Headline finding · measured 2026-08-11

69% of MSPs that sell cybersecurity hold no security certification at all.

The whole industry sells security. Two-thirds of it shows no third-party proof.

69%

of cybersecurity-selling MSPs list zero certifications

10,226 in-scope firms advertise cybersecurity services; 7,077 of them list zero certifications of any kind. n = 10,226 · as of 2026-08-11.

MSPs advertising cybersecurity services
69.2% No certification listed · 7,077At least one certification · 3,149

base 10,226

What we found

Cybersecurity is the single most commonly advertised service line in the US MSP market: 10,226 of the 21,555 firms in scope name it on their own website. Nearly half the industry is selling security.

Of those 10,226 firms, 7,077 — 69% — list no security certification anywhere a buyer can find it. Not SOC 2, not ISO 27001, not CMMC, not CISSP or CISM on the team page. Nothing.

Why it matters

Security is the one service where the buyer cannot evaluate the work before something goes wrong. Certification is the cheapest available substitute for that evaluation — it is a third party saying the controls exist.

When two-thirds of the market advertises the service without producing that proof, the certification stops being a differentiator for the firms that hold it and starts being a filter for the buyer. Any procurement process that asks for it eliminates most of the field in one question.

The read for MSPs

If you hold a certification and it is not on your website, you are invisible in exactly the comparison where it would win. This is a publishing problem far more often than it is a credentialing problem.

If you do not hold one, note that the bar is currently low enough that a single credible attestation moves you into the top third of the firms you compete with on security work.

What this number can't tell you

  • ·We measure what a company lists publicly, not what it holds. A firm with SOC 2 and no mention of it on its site counts as uncertified here.
  • ·That limitation is part of the finding: buyers also only see what you list.

What to do about it

  • Put every certification — company and individual — on a single page and link it from the security service page.
  • Name the issuing body and the year. An unattributed badge image reads as decoration.
  • If a certification is in progress, say so with a date rather than leaving the section blank.

Where does your firm sit on this?

Claim your MSP with a magic link from your company email to see your own certifications, reviews, web footprint and local rank measured against every provider we track.

Claim your MSP ▸

More findings

◂ All twelve findings