Compliance

Last updated

Definition

Compliance is demonstrable conformance to an external standard – a law, a regulation, a contractual framework, or an insurer's requirements – proven with evidence a third party can examine. It is not the same thing as security. Security is the actual state of your controls; compliance is the documented proof that specific required controls exist, operate, and are checked on a schedule. A client can be compliant and still get ransomed, and a well-secured client with no evidence trail still fails the audit.

Why it matters to an MSP

For an SMB-focused MSP, four frameworks cover most of the demand: HIPAA for healthcare clients and their business associates, SOC 2 for services firms whose customers require it, CMMC for defense-supply-chain manufacturers, and PCI DSS for card payments. They overlap heavily – MFA, patching, logging, backup, access review – so the CIS Controls work as one baseline mapped to whichever framework a client needs; see compliance frameworks comparison for the differences.

The economics make compliance worth specializing in. The work is recurring – evidence collected monthly, policies reviewed annually, audits repeated on a cycle – so it fits a managed contract naturally. Compliance-managed seats typically price 15–35% above a standard plan depending on the framework, and regulated clients churn less because switching providers means re-proving everything to an auditor. The same artifacts do triple duty: a monthly patch-compliance report is QBR material, audit evidence, and cyber insurance documentation. Exposure cuts both ways: as the client's IT provider you are inside their audit scope, and a control you promised but did not run becomes your finding and your liability, so treat every contractual compliance commitment as a deliverable with an owner and a schedule. Productizing it is covered in compliance as a service.

Related terms: HIPAA, SOC 2, CMMC, vCISO