Compliance as a Service
Last updated
Why compliance is the stickiest revenue you can sell
Compliance work is recurring by nature: regulations don't churn, audits and renewals come every year, and evidence has to be collected every month. It's high-margin because you're selling expertise and process, not reselling licenses at thin markup. And it's a moat – a generalist competitor can undercut your per-seat price, but they can't quote a CMMC enclave or walk a dental practice through a HIPAA risk analysis. Healthcare-focused MSPs typically command 25–35% price premiums as of 2026, which is the niche math working as intended – see choosing a niche.
The standard packaging: an initial paid gap assessment as the anchor engagement, then an ongoing compliance retainer sold as a $500–2,500/mo add-on per client, depending on framework and client size.
The frameworks an SMB-focused MSP actually meets
| Framework | Who it hits | Status as of 2026 |
|---|---|---|
| HIPAA | Medical, dental, health-adjacent | Proposed Security Rule overhaul pending; sell to it now |
| CMMC 2.0 | Defense contractors and their suppliers | DFARS clauses live in DoD contracts since Nov 2025 |
| FTC Safeguards Rule | Auto dealers, mortgage/finance-adjacent | Fully enforced since June 2023 |
| SOC 2 | Any client selling B2B services | Market-driven, demanded by clients' customers |
| State privacy laws | Consumer-data businesses | Growing state-by-state patchwork |
HIPAA. As the IT provider for a covered entity, your MSP is a Business Associate: you sign BAAs and your own stack must be HIPAA-fit. The December 2024 HHS OCR proposed rule – the biggest Security Rule update since 2003 – would make MFA, encryption, asset inventories, and annual penetration testing mandatory rather than "addressable." It remained pending through 2025–26, but sell to it now: clients who close those gaps early avoid a scramble later.
CMMC 2.0. The program rule took effect December 16, 2024, and the DFARS acquisition rule took effect November 10, 2025 – CMMC clauses now appear in actual DoD contracts, in Phase 1 of a three-year rollout (self-assessments first, then third-party certification). Level 1 covers FCI with 17 self-assessed practices; Level 2 covers CUI with 110 NIST 800-171 controls, mostly third-party assessed. The critical catch for MSPs: if you touch CUI or the systems holding it, your MSP must meet the client's CMMC level, and assessors expect a Shared Responsibility Matrix documenting who does what. Typical delivery is a GCC High enclave plus a managed 800-171 stack in $50K+ engagements – lucrative, but enter deliberately, not opportunistically.
FTC Safeguards Rule. Applies to auto dealers and other finance-adjacent "financial institutions"; fully enforced since June 2023, with a 2025 FTC FAQ clarifying dealer expectations. It requires a written information security program, a designated Qualified Individual (often an MSP-supported role, though the dealer keeps legal responsibility), risk assessments, MFA – explicitly including service-provider and DMS vendor access – encryption, monitoring and pen testing, vendor oversight, an IR plan, and FTC breach notification within 30 days once 500+ consumers are affected. Dealers are an underserved vertical tailor-made for a packaged compliance bundle.
SOC 2. Not a law but a market force: your clients' enterprise customers demand it in vendor reviews. The MSP implements and evidences the controls; an independent CPA firm performs the audit. Helping a client reach SOC 2 makes you structurally involved in how they win their own deals – stickiness money can't buy.
State privacy laws. A growing patchwork of state statutes governing consumer data. The practical MSP work is data inventory and mapping, retention and minimization, and breach-notification readiness – usually folded into the broader compliance retainer rather than sold standalone.
What you actually deliver
- Gap assessment – paid, always. The anchor engagement: assess the client against the framework and produce a findings report. HIPAA security risk analyses typically run $2K–20K as of 2026 depending on practice size. A prescriptive checklist like CIS Controls IG1 mapped to the target framework keeps assessments consistent and repeatable. Never do this free – free assessments position you as a sales gimmick, paid ones as a professional.
- Remediation roadmap. A prioritized, priced plan to close the gaps. This is where your standard security stack gets sold – the same EDR, MFA, backup, and training the framework demands.
- Policies and procedures. A tailored policy library, typically $2K–5K as of 2026 – tailored being the operative word; auditors and regulators recognize an untouched template instantly.
- Workforce training. Framework-specific training on top of general security awareness, typically $20–100/employee/yr.
- Evidence collection. Continuously filed proof – EDR console exports, backup restore-test logs, MFA enforcement reports, access reviews, tickets. Audits are won or lost here, not in the two weeks before the auditor arrives.
- Ongoing monitoring and quarterly reviews. Compliance drift review in the QBR, plus vCISO-style reporting that translates control status for the client's leadership.
Tooling
Compliance platforms automate control mapping, evidence collection, and reporting so the retainer doesn't drown in spreadsheets. Acronis Cyber Compliance, built into Acronis Cyber Protect Cloud, provides CIS Controls v8.1 scoring, centralized visibility across client tenants, and guidance for closing technical-control gaps. For framework-specific workflows, healthcare platforms such as Compliancy Group and ComplyAssistant typically run $100–500 per practice per month as of 2026. Todyl also bundles GRC functions with its security platform. Treat the platform as the delivery vehicle: the license is a pass-through cost, and the margin lives in the assessment, remediation, and review services wrapped around it.
The attestation trap
Insurance carriers and compliance frameworks send questionnaires the client can't answer alone – "Is MFA enforced on all remote access?" – so the MSP maps each question to deployed controls and supplies the evidence. Do that work. But the hard rule, backed by broker guidance and channel consensus: fill in the facts, never sign the form.
Misstatements on insurance applications have led carriers to rescind coverage or deny claims after a breach – the ICSR/Travelers rescission case is the canonical example – and an MSP that wrongly attested "MFA everywhere" lands in the E&O crossfire alongside its client. The safe practice: provide written control status to the client, have the client's own officer sign the attestation, keep your evidence on file, carry your own E&O and cyber coverage, and put client-must-carry-cyber insurance language in your MSA – see MSP legal and insurance.
When to partner instead of DIY
- Certified assessments. CMMC Level 2 requires a C3PAO; SOC 2 requires a CPA firm. You can't audit your own work, and the frameworks require independent assessors anyway.
- Legal judgment calls. Breach notification decisions, BAA disputes, and regulator responses are attorney territory – notification clocks are counsel's call, not yours.
- Penetration testing. Use independent testers; HIPAA's proposed update would make annual pen tests mandatory, and self-testing convinces no one.
- Your first engagement in a new framework. Partner with an experienced consultant on client one, keep the managed-services side, learn the process, then deliver client two yourself.
The governing principle from the CMMC world applies everywhere: compliance can be outsourced in implementation, but never in accountability. The client owns the outcome – say so in writing.
Where to start
Pick the one framework your niche actually faces – Safeguards for dealers, HIPAA for practices, CMMC only if you're prepared to certify your own shop. Productize a fixed-price gap assessment, take one client end-to-end with a consultant partner if needed, then package what you learned as a monthly retainer. Compliance clients rarely leave: every audit cycle, insurance renewal, and new regulation deepens the relationship you already own.