UCS certification usually takes 3 to 6 months. MSPs with documented policies and controls already in place can finish in a few weeks. Your timeline depends most on how much of your practice is already written down, because closing gaps is the slow part. Most MSPs close their critical gaps in 60 to 120 days.
Last updated: September 25, 2026
UCS, the Unified Certification Standard, is MSPAlliance's standard for how an MSP should run. UCS has been around since 2004. Cyber Verify is the certification you earn against it, and the platform where you do the work. Cyber Verify launched in 2023 and uses UCS as the framework for its certification program.
MSPAlliance's UCS-based certifications also include MSP Verify, for MSPs that manage client infrastructure, and Cloud Verify, for SaaS and cloud providers. Hybrid MSPs start with MSP Verify. Whichever you pick, an independent audit firm, pre-approved by MSPAlliance, performs the audit.
The full standard is free to read at mspalliance.com/ucs, with no signup: 5 domains, 10 objectives and 72 requirements.
Read it first. It's the cheapest way to guess your own timeline, because you'll see fast which parts you already meet.
What are the stages, and how long does each one take?
Here's the path from start to certificate. Where we've published a number, we give it. Where we haven't, we describe the stage and leave the time out rather than guess.
- Assessment (CVAT). You answer the Cyber Verify Assessment Tool's guided questions, and it scores you across the 5 UCS domains. Time: under an hour, or about 30 minutes for Cloud Verify (source).
- Gap analysis. You get a list of what's missing, sorted by impact and effort, so you fix the things that count first.
- Remediation. You write missing policies and fix missing controls, using our templates. Time: 60 to 120 days for critical gaps, for most MSPs (source).
- Evidence collection. You upload proof for each requirement. A compliance sherpa reviews it before the auditor sees it.
- Audit. An independent audit firm, pre-approved by MSPAlliance, checks your evidence against UCS.
- Certification. You get a written report signed by the audit firm, and a seal to use in marketing and sales. There's no public directory of certified MSPs, so the report and seal are how you show it.
- Renewal. You recertify every year to stay current.
End to end, most MSPs finish in three to six months. MSPs with documented policies and controls already in place can finish in a few weeks.
What does the sherpa check, and what's the audit like?
Your compliance sherpa is trained in how auditors review evidence. When you submit something, they review it first and approve it or send it back with a note. They'll catch things like a screenshot with no timestamp before the auditor does.
That review happens before the audit, so a fix costs you a message instead of a finding. Messages are unlimited, with no per-question billing, and we aim to reply within one hour, Monday to Friday, 9 to 5 Eastern.
Neil Holme, Founder and CEO of Impact Business Technology, describes the audit this way: "It's a friendly audit. They really want you to get through this and they will help you do it."
Which parts of UCS aren't about your tech stack?
This part is easy to miss if you expect a security checklist. UCS looks at how you run the business, not only how you secure it.
Two of the ten objectives are Billing and Reporting, and Corporate Health (mspalliance.com/ucs). The Transparency domain covers policy governance, data geolocation, external service provider access, service-level categorization, accurate invoicing and revenue concentration risk. The Trust domain covers internal audit, service transition, capacity management, problem resolution, secure remote access and customer reporting.
None of that lives in your RMM. It lives with whoever runs contracts, billing and finance. If only your tech lead is working on certification, these items stall while everything else moves. Bring your finance or operations owner in at the start, and have them read those sections of the standard alongside your CVAT results.
What speeds it up, and what slows it down?
Of the stages with a published number, remediation takes longest: 60 to 120 days for critical gaps, out of 3 to 6 months in total. You spend it writing down what you already do, and proving you do it.
It goes faster when:
- Your onboarding, offboarding, backup and incident steps are written and followed.
- One named owner has time set aside each week.
- Your RMM, PSA, identity, backup and Microsoft 365 tools already log what happens, with dates.
- You fix returned evidence the same week.
It goes slower when:
- Policies live in someone's head, so you write them, then run them long enough to show proof.
- The work sits with a shared login that nobody owns.
- Evidence has no date or no owner, so it comes back for a redo.
- Scope keeps changing. Decide up front which services are in.
The tools point is where Cyber Verify helps directly. Our CORTEX engine maps your RMM, ticketing, identity, backup and M365 tools to evidence sources (source). A lot of your proof then comes from systems you already run.
New requirements also add time. UCS 4.0 took effect July 1, 2026 and brings the count to 72 requirements, up from 71, including three SaaS special requirements. It keeps the same 5 domains and 10 objectives, with no renumbering. It adds 06.15, an Identity and Access Management Framework, and expands 01.05 so your review of outside providers covers AI-enabled services, on a regular schedule. If you use AI tools from outside vendors in client work, expect to document how you approve and review them.
Before you promise anyone a date, run CVAT. It takes under an hour, and it'll show you which of those two lists you're closer to.
Does UCS time count toward SOC 2 or ISO 27001?
Yes, much of it does, because the controls overlap. Cyber Verify maps each UCS requirement to the matching SOC 2 criteria and ISO 27001 controls. The policies and proof you built for UCS carry forward. Our MSP Verify page puts it this way: SOC 2 and ISO 27001 then "layer on top with relatively little marginal effort."
The auditor still decides, though. Each auditor judges whether your UCS proof meets their criteria. Some will ask for more.
And some SOC 2 time can't be reused. A SOC 2 Type 2 tests your controls over a period, typically 3 to 12 months. UCS work gets you ready to start that clock sooner. It doesn't shorten the clock itself. For reference, most MSPs have a SOC 2 Type 1 report four to six months after they start, including readiness work.
Certification is also the starting point for selling compliance. Once you're certified, you can add frameworks and run the same process for your clients as Compliance-as-a-Service. Cyber Verify bills you per client, and you set your own price.
If you know a client will ask for SOC 2 next year, tell us at the start. We'll line up your UCS evidence so it's ready for both.
See your own timeline
A 30-minute demo with one of our compliance specialists will show you CVAT, the gap list and the sherpa workflow. Bring your service list, and we'll walk through a realistic timeline for your practice.