Who Is Qualified to Run a Security Risk Assessment?

TU0LZJQA1-U0B3VV05084-10fa14008046-512
Diana Wright Publication date: 7 September, 2026
Education

Somewhere in a sales call or a QBR, a client eventually asks the question directly: who actually ran this assessment, and what makes them qualified to run it? For certification and attestation work, a credential is required, not by convention but by the frameworks themselves. For readiness work, gap analysis, internal risk and posture assessment, and advisory, no framework or regulator imposes a credential requirement, and qualification is a property of the process rather than the person. Knowing where that line sits lets you assign the work confidently and defend the assignment when someone asks.

Who Can Run a Risk Assessment?

Can anybody do a risk assessment? MSP owners ask it when deciding who to staff on an engagement, and their clients ask it when deciding whether to trust the output. Scaling a security practice means partitioning the work across your bench; keeping clients means every deliverable earns their trust. The two are not mutually exclusive, but the balance is delicate, and it starts with the fact that “risk assessment” covers two different kinds of work with two different rules.

The first kind produces a formal certification or attestation that a third party will rely on: a SOC 2 report a prospect’s procurement team reads, a PCI Report on Compliance an acquiring bank requires, a Cybersecurity Maturity Model Certification (CMMC) assessment a defense contract depends on. That work is regulated. The frameworks name who is allowed to sign, and no amount of skill substitutes for the credential.

The second kind is the work that fills most of a security practice’s calendar: assessing a client’s posture, finding the gaps against a framework, building the roadmap, preparing a client to pass the formal audit when it comes. No framework, regulator, or standards body restricts who performs it. A practice can staff it however it judges best, and the judgment that matters is about process quality, supervision, and knowing which decisions need a senior in the room.

Part of this work is regulated, and you need to know exactly which part. Every staffing decision, and every claim you make to a client about who does what, builds from that line.

When a Credential Is Required

The regulated half of the line is a matter of published fact, and you want it on hand the next time a client or prospect asks. These are the assessments where the framework itself names the assessor:

AssessmentWho is allowed to perform it
SOC 2 reportA licensed CPA firm operating under American Institute of Certified Public Accountants (AICPA) attestation standards
PCI Report on ComplianceA Qualified Security Assessor certified by the PCI Security Standards Council
CMMC Level 2 certification assessmentA certified third-party assessment organization (C3PAO) accredited within the CMMC ecosystem
HITRUST validated assessmentAn authorized external assessor approved by HITRUST
ISO 27001 certification auditAuditors whose competence is formally evaluated by an accredited certification body under ISO/IEC 17021-1

Two things follow from the table, and the first is a rule your practice should never bend: internal assessment output is never presented as any of these, whoever ran it, and that includes a brilliant senior with 20 years of experience. Without the credential, it is not a SOC 2 report or a Report on Compliance. The second is that the table is narrower than people assume. It covers the final certification or attestation event, and it says nothing about the months of readiness work in front of it. If you want the framework-specific detail on the first row, the who can perform a SOC 2 audit question has its own answer.

Who Can Run Readiness and Internal Risk Assessments?

Everything outside the table, which is most of the assessment work your practice sells, carries no credential requirement. That is not a loophole but how the system is designed: the regulated event is the audit, and the preparation for it is ordinary professional work, staffed at the practice’s discretion like any other engagement. The same is true of a standing cybersecurity risk assessment run for a client who may never pursue a certification at all.

So what makes someone qualified to run one? In practice, three things, and none of them is a certificate on the wall:

  • A sound method. The assessment asks the right questions for this client’s environment and business, in a defensible order, against a recognized baseline. The method carries the expertise; the operator works it.
  • Clean evidence handling. Answers trace to something real: a configuration, a document, a scan, a named person’s confirmation. An assessment is only as good as what it can show for each answer.
  • Judgment about escalation. The operator knows which findings are routine and which need a senior’s interpretation before anything reaches the client. This is the skill that actually separates staffing levels, and it is teachable.

The security profession itself backs this up. In ISC2’s 2025 workforce study, 56% of practitioners entered cybersecurity through an IT role, which means the analyst learning assessment work on your bench is walking the same road most of today’s senior people walked. The same study found 22% of organizations now cross-train staff from outside the security team entirely, and that 59% name critical skills gaps as their pressing constraint. The industry’s own answer to that constraint has been to develop the people it has rather than wait for credentialed hires.

Can Any Staff Member Complete a Risk Assessment?

You will also hear a second version of the question, typically from the other side of the engagement: can the client’s own staff fill in the assessment? An office manager gets handed the questionnaire, answers what they can, guesses at the rest, and the result comes back looking complete. Nothing about that is illegal either. It is just close to worthless, and occasionally worse than worthless, because a confidently wrong answer about backups or access control shapes real decisions.

The problem is not who typed the answers but that self-attestation without oversight produces answers nobody verified. A client-side contact is often the right person to supply information: they know where the data lives, which vendors have access, and what happened during the last outage. They are the wrong person to own the assessment, because ownership means checking claims against evidence, recognizing when an answer does not add up, and knowing what a given gap means for this business. That is the provider’s job, and it is the difference clients are paying for.

Most good engagements land on the same practical shape: client staff contribute answers and artifacts, the practice’s analyst validates them against evidence and works the method, and findings pass a senior review before anyone presents them. Each party does the part they are qualified for, and the qualification question dissolves into a process question.

Why the Question Matters to Your Clients

Nobody regulates who runs readiness work, yet the question keeps coming up, because trust is what a security practice actually sells. Your client typically cannot evaluate the work itself, so they evaluate the person. UK government research puts a number on this: 23% of businesses that outsource cyber security lack confidence they can assess whether their provider offers value for money. The typical cyber team in that same research is 3 to 4 people. Your client is small, stretched, and buying judgment they cannot independently verify. Who ran the assessment is their proxy for whether the judgment is real.

What the client needs to hear is not a job title. They need to know the assessment followed a consistent method rather than one person’s habits, that every answer has evidence behind it, and that a senior reviewed the findings and stands behind the interpretation. A practice that can say those three things truthfully has a stronger answer than “our most expensive person did it,” because the expensive person’s output varies with their calendar, and a reviewed process does not.

Nobody buys security advice priced like it required no advisor, so keep the expertise in the pitch and put it where it actually sits: in the method your practice runs and the senior review every engagement passes through. Said that way, the quality claim holds whether your most experienced person ran the interviews or reviewed the output afterward.

The Review Gate That Makes the Assignment Safe

Which brings the question back to the operating decision it always was. Instead of asking whether a given person is qualified to do assessments, a well-run practice asks which parts of the engagement each person owns, and where the review gate sits.

Analysts own the repeatable path: gathering context, working the assessment, assembling evidence and drafts, inside clear guardrails. Consultants own client programs and keep the roadmap moving. Seniors review strategy, exceptions, and anything headed to a client conversation, which in practice means 20 minutes on a well-evidenced draft instead of an afternoon rebuilding it. The credential-required work from the table above goes to the credentialed party it legally belongs to, with your practice doing the preparation that makes it go smoothly. That is how practices split the work across roles without either wasting senior hours on data gathering or letting unreviewed work reach a client.

The review gate is what makes the whole structure defensible in front of the client who asked who ran the assessment. The answer becomes: the engagement ran on the practice’s methodology, a named senior reviewed the findings, and here is the evidence behind every answer. Platforms built for this delivery model make the gate real rather than aspirational. Cynomi embeds the assessment methodology and the standardized workflows the review sits on top of, so the guardrails your junior team works inside are the system itself, and your senior’s name goes on work they actually reviewed.

Qualified was never about the individual. For the regulated work, the framework decides, and the table above is the whole answer. For everything else, qualification lives in the method, the evidence, and the review gate, which means it is something your practice builds once and every engagement inherits. Build it, and the next time a client asks who ran their assessment, the answer will be better than a job title.