Why MSPs Should Offer Compliance-as-a-Service in 2026
Compliance is becoming table stakes in the MSP industry. This article makes the business case for adding compliance monitoring and certification services to your MSP offering, with detailed margin analysis and go-to-market strategy.

Section 01
Why MSPs Should Offer Compliance-as-a-Service in 2026
Compliance-as-a-Service is a managed offering where an MSP supports evidence collection, control monitoring and preparation for the frameworks its clients actually need. Certification decisions remain with the relevant licensed or accredited body. The prices, margins and adoption rates below are an illustrative model for one MSP, not measured UK market averages.
Some MSP customers ask for documented controls, evidence and certification support. Whether a managed compliance service is profitable depends on actual demand and delivery costs. This article supplies a hypothetical planning model and a pilot-led service playbook.
Section 02
The Market Reality: Why Now?
Three forces are converging to make compliance essential for MSPs:
1. Customer Demand
MSP customers are facing increasing compliance pressure:
- Small businesses (10-50 employees) increasingly need Cyber Essentials to bid on government contracts or partner with larger firms
- Mid-market firms may face sector or buyer requirements; EU NIS2 applies only where its jurisdiction and entity criteria are met
- Large enterprises expect their MSPs to demonstrate compliance capabilities as part of vendor qualification
Customers aren't asking for compliance as a nice-to-have. They're requiring it before engaging or renewing MSP contracts.
2. Regulatory Mandates
Compliance frameworks are expanding:
- EU NIS2 can affect relevant EU entities and their supply chains; it is not a blanket UK MSP duty
- Cyber Essentials v3.3 explicitly addresses cloud and hybrid environments
- CMMC 2.0 (US defence sector) can affect managed service providers where the customer's covered contract, systems and assessment scope bring them into the requirement
- DORA (EU financial services) mandates ICT risk management including third-party oversight
Check each entity, jurisdiction, service and contract before treating any framework as applicable to an MSP or its customer.
3. Insurance Pressure
Cyber insurance is increasingly conditional on compliance. Insurers are offering:
- Evidence requests that differ by insurer and policy
- Control-maintenance conditions where the actual policy says so
- Monitoring records that a customer may choose to share with an insurer; the insurer decides their relevance
Ask each customer and insurer what the actual contract or policy requires; no universal MSP-certification or premium percentage follows from Cyber Essentials.
This insurance-driven demand is creating pull-through for compliance services from MSP customers.
Section 03
The Business Case: Unit Economics
The following is a hypothetical planning model, not observed Fig Group customer economics. Replace every price, workload, platform fee and uptake assumption with the MSP's own pilot data before using it in a business case.
Revenue Model
Scenario: An MSP offers two compliance service tiers:
Tier 1: Compliance Monitoring (Basic)
- Continuous security monitoring mapped to Cyber Essentials
- Monthly compliance reporting
- Annual Cyber Essentials certification support
- Price: £300-£500/month per customer
- Typical customer: 10-50 employees
Tier 2: Compliance Management (Advanced)
- Everything in Tier 1
- NIS2 / ISO 27001 readiness assessment
- Compliance gap remediation planning
- Regulatory reporting and evidence compilation
- Quarterly business reviews
- Price: £800-£1,500/month per customer
- Typical customer: 50-500 employees
Cost Structure
Setup Cost (Per Customer)
- Initial compliance assessment: 8 hours × £50/hour = £400
- Tool configuration and integration: 4 hours × £50/hour = £200
- Staff training and onboarding: 2 hours × £50/hour = £100
- Total setup: £700 per customer
Ongoing Costs (Per Month)
Replace these placeholder allocations with the MSP base fee, all client corporate-package charges and actual support costs from your own quote before using the model. Fig Group’s published MSP plans price the MSP subscription and client packages separately.
For Tier 1 (basic monitoring):
- Placeholder allocated platform cost: £30/month (illustrative input, not a Fig Group price)
- Monitoring and reporting (automated): £20/month
- Occasional escalation and support: £50/month
- Total: £100/month
For Tier 2 (advanced management):
- Platform subscription: £50/month
- Continuous monitoring and remediation: £100/month
- Monthly review and gap analysis: 2 hours × £50/hour = £100/month
- Quarterly business reviews: 2 hours × £50/hour = £100/quarter, or £33.33/month averaged
- Total: £283.33/month averaged
Unit Economics by Tier
Tier 1: Compliance Monitoring
- Revenue: £400/month (using mid-range price)
- Costs: £100/month
- Gross margin: 75%
- Gross margin dollars: £300/month
- Payback period: 2.3 months (£700 setup ÷ £300 monthly margin)
Tier 2: Compliance Management
- Revenue: £1,150/month (mid-range)
- Costs: £283.33/month
- Gross margin: 75.36%
- Gross contribution: £866.67/month
- Illustrative setup-cost payback: about 0.81 months (£700 ÷ £866.67), before sales and central costs
Portfolio Impact
Assume an MSP with 200 customers:
Scenario A: 30% of customers on Tier 1, 10% on Tier 2
- Tier 1 customers: 60 × £300 gross margin = £18,000/month
- Tier 2 customers: 20 × £866.67 gross contribution = about £17,333/month
- Annual gross contribution: about £424,000, before setup and any costs excluded from the unit model
- Year-one investment: 60 setups + 20 setups = 80 × £700 = £56,000
- Year-one gross contribution after example setup costs: about £368,000, before sales, central overhead, taxes and any additional costs demonstrably outside the unit model
The unit costs above already include £30 or £50 per customer per month for platform access and line-item staff work. A further £2,000/month platform charge or £25,000 staff allocation can only be deducted if it represents a distinct cost not included in those unit amounts. This model has no evidence for that distinction.
After the illustrative £56,000 setup cost, gross contribution would be about £368,000 before sales, central overhead, taxes and any additional distinct platform or staff costs. This is not a net profit forecast.
Pilot conversion, delivery time and support cost determine whether this is attractive in a real portfolio.
Section 04
The Go-to-Market Strategy
Phase 1: Understand Your Customer Base (Month 1)
Audit your current customer base:
- What's the customer size distribution?
- What industries are they in? (Are they regulated? Are they selling to government?)
- Do they currently have compliance certifications? (Cyber Essentials, ISO 27001, etc.)
- What's their compliance readiness? (Are they already monitoring security?)
This audit informs your go-to-market. A portfolio of defence contractors will have different compliance needs than retail businesses.
Phase 2: Define Your Service Offering (Month 1-2)
Build a service definition that fits your expertise and customer base:
Option A: Cyber Essentials-First
Start with Cyber Essentials compliance (the five controls). Most MSPs already monitor these in some form. Packaging and formalising this into a compliance service is relatively straightforward.
- Planning assumption to test: 2-4 weeks per customer
- Complexity: Low-Medium
- Revenue potential: £300-£500/month per customer
- Suitable for: MSPs with strong monitoring and EDR already deployed
Option B: NIS2/ISO 27001-Ready
Target mid-market customers preparing for NIS2 or ISO 27001. This requires deeper expertise around risk management and evidence documentation but commands higher pricing.
- Planning assumption to test: 4-8 weeks per customer
- Complexity: Medium-High
- Illustrative proposed price: £800-£2,000/month per customer; validate it with quotes and pilot uptake
- Suitable for: MSPs with security consulting expertise or willing to upskill
Option C: Hybrid Approach
Offer Tier 1 (Cyber Essentials) to most customers, Tier 2 (NIS2/ISO) to customers who need it. This segments your market and allows you to scale Tier 1 while building expertise in Tier 2.
Phase 3: Build Your Technology Foundation (Month 2-3)
You need a platform that:
1. Integrates with your existing tools (your RMM, endpoint protection, network monitoring)
2. Provides compliance reporting against your chosen frameworks
3. Automates evidence collection so you're not manually compiling reports monthly
4. Grows with you so adding new customers doesn't create linear support load
Options include:
Build custom integration (estimate engineering effort from your actual integration scope)
- Pros: Fully customised, no ongoing licensing costs
- Cons: Requires deep technical expertise, updates required as tools change
Use a compliance platform (for example Fig Group, Drata, Vanta or Secureframe; compare actual capabilities and agreements)
- Pros: Pre-built integrations, regular updates, professional evidence collection
- Cons: Licensing costs depend on the selected platform, scope and agreement
Hybrid approach (recommended)
- Integrate your existing monitoring (Solarwinds, N-Able, etc.) with a compliance platform
- This minimises custom development while providing professional compliance reporting
Phase 4: Launch Pilot Programme (Month 3-4)
Don't launch to all 200 customers simultaneously. Start with a pilot:
- Select 5-10 existing customers who are enthusiastic about compliance
- Choose a written pilot price and duration; a 50% discount for three months is one possible test, not a measured market practice
- Refine your service delivery based on their feedback
- Generate case studies and testimonials
- Measure time and cost per customer
This pilot teaches you what actually works before you scale.
Phase 5: Soft Launch to Warm Leads (Month 4-5)
With pilot learnings, approach customers who explicitly asked for compliance services:
- Customers preparing for government contracts
- Customers who received compliance-related RFPs
- Customers worried about insurance or regulations
These customers have already identified the need. Your job is to show them you can address it.
Phase 6: Full Market Launch (Month 5+)
Once you've proven the model with 20-30 customers:
- Update your marketing website with compliance services
- Create case studies and ROI calculators
- Train sales team on positioning
- Add compliance to renewal conversations
Don't position compliance as an expensive, complicated product. Position it as a risk mitigation service that potentially reduces insurance costs, wins contracts, and improves security.
Section 05
Positioning: How to Sell Compliance Services
Compliance services sell better when positioned around customer pain, not regulatory requirements.
DON'T say: "You need to be Cyber Essentials certified to comply with UK regulations."
DO say: "Which customers have asked about your security practices before signing? Let's build a formal evidence programme around their actual requirements and check any insurance terms directly."
Position compliance as:
- Risk mitigation: "Reduce your exposure to fines, breach notification costs, and reputational damage"
- Business enablement: "Access government contracts and partnerships that require compliance certification"
- Insurance optimisation: "Demonstrate security maturity to your insurer and potentially reduce premiums"
- Trusted partner: "When your customers ask about your security practices, you have audited, certified evidence"
Section 06
Overcoming Objections
"We don't have expertise in compliance"
True initially, but expertise is built by doing. Start with Cyber Essentials (relatively straightforward). Train your team. Move to more complex frameworks over time. A compliance platform handles much of the heavy lifting.
"Our customers don't ask for compliance"
Ask customers what they need and test a small offer. Regulation and insurer requirements differ; a pilot can establish whether there is local demand.
"This seems expensive to implement"
Use the unit model above with your own staff, platform, sales and setup costs. It does not establish a £50k-£150k investment or a 6-12 month payback for a real MSP.
"We already do monitoring - isn't compliance monitoring the same?"
Monitoring and compliance are related but different. Monitoring tells you what's happening in your infrastructure. Compliance tells you whether your infrastructure meets regulatory or customer requirements. Packaging monitoring as formal compliance, with reporting and certification, is a service layer most MSPs haven't yet built.
Section 07
Timeline and Quick Wins
You don't need to build this all at once. Start with quick wins:
Months 1-3: Define the offering and invite 5-10 pilot customers. Record contracted pilot revenue; a 50% discount is not £0 revenue.
Months 3-6: Refine delivery and expand only if the measured unit economics and customer feedback justify it.
Months 6-12: Consider a wider launch after validating conversion, delivery capacity and margins.
Year 2+: For a hypothetical 40-80 retained customers, calculate revenue from the actual tier mix and contracted prices; no fixed range follows from customer count alone.
The potential contribution can be material, but a real forecast requires contracted prices, retention, workload and platform costs.
Section 08
The Bottom Line
Compliance-as-a-Service can add a useful managed offering where customers have a documented need and the MSP can deliver it profitably. Pilot the service before forecasting lifetime value or margins.
Start with a scoped customer discovery and pilot, then decide whether to expand using the results.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Learn how MSPs are building profitable compliance-as-a-service offerings with Fig Group's multi-tenant platform.
Request a demoRelated guides
Continue reading
Compliance
IASME-Licensed Cyber Essentials Bodies: What to Look For in 2026
What does IASME licensing actually mean, and why does it matter when choosing a Cyber Essentials certification body? A guide to navigating the market.
Read articleCompany
What Is Fig Group? The MSP Compliance Platform, Not Financial Institutions Group
What MSPs can do with the Fig Group platform: manage client compliance, risk, monitoring and evidence, with separately licensed certification services.
Read articleIndustry
Cyber Essentials for MSPs: Why Certification Is About to Become Non-Negotiable
The Cyber Security and Resilience Bill proposes duties for managed service providers that meet its defined scope. It does not currently impose a blanket Cyber Essentials certification duty on every MSP. Here is how to assess the proposal and prepare your service.
Read article

