08/13/2026
A SaaS founder eighteen months from IPO sat down with two well-regarded Bay Area MSPs. Both gave him confident answers on device management, help desk response times, and uptime.
Neither one asked about segregation of duties, audit logging retention, or who owns evidence collection once the auditors show up.
He hired the third firm; the one that asked what his auditors would actually test for.
That's the gap between managed IT for a typical small business and managed IT for a company heading toward an S-1. Once SOX auditors are involved, your MSP isn't just keeping the lights on, but building the evidence trail: timestamped change logs, standing quarterly access reviews, named approvers, available on request rather than assembled after the fact.
Two domains break generalist providers fastest: access management (access creep, segregation of duties) and change management (documented requests, tested in non-prod, named approvers, post-deployment records).
Before signing with any MSP, ask them to produce evidence, not describe a control. If they can't hand you a timestamped change log for an existing client right now, that's your answer.
Full breakdown of what to require: https://na2.hubs.ly/H079vmQ0