Skip to content
MSP Growth

Why MSPs Should Offer Compliance-as-a-Service in 2026

Compliance is becoming table stakes in the MSP industry. This article makes the business case for adding compliance monitoring and certification services to your MSP offering, with detailed margin analysis and go-to-market strategy.

Colleagues working together around a laptop in an office
Illustrative stock image. Stock image via Unsplash.

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

8 min read

Share

Section 01

Why MSPs Should Offer Compliance-as-a-Service in 2026

Compliance-as-a-Service is a managed offering where an MSP supports evidence collection, control monitoring and preparation for the frameworks its clients actually need. Certification decisions remain with the relevant licensed or accredited body. The prices, margins and adoption rates below are an illustrative model for one MSP, not measured UK market averages.

Some MSP customers ask for documented controls, evidence and certification support. Whether a managed compliance service is profitable depends on actual demand and delivery costs. This article supplies a hypothetical planning model and a pilot-led service playbook.

Section 02

The Market Reality: Why Now?

Three forces are converging to make compliance essential for MSPs:

1. Customer Demand

MSP customers are facing increasing compliance pressure:

  • Small businesses (10-50 employees) increasingly need Cyber Essentials to bid on government contracts or partner with larger firms
  • Mid-market firms may face sector or buyer requirements; EU NIS2 applies only where its jurisdiction and entity criteria are met
  • Large enterprises expect their MSPs to demonstrate compliance capabilities as part of vendor qualification

Customers aren't asking for compliance as a nice-to-have. They're requiring it before engaging or renewing MSP contracts.

2. Regulatory Mandates

Compliance frameworks are expanding:

  • EU NIS2 can affect relevant EU entities and their supply chains; it is not a blanket UK MSP duty
  • Cyber Essentials v3.3 explicitly addresses cloud and hybrid environments
  • CMMC 2.0 (US defence sector) can affect managed service providers where the customer's covered contract, systems and assessment scope bring them into the requirement
  • DORA (EU financial services) mandates ICT risk management including third-party oversight

Check each entity, jurisdiction, service and contract before treating any framework as applicable to an MSP or its customer.

3. Insurance Pressure

Cyber insurance is increasingly conditional on compliance. Insurers are offering:

  • Evidence requests that differ by insurer and policy
  • Control-maintenance conditions where the actual policy says so
  • Monitoring records that a customer may choose to share with an insurer; the insurer decides their relevance

Ask each customer and insurer what the actual contract or policy requires; no universal MSP-certification or premium percentage follows from Cyber Essentials.

This insurance-driven demand is creating pull-through for compliance services from MSP customers.

Section 03

The Business Case: Unit Economics

The following is a hypothetical planning model, not observed Fig Group customer economics. Replace every price, workload, platform fee and uptake assumption with the MSP's own pilot data before using it in a business case.

Revenue Model

Scenario: An MSP offers two compliance service tiers:

Tier 1: Compliance Monitoring (Basic)

  • Continuous security monitoring mapped to Cyber Essentials
  • Monthly compliance reporting
  • Annual Cyber Essentials certification support
  • Price: £300-£500/month per customer
  • Typical customer: 10-50 employees

Tier 2: Compliance Management (Advanced)

  • Everything in Tier 1
  • NIS2 / ISO 27001 readiness assessment
  • Compliance gap remediation planning
  • Regulatory reporting and evidence compilation
  • Quarterly business reviews
  • Price: £800-£1,500/month per customer
  • Typical customer: 50-500 employees

Cost Structure

Setup Cost (Per Customer)

  • Initial compliance assessment: 8 hours × £50/hour = £400
  • Tool configuration and integration: 4 hours × £50/hour = £200
  • Staff training and onboarding: 2 hours × £50/hour = £100
  • Total setup: £700 per customer

Ongoing Costs (Per Month)

Replace these placeholder allocations with the MSP base fee, all client corporate-package charges and actual support costs from your own quote before using the model. Fig Group’s published MSP plans price the MSP subscription and client packages separately.

For Tier 1 (basic monitoring):

  • Placeholder allocated platform cost: £30/month (illustrative input, not a Fig Group price)
  • Monitoring and reporting (automated): £20/month
  • Occasional escalation and support: £50/month
  • Total: £100/month

For Tier 2 (advanced management):

  • Platform subscription: £50/month
  • Continuous monitoring and remediation: £100/month
  • Monthly review and gap analysis: 2 hours × £50/hour = £100/month
  • Quarterly business reviews: 2 hours × £50/hour = £100/quarter, or £33.33/month averaged
  • Total: £283.33/month averaged

Unit Economics by Tier

Tier 1: Compliance Monitoring

  • Revenue: £400/month (using mid-range price)
  • Costs: £100/month
  • Gross margin: 75%
  • Gross margin dollars: £300/month
  • Payback period: 2.3 months (£700 setup ÷ £300 monthly margin)

Tier 2: Compliance Management

  • Revenue: £1,150/month (mid-range)
  • Costs: £283.33/month
  • Gross margin: 75.36%
  • Gross contribution: £866.67/month
  • Illustrative setup-cost payback: about 0.81 months (£700 ÷ £866.67), before sales and central costs

Portfolio Impact

Assume an MSP with 200 customers:

Scenario A: 30% of customers on Tier 1, 10% on Tier 2

  • Tier 1 customers: 60 × £300 gross margin = £18,000/month
  • Tier 2 customers: 20 × £866.67 gross contribution = about £17,333/month
  • Annual gross contribution: about £424,000, before setup and any costs excluded from the unit model
  • Year-one investment: 60 setups + 20 setups = 80 × £700 = £56,000
  • Year-one gross contribution after example setup costs: about £368,000, before sales, central overhead, taxes and any additional costs demonstrably outside the unit model

The unit costs above already include £30 or £50 per customer per month for platform access and line-item staff work. A further £2,000/month platform charge or £25,000 staff allocation can only be deducted if it represents a distinct cost not included in those unit amounts. This model has no evidence for that distinction.

After the illustrative £56,000 setup cost, gross contribution would be about £368,000 before sales, central overhead, taxes and any additional distinct platform or staff costs. This is not a net profit forecast.

Pilot conversion, delivery time and support cost determine whether this is attractive in a real portfolio.

Section 04

The Go-to-Market Strategy

Phase 1: Understand Your Customer Base (Month 1)

Audit your current customer base:

  • What's the customer size distribution?
  • What industries are they in? (Are they regulated? Are they selling to government?)
  • Do they currently have compliance certifications? (Cyber Essentials, ISO 27001, etc.)
  • What's their compliance readiness? (Are they already monitoring security?)

This audit informs your go-to-market. A portfolio of defence contractors will have different compliance needs than retail businesses.

Phase 2: Define Your Service Offering (Month 1-2)

Build a service definition that fits your expertise and customer base:

Option A: Cyber Essentials-First

Start with Cyber Essentials compliance (the five controls). Most MSPs already monitor these in some form. Packaging and formalising this into a compliance service is relatively straightforward.

  • Planning assumption to test: 2-4 weeks per customer
  • Complexity: Low-Medium
  • Revenue potential: £300-£500/month per customer
  • Suitable for: MSPs with strong monitoring and EDR already deployed

Option B: NIS2/ISO 27001-Ready

Target mid-market customers preparing for NIS2 or ISO 27001. This requires deeper expertise around risk management and evidence documentation but commands higher pricing.

  • Planning assumption to test: 4-8 weeks per customer
  • Complexity: Medium-High
  • Illustrative proposed price: £800-£2,000/month per customer; validate it with quotes and pilot uptake
  • Suitable for: MSPs with security consulting expertise or willing to upskill

Option C: Hybrid Approach

Offer Tier 1 (Cyber Essentials) to most customers, Tier 2 (NIS2/ISO) to customers who need it. This segments your market and allows you to scale Tier 1 while building expertise in Tier 2.

Phase 3: Build Your Technology Foundation (Month 2-3)

You need a platform that:

1. Integrates with your existing tools (your RMM, endpoint protection, network monitoring)

2. Provides compliance reporting against your chosen frameworks

3. Automates evidence collection so you're not manually compiling reports monthly

4. Grows with you so adding new customers doesn't create linear support load

Options include:

Build custom integration (estimate engineering effort from your actual integration scope)

  • Pros: Fully customised, no ongoing licensing costs
  • Cons: Requires deep technical expertise, updates required as tools change

Use a compliance platform (for example Fig Group, Drata, Vanta or Secureframe; compare actual capabilities and agreements)

  • Pros: Pre-built integrations, regular updates, professional evidence collection
  • Cons: Licensing costs depend on the selected platform, scope and agreement

Hybrid approach (recommended)

  • Integrate your existing monitoring (Solarwinds, N-Able, etc.) with a compliance platform
  • This minimises custom development while providing professional compliance reporting

Phase 4: Launch Pilot Programme (Month 3-4)

Don't launch to all 200 customers simultaneously. Start with a pilot:

  • Select 5-10 existing customers who are enthusiastic about compliance
  • Choose a written pilot price and duration; a 50% discount for three months is one possible test, not a measured market practice
  • Refine your service delivery based on their feedback
  • Generate case studies and testimonials
  • Measure time and cost per customer

This pilot teaches you what actually works before you scale.

Phase 5: Soft Launch to Warm Leads (Month 4-5)

With pilot learnings, approach customers who explicitly asked for compliance services:

  • Customers preparing for government contracts
  • Customers who received compliance-related RFPs
  • Customers worried about insurance or regulations

These customers have already identified the need. Your job is to show them you can address it.

Phase 6: Full Market Launch (Month 5+)

Once you've proven the model with 20-30 customers:

  • Update your marketing website with compliance services
  • Create case studies and ROI calculators
  • Train sales team on positioning
  • Add compliance to renewal conversations

Don't position compliance as an expensive, complicated product. Position it as a risk mitigation service that potentially reduces insurance costs, wins contracts, and improves security.

Section 05

Positioning: How to Sell Compliance Services

Compliance services sell better when positioned around customer pain, not regulatory requirements.

DON'T say: "You need to be Cyber Essentials certified to comply with UK regulations."

DO say: "Which customers have asked about your security practices before signing? Let's build a formal evidence programme around their actual requirements and check any insurance terms directly."

Position compliance as:

  • Risk mitigation: "Reduce your exposure to fines, breach notification costs, and reputational damage"
  • Business enablement: "Access government contracts and partnerships that require compliance certification"
  • Insurance optimisation: "Demonstrate security maturity to your insurer and potentially reduce premiums"
  • Trusted partner: "When your customers ask about your security practices, you have audited, certified evidence"

Section 06

Overcoming Objections

"We don't have expertise in compliance"

True initially, but expertise is built by doing. Start with Cyber Essentials (relatively straightforward). Train your team. Move to more complex frameworks over time. A compliance platform handles much of the heavy lifting.

"Our customers don't ask for compliance"

Ask customers what they need and test a small offer. Regulation and insurer requirements differ; a pilot can establish whether there is local demand.

"This seems expensive to implement"

Use the unit model above with your own staff, platform, sales and setup costs. It does not establish a £50k-£150k investment or a 6-12 month payback for a real MSP.

"We already do monitoring - isn't compliance monitoring the same?"

Monitoring and compliance are related but different. Monitoring tells you what's happening in your infrastructure. Compliance tells you whether your infrastructure meets regulatory or customer requirements. Packaging monitoring as formal compliance, with reporting and certification, is a service layer most MSPs haven't yet built.

Section 07

Timeline and Quick Wins

You don't need to build this all at once. Start with quick wins:

Months 1-3: Define the offering and invite 5-10 pilot customers. Record contracted pilot revenue; a 50% discount is not £0 revenue.

Months 3-6: Refine delivery and expand only if the measured unit economics and customer feedback justify it.

Months 6-12: Consider a wider launch after validating conversion, delivery capacity and margins.

Year 2+: For a hypothetical 40-80 retained customers, calculate revenue from the actual tier mix and contracted prices; no fixed range follows from customer count alone.

The potential contribution can be material, but a real forecast requires contracted prices, retention, workload and platform costs.

Section 08

The Bottom Line

Compliance-as-a-Service can add a useful managed offering where customers have a documented need and the MSP can deliver it profitably. Pilot the service before forecasting lifetime value or margins.

Start with a scoped customer discovery and pilot, then decide whether to expand using the results.

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

Learn how MSPs are building profitable compliance-as-a-service offerings with Fig Group's multi-tenant platform.

Request a demo

Related solutions

Continue exploring Fig Group