Cloud Intelligence™Cloud Intelligence™

Cloud Intelligence™

AWS MSP Program VCL 8.0: The Complete AI-First Gap Analysis

AWS MSP Program VCL 8.0 adds 24 new controls and updates 27 more for AI-first delivery. See exactly what changed, what's still unconfirmed, and how to prepare before VCL 7.1 retires on January 1, 2027.

This page is also available in Deutsch, Español, Français, Italiano, 日本語, and Português.

Sep 11, 202614 min read
Josh Palmer

About Josh Palmer

I'm Josh Palmer, Head of Content at DoiT, where I split my time across multiple business units including DoiT Cloud Intelligence, PerfectScale (Kubernetes cost optimization), and SELECT (Snowflake, Databricks, and BigQuery cost optimization). Before DoiT, I spent four and a half years at OnBoard building content for a board intelligence platform used by 6,000+ organizations, and before that, two years as Content Marketing Manager at Zylo, a SaaS management platform.

My personal page

TL;DR: Passing AWS's MSP Program Validation Checklist unlocks AWS's incentive on managed services revenue, up to 5% of gross billed revenue, capped at $0.5M. In August 2026, AWS raised the bar for earning it: Validation Checklist (VCL) 8.0, the program's "AI-First" release, adds 24 net-new controls and updates 27 existing ones across agentic AI platforms, Responsible AI governance, prompt injection prevention, and Forward Deployed Engineering roles, out of 61 controls total. VCL 8.0 becomes the only accepted checklist on January 1, 2027; VCL 7.1 stays valid for audits and renewals only through December 31, 2026. AWS has publicly named 19 of the 61 controls as confirmed new, updated, or retained. The remaining 42 are not individually itemized in AWS's public Summary of Changes, so partners need their own control-by-control review rather than relying on the public change log alone.

AWS's MSP Program Validation Checklist 8.0 is the biggest revision to MSP audit requirements since the program's AI capabilities were first introduced, and it changes what "compliant" means, and what incentive dollars are on the line, for any partner applying, renewing, or preparing for a Full Audit after January 1, 2027. This guide breaks down what AWS has confirmed, what it hasn't, and what to do next. The full checklist is published by AWS at apn-checklists.s3.amazonaws.com.

Why Does VCL 8.0 Matter for AWS MSP Partners?

Passing the MSP Program Validation Checklist doesn't just validate your practice. It unlocks AWS's incentive on managed services revenue: up to 5% of gross billed revenue, capped at $0.5M. VCL 8.0 raises what it takes to earn and keep that incentive, since partners are only paid while they stay validated against whichever checklist version is current.

AWS isn't moving on AI in isolation. Across the broader MSP market, the same pressure is showing up in independent research: OpenText Cybersecurity's 2025 Global Managed Security Survey (1,019 MSPs surveyed) found 92% of MSPs report AI-driven growth, but only about half feel prepared to guide customers on AI adoption, a readiness gap that's widening, not closing, from 90% just a year earlier. Kaseya's 2026 State of the MSP Report (1,000+ MSPs surveyed) found 48% of MSPs now rank AI and automation as their number one client need.

Gartner predicted in August 2025 that 40% of enterprise applications will ship with task-specific AI agents by the end of 2026, up from under 5% in 2025. Yet McKinsey research shows only 23% of organizations have actually scaled an agentic AI system into production, despite high adoption intent. VCL 8.0's new controls are AWS's attempt to make sure the partners it validates, and pays incentives to, can actually close that gap for customers.

What Is AWS MSP Program VCL 8.0?

VCL 8.0 is the eighth major version of the Validation Checklist AWS auditors use to certify Managed Service Provider (MSP) Program partners. It has a pilot date of August 21, 2026, and covers 61 total controls across six sections: Business, People, Governance, Platform, Security, and Operations.

AWS calls it the AI-First release because it raises the bar from proving cloud infrastructure management to proving AI-driven delivery at scale with measurable business outcomes. AWS publishes the full checklist at apn-checklists.s3.amazonaws.com.

Why Is VCL 8.0 Called the "AI-First" Release?

VCL 8.0 is AI-first because its new and updated controls concentrate on agentic AI platforms, AI/data governance, prompt injection prevention, agentic Zero Trust security, GenAI observability, and new operating roles like Forward Deployed Engineers and AI Practice Leads. These weren't meaningful audit categories in VCL 7.1. In VCL 8.0, they account for the large majority of what changed.

What Changed Between VCL 7.1 and VCL 8.0?

AWS's own published Summary of Changes gives these totals across the 61 controls:

Section Total Controls New Updated Retained
Business 9 5 2 2
People 8 3 5 0
Governance 10 5 5 0
Platform 8 3 3 2
Security 12 5 3 4
Operations 14 3 9 2
Total 61 24 27 10

AWS also notes that 15 VCL 7.1 controls were retired through consolidation into broader controls. For example, separate Role-Based Access, MFA, and IAM controls were merged into a single IAM control, and two AWS Support Plan controls were merged into one.

What Are the Confirmed New Controls in VCL 8.0?

AWS's Summary of Changes names 7 themes that account for 12 of the 24 net-new controls. These are the changes partners can act on with full confidence they're new territory, not a reworded existing control.

Control ID Control Name Level What You Need to Prove
PLAT-004 Agentic AI Platform Recommended Build, deploy, and manage AI agents at scale (e.g., Bedrock AgentCore) across Runtime, Memory, Identity, Gateway, or Observability.
GOV-002 AI Agent and Model Governance and Lifecycle Recommended Model/agent registry with versioning, promotion approval gates, explainability, bias monitoring, and retirement procedures.
GOVP-002 Responsible AI Policy and Framework Mandatory Formal framework covering fairness, accuracy, transparency, accountability, privacy, and safety, plus one applied example.
GOV-003 Data Governance for AI Mandatory Policies for data quality, lineage, consent, retention, sovereignty, and synthetic data used by AI agents.
SECP-004 Prompt Injection Prevention Mandatory Input validation, content filtering, and guardrails across all AI-facing endpoints.
SEC-007 Agentic Zero Trust and Blast Radius Containment Recommended Zero Trust between agents: identity verification, traffic inspection, data isolation, and a contained-compromise demonstration.
OPS-004 GenAI and Agentic AI Observability Recommended Agent session tracing, inference performance monitoring, drift detection, decision audit trails, and cost observability.
OPSP-003 Toil Measurement and Reduction Recommended Toil tracked as a percentage of ops time, an automation backlog, and demonstrated quarterly reduction.
BUS-002 AI Transformation Roadmap Mandatory Documented strategy showing the shift from traditional MSP to AI-first delivery, with milestones and a dated progress artifact.
BUS-006 Industry Vertical Specialization Recommended Deep expertise in one specialized vertical, or an AWS Industry Competency (exempt if already held).
PEO-003 Dedicated AI Practice Lead Recommended A named individual responsible for AI strategy, delivery quality, innovation pipeline, and outcome measurement.
PEO-004 Forward Deployed Engineers (FDE) Team Recommended A defined FDE role or operating model embedded in customer engagements to drive agentic AI use cases.

DoiT operates its own Forward Deployed Engineering practice, the same operating model PEO-004 asks partners to formalize. More on that in the "How Can DoiT Help" section below.

What Existing Controls Were Updated for AI?

AWS states that 27 existing controls were updated to incorporate AI capabilities, and names three explicit examples. If your organization already has these documented from a prior audit, don't assume the old evidence is still sufficient. Each now carries an AI-specific requirement layered on top.

Control ID Control Name Level What Changed
GOVP-001 Change Management Process Mandatory Now explicitly covers infrastructure, application, and AI workload changes, not just traditional infrastructure and app changes.
SEC-003 Vulnerability Management Mandatory Now explicitly covers AI model and agent dependencies alongside infrastructure, application, and container scanning.
OPS-009 Cloud Financial Management (FinOps) Mandatory Now explicitly includes AI workload cost optimization, such as GPU right-sizing, Spot for training, and inference cost tracking.

Cloud bill shouldn't be a mystery

One platform for AI and Cloud optimization.

What Controls Remain Unchanged in VCL 8.0?

AWS confirms 10 controls were retained unchanged, and names four examples. If you passed a prior audit on these, you're likely still covered, though a quick evidence-currency check is still worthwhile.

Control ID Control Name Level
SECP-001 Encryption and Key Management Mandatory
SEC-001 Identity and Access Management Mandatory
PLAT-005 Well-Architected Mandatory
OPS-010 Patch and Release Management Mandatory

What Hasn't AWS Individually Published?

The 19 controls confirmed above account for less than a third of the full 61-control checklist. AWS's public Summary of Changes categorizes the rest in aggregate ("24 new," "27 updated," "15 retired via consolidation") without naming every individual control ID. The remaining roughly 42 controls may be new, meaningfully updated, or unchanged, and AWS's public documentation doesn't say which, control by control.

Several of these unconfirmed controls read like clear AI-era additions even though AWS didn't name them explicitly: Amazon Bedrock and Foundation Model Platform (PLAT-003), AWS AI Service Expertise (PLAT-006), AWS Certifications for AI/ML (PEOP-002), and Agentic AI Business Impact (GOV-007).

Treating these as "probably fine because AWS didn't call them out" is a risky assumption going into a Full Audit. Partners should verify their own status control by control rather than relying on the public change log alone. Automated AWS environment scanning can independently confirm where your infrastructure already satisfies a technical control, regardless of whether AWS categorized it as new, updated, or unchanged.

When Do I Need to Comply With VCL 8.0?

Date What Happens
August 21, 2026 VCL 8.0 pilot date: released and available for use.
Through December 31, 2026 VCL 7.1 remains valid for audits and renewals.
January 1, 2027 VCL 8.0 becomes the only accepted checklist version.

Separately, every MSP partner follows a standing renewal cycle from their own original award date: Year 0 is a Full Audit, Years 1 and 2 are Performance-Based Renewals, and Year 3 is a Full Audit again, repeating every 36 months. Whichever of these falls due next, it will be assessed against whichever checklist version is current on that date: VCL 8.0 for anything from January 2027 onward.

How Should MSP Partners Prepare for VCL 8.0?

  1. Map all 61 controls against your current evidence, prioritizing Mandatory controls and the Confirmed New controls first.
  2. Check exemption clauses. Several controls (SECP-001, SECP-002, PLAT-003, PLAT-006, OPS-008, BUS-006, PLAT-007, and SEC-001 through SEC-004) are waived if you already hold a relevant AWS Competency (MSSP, AI, DevOps, Migration and Modernization, or Industry). Confirm which of these you already qualify for before building new evidence from scratch.
  3. Start evidence collection early on controls with no prior audit history. Responsible AI Policy, Data Governance for AI, and Prompt Injection Prevention in particular require documentation most MSPs have never had to produce before.
  4. Work backward from your renewal date. AWS recommends starting your review 3 to 6 months ahead of a Full Audit. The Self-Assessment Spreadsheet is due to AWS at least 30 days before your scheduled date.

How Can DoiT Help Protect and Capture the VCL 8.0 Incentive?

Mapping evidence in a spreadsheet is a solid first pass, but it doesn't scale between audit cycles and it won't monitor your AWS environment on its own, and it won't protect the incentive dollars tied to staying validated. DoiT's Channel Management, part of DoiT PartnerOps, gives AWS channel partners (resellers, ISVs, SIs, and MSPs alike) the full pathway to MSP status and keeps you there: automated AWS environment scanning, AI-drafted evidence documents, and lifecycle tracking between audits.

Read more about how it maps directly to VCL 8.0 in DoiT's Channel Management for AWS VCL 8.0 and in the product changelog announcing PartnerOps Channel Management.

If your gap analysis turns up work on the AI-specific controls themselves, not just how to document them, DoiT's AWS AI Assessment is a complementary, AWS-funded 45-day engagement that turns a list of AI ideas into 3 to 5 funded use cases on Bedrock AgentCore and Quick Suite, delivered by DoiT's Forward Deployed Engineers working alongside your AWS account team.

Passing VCL 8.0 gets you accredited, and gets you the incentive that comes with it. Actually capturing that incentive correctly, across every customer contract, is a separate problem: most partners reconstruct it manually at month-end. DoiT's Revenue Management reconciles managed-services incentive revenue automatically against AWS's payout, so nothing is missed or miscalculated. It's a natural next step once compliance is handled, not a replacement for it.

Learn more about becoming or growing as an AWS MSP with DoiT at doit.com/solutions/msps-distributors.

FAQ

What financial incentive is tied to passing AWS MSP Program VCL 8.0? Passing the MSP Program Validation Checklist unlocks AWS's incentive on managed services revenue: up to 5% of gross billed revenue, capped at $0.5M. Partners are only paid this incentive while they stay validated against whichever checklist version is current, which is VCL 8.0 starting January 1, 2027.

What is AWS MSP Program VCL 8.0? VCL 8.0 is the current version of AWS's Validation Checklist for the Managed Service Provider Program, released August 21, 2026. It covers 61 controls across Business, People, Governance, Platform, Security, and Operations, and is known as the AI-First release because of its focus on agentic AI, AI governance, and AI-specific security controls.

When does VCL 8.0 become mandatory? VCL 8.0 becomes the only accepted checklist version on January 1, 2027. VCL 7.1 remains valid for audits and renewals only through December 31, 2026.

How many new controls does VCL 8.0 add? VCL 8.0 adds 24 net-new controls out of 61 total. AWS has explicitly named 12 of these 24 in its public Summary of Changes; the rest are confirmed in aggregate but not individually itemized.

Does VCL 8.0 affect MSPs that don't use AI today? Yes. Several new controls, such as the AI Transformation Roadmap (BUS-002) and Dedicated AI Practice Lead (PEO-003), are Mandatory or Recommended regardless of how much AI a partner currently uses, since they assess strategy and readiness, not just current deployment.

Are any VCL 8.0 controls waived by existing AWS Competencies? Yes. Controls including SECP-001, SECP-002, PLAT-003, PLAT-006, OPS-008, BUS-006, PLAT-007, and SEC-001 through SEC-004 can be waived for partners holding a relevant AWS Competency, such as MSSP, AI, DevOps, Migration and Modernization, or Industry.

What should MSP partners do first to prepare for VCL 8.0? Start by mapping all 61 controls against current evidence, prioritizing Mandatory and Confirmed New controls, then check which controls are waived by existing AWS Competencies before building new evidence from scratch. AWS recommends beginning this review 3 to 6 months ahead of a scheduled Full Audit.

This article is independently prepared by DoiT based on AWS's publicly published MSP Program Validation Checklist 8.0. It is not an official AWS publication. Always confirm current requirements against the live AWS MSP Program Validation Checklist and your AWS Partner Development Manager.