a service provider can be responsible for doing the work, but accountability for the outcome does not transfer with the task. Where a cell is genuinely shared, write down the split rather than leaving it blank.

How to split the work

ColumnWhat it meansTypical answer
ImplementWho performs the initial build or configuration.Often the service provider.
OperateWho runs it day to day and responds when it breaks.Often the service provider.
EvidenceWho produces and retains the artifacts that prove it operates.Frequently unassigned — this is the row that causes trouble.
AccountableWho answers for the outcome to a customer, an assessor, or a regulator.Always the contractor.
Evidence is the column that gets skipped

A provider can implement and operate a control perfectly and still leave you with nothing to show for it. Agree who exports the configuration, who retains the reports, where they are stored, and for how long — before the engagement starts, not during an assessment.

Responsibility matrix

PracticeTrackImplementOperateEvidenceAccountable
IT-01 — Phishing-resistant MFAIT    
IT-02 — Asset inventoryIT    
IT-03 — Technical debt reductionIT    
IT-04 — Flexible technology stackIT    
IT-05 — Logical segmentationIT    
IT-06 — Risk-based vulnerability managementIT    
IT-07 — Security in the development lifecycleIT    
IT-08 — Secure AI adoptionIT    
IT-09 — Backup and disaster recoveryIT    
IT-10 — Technical workforce readinessIT    
OT-01 — OT identity and access controlOT    
OT-02 — Validated OT asset inventoryOT    
OT-03 — OT network segmentationOT    
OT-04 — OT incident response and recoveryOT    
OT-05 — OT vulnerability managementOT    
OT-06 — OT remote access pathwaysOT    
OT-07 — OT continuous monitoringOT    
OT-08 — OT system resiliencyOT    
OT-09 — OT supply chain securityOT    
OT-10 — OT change reviewOT    

Agreed by

NameOrganizationRoleDate
    
    

Limitations

MSP / MSSP Responsibility Matrix · version 1.0 · reviewed 2026-07-28 · file name batb-msp-responsibility-matrix

Generated from IT Top 10, OT Top 10 at brilliantatthebasics.us. The live pages carry the current version of this guidance.

Independent educational material published by inDirectIT, Inc. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Cybersecurity practices must be tailored to each organization’s technical, operational, contractual, regulatory, and safety requirements.

All downloads

Printing produces a paginated document. Choose “Save as PDF” in the print dialog and name it batb-msp-responsibility-matrix to keep filenames consistent across your team.