SOP (Standard Operating Procedure)
Last updated
Definition
A standard operating procedure (SOP) is a written, approved description of how your MSP performs a recurring activity – who does it, in what order, with what tools, and what "done" looks like. It differs from a runbook, which is a technical fix script for a specific ticket type ("printer offline at client X"); an SOP governs a business or operational process that spans tickets – onboarding a client, offboarding a user, handling a security alert.
Why it matters to an MSP
An MSP without SOPs runs on the owner's memory, and the owner's memory does not scale, take vacations, or survive a hire. SOPs are what make a first technician productive in weeks instead of months: they follow the procedure for a new-user request instead of asking you, and the output is the same either way. Clients buy a managed service because it is repeatable, and an SOP is the only evidence that it is.
A documented process cuts labor hours per instance (a client onboarding that takes 40 hours ad hoc typically drops to 15–25 with a checklist), reduces rework from skipped steps, and lets you push work down to cheaper tiers. SOPs are also audit and insurance artifacts: SOC 2, CMMC, and cyber insurance questionnaires ask for documented procedures for access, patching, backup verification, and incident handling – "we just know how" does not pass.
Keep them short – one page where possible – with an owner and a review date. Store them in your documentation platform, link them to the ticket types or PSA workflows that trigger them, and revise them when a process fails: a postmortem that does not update an SOP has not finished. Conventions for naming and structure are in the documentation standards.