The Compliance Practice Nobody Bills For
Three years ago compliance was the service MSPs most wanted to add. Today four in ten sell it and fewer than one in ten make real money from it. This is a guide to closing that gap: what the practice sells, who buys it, how it gets priced, who runs it, what it costs to start, whether AI governance belongs in it, and what a buyer pays for it when the platform is sold.
Where compliance sits in the numbers
In Kaseya’s 2023 benchmark survey (1,091 MSPs, fielded late 2022), regulatory compliance management was the service more MSPs planned to add than any other: 39 percent, ahead of managed detection and response and dark web monitoring. That was the plan.
Here is where it landed. In Kaseya’s 2026 State of the MSP report (1,061 MSPs, fielded November 2025), 42 percent of MSPs now offer regulatory compliance and reporting. Asked to name their top three revenue sources, 8 percent named it. Endpoint and network management was named by 64 percent, security by 52, backup by 41. Compliance sits near the bottom of the list, next to training and support.
The growth number has not moved either. The share of MSPs reporting that compliance revenue rose in the past year was 35 percent in the 2023 report, 36 percent in the 2024 report, and 36 percent in the 2026 report. Security revenue rose for 71 percent of MSPs in the 2026 report. Compliance rose for half as many, and it has been that way for three years.
| Kaseya benchmark | 2023 report (n=1,091) | 2024 report (n=984) | 2026 report (n=1,061) |
|---|---|---|---|
| Planned to add compliance services | 39% (top of the list) | not asked | not asked |
| Offer regulatory compliance and reporting | not asked | not asked | 42% |
| Name compliance a top-three revenue source | 8% (executives) | 5% | 8% |
| Report compliance revenue increased | 35% | 36% | 36% |
| Report security revenue increased | 65% | 73% | 71% |
Question wording changed between editions (the 2023 revenue question went to executives only; the 2026 version asks for exactly three choices), so read the table as levels, not as a trend line. The levels tell the story on their own.
ScalePad’s 2026 MSP Trends Report (1,100 or more North American MSPs, fielded November 2025) gives the same picture from a different angle. Among MSPs that sell compliance, 11 percent get less than 5 percent of revenue from it, 32 percent get 6 to 10 percent, 38 percent get 11 to 25 percent, and 12 percent get more than a quarter of their revenue from it. Seven in ten sit in the 6 to 25 percent band. ScalePad also found that 90 percent of MSPs rate compliance as important to their business over the next three years, and that the MSPs who rate it that way report higher revenue, higher revenue per client and more recurring revenue than the ones who do not.
| Share of MSP revenue from compliance (ScalePad 2026) | Share of MSPs |
|---|---|
| Under 5% | 11% |
| 6 to 10% | 32% |
| 11 to 25% | 38% |
| More than 25% | 12% |
| Don’t know | 5% |
| None | 2% |
So the practice exists at most MSPs and earns at few. That is not a demand problem. It is a build problem, and the rest of this guide is the build.
What the client is buying
Start with the buyer, because the buyer explains the pricing failure.
Barracuda’s MSP Customer Insight Report 2025 (2,000 senior security decision-makers at organizations with 50 to 2,000 employees, fielded April and May 2025, so a larger client than most MSPs serve) asked why organizations outsource security to an MSP. The challenge of meeting regulatory compliance was named by 45 percent. On regulatory compliance specifically, 38 percent already get it from their MSP and another 34 percent expect to need it in the next one to two years.
Then it asked what they would pay. For regulatory compliance support, 34 percent would pay up to 25 percent more, 36 percent would pay up to 10 percent more, and 11 percent would not pay more at all. Seven in ten will pay a premium for it. The same report notes reluctance to spend on what it calls softer services: tabletop exercises, building the case for security spend, advice on what to buy. Compliance is not on that list. It is a hard deliverable with an auditor at the end of it, and buyers treat it that way.
| What buyers will pay for regulatory compliance support (Barracuda 2025, n=2,000) | Share |
|---|---|
| Up to 25% more | 34% |
| Up to 10% more | 36% |
| Not prepared to pay more | 11% |
Now the MSP side. In a March 2025 reader survey by MSP Success (a Kaseya-owned outlet that does not disclose its sample size, so treat every figure from it as a practitioner poll), 37 percent of MSPs that sell compliance fold it into the all-inclusive package, 56 percent price it in tiers, and 34 percent bill it by the hour or the project. The same survey found that 63 percent of MSPs say their clients do not budget for compliance inside the IT budget at all.
Put those two findings together. The buyer will pay 10 to 25 percent more for compliance and does not fund it from the IT line. A third of MSPs give it away inside the IT fee anyway. That is the 42-versus-8 gap in one sentence: the service is delivered, and the money is left in the client’s other budget.
What the practice sells
A compliance practice is not one product. It is a ladder, and each rung bills differently.
The MSP Success survey lists what MSPs that sell compliance deliver: security awareness training (91 percent), risk assessments (88), continuous monitoring (86), policy creation and documentation (78), remediation planning (71), and audit preparation and support (60). ScalePad’s 2026 report adds a sobering line: only 34 percent of MSPs do annual assessments for their clients, and among those that sell compliance, 54 percent offer risk assessments.
Roy Richardson of Aurora InfoTech described the shape that works in the MSP Success piece: bill the work of getting a client to baseline as a project, then keeping them in compliance becomes recurring revenue. That is the whole design.
| Rung | What it is | How it bills | Who does the work |
|---|---|---|---|
| Assessment | Gap analysis against the framework the client is held to (HIPAA, PCI DSS, CMMC, SOC 2, a state privacy law) | Project fee | Compliance lead, with the platform’s assessment templates |
| Remediation | Closing the gaps: policies, controls, training, evidence | Project fee or a fixed-term managed engagement | Technicians for controls, compliance lead for policy |
| Continuous compliance | Monitoring, evidence collection, policy review, quarterly reporting, the annual reassessment | Monthly recurring | Compliance analyst on a GRC platform |
| Audit support | Working with the client’s auditor or assessor through the audit window | Project fee, recurring where the audit is annual | Compliance lead |
| Virtual CISO | Standing security leadership for clients with no one in the seat | Monthly retainer | Senior compliance lead, fractional across clients |
The mistake most MSPs make is selling the first rung and the fourth rung and skipping the middle. An assessment is a project. Audit support is a project. Continuous compliance is the recurring revenue, and it is the part that turns compliance from a line item into a practice. It is also the part a buyer of the MSP pays a multiple on, which we come back to at the end.
The frameworks the client base is held to
The practice sells against whatever the client is required to follow. Two surveys say what that is. The MSP Success poll found that among MSPs selling compliance, 81 percent support HIPAA, 71 percent PCI DSS, 60 percent NIST CSF and 45 percent CMMC. Datto’s State of the MSP Report 2024 (1,262 MSPs worldwide) asked which frameworks clients are required to follow and got NIST 33 percent, HIPAA 31, CMMC 29, ISO 27001 28 and GDPR 26, with the global sample explaining the GDPR row.
The point for an owner is that HIPAA and PCI DSS are where the client base already lives. CMMC gets the trade press. HIPAA and PCI get the invoices.
Here is where each of the frameworks an American SMB is held to stood in September 2026, from the primary sources.
| Framework | Who it reaches | Status, September 2026 |
|---|---|---|
| HIPAA Security Rule | Healthcare providers, plans, and every vendor that touches patient data | Current rule in force. HHS proposed a rewrite on December 27, 2024; as of this month it is still a proposal. |
| PCI DSS v4.0.1 | Anyone that stores, processes or transmits card data | The 51 future-dated requirements became mandatory on March 31, 2025, per the PCI Security Standards Council. |
| CMMC | Defense contractors and their subcontractors; DoD’s own analysis counts 221,286 companies, 76,598 of them needing Level 2 certification | The contract clause rule took effect November 10, 2025. On July 13, 2026 the Department of War suspended the Phase II requirements that were due November 10, 2026 and opened a review. The Cyber AB’s June 2026 town hall counted 107 authorized assessors and more than 1,000 certified individual assessors. |
| FTC Safeguards Rule | Non-bank financial institutions: auto dealers, mortgage brokers, tax preparers, CPAs | Breach notification to the FTC required since May 13, 2024. |
| State privacy laws | Businesses over each state’s thresholds of residents or revenue | Nineteen states had passed comprehensive privacy laws as of IAPP’s October 2025 count. |
| SOC 2 | Any vendor whose customers ask for it; the audit report, not a law | An attestation issued by a CPA firm. One CPA firm, The Pun Group, publishes fee ranges of $5,000 to $20,000 for a Type I report and $20,000 to $50,000 for a Type II. |
Note what the CMMC row says. The suspension in July did not end the requirement; it paused the certification phase and opened a review. An MSP that built its compliance practice on the CMMC calendar has watched that calendar move three times. An MSP that built it on HIPAA and PCI has clients who were already required to comply and already are being asked to prove it.
Pricing: the number that decides whether it is a practice
Three pricing models are in use and only one of them builds a practice.
Bundled (the 37 percent) hides compliance inside the managed services fee. The client gets it, the MSP eats the labor, and nobody can say what compliance earns. Hourly or per project (the 34 percent) bills the assessment and the audit and skips the recurring middle. Tiered (the 56 percent) is the model that works: a compliance tier priced above the standard managed services tier, with continuous compliance inside it.
Tommy Thornton of Automates put the economics plainly in the MSP Success piece: the margins are better, because raising the seat price does not add labor hours when the work is tool based. Not one operator in that survey put a number on the margin, and no MSP benchmark I can find publishes one. Service Leadership’s service-line breakouts sit behind its paid report.
For planning, the only published price anchors are a tool vendor’s. ScalePad’s ControlMap build guide lays out three tiers, $750 to $1,500 a month, $1,500 to $3,500 a month, and $3,500 to $8,000 or more a month, at what it calls 60 to 70 percent or better gross margin, with a disclaimer that these are indicative planning anchors from commonly observed market practice and not benchmarks or guarantees. Read them as the vendor’s sales math, not as survey data. They are useful for one thing: they show the shape, a low tier that is mostly platform, a top tier that is mostly people.
The owner’s test is simpler than any of that. Does the compliance tier exist in the service catalog as its own line, with its own price, and can finance tell you compliance revenue per client for the last twelve months? If the answer is no, compliance is bundled whatever the rate card says.
Who buys it, and why the IT rep cannot sell it
The 63 percent figure above is the most useful number in this guide. Clients do not budget compliance under IT. It is funded by the office manager who got the letter from the payer, the CFO who got the questionnaire from the bank, the practice administrator whose cyber insurance renewal came back with new conditions. Peter Cole of PDC Technology said it in one line: it is a business discussion more than an IT discussion.
That changes who sells it. An account manager who sells endpoint seats to the IT contact is talking to the wrong person about the wrong budget. The compliance sale goes to the owner or the operator of the client business, it starts from the thing they were asked to produce (an attestation, a questionnaire, an audit date), and it ends in a scoped project with a recurring tail.
The order of operations matters too. Sell it into the base first. Kaseya’s 2026 report says 42 percent of MSPs already offer compliance, and the client base of any MSP in healthcare, legal, financial services or manufacturing already contains clients who are required to comply and are not paying anyone to help. Those clients already trust the MSP with their systems. The assessment is the door; it is scoped, priced and finished in weeks, and it produces a gap list that is the proposal for everything after it.
People and platform
A compliance practice runs on one senior person and a platform, and the number of clients that person can carry sets the margin.
The senior person needs a credential the client’s auditor recognizes. The operators in the MSP Success survey named CISSP and CISM; ISACA lists the CISM exam at $575 for members and $760 for non-members. For CMMC work, the Cyber AB’s entry credential, the CMMC Certified Professional, carries a $275 exam fee plus a $200 registration fee, and the training on top of it is sold by licensed providers at their own prices. The hard cost of credentials is small. The real cost is that the person who holds them is senior, scarce, and cannot be a technician on the side.
How many clients that person can carry is the whole staffing question. Cynomi, which sells a vCISO platform, publishes its own arithmetic: at 25 hours per client, one senior person carries five or six engagements before something gives, and its platform target is 15 to 20 clients per analyst. Treat both numbers as a vendor’s. The direction is right even if the figures are marketing: without a platform the practice is a consultancy with one bottleneck, and with one it is a managed service.
The platforms built for MSPs are a short list, and their dates say how young the category is.
| Platform | What it is | Dates and claims (all the vendors’ own) |
|---|---|---|
| ControlMap (ScalePad) | MSP-native vCISO and GRC platform | ScalePad acquired it in March 2023; publishes the build guide and price anchors quoted above |
| Compliance Manager GRC (Kaseya) | Policies, controls and audits in one workflow; frameworks can be customized | Pricing by quote only |
| Cynomi | vCISO platform for service providers | $37 million Series B, April 23, 2025; “hundreds of service providers … thousands of companies” |
| Vanta | Compliance automation with an MSP partner program | MSP program launched March 1, 2023 |
| Drata | Compliance automation; channel partners inside its “Launch” alliance program | Program announced February 13, 2024; MSPs not named in the release |
| Apptega | Multi-tenant security and compliance platform for MSSPs and MSPs | ”15,000+ security and compliance programs” on the platform (programs, not customers) |
None of them publishes an MSP count or a price list. The right way to read the table is that the tooling exists, it is three years old at most in its MSP form, and it is what lets one analyst carry fifteen clients instead of five.
AI governance: a line extension, not a new practice
This is the question owners are asking, so here is the honest read.
There is no United States rule that requires the typical small business to run an AI governance program. What exists is narrower. Texas’s Responsible Artificial Intelligence Governance Act took effect January 1, 2026 and reaches any business operating in Texas, but its core prohibition is deploying AI with intent to discriminate, and the statute says disparate impact alone does not establish intent. Colorado passed the first comprehensive state AI law in 2024, moved its effective date from February 1, 2026 to June 30, 2026, and has been rewriting it since. California’s rules on automated decision-making apply from January 1, 2027 to businesses already inside the state privacy law. New York City has required bias audits of automated hiring tools since July 5, 2023. The one obligation that already bites a class of SMB clients is federal: HHS’s Section 1557 rule requires healthcare providers to guard against discrimination through patient care decision support tools, with compliance due about May 1, 2025. Claims that insurers now ask about AI use on renewal applications show up in vendor blogs; I could not find a carrier’s own questionnaire to confirm it.
| US AI rule an SMB client can be held to | Reaches | In force |
|---|---|---|
| Texas TRAIGA (HB 149) | Any business operating in Texas; intent standard | January 1, 2026 |
| Colorado SB 24-205 | Developers and deployers of high-risk AI in consequential decisions | Delayed to June 30, 2026; still being rewritten |
| California CPPA ADMT regulations | Businesses under the state privacy law using automated decisions | January 1, 2027 |
| HHS Section 1557, 45 CFR 92.210 | Healthcare covered entities using patient care decision support tools | About May 1, 2025 |
| NYC Local Law 144 | Employers using automated hiring tools in New York City | Enforced since July 5, 2023 |
| Utah AI Policy Act (SB 149) | Businesses using generative AI with Utah consumers; disclosure only | Signed March 13, 2024 |
So the regulatory floor is thin. The policy demand is not. GTIA’s August 27, 2026 survey of 520 small and midsize businesses found 44 percent have an acceptable-use policy for AI tools, 39 percent have data security and confidentiality requirements for AI, 28 percent name developing AI governance policies as a top challenge, and half already work with an outside technology partner on AI. On the MSP side, Kaseya’s 2026 report has 48 percent of MSPs naming AI and automation the top client need and 13 percent earning meaningful revenue from it, with the report’s own explanation that providers are still defining, packaging and pricing these services. No MSP survey I can find, Kaseya, ScalePad, N-able, GTIA or WatchGuard, tracks AI governance as a service line at all.
Of the PE-backed platforms whose compliance pages I checked this month, one sells it. Dataprise lists an AI Readiness Assessment and an AI Strategy and Governance Advisory service, framework included. The compliance pages of Thrive, Ntiva, Coretelligent and Sourcepass do not mention it.
The read for an owner: AI governance is not a practice. It is a rung on the compliance ladder. The compliance team already writes policies (78 percent of compliance-selling MSPs do, per the MSP Success poll), already runs an annual review, already keeps evidence. An AI acceptable-use policy, a data-handling rule for AI tools, and an annual review of both is a scoped addition that sells to the existing compliance base this quarter, at compliance-tier pricing, with no new product and no new hire. Build it as a product line for clients who are not yet compliance clients and it will look like the 13 percent: demand everyone names and revenue nobody books.
What a buyer pays for it
The last question is what the practice is worth when the platform itself is sold, and the honest answer is that the deal tape does not say.
Drake Star’s first-quarter 2026 MSP report and M&A Signal’s 2026 MSP M&A Report, the two references buyers use, contain no compliance-specific commentary at all. The closest M&A Signal comes is its vertical row, a premium of one to three turns of profit for healthcare, legal and financial-services specialists, with the reason given in the report’s own words: compliance complexity creates client moat and pricing power. The same report says a healthcare MSP with HIPAA expertise and standing business associate agreement templates can charge 20 to 40 percent more than a generalist for the same endpoint coverage. That is the compliance practice priced at the client level, and it is what the multiple is built on.
The acquisitions confirm the appetite and hide the price. Thrive bought Abacode, a Tampa managed cybersecurity and compliance provider, on July 8, 2025; Thrive’s CEO Bill McLaughlin described compliance as a hurdle for small and mid-sized enterprises that lack the time or resources to track every change. Summit 7 bought GRC Academy, a CMMC training business, on September 4, 2025. Neither deal disclosed revenue, client count or price. Anyone advertising a compliance multiple is quoting their own opinion.
What a buyer will underwrite here is what a buyer underwrites everywhere else: recurring revenue with a reason to stay. Continuous compliance is recurring by construction, the client’s regulator or auditor supplies the reason, and the assessment that opened the account is on file as proof the relationship is documented. That is why the middle rung matters more than the multiple.
The owner’s list
Six things to ask for at the next operating review, in order.
- Compliance revenue per client for the trailing twelve months, from finance, not from the rate card. If it cannot be produced, compliance is bundled.
- The client list against the framework list: every client in healthcare, card payments, defense, financial services or a privacy-law state, with a yes or no on whether they buy compliance from us today. That gap is the pipeline.
- The compliance tier in the service catalog, with its own price and its own line on the invoice.
- The name of the person who sells it, and whether that person is talking to the owner of the client business or to its IT contact.
- The senior credential holder, the platform, and the clients-per-analyst number.
- The AI acceptable-use policy and review, priced as an addition to the compliance tier and quoted to existing compliance clients this quarter.
Forty-two percent of MSPs put compliance on the menu. Eight percent count it as a revenue source. Everything between those two numbers is a build, and none of it requires a market that does not already exist.
Frequently Asked Questions
How many MSPs offer compliance services, and how many make money from it?
Kaseya's 2026 State of the MSP report, a survey of 1,061 providers fielded in November 2025, found 42 percent offer regulatory compliance and reporting, while only 8 percent named it among their top three revenue sources, the same level as training and support. ScalePad's 2026 MSP Trends Report, from 1,100 or more North American MSPs, found that among providers selling compliance, 32 percent earn 6 to 10 percent of revenue from it, 38 percent earn 11 to 25 percent, and only 12 percent earn more than a quarter. The share of MSPs reporting compliance revenue growth has stayed at 35 to 36 percent across Kaseya's 2023, 2024 and 2026 editions.
How should an MSP price a compliance practice?
Three models are in use. Bundling compliance into the managed services fee hides what it earns; in MSP Success's 2025 reader survey, 37 percent of MSPs did this. Billing by the hour or the project, which 34 percent did, captures the assessment and the audit and skips the recurring middle. Tiered pricing, used by 56 percent, puts a compliance tier above the standard tier with continuous compliance inside it. The design that works bills the work of getting a client to baseline as a project, then keeps the client in compliance on a monthly recurring fee. Barracuda's 2025 survey found 34 percent of buyers would pay up to 25 percent more and 36 percent up to 10 percent more for regulatory compliance support, with only 11 percent unwilling to pay more.
Is AI governance something an MSP can sell as a compliance service?
As a line extension of an existing compliance practice, yes; as a new standalone product, not yet. No United States rule requires the typical small business to run an AI governance program: Texas's law took effect January 1, 2026 with an intent standard, Colorado's has been delayed and rewritten, California's automated decision-making rules apply from January 1, 2027, and the one binding obligation on a class of small clients is HHS's Section 1557 rule for healthcare providers. The policy demand is real: GTIA's August 2026 survey of 520 small and midsize businesses found 44 percent already have an acceptable-use policy for AI tools and 28 percent name developing AI governance policies a top challenge. Kaseya's 2026 report found 48 percent of MSPs call AI the top client need and 13 percent earn meaningful revenue from it. An AI acceptable-use policy, a data-handling rule and an annual review sold to existing compliance clients at compliance-tier pricing is the practical version.