Skip to content

AWS MSP VCL 8.0

The AWS MSP Program Validation Checklist (VCL) 8.0 becomes the only accepted checklist for AWS MSP Partner (re)validation on 1 January 2027; VCL 7.1 sunsets on 31 December 2026. Version 8.0 has 61 controls, 24 new and 27 rewritten, and shifts the emphasis to demonstrable AI delivery: observability of GenAI/agentic workloads, toil measurement, AI governance and AI dependencies in vulnerability management.

monsys measures the technical controls on that list and bundles the evidence in an Ed25519-signed evidence pack. The declarative controls (policy, roadmap, practice lead) are attested by the MSP on the last page of that pack.

Sidebar → Security & compliance → AWS MSP VCL 8.0 (/compliance/VCL8). Above the generic control table sit three KPI blocks:

Block Controls Source
GenAI & agentic AI observability OPS-004, OPS-009, GOV-002, GOV-003 ai_apps, ai_traces, ai_agent_sessions
Toil measurement & reduction OPSP-003 toil_metrics
Vulnerability, change & access management SEC-003, GOVP-001, SEC-001, SECP-001 inventory_dependency_cves, os_package_cves, emergency_tokens, users, agent_certificates

Below that is the control table as for NIS2/CRA/ISO 27001: id, description (NL/FR/EN), coverage level, evidence count and review status.

Control What VCL 8.0 asks monsys evidence Level
OPS-004 GenAI & agentic AI observability agent session tracing, inference performance, drift, decision audit trail, cost ai_traces + ai_spans (tokens, latency, model, refusal, PII hits), ai_agent_sessions (per session hash), ai_alerts (drift/cost rules) automatic
OPS-009 FinOps incl. AI cost inference cost per app/model total_cost_micro_eur per trace, pricing snapshot automatic
OPSP-003 Toil measurement toil as % of ops time, quarterly reduction toil_metrics: automation ratio, auto-resolved alerts, MTTA/MTTR per month + quarter delta automatic
SEC-003 Vulnerability mgmt incl. AI deps scan AI model/agent dependencies OSV/EPSS/KEV on app dependencies (pypi/npm/Go), OS packages, kernel, images automatic
OPS-010 Patch & release documented patch execution remediation_latency per host, signed result automatic
GOV-003 Data governance for AI PII protection redaction level per AI app, PII redaction at source automatic
GOVP-001 Change management incl. AI workloads approved, traceable changes Emergency Action Tokens: signed, single-use, with result partial
SEC-007 Agentic zero trust & blast radius containment of agent actions per-host exposure (centrality, internet-facing), single-use tokens with action list partial
SECP-001 Encryption & key management mTLS with per-agent certificates, Ed25519-signed evidence partial
SEC-001 IAM scoped roles, TOTP, access-review report partial
SECP-004 Prompt injection prevention guardrails on AI endpoints refusal and anomaly detection via ai_alerts; guardrails themselves are app-side partial
GOV-002 AI agent & model governance inventory with owner and risk tier ai_apps with owner_email, declared_risk_tier, declared_models partial
PLAT-004 Agentic AI platform human approval before every action (EAT + TOTP), never autonomous LLM execution partial
PLAT-005 Well-Architected Trust Score per tenant partial
GOVP-002, BUS-002, BUS-006, PEO-003, PEO-004 policy, roadmap, specialisation, people attestation checklist in the evidence pack manual

ToilMetricsWorker recomputes daily, per tenant per calendar month:

  • total_actions — executed Emergency Action Tokens
  • automated_actions — tokens issued by a monsys worker (reason starts with auto-: auto-patch, auto-update-all)
  • manual_actions — tokens issued by a person
  • automation_pct — automated / total × 100
  • total_alerts, auto_resolved_alerts (resolution_notes LIKE 'auto:%')
  • mtta_seconds, mttr_seconds

The quarter delta compares the mean automation_pct of the last three months with the three before. Positive = more automation = less toil. Without two full windows the hub shows n/a — a trend is never invented.

API: GET /api/v1/ops/toil?months=6

AIAgentSessionsWorker rolls up the last 90 days of ai_traces hourly per (tenant, app, user_session_hash): number of traces and spans, tool calls, tokens in/out, cost, models used, refusals, errors, PII hits. The hash is set by the SDK; the hub never sees a raw session id or user identity.

API: GET /api/v1/ai/agent-sessions?days=30&app_id=&limit=100

Reports → AWS MSP VCL 8.0 evidence pack (aws_msp_vcl8, tenant scope, admin). Sections:

  1. Control coverage (all mapped controls, level, evidence count, review status)
  2. GenAI & agentic observability per app + session KPIs
  3. Toil & automation (6 months, quarter delta, method)
  4. Vulnerability management incl. AI dependencies (per ecosystem/severity, KEV, fix available)
  5. Change management & blast radius (signed actions auto/manual, failure rate, top-exposure hosts)
  6. Attestation checklist for the declarative controls, with signature line

The pack is Ed25519-signed and offline-verifiable like every other audit pack (monsys-verify). Toil and session aggregates are recomputed fresh before rendering.

  • No compliance verdict: monsys supplies measurements, the auditor judges.
  • No guardrails inside your AI app: SECP-004 requires input validation on the endpoint itself; monsys detects the consequences (refusals, anomalies).
  • No measurement of human hours: toil is a proxy based on automated vs manual actions.
  • No roadmap, practice lead or vertical specialisation: you attest those yourself.