SMB1001··4 min read

SMB1001:2027 for MSPs: What to Do With Your Clients This Quarter

SMB1001:2027 names the Technical Support Specialist as a role and tells small businesses to start with their MSP. Here is what that means for you and a five-step plan for your client base.

By Pardeep Sharma

The short version: SMB1001:2027 tells small businesses to engage a Technical Support Specialist first, and says an existing MSP "is usually the right place to start". That's you. The new controls (AI governance, device management, network separation, stronger admin logins) are hands-on work most clients can't do alone. This quarter: sort your clients by target level, run an AI check for all of them, and list their end-of-life gear.

What changed for MSPs

You're now written into the standard. The 2027 edition defines the Technical Support Specialist (TSS) role. The very first measure asks businesses to engage one. A TSS checks each measure is set up correctly and that it will pass certification.

The new work sits at Level 4 and 5. Most of your clients are at Level 1 or 2 today, so for them 2027 means small tweaks. The bigger projects are for clients moving up.

The new controls, and what you'd actually do

RequirementLevelWhat you'd do in Microsoft 365
AI governance framework4Write the AI policy, then review Copilot and third-party AI app consents in Entra
Control unapproved AI use5Turn on app discovery in Defender for Cloud Apps and block or sanction AI apps
Mobile Device Management4Enrol devices in Intune with compliance policies
Separate office, smart device and OT networks4Put printers, cameras and IoT on their own VLAN
Phishing-resistant MFA for admins5Conditional Access with "Phishing-resistant MFA" strength for admin roles; issue FIDO2 keys or passkeys

Reference: controls 4.12.0, 4.13.0, 1.13.0, 1.14.0 and 2.13.0.

Also tightened for every client: automatic patching on all devices and servers, a formal decision on end-of-life products, encryption at rest, Remote Desktop only over VPN with MFA, and a password manager.

Four things you can sell

  1. AI use policy. Relevant to nearly every client. A quick, fixed-price entry service. Upsell to a governance framework for Level 4+.
  2. End-of-life clean-up. Old products now need replacing, upgrading, or a documented exception. That's an audit, a report and a project.
  3. Intune rollout. Level 4 clients now need device management. If you already run Intune, it's an easy extension.
  4. Annual recertification. Certificates last one year and the standard updates yearly. Put it in your service calendar as a recurring line item.

Who does the sign-off

  • Levels 1 to 3: the client self-attests. You implement and keep the evidence tidy.
  • Levels 4 and 5: an independent Dynamic Standard Certifier assesses them. Your job is to get it right first time so nothing gets redone at assessment.

Worked example

An MSP with 30 clients. 22 sit at Level 1 or 2. For them, you check auto-updates, roll out a password manager and offer the AI policy. 6 are at Level 3: add a refreshed cybersecurity policy and incident response plan. 2 want Level 4 for a government contract: they get Intune, network separation and an AI governance framework, quoted as projects. One sweep turns a standards update into a clear pipeline.

Your checklist

  • List every client with their current level and certificate expiry date.
  • Flag the clients aiming for Level 4 or 5.
  • Send every client a short note: "SMB1001:2027 is out, here's what it means for you."
  • Run an AI tools check across all clients.
  • Pull a list of end-of-life devices and software per client.
  • Add recertification dates to your calendar.

How CYBERWHITE helps

CYBERWHITE is built for MSPs delivering compliance across many clients. Run SMB1001 assessments for your whole portfolio from one dashboard, scan each client's Microsoft 365 for gaps, and deploy fixes with snapshot and rollback. The platform maps 151 remediation actions, and 48 deploy in one click.

We are a DSI Founding Mission Supporter and Licensed Commercial Holder of SMB1001. The platform assesses SMB1001:2026 today. We hold SMB1001:2027 and are building its controls in.

See MSP solutions, the SMB1001 page, or what SMB1001:2027 means for small businesses (handy to send to clients).


Keep reading: Delivering Essential 8 as an MSP: Turning Compliance into Recurring Revenue

Frequently asked questions

What is a Technical Support Specialist in SMB1001?
SMB1001:2027 defines the Technical Support Specialist as the technical help a business engages under the first measure. A TSS checks each measure is set up correctly and will pass certification. DSI notes an existing MSP is usually the right place to start.
Which SMB1001:2027 changes create MSP work?
AI governance, controlling unapproved AI use, Mobile Device Management, network separation and phishing-resistant MFA for admins, plus end-of-life product clean-up for all clients.
Can MSP clients self-attest to SMB1001?
Levels 1 to 3 can self-attest. Levels 4 and 5 need independent assessment by a Dynamic Standard Certifier.

Ready to assess your compliance?

CYBERWHITE helps Australian businesses reach Essential 8 and SMB1001 audit-readiness faster. Start with our free 5-minute assessment.