Buyer Guide · 2026

Managed IT and compliance: what an MSP can and cannot do

An independent guide to the frameworks SMBs face — HIPAA, PCI DSS, SOC 2, CMMC and more — the security controls auditors expect, and exactly where a managed service provider helps versus where the legal responsibility stays with you.

Quick answer

A managed service provider helps you meet frameworks like HIPAA, PCI DSS, SOC 2, and CMMC by implementing security controls, documenting policies, and supplying audit evidence. But compliance stays your legal responsibility — no MSP can “certify” you, and HIPAA has no official certification at all.

Start here

Why IT compliance is now a board-level issue

Compliance used to be a problem for large enterprises. In 2026 it lands on businesses of every size, because three forces converged: regulators expanded the rules to smaller firms, cyber-insurance underwriters made specific controls a condition of coverage, and enterprise customers began pushing security requirements down to their vendors through contracts and questionnaires.

For most small and mid-sized businesses, “IT compliance” means demonstrating — with evidence — that you protect sensitive data the way a specific framework requires. That could be patient records under HIPAA, cardholder data under PCI DSS, customer financial data under the FTC Safeguards Rule, or controlled defense information under CMMC. The framework that applies to you depends on your industry, your customers, and the data you handle.

This is where a managed service provider earns its place. Most of what a framework demands — multi-factor authentication, encryption, logging, access control, documented policies, continuous monitoring — is exactly the work an MSP already does, and doing it across many regulated clients makes a specialist provider faster and more credible than a stretched internal team. But there is a hard line this guide keeps returning to: an MSP can build and operate your controls, yet the legal accountability for compliance never leaves your organization.

The distinction that trips everyone up

Security and compliance are related but not the same. Security is whether your data is actually protected. Compliance is whether you can prove, with documentation and evidence, that you meet a defined standard. A business can be reasonably secure and still fail an audit for lack of evidence — which is why documentation, not just tooling, is half the job.

The rulebooks

The compliance frameworks SMBs actually face

You rarely get to choose your framework — your industry, customers, and data decide it for you, and many businesses fall under more than one. These are the standards a managed service provider is most often asked to support.

FrameworkWho it applies toWhat it governs
HIPAAHealthcare providers, plans, and their vendorsProtected health information (PHI); security and privacy of patient data
PCI DSSAny business that stores or processes card paymentsCardholder data; a contractual standard set by the card brands
SOC 2SaaS and service firms that hold customer dataAn independent attestation of security controls; often demanded by customers
CMMC / NIST 800-171Defense contractors and the DoD supply chainControlled unclassified information (CUI); required to win contracts
GLBA / FTC Safeguards RuleFinancial institutions and many lenders, advisers, dealersCustomer financial information; a written security program
GDPR / CCPAAnyone handling EU or California resident dataPersonal data privacy, consent, and breach notification
ISO 27001Firms wanting a recognized global security certificationAn information security management system (ISMS)
NIST CSF 2.0Any organization, as a voluntary best-practice baselineA framework of security functions many others map back to

Two clarifications save a lot of confusion. SOC 2 and ISO 27001 produce a real, third-party attestation or certificate you can show customers; HIPAA, by contrast, has no official government certification — any vendor claiming to be “HIPAA certified” is using marketing language, not a recognized credential. And most frameworks overlap heavily at the control level, so meeting one well puts you most of the way toward the next.

The MSP role

What an MSP actually does for compliance

A compliance-capable MSP does far more than install antivirus. Its work spans the technical controls, the paperwork that proves them, and the ongoing operation that keeps you compliant between audits. These are the six things the right provider brings.

1

Risk assessment & gap analysis

Maps your current state against the framework that applies to you and produces a prioritized list of gaps. Most frameworks require a documented risk assessment as a starting point.

2

Implementing technical controls

Deploys and operates the safeguards auditors look for: MFA, EDR/MDR, encryption, email security, patching, and least-privilege access across your environment.

3

Policies & documentation

Drafts and maintains the written policies, procedures, and an incident-response plan that frameworks demand. This paperwork is what most businesses lack and what auditors check first.

4

Continuous monitoring & SIEM

Runs logging, alerting, and often a 24/7 security operations center, so controls keep working between audits and you can detect and respond to incidents.

5

Audit evidence & reporting

Collects and organizes the logs, configurations, and reports an assessor will ask for, so audit season is a document hand-off rather than a scramble.

6

Training, BAAs & vendor management

Delivers security awareness training, signs a business associate agreement (BAA) where PHI is involved, and helps manage the security of your other vendors.

What an MSP cannot do is sign your name on the compliance attestation or assume your liability. It also cannot replace the independent auditor: a SOC 2 report or PCI assessment is issued by a qualified third party, never by the MSP that built your controls. The provider gets you ready; an external assessor certifies the result.

The common core

The security controls auditors expect

Frameworks differ in wording, but they converge on the same core safeguards. Put these in place well and you are most of the way to satisfying almost any standard you are likely to face. This is also the layer cyber-insurance underwriters now require before they will write a policy.

ControlWhat it isWhy frameworks require it
Multi-factor authentication (MFA)A second factor beyond a password on every accountThe single most effective control against account takeover; now near-universal
EDR / MDREndpoint detection and response, often managed 24/7Detects and contains threats antivirus misses; expected by insurers and auditors
EncryptionProtecting data at rest and in transitRequired for PHI, cardholder, and financial data; limits breach impact
Logging & monitoring (SIEM)Centralized, retained logs with alertingMost frameworks require audit trails and the ability to detect incidents
Access control & least privilegeRole-based access and periodic access reviewsLimits who can reach sensitive data; a core requirement everywhere
Patch & vulnerability managementTimely updates and regular vulnerability scansCloses known weaknesses attackers exploit; explicitly required by most rules
Backup & disaster recoveryTested, isolated backups with a recovery planSupports availability and resilience requirements and ransomware recovery
Security awareness trainingRegular staff training and phishing simulationsPeople are the top attack vector; many frameworks mandate documented training

Notice how little of this is exotic. The same controls that lower your cyber-insurance premium, reduce your breach risk, and satisfy an enterprise customer’s security questionnaire are the controls that map onto HIPAA, PCI DSS, SOC 2, and CMMC. Good security and good compliance are built on the same foundation; compliance simply adds the requirement to document and prove it.

Read this twice

Who is actually responsible

This is the most misunderstood part of working with an MSP on compliance, and getting it wrong creates real legal exposure. The model is shared responsibility: the provider operates controls on your behalf, but accountability to the regulator, the card brands, or your customer remains yours.

In practical terms, the MSP is responsible for building, running, and evidencing the safeguards you contract it to manage — and a good one will put that scope in writing. You remain responsible for governance decisions: which framework applies, what data you collect, who is authorized to access it, whether to accept a given risk, and signing the attestation. If a breach or audit finding occurs, the regulator looks to you, not your vendor, even if the failure was technical.

Two safeguards make this relationship work. First, define scope explicitly: a written statement of which controls the MSP owns and which you retain, so nothing falls through the gap between you. Second, where regulated data is involved, get the contract right — a HIPAA business associate agreement (BAA) when the MSP can access PHI, and equivalent data-protection terms for other frameworks. A provider that will not sign a BAA should not be touching your patient data.

The claim to walk away from

No MSP can “make you compliant” or “certify” you, and for HIPAA there is no certification to give. A provider can make you audit-ready and operate your controls superbly — but if a sales pitch promises guaranteed compliance or a certification it issues itself, treat it as a red flag, not a feature.

By sector

Compliance by industry

Your industry usually decides your primary framework. Here is how the obligations and the typical MSP scope line up across the sectors that face the most scrutiny — the same verticals where a specialist provider is most worth paying for.

IndustryPrimary frameworksTypical MSP scope
HealthcareHIPAA / HITECHPHI safeguards, BAA, risk assessment, audit logging, staff training
Financial servicesGLBA, FTC Safeguards, FINRA, SECWritten security program, encryption, access control, monitoring, reporting
Defense & aerospaceCMMC, NIST 800-171CUI controls, system security plan, evidence for assessment readiness
Retail & e-commercePCI DSSCardholder-data segmentation, scanning, logging, and self-assessment support
SaaS & technologySOC 2, ISO 27001Control implementation, evidence collection, audit readiness for the report
Legal & professionalClient & ethics requirements, state privacy lawConfidentiality controls, encryption, access governance, training

If your business sits in one of these sectors, look for a provider with direct, referenceable experience in your specific framework rather than a generalist. You can shortlist regional specialists from our rankings for healthcare, financial services, and defense contractors — the three verticals where compliance experience separates the credible providers from the rest.

The investment

What compliance support costs

Compliance work sits on top of standard managed IT, so it costs more than a baseline plan. Think of it in three layers: a higher recurring rate for the heavier control set, one-time assessment and remediation, and the separate fees paid to an independent auditor. These are typical 2026 ranges, not quotes.

Compliance serviceTypical 2026 rangeWhat it covers
Compliance-focused managed IT$250–$300 / user / moThe heavier control, documentation, and monitoring set regulated firms need
Risk assessment / gap analysis$5,000–$25,000 one-timeThe documented assessment most frameworks require to begin
Remediation project workProject-basedClosing the gaps the assessment finds; scoped to your environment
vCISO / compliance advisory$1,500–$5,000 / moOngoing strategy, policy ownership, and audit liaison; sometimes bundled
Independent audit / attestationPaid to a third partySOC 2, PCI, or ISO assessment fees go to the auditor, not the MSP

For context, standard fully managed IT typically runs $75 to $200 per user per month; the compliance-heavy tier reaches $250 to $300 because of the added controls, evidence collection, and advisory work. The full breakdown of MSP pricing models lives in our MSP pricing guide. The one cost to never confuse is the audit itself — a SOC 2 or PCI assessment is performed and signed by an independent firm, so those fees are separate from anything your MSP charges.

Due diligence

How to choose a compliance-capable MSP

Most MSPs claim compliance experience; fewer can prove it. Run any provider that will touch regulated data through this checklist before you sign, and ask for specifics rather than reassurance.

  • Direct experience in your framework. Ask for referenceable clients in your industry and your specific standard — HIPAA, PCI DSS, SOC 2, or CMMC — not generic “security” experience.
  • Willingness to sign a BAA or data-protection terms. If they handle PHI, a signed business associate agreement is non-negotiable; for other frameworks, equivalent contractual terms.
  • Evidence and documentation as a deliverable. Confirm they produce the policies, reports, and audit evidence in writing, not just operate tooling quietly in the background.
  • Continuous monitoring, not point-in-time. Compliance is ongoing; look for logging, alerting, and periodic reviews rather than a one-time setup.
  • Their own security posture. A credible compliance partner can speak to its own controls — many hold SOC 2 themselves. Ask.
  • A clear scope statement. Insist on a written split of which controls they own and which remain yours, so accountability is unambiguous.

For the broader vendor-selection process beyond compliance — references, SLAs, pricing, and contract terms — pair this with our guide on how to choose an MSP and the six-factor Trust Score methodology behind every provider we rank.

The path

The compliance journey, step by step

Compliance is a program, not a project with an end date. With the right MSP, the path from “we have an obligation” to “we can prove it, and keep proving it” follows a predictable sequence.

  • Determine what applies. Confirm which frameworks govern your data and customers. Many businesses fall under more than one, and scope errors here are expensive later.
  • Run a gap assessment. Measure your current controls and documentation against the requirements to produce a prioritized, evidence-based gap list.
  • Build a remediation roadmap. Sequence the fixes by risk and effort, with owners and timelines, so the work is fundable and trackable.
  • Implement the controls. Deploy MFA, EDR, encryption, logging, access control, and the rest, and configure them to the standard’s requirements.
  • Document policies and procedures. Write the security policies, incident-response plan, and procedures the framework requires — the evidence auditors check first.
  • Monitor continuously. Operate logging, alerting, and reviews so controls keep working and drift is caught between audits.
  • Complete the audit or attestation. Hand the assembled evidence to an independent assessor for the SOC 2 report, PCI assessment, or readiness review.
  • Maintain and re-assess. Re-test, retrain, and update as your environment, the threats, and the rules change. Most attestations renew annually.

Watch out

Compliance red flags

A few patterns reliably signal a provider that will leave you exposed at audit time or in front of a regulator. Treat any of these as a reason to keep looking.

  • “We’ll make you compliant” or “certified.” No MSP can guarantee compliance or issue a certification, and HIPAA has none to issue. This promise reveals either a misunderstanding or a sales tactic.
  • Refusing to sign a BAA. If a provider handling PHI will not sign a business associate agreement, it is not a serious healthcare compliance partner.
  • Conflating security with compliance. A provider that says “we have you secured, so you’re compliant” misses the documentation and evidence half of the job.
  • No documentation deliverables. If policies, reports, and audit evidence are not in the scope of work, you will be exposed when an assessor asks for them.
  • Treating compliance as one-time. A setup-and-forget approach fails, because frameworks require continuous monitoring and annual re-assessment.
  • No clear scope or its own security story. A partner that cannot say in writing which controls it owns, or speak to its own posture, cannot be relied on for yours.

Questions

MSP compliance FAQs

An MSP can make you audit-ready and operate the controls a framework requires, but it cannot “make you compliant” in a legal sense or assume your accountability. Compliance is a shared responsibility: the provider builds, runs, and evidences the safeguards you contract it to manage, while the obligation to the regulator, card brands, or customer remains yours.

The practical value is real — a specialist MSP implements MFA, encryption, logging, and documentation faster and more credibly than most internal teams. Just treat any promise of “guaranteed compliance” as a red flag.

No. There is no official government HIPAA certification, so any vendor advertising itself as “HIPAA certified” is using marketing language rather than a recognized credential. What matters instead is demonstrable HIPAA experience, a willingness to sign a business associate agreement (BAA), and the ability to implement and document the required safeguards.

This differs from SOC 2 or ISO 27001, which do produce a genuine third-party attestation or certificate. For HIPAA, judge a provider on evidence and references, not on a certification claim.

Security is whether your data is actually protected; compliance is whether you can prove, with documentation and evidence, that you meet a defined standard. They overlap heavily — the same controls underpin both — but they are not identical.

A business can be reasonably secure yet fail an audit because it cannot produce the required policies, logs, and reports. That is why a good MSP treats documentation and evidence collection as core deliverables, not an afterthought to the technical work.

The most common are HIPAA (healthcare), PCI DSS (any business taking card payments), SOC 2 (SaaS and service firms holding customer data), CMMC and NIST 800-171 (defense contractors), GLBA and the FTC Safeguards Rule (financial institutions), and GDPR or CCPA (handling EU or California resident data). ISO 27001 and the NIST Cybersecurity Framework are widely used baselines.

Your industry, customers, and the data you handle decide which apply, and many businesses fall under more than one. The good news is that the frameworks overlap at the control level, so meeting one well advances the others.

A business associate agreement (BAA) is a HIPAA-required contract between a healthcare organization and any vendor that can access protected health information (PHI). If your MSP manages systems that hold patient data, you need a signed BAA before they begin — it defines each party’s safeguards and responsibilities.

A provider that handles PHI but will not sign a BAA is not a serious healthcare partner. For non-healthcare frameworks, the equivalent is a data-protection or security addendum with comparable terms.

Compliance-focused managed IT typically runs $250 to $300 per user per month — above the $75 to $200 standard range — because of the heavier control set, documentation, and monitoring. On top of that, expect a one-time risk assessment or gap analysis in the $5,000 to $25,000 range, remediation billed as project work, and optional vCISO advisory at roughly $1,500 to $5,000 per month.

The independent audit itself — a SOC 2, PCI, or ISO assessment — is performed and signed by a separate qualified firm, so those fees are paid to the auditor, not to your MSP. See the MSP pricing guide for the full picture.

Despite different wording, frameworks converge on a common core: multi-factor authentication (MFA), endpoint detection and response (EDR/MDR), encryption of data at rest and in transit, centralized logging and monitoring, role-based access control with least privilege, patch and vulnerability management, tested backups and disaster recovery, and documented security awareness training.

These are the same controls cyber-insurance underwriters require and the same ones that satisfy enterprise security questionnaires, which is why implementing them well advances security and compliance at the same time.

Look for direct, referenceable experience in your specific framework rather than generic security claims; a willingness to sign a BAA or equivalent data-protection terms; documentation and audit evidence as explicit deliverables; continuous monitoring rather than a one-time setup; a clear written statement of which controls they own versus which stay with you; and a credible account of their own security posture, ideally including their own SOC 2.

Shortlist specialists from our rankings for healthcare, financial services, and defense contractors, then compare them with our how to choose an MSP guide.

Find a compliance-ready provider

Compliance experience you can verify.

Browse independently scored MSPs across dozens of US cities and 20 industry verticals, including the regulated sectors where compliance depth matters most. Every provider is measured against the same six-factor Trust Score — no paid placements.