Skip to content

84 answers

MSP GRC and compliance FAQ

Compliance, vCISO, GRC, evidence, liability, and pricing questions for MSPs that need the scope to match the risk.

Maintained by
Scopable Team
Reviewed
2026-07-23
Primary page
MSP GRC and compliance software

GRC & Compliance

What does Scopable do for MSP GRC workflows?

Scopable helps MSPs activate client-linked frameworks, review evidence signals, inspect compliance gaps, summarize posture, and carry remediation decisions into assessment, roadmap, scope, or quote work. It is workflow support, not a legal or audit opinion.

Which compliance frameworks does Scopable support?

The current GRC setup flow exposes frameworks such as SOC 2, HIPAA, PCI-DSS, and CIS Controls. Framework availability can vary by account, so verify the exact framework and version before selling a client engagement around it.

What evidence can Scopable use for compliance work?

Microsoft 365 can feed customer mapping, user, license, MFA, and related evidence signals when consent, GDAP, and tenant mapping are configured. Other connector depth depends on rollout status and permissions. Do not promise evidence coverage until the client's stack has been tested.

Can Scopable AI change compliance records?

No. GRC chat tools are read-only today. They can list gaps, show control details, check MFA status, generate compliance summaries, and search controls. They cannot create gaps, attach evidence, change status, or build remediation plans.

How much do MSP compliance services typically cost?

MSP compliance services typically range from $25-150 per user per month depending on the service level. Basic compliance add-ons (policy templates, evidence collection) run $25-50/user. Managed compliance services (assessments, gap remediation, audit prep) run $75-150/user. vCISO-level services are priced per client at $3,000-15,000/month, not per user.

What is the profit margin on compliance services for MSPs?

Well-run compliance programs generate 30-40% net margins. Poorly scoped programs run 10-15% or negative. The difference comes down to scope discipline, pricing accuracy, and client selection. Most MSPs underestimate the hidden costs (scope creep, audit panic, client education) that erode margins.

Should MSPs offer vCISO services?

Most MSPs should not offer full vCISO services. The expertise required (strategic security leadership, risk quantification, executive communication) differs fundamentally from managed IT. MSPs who want to move in this direction should start with managed compliance services and develop strategic capabilities over time.

What is the difference between vCISO and vCIO for MSP clients?

A vCIO owns technology strategy, lifecycle planning, budgets, and vendor decisions. A vCISO owns security leadership, risk, compliance, incident readiness, and executive security reporting. MSPs should not sell vCISO as vCIO with security slides because the scope, liability, buyer, and pricing logic are different.

What should an MSP vCISO package include?

An MSP vCISO package should include an initial security assessment, risk register ownership, policy and procedure management, compliance tracking, incident response planning, and executive reporting. The package should sit above managed IT operations and turn tool data into business decisions, budgets, accepted risks, and remediation plans.

How should MSPs price vCISO services?

Ongoing vCISO services usually work best as a monthly retainer, not hourly work. Starter packages can land around $2,500-$5,000 per month, core packages around $5,000-$10,000 per month, and regulated or audit-heavy engagements around $10,000-$20,000 per month when the scope and risk justify it. Price from scope, delivery hours, client risk, and decision-maker access.

When should an MSP avoid selling full vCISO services?

An MSP should avoid full vCISO services when it cannot separate advisory work from help desk work, lacks someone who can discuss risk with executives, cannot document accepted risk, or has contracts that do not define advisory scope and liability. A safer starting point is a fixed-scope assessment, managed compliance, or partner-led delivery.

Which is better for MSPs, Apptega or ControlMap?

Apptega is usually better when the MSP needs broader GRC, framework crosswalking, evidence, audit prep, and policy workflow. ControlMap is usually better when the MSP needs a packaged vCISO motion with client reporting, roadmaps, and repeatable delivery. Pick by operating model, not by feature count.

When is Apptega the better fit for an MSP?

Apptega is the better fit when the MSP needs multi-framework coverage, audit readiness, risk and policy management, and a stronger evidence layer that can handle messy compliance work across different standards.

When is ControlMap the better fit for an MSP?

ControlMap is the better fit when the MSP is selling compliance as a service, needs a repeatable vCISO workflow, and wants executive reporting, roadmaps, and a clearer client-facing delivery motion.

Which tool is easier to price and package, Apptega or ControlMap?

ControlMap is easier to sanity-check upfront because it has public tier information. Apptega is harder to compare from the public site, so the buyer usually has to ask sharper packaging and scope questions early.

Why does cleanup ownership matter in Apptega vs ControlMap?

Because neither tool fixes a missing decision owner. If findings do not become a task, project, quote, or accepted risk, the platform is just producing prettier evidence.

Is Cynomi or vCIOToolbox better for MSPs?

Cynomi is usually better for MSPs building a paid vCISO, managed compliance, or recurring security program. vCIOToolbox is usually better for MSPs that need a stronger vCIO, QBR, TBR, account management, roadmap, and budget planning workflow.

Which platform is better for MSP vCISO services?

Cynomi is the more natural fit for vCISO services because the work centers on assessments, risk registers, framework mapping, remediation tracking, policy work, accepted-risk documentation, and executive security reporting. vCIOToolbox can support advisory conversations, but its center of gravity is client review and account planning.

Which platform is better for QBRs and client roadmaps?

vCIOToolbox is usually the better fit for QBRs, TBRs, client roadmaps, account strategy, and budget planning. Cynomi can produce executive security reporting, but the buying reason should be security program management, not general QBR discipline.

Can an MSP use Cynomi and vCIOToolbox together?

Yes, but only if the MSP has two defined motions: vCIOToolbox for vCIO account reviews and roadmaps, and Cynomi for vCISO security program delivery. The handoff must be clear so recommendations become risks, roadmap items, quotes, projects, or accepted decisions instead of living in two separate tools.

What liability do MSPs have for client compliance failures?

MSPs providing compliance services have contractual liability (what the MSA promised), professional liability (errors and omissions in advice), and potential regulatory liability (as business associates under HIPAA or data processors under GDPR). Liability can be limited through clear scope documents, refusal waivers, appropriate insurance, and shared responsibility matrices.

What client obligations should an MSP SLA include?

An MSP SLA should include client obligations for access, approvals, change notification, accepted risk, inventory updates, and personnel changes. Without those obligations, client-side delays or unmanaged changes can become the MSP's problem by default.

Should clients notify an MSP before making IT changes?

Yes. If a client changes infrastructure, credentials, vendors, software, or security settings that affect managed systems, the MSP needs notice before the change or as soon as practical during an emergency. Otherwise, the MSP may be blamed for damage caused by a change it never reviewed.

How should MSPs document declined security recommendations?

Document the specific risk, the MSP recommendation, the client's decision to decline or defer, and the next review date. For meaningful risks, get written acknowledgment from the client so the accepted risk is not lost in meeting notes or someone's memory.

What is an out-of-scope liability carveout in an MSP SLA?

An out-of-scope liability carveout says the MSP is not responsible for incidents caused by unmanaged systems, undocumented assets, client-managed changes, or approved exceptions. It should connect back to the quote, SOW, or service scope so both sides know what is covered.

What is the average price for MSP compliance services?

MSP compliance services typically range from $50-150 per user per month for ongoing management, with project-based assessments running $5,000-40,000 depending on framework and complexity. HIPAA tends toward the lower end ($50-100/user), while SOC 2 and CMMC command higher rates ($75-150/user). Minimums of $1,500-3,000/month apply regardless of user count.

Should I use per-user or retainer pricing for compliance?

Per-user pricing works for ongoing compliance management where effort scales with organization size. Retainer pricing works better for complex engagements where user count doesn't reflect actual effort, or for vCISO-level services. Many MSPs use per-user for standard compliance management and retainers for strategic advisory services.

How do I price compliance services for multiple frameworks?

Don't add framework prices together at full value. Use declining percentages: first framework at 100%, second at 60-70%, third at 50-60%. This accounts for control overlap while recognizing the additional complexity of multi-framework management.

What should be excluded from compliance pricing?

Always exclude: actual audit/assessment fees (client pays directly), legal review of policies and contracts, penetration testing (unless specifically included), infrastructure changes required for compliance, and security tool licensing. Define exclusions in your scope document before quoting.

What ISO 27001 services can an MSP provide to SMB clients?

MSPs can provide ISO 27001 scoping, gap analysis, risk assessment support, control implementation, policy support, evidence collection, internal audit preparation, and ongoing compliance review. The MSP should sell readiness and operating support, not the certificate itself.

How do MSPs define the ISMS scope for an SMB client?

Start with the business trigger. Name the systems, data types, locations, users, vendors, and services tied to that requirement. Then document what is out of scope. The right first scope is usually the smallest defensible scope that satisfies the client contract or insurance requirement.

How should MSPs price ISO 27001 compliance services?

Separate assessment, readiness, and ongoing support. Assessment is a one-time gap analysis. Readiness is a milestone project. Ongoing support is a monthly or quarterly retainer for evidence, policy, risk, and review cadence. Do not price audit fees, legal review, or major remediation as hidden inclusions.

Can an MSP certify a client to ISO 27001?

No. An MSP can prepare the client for certification, help implement controls, and organize evidence. The certification decision comes from an accredited certification body after audit. If the MSP has an auditor partner, that relationship still needs to be disclosed and scoped separately.

What evidence work can an MSP own for an ISO 27001 client?

An MSP can collect and organize technical evidence such as access reviews, backup test records, patch reports, vulnerability remediation history, logging coverage, asset inventories, and policy review records. The client still owns business risk decisions and management sign-off.

Do I need special insurance for compliance services?

Yes. Standard E&O policies may not cover compliance advisory services. Verify that your policy explicitly covers technology consulting and compliance services, and that it includes coverage for regulatory proceedings. Recommended minimum coverage is $2 million per occurrence for MSPs offering compliance services.

What is a shared responsibility matrix?

A shared responsibility matrix documents who is responsible for what in a compliance engagement. It specifies which controls and activities are the MSP's responsibility, which are the client's, and how shared responsibilities are divided. For CMMC, it's required. For all compliance services, it's essential for limiting liability.

How do I protect myself when clients refuse recommendations?

Use refusal waivers. Document the specific risk, your recommendation, the consequences of non-implementation, and the client's decision to decline. Get the client's signature acknowledging they understand the risk and accept responsibility. This provides evidence for your defense if the risk materializes.

How do I know if my MSP is ready for compliance services?

You're ready if you have real compliance expertise (not just vendor training), clients who need compliance services, ability to invest $20,000-50,000 over 6-12 months, willingness to accept advisory-level liability with proper protections, and ability to fire bad clients. If any of these are missing, address the gap first or consider alternatives.

Is ConnectSecure or Galactic Advisors better for MSPs?

ConnectSecure is usually better for MSPs that need recurring vulnerability management, multi-client scanning, prioritization, remediation workflow, and reporting. Galactic Advisors is usually better when the MSP needs independent validation, evidence, documentation, advisory guidance, and a stronger client security story.

Is a vulnerability assessment the same as a remediation plan?

No. A vulnerability assessment identifies and prioritizes findings. A remediation plan assigns owners, timeline, budget, exclusions, accepted risk, and client approval. MSPs should not treat a scan report as a signed scope of work.

Should MSPs run security assessments during pre-sales?

Only with written permission and a clear scope. Define systems in scope, data handling, scan method, report audience, remediation limits, and liability language before scanning a prospect environment. Free security discovery without boundaries can create unpaid consulting and messy blame.

How should MSPs turn assessment findings into quotes?

Classify every finding as included work, separately quoted remediation, roadmap item, accepted risk, or no action. Then carry the approved items into the SOW, quote, or QBR decision record. The finding is only useful when it becomes a client decision.

Is ConnectSecure or CYRISMA better for MSPs?

ConnectSecure is usually better when the MSP wants a direct vulnerability-management workflow with public MSP pricing, scanning, prioritization, reporting, and guided remediation. CYRISMA is usually better when findings need broader risk scoring, sensitive data context, compliance workflow, policies, and MSP portfolio reporting.

Which is cheaper for MSPs, ConnectSecure or CYRISMA?

ConnectSecure publishes MSP pricing starting at $300 per month, which makes early budget modeling easier. CYRISMA does not publish a simple public MSP price table, so MSPs should compare quoted total cost against the labor saved in scanning, reporting, remediation tracking, and client review.

Does a vulnerability scanner own remediation?

No. A scanner can find, prioritize, report, and sometimes guide remediation work. The MSP still needs to define who owns the fix, whether the work is included or separately quoted, when the client must approve it, and how accepted risk is recorded.

What should MSPs quote separately after a vulnerability scan?

Quote major remediation, emergency cleanup, project work, and exception follow-up separately unless the agreement explicitly includes them. Monthly vulnerability review can fit a managed security tier, but the included work, exclusions, and approval path need to be written down.

Which endpoint security platform is better for MSPs, CrowdStrike or SentinelOne?

There is no universal winner. CrowdStrike is the safer pick when you want a mature partner program, public bundle pricing, and a platform your technicians already know. SentinelOne is the better fit when you want a very explicit MSSP program, public package pricing, and a cleaner partner story for managed services. Pick the platform your team can deploy, tune, and support without inventing extra process.

Was the 2024 CrowdStrike outage caused by a kernel driver problem?

Yes. Microsoft's analysis says the crash traced to a read out-of-bounds access violation in CrowdStrike's CSagent driver, and Microsoft also estimated the July 2024 update affected 8.5 million Windows devices. The real lesson is that kernel-mode security software needs the same reliability discipline you would give any other production dependency.

Does CrowdStrike publish pricing for MSPs?

Yes, for its public bundles. CrowdStrike lists Falcon Go, Pro, and Enterprise with monthly and annual per-device pricing, while Falcon Complete is quote-based. Its partner terms also say partner pricing is list price minus the applicable discount, so MSP economics still depend on the deal you negotiate.

Does SentinelOne publish pricing for MSPs?

Yes. SentinelOne publishes package pricing for Singularity Complete, Commercial, and Enterprise, and the pricing page says purchases flow through an authorized third-party partner. That means the headline price is public, but the actual MSP deal still depends on the partner agreement.

What should an MSP compare before switching EDR vendors?

Compare support coverage, partner discount structure, multi-tenant operations, integration coverage, and the real migration cost of redeploying agents and retraining technicians. Detection quality matters, but switching friction usually decides the economics.

Should MSPs choose Huntress or Sophos MDR?

Choose Huntress when you want MSP-focused managed endpoint security, public endpoint pricing, and simple Microsoft Defender management. Choose Sophos MDR when the client needs wider MDR coverage, Microsoft telemetry, third-party integrations, and a tiered response model. The right answer depends on the response promise in the agreement.

What's the difference between Sophos MDR Essentials and Complete for MSPs?

Sophos MDR Essentials is built for organizations that can handle their own incident response after Sophos contains and escalates threats. Sophos MDR Complete is built for organizations with limited security resources and includes full-scale incident response, an incident response lead, threat elimination, and root cause investigation.

What response scope should MSPs define before selling MDR?

Define who can isolate endpoints, disable users, revoke sessions, approve client disruption, call the client after hours, write PSA notes, perform cleanup, and bill follow-up work. MDR without response scope turns a tool decision into a service delivery gap.

Should MSPs choose Arctic Wolf or Blackpoint Cyber?

Choose Arctic Wolf when the client needs a broader security operations partner, named guidance, posture improvement, and a concierge-style MDR relationship. Choose Blackpoint Cyber when the MSP wants channel-focused SOC response, endpoint and cloud identity coverage, and clearer active response language. The right answer depends on the response promise in the agreement.

How should MSPs compare Blackpoint Cyber and Arctic Wolf response scope?

Compare who investigates, who can isolate endpoints, who can disable users or revoke sessions, who calls the client, who writes PSA notes, who performs cleanup, and what becomes billable after containment. MDR language is not enough. The response owner has to be named.

Why does cloud MDR matter for MSP clients?

Cloud MDR matters because many real incidents start with identity, mailbox, or session abuse instead of malware on a device. MSPs should define which Microsoft 365 tenants, admin accounts, user identities, response actions, and reporting evidence are covered before selling it.

Is Coro or Guardz better for MSPs?

Coro is usually better when the MSP wants flexible workspace security coverage across endpoint, email, cloud apps, identity, network, data, and users. Guardz is usually better when the MSP wants an MSP-native managed security package with MDR, Microsoft 365-heavy controls, and client-ready reporting.

What MDR scope should MSPs verify before choosing Coro or Guardz?

Verify who can isolate endpoints, suspend users, approve disruptive response, call the client, write PSA notes, review policy drift, and decide what cleanup becomes billable work. MDR language is not enough. The response owner has to be named in the agreement.

What should security platform reports include for MSP clients?

Client reports should separate findings into included remediation, quoted remediation, roadmap work, accepted risk, no action, policy changes, and training needs. A report is useful only when it turns security noise into a client decision.

Should MSPs choose ESET PROTECT or Bitdefender GravityZone?

Choose ESET PROTECT when the client needs dependable endpoint-first security, broad OS coverage, and a cleaner modular path into XDR or MDR. Choose Bitdefender GravityZone when the MSP wants a broader multi-tenant security suite with hardening, risk analytics, EDR/XDR, email security, and MDR packaging.

How should MSPs compare ESET PROTECT MDR and Bitdefender MDR?

Compare response scope before features. MSPs should verify who monitors alerts, who can isolate endpoints, what actions are pre-approved, who calls the client, who writes PSA notes, and what cleanup becomes billable work after containment.

Do ESET PROTECT and Bitdefender GravityZone integrate with MSP tools?

Both have MSP management and integration paths, but MSPs should test the exact workflow before selling it. Confirm client creation, agent deployment, policy assignment, alert handling, PSA ticket path, service-account permissions, and what still needs manual work.

What can I offer clients if I'm not ready for full compliance services?

Alternatives include compliance-adjacent technical services (implementing controls without advisory), partnering with compliance specialists for joint engagements, security-first services where compliance is a byproduct, and framework education and preparation without recommendations.

Should I stop offering compliance services if they're not working?

Consider your options: invest to fix capability gaps, narrow scope to what you can actually deliver, partner with specialists and transition advisory work, or exit cleanly if there's no viable path to profitability. Continuing to lose money while accumulating liability is the worst option.

Is it true that every MSP needs to offer compliance services?

No. That narrative serves vendors, not MSPs. Compliance services require expertise, investment, and risk tolerance that not every MSP has. You can build a successful MSP without offering compliance services by focusing on what you're good at and partnering for what you're not.

What is a shared responsibility matrix in compliance?

A shared responsibility matrix documents who is responsible for what in a compliance engagement. For every control and activity, it specifies whether the MSP is responsible, the client is responsible, or responsibility is shared. It prevents disputes by documenting responsibilities before work begins.

Is a shared responsibility matrix required for CMMC?

Yes. CMMC requires that organizations seeking certification document shared responsibilities when using service providers. The assessor will ask for this documentation. Without it, the assessment cannot proceed.

How often should I update the shared responsibility matrix?

Review annually at minimum, and update whenever services change significantly. If you add new services, new systems come into scope, or responsibilities shift, update the SRM accordingly.

What happens if the client doesn't sign the shared responsibility matrix?

An unsigned SRM provides weaker protection than a signed one. If the client won't sign, document their acknowledgment in meeting notes or email. Include language in your SOW that references the SRM and their acceptance of it.

What is CMMC ESP scoping for MSPs?

CMMC ESP scoping for MSPs is the process of deciding whether an MSP's tools, people, or systems are part of a client's CMMC assessment scope because they process, store, transmit, or protect CUI, FCI, or security protection data. MSPs should do this before quoting remediation or audit support.

Which MSP tools can be in CMMC scope?

RMM, EDR, SIEM, backup, remote access, ticketing, documentation, identity, and Microsoft 365 administration tools may need review when they touch in-scope systems or security protection data. The question is not the tool category alone. It is what data the tool can process, store, transmit, or protect.

What is the difference between an ESP and a CSP in CMMC?

An External Service Provider is a broader service-provider category covering external people, technology, or facilities used for IT or cybersecurity services. A Cloud Service Provider is a cloud provider. Under CMMC scoping rules, the treatment depends on whether the provider handles CUI, security protection data, or neither.

Should an MSP quote CMMC cleanup before scoping CUI?

No. Quote a fixed-scope discovery or gap analysis first. Until the MSP traces CUI, security protection data, tools, access, evidence, and shared responsibilities, the cleanup quote is likely to miss work or assign responsibility to the wrong party.

Can an MSP build a controlled enclave for CMMC clients?

Yes, if the enclave is designed, documented, and operated with clear separation from the rest of the MSP delivery environment. An enclave can reduce ambiguity, but it does not remove assessment obligations when the enclave processes, stores, transmits, or protects CUI or security protection data.

What HIPAA changes are coming in 2026?

The 2026 HIPAA Security Rule update eliminates the 'addressable' vs 'required' distinction for controls, mandates encryption at rest, expands business associate requirements, and requires complete technology asset inventories. It's the biggest overhaul since the original Security Rule.

Do MSPs need to comply with HIPAA 2026?

Yes. MSPs that handle ePHI are considered business associates under HIPAA and must meet the same security standards as covered entities. The 2026 update expands BA requirements including verification, contingency planning, and incident response timelines.

Is encryption at rest required under HIPAA 2026?

Yes. The 2026 HIPAA Security Rule update makes encryption at rest mandatory. Previously it was 'addressable,' meaning organizations could document why they skipped it. That flexibility is being eliminated.

What is the MSP risk in keeping Windows 10 devices active after end of support?

The risk is that the device still works but no longer gets normal Windows security updates or support. That leaves the MSP carrying a known exception that should be documented, quoted, or retired.

What should an MSP include in an AI governance package?

An AI governance package should include an AI tool inventory, data exposure review, acceptable use policy, risk register, remediation roadmap, and recurring review cadence. A one-time assessment can start around $2,500-$4,500, while a quarterly governance retainer often fits around $750-$2,500 per month depending on client size and risk.

Should MSPs choose Todyl or Cato for SASE?

MSPs should look at Cato first when the client has multiple sites, private apps, WAN design, or VPN replacement complexity. MSPs should look at Todyl first when SASE needs to sit beside endpoint security, SIEM, MXDR, GRC, and security reporting. The right choice depends on what the MSP is ready to support after the sale.

When is Cato a better SASE fit for MSP clients?

Cato is usually a better first look when the client has several sites, legacy VPN appliances, private applications, firewall cleanup, or traffic-routing needs. The MSP should be ready to own network design, site cutovers, access policies, and tunnel support.

When is Todyl a better SASE fit for MSP clients?

Todyl is usually a better first look when the MSP wants SASE inside a broader managed security package with endpoint security, SIEM, MXDR, GRC, compliance evidence, and reporting. The MSP still needs to define which modules are included and what work becomes a paid project.

Do SASE projects need a client responsibility matrix?

Yes. A SASE responsibility matrix should name what the MSP owns, what the client approves, what the vendor supports, and what is excluded. It is especially important for disruptive actions such as DNS bypasses, tunnel changes, endpoint agent repairs, and after-hours outages.

Browse another FAQ cluster

Want the system behind the answers?

Scopable turns client context into roadmaps, scopes, and quotes your team can defend.