Client Cybersecurity Risk Assessment Checklist Template

The annual risk assessment is where an MSP tells an existing client the truth about their security, in writing, with a plan. Skip it, and the first time the client hears about a gap may be after someone has used it.

Managed services clients assume that because they pay an MSP, they are secure. Usually they are more secure than they were, but every environment drifts. Staff join and leave, new SaaS applications appear, a supplier is given remote access, a server passes end of support, an exception made for one user becomes permanent. The annual client cybersecurity risk assessment is where you step back from day-to-day operations, measure the whole environment against a recognised framework, score what you find and agree a remediation roadmap with the client’s decision-maker. This free checklist is written for MSP owners, vCIOs and security leads who run that review for existing clients. It is organised around the six functions of the NIST Cybersecurity Framework 2.0, collects evidence for each finding, and ends with a scored report, a risk register and a presentation to the client. Extra tasks appear for clients in regulated sectors that require a documented risk assessment.

Use This Template Free See Live Example
No Credit Card Required

A Prospect Assessment Wins the Deal. A Client Risk Assessment Keeps the Client Safe.

Many MSPs already run a network assessment during the sales process: a quick scan that finds enough problems to justify the proposal. That is a useful tool, but it is not a risk assessment. It is designed to be fast, it looks mainly at technology, and its audience is someone who hasn’t yet bought anything.

The annual client risk assessment has a different job. You already manage the environment, so the question is no longer “what is wrong?” but “what risks remain, how serious are they, and what has the client decided to do about each one?”. It covers governance, people and suppliers as well as technology. It compares this year with last year. And it produces a record of decisions, including the risks the client chose to accept, which protects both of you when something goes wrong.

Prospect network assessment

Part of the sales process

Scope: mostly technical: devices, patching, exposed services.

Depth: a snapshot, often automated.

Output: a findings report that supports a proposal.

Annual client risk assessment

Part of the service you deliver

Scope: governance, identity, devices, data, suppliers, detection and recovery.

Depth: evidence-based, scored and compared year on year.

Output: a risk register, a remediation roadmap and recorded client decisions.

What the Client Cybersecurity Risk Assessment Checklist Covers

Seven phases take the assessment from scoping to a presented, agreed roadmap. Two extra tasks appear for clients in regulated sectors.

Phase 1

Phase 1: Scope & Plan

  • Agree the scope — sites, cloud tenants, key applications and any systems the client manages itself
  • Choose the framework — NIST CSF 2.0, the CIS Controls or Cyber Essentials, matched to the client’s size and obligations
  • Pull last year’s assessment — findings, scores, accepted risks and the remediation actions still open
  • Check regulatory obligations — ask whether any law, regulator or contract requires the client to keep a documented risk assessment
  • Record the regulatory scope — for regulated clients, the rules that apply and the systems and data they cover
  • Book the client stakeholders — the decision-maker for the presentation, and the people who can answer questions about policy, HR and suppliers
Phase 2

Phase 2: Govern & Identify

  • Review security policies — information security, acceptable use and incident response policies exist, are current and have an owner
  • Reconcile the asset inventory — hardware, software and cloud services, compared with the RMM and the documentation platform
  • Map sensitive data — where personal, financial, health or confidential data is stored, and who can reach it
  • Review suppliers with access — every third party with network, cloud or data access, and how that access is controlled
  • Confirm security roles — who at the client is accountable for security decisions, and who the MSP escalates to
Phase 3

Phase 3: Protect: Identity & Access

  • Check MFA coverage — all users, all admin accounts and every remote access route
  • Review privileged accounts — who holds admin rights, whether admin and daily-use accounts are separate, and service account ownership
  • Test the leaver process — sample leavers from the last 12 months and confirm their accounts were disabled promptly
  • Review access to sensitive data — shares, sites and applications holding the data mapped in Phase 2
Phase 4

Phase 4: Protect: Devices, Network & Data

  • Assess patching and end-of-life systems — patch compliance, time to apply critical updates and every unsupported system
  • Check secure configuration — device baselines, local admin rights and disk encryption on laptops
  • Review the firewall and exposed services — firewall rules, and an external scan of internet-facing services
  • Check email security — filtering, SPF, DKIM and DMARC for every sending domain
  • Review security awareness training — completion rates and phishing simulation results
Phase 5

Phase 5: Detect, Respond & Recover

  • Check detection coverage — EDR on every endpoint and server, log collection, and who responds to alerts and when
  • Review the incident response plan — current, with named contacts, and tested within the last year
  • Verify backups — coverage, an offline or immutable copy and the date of the last successful restore test
  • Confirm recovery objectives — agreed recovery time and recovery point for critical systems, and whether current backups can meet them
Phase 6

Phase 6: Score & Report

  • Rate each finding by likelihood and impact — using the same scale as last year, so scores can be compared
  • Compare with last year — what improved, what got worse and which previous actions were not completed
  • Build the remediation roadmap — each finding with a recommendation, a priority, a cost estimate and a suggested quarter
  • Write the executive summary — one page for the decision-maker, in business terms, with the three biggest risks first
  • Map findings to regulatory requirements — for regulated clients, show which findings relate to which obligation
Phase 7

Phase 7: Present & Track

  • Present to the decision-maker — walk through the summary, the top risks and the roadmap
  • Record the client’s decision on each finding — remediate, defer or accept, with a name and a date
  • Update the risk register — accepted risks recorded with the client’s acceptance
  • Raise remediation projects — quotes and projects in the PSA for approved work, and roadmap items carried into the QBR
  • Schedule the next assessment — in 12 months, or sooner after a significant change

How the Checklist Maps to the Frameworks Your Clients Recognise

The checklist follows the six functions of the NIST Cybersecurity Framework 2.0, published in February 2024: Govern, Identify, Protect, Detect, Respond and Recover. Version 2.0 added Govern, which covers strategy, roles, policy and supplier risk. That is the part smaller clients most often miss. For clients who need something more prescriptive, the CIS Critical Security Controls v8.1 define Implementation Group 1, a set of 56 safeguards described as essential cyber hygiene for organisations with limited security expertise. UK clients will often know Cyber Essentials, whose five technical controls cover firewalls, secure configuration, security update management, user access control and malware protection.

Checklist phase NIST CSF 2.0 function Cyber Essentials control
Phase 2: Govern & IdentifyGovern, Identify— (outside Cyber Essentials’ technical scope)
Phase 3: Identity & AccessProtectUser access control
Phase 4: Devices, Network & DataProtectFirewalls, secure configuration, security update management, malware protection
Phase 5: Detect, Respond & RecoverDetect, Respond, Recover— (outside Cyber Essentials’ technical scope)

Some clients are legally required to carry out a documented risk assessment, not just advised to. In the US, the HIPAA Security Rule requires covered entities and their business associates to conduct a risk analysis. The FTC Safeguards Rule requires a written risk assessment from the non-bank financial institutions it covers, which include tax preparers, mortgage brokers and many other small firms. For these clients, the conditional tasks in Phases 1 and 6 record the obligation and map findings to it. The checklist supports that work, but it is not legal advice. The client’s compliance adviser should confirm what their regulator expects.

Why Run Client Risk Assessments in CheckFlow?

1

Every client assessed on schedule

Set a yearly recurring schedule for each client, staggered across the year so assessments don’t all land in the same month. The grid view shows which clients are due, in progress or overdue.

2

Evidence behind every finding

Scan results, MFA reports, sampled leaver records and restore tests are attached to the task they support. When the client, an auditor or an insurer asks how a finding was reached, the evidence is there with the date it was collected.

3

Client decisions on the record

Each finding ends with the client’s decision (remediate, defer or accept) recorded by name and date. Accepted risks are no longer a line in an email. They are part of a dated record that you can bring back at the next QBR.

The annual risk assessment is one of the core recurring security processes in the CheckFlow for MSPs toolkit, alongside client onboarding, monthly reviews and QBRs.

For clients who must evidence the result to an auditor or a regulator, CheckFlow’s compliance checklist software shows how recurring reviews and approvals build a single audit trail. Clients buying cyber insurance can reuse much of the same evidence in the Cyber Insurance Readiness Checklist.

Frequently Asked Questions

What is a client cybersecurity risk assessment?

+

It is a structured, evidence-based review of a client’s security posture, usually run once a year by their MSP. It identifies the risks that remain in the environment, rates them by likelihood and impact, and agrees what the client will do about each one. The output is a scored report, a remediation roadmap and a record of the client’s decisions, including the risks they chose to accept.

How often should an MSP assess a client’s security risk?

+

At least once a year, and again after any significant change such as a merger, a new site, a move to a new core system or a serious incident. Some regulations expect the risk assessment to be kept up to date as the environment changes, not just repeated on a date. Between assessments, the monthly report and the QBR track progress on the roadmap.

Which framework should we use?

+

Use the one your client will recognise and can realistically meet. NIST CSF 2.0 works well as an organising structure for most clients because its six functions are easy to explain. The CIS Controls Implementation Group 1 gives a prescriptive baseline for small organisations. Cyber Essentials is widely recognised in the UK. Many MSPs use NIST CSF 2.0 for the structure and one of the others for the detailed checks.

How is this different from a network assessment for a prospect?

+

A prospect assessment is a quick, mainly technical snapshot used in the sales process. The annual client risk assessment covers governance, identity, suppliers, detection and recovery as well as technology. It compares results year on year and records the client’s decisions. It is part of the service you deliver, not part of the sale.

What if the client won’t fund the remediation?

+

Record the decision. Phase 7 asks for the client’s decision on every finding (remediate, defer or accept) with a name and a date. An accepted risk is a legitimate business choice, as long as it is an informed one. Bring accepted and deferred risks back at the next QBR, and revisit them if circumstances change, such as a new insurance requirement or a customer contract.

Can scanning tools do this automatically?

+

Scanners, RMM reports and identity tools produce much of the evidence, and you should use them. They can’t judge whether a policy is followed, whether a supplier’s access is still needed or which risk matters most to this particular business, and they can’t record what the client decided. The checklist structures that judgement and keeps the tool output attached to the finding it supports.

Is CheckFlow free for this template?

+

14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.

One Honest Assessment a Year, With Every Decision on the Record

Free trial — no credit card required.