The short answer
Security assessors evaluating managed security services focus on whether the provider can demonstrate compliance with specific regulatory requirements, such as NIST SP 800-171 for organizations handling Controlled Unclassified Information. Leadership must understand that an assessor's role is independent verification of security controls, not implementation advice, and that responsibility for compliance outcomes remains with the organization even when technical work is delegated to a managed service provider.
When a security assessor evaluates managed security services, they are performing independent verification that specific regulatory requirements have been met. The assessment is not a consultation about what to do next. It is a formal examination of what has been done, measured against published standards such as NIST Special Publication 800-171, which governs the protection of Controlled Unclassified Information in nonfederal systems and organizations.
Leadership must understand two fundamental points. First, the assessor's findings reflect the organization's accountability, not the managed service provider's assurances. Second, passing an assessment requires documented evidence of working controls, not promises or contract terms.
1The Assessor's Role and Authority
A security control assessor is the individual, group, or organization responsible for conducting a security assessment. According to NIST SP 800-171A Revision 3, assessments can be conducted as independent third-party assessments or as government-sponsored assessments. The assessment procedures are designed to be flexible and can be customized to the needs of organizations and assessors, applied with various degrees of rigor based on customer-defined depth and coverage attributes.
The assessor does not work for the organization being assessed. Their responsibility is verification, not improvement. They examine whether security requirements have been implemented correctly, consistently and completely. Where controls depend on a managed security service provider, the assessor evaluates the same things they would evaluate if the work were performed internally: documented procedures, technical evidence, operational records and the ability to sustain the control over time.
2What the Assessment Covers
NIST SP 800-171A provides assessment procedures for the security requirements established in NIST SP 800-171. These requirements address access control, awareness and training, audit and accountability, assessment and authorization, configuration management, identification and authentication, incident response, maintenance, media protection, physical and environmental protection, planning, personnel security, risk assessment, system and services acquisition, system and communications protection, system and information integrity, and supply chain risk management.
The assessor examines whether each requirement is met through a combination of examination, interview and testing. Examination involves reviewing documentation such as policies, procedures, plans and system security plans. Interview involves discussions with personnel who are responsible for implementing or using the controls. Testing involves hands-on evaluation of mechanisms and activities to determine whether they operate as documented.
When managed security services are part of the control implementation, the assessor will look for evidence that the provider's activities are documented, integrated into the organization's security plan, monitored for effectiveness and subject to the same governance as internal controls. A contract stating that the provider will perform certain functions is not evidence. Logs, configuration records, incident reports and evidence of oversight are evidence.
3The Accountability Gap
The most consequential misunderstanding in organizations relying on managed security services is the belief that outsourcing implementation transfers accountability. It does not. The organization being assessed remains responsible for meeting the security requirements, regardless of who performs the technical work.
NIST SP 800-171 applies to nonfederal systems and organizations that process, store or transmit Controlled Unclassified Information. The Defense Federal Acquisition Regulation Supplement requires Department of Defense contractors handling such information to meet these requirements. An organization cannot delegate this obligation. It can delegate tasks, but the regulatory burden and the consequences of noncompliance remain with the organization.
This creates a governance requirement. Someone inside the organization must be accountable for understanding what the assessment will cover, ensuring that the managed service provider's work aligns with those requirements, maintaining the documentation the assessor will examine, and making risk decisions when the provider's standard offerings do not fully satisfy a control. That role is strategic, not technical. It requires understanding the regulatory landscape, interpreting requirements in the organization's specific context, and ensuring that leadership can demonstrate due care.
4Managed Security Service Providers in the Assessment Context
A managed security services provider is an organization that provides security services, typically including monitoring, detection and response capabilities. NIST recognizes the role of such providers in the broader security ecosystem. For organizations in the Defense Industrial Base, NIST has compiled resources to help small and medium-sized businesses select a managed service provider that can assist with compliance.
The National Defense Information Sharing and Analysis Center, in collaboration with member companies, has published a shopping guide for Defense Industrial Base organizations selecting managed service providers to assist with Department of Defense cybersecurity requirements. That guide addresses the practical realities of selecting a provider whose capabilities align with regulatory obligations.
However, selecting a capable provider does not resolve the accountability gap. The assessor will evaluate whether the organization has integrated the provider's services into a coherent security program, not whether the provider is competent. Integration requires governance: documented roles and responsibilities, oversight mechanisms, regular review of the provider's performance against the organization's obligations, and a process for identifying and addressing gaps.
5Evidence the Assessor Expects
The assessment is evidence-based. NIST SP 800-171A specifies assessment methods for each security requirement, and those methods determine what the assessor will examine. Organizations relying on managed security services must be able to produce the same evidence they would produce for internally implemented controls.
For requirements related to incident response, the assessor will expect to see documented procedures, evidence of testing, records of actual incidents and the organization's response, and proof of coordination between the managed service provider and internal personnel. For access control requirements, the assessor will examine how accounts are provisioned, how access is reviewed, and how the organization ensures that the provider's access to systems is appropriate and monitored. For audit and accountability requirements, the assessor will review logs, retention policies, and evidence that someone in the organization is actually reviewing the data the provider collects.
The evidence must demonstrate that controls are not only implemented but sustained. The assessor may examine records over time to verify consistency. A control that was implemented at one point but is no longer functioning will not satisfy the requirement. Organizations must have mechanisms to detect when a control degrades, whether that control is operated by internal staff or a managed service provider.
6Who Inside the Organization Owns This
Accountability for compliance cannot rest with the IT team, the procurement function, or the managed service provider. It is a governance responsibility. Someone at the executive level must be able to attest that the organization understands its obligations, has implemented controls to meet them, monitors those controls for effectiveness, and can demonstrate compliance through documented evidence.
In organizations subject to NIST SP 800-171, this often requires a system security plan, which documents the system boundary, the security controls in place, and the responsibility for each control. When a managed service provider is responsible for certain controls, that must be documented in the plan, along with how the organization oversees the provider's work and verifies its effectiveness.
This is a strategic function, not an operational one. It requires someone who can interpret regulatory requirements, translate them into organizational policy, ensure that third-party relationships align with those requirements, and provide leadership with the assurance that compliance is being maintained. Many organizations recognize this as a virtual CISO (vCISO) function, providing executive-level ownership of the security program without requiring a full-time internal hire.
7What Leadership Should Do Now
If your organization is subject to security assessment, or expects to be, leadership should take the following steps:
- Identify the specific regulatory requirements that apply to your organization. For government contractors handling Controlled Unclassified Information, this typically includes NIST SP 800-171. Understand the scope precisely.
- Review your agreements with managed security service providers to determine which security controls they are responsible for implementing. Ensure those responsibilities are documented and aligned with the assessment procedures in NIST SP 800-171A.
- Establish internal ownership of compliance. Assign a senior leader to be accountable for ensuring that the organization can demonstrate compliance, regardless of who performs the technical work.
- Conduct a gap analysis to identify where the evidence required for assessment does not currently exist. This is not a technical review. It is a review of governance, documentation, oversight and the ability to produce records.
- Develop a plan to close identified gaps. This may include changes to contracts with providers, new internal processes for oversight, documentation that was never created, or strategic decisions about risk acceptance where full compliance is not feasible.
If your organization lacks the internal expertise to interpret regulatory requirements, map them to your specific environment, and establish the governance needed to sustain compliance, that is a strategic gap. Heights Consulting Group provides virtual CISO leadership for organizations that need executive-level ownership of their security program without the overhead of a permanent internal position. If this describes your situation, a confidential consultation can clarify what adequate ownership looks like in your specific context and how to establish it before the assessor arrives.
Related service: Managed Security Services
Continuous monitoring, detection and response, and vulnerability management, run against priorities the security strategy has already set.