Managed IT and compliance: what an MSP can and cannot do
An independent guide to the frameworks SMBs face — HIPAA, PCI DSS, SOC 2, CMMC and more — the security controls auditors expect, and exactly where a managed service provider helps versus where the legal responsibility stays with you.
A managed service provider helps you meet frameworks like HIPAA, PCI DSS, SOC 2, and CMMC by implementing security controls, documenting policies, and supplying audit evidence. But compliance stays your legal responsibility — no MSP can “certify” you, and HIPAA has no official certification at all.
Start here
Why IT compliance is now a board-level issue
Compliance used to be a problem for large enterprises. In 2026 it lands on businesses of every size, because three forces converged: regulators expanded the rules to smaller firms, cyber-insurance underwriters made specific controls a condition of coverage, and enterprise customers began pushing security requirements down to their vendors through contracts and questionnaires.
For most small and mid-sized businesses, “IT compliance” means demonstrating — with evidence — that you protect sensitive data the way a specific framework requires. That could be patient records under HIPAA, cardholder data under PCI DSS, customer financial data under the FTC Safeguards Rule, or controlled defense information under CMMC. The framework that applies to you depends on your industry, your customers, and the data you handle.
This is where a managed service provider earns its place. Most of what a framework demands — multi-factor authentication, encryption, logging, access control, documented policies, continuous monitoring — is exactly the work an MSP already does, and doing it across many regulated clients makes a specialist provider faster and more credible than a stretched internal team. But there is a hard line this guide keeps returning to: an MSP can build and operate your controls, yet the legal accountability for compliance never leaves your organization.
The distinction that trips everyone up
Security and compliance are related but not the same. Security is whether your data is actually protected. Compliance is whether you can prove, with documentation and evidence, that you meet a defined standard. A business can be reasonably secure and still fail an audit for lack of evidence — which is why documentation, not just tooling, is half the job.
The rulebooks
The compliance frameworks SMBs actually face
You rarely get to choose your framework — your industry, customers, and data decide it for you, and many businesses fall under more than one. These are the standards a managed service provider is most often asked to support.
| Framework | Who it applies to | What it governs |
|---|---|---|
| HIPAA | Healthcare providers, plans, and their vendors | Protected health information (PHI); security and privacy of patient data |
| PCI DSS | Any business that stores or processes card payments | Cardholder data; a contractual standard set by the card brands |
| SOC 2 | SaaS and service firms that hold customer data | An independent attestation of security controls; often demanded by customers |
| CMMC / NIST 800-171 | Defense contractors and the DoD supply chain | Controlled unclassified information (CUI); required to win contracts |
| GLBA / FTC Safeguards Rule | Financial institutions and many lenders, advisers, dealers | Customer financial information; a written security program |
| GDPR / CCPA | Anyone handling EU or California resident data | Personal data privacy, consent, and breach notification |
| ISO 27001 | Firms wanting a recognized global security certification | An information security management system (ISMS) |
| NIST CSF 2.0 | Any organization, as a voluntary best-practice baseline | A framework of security functions many others map back to |
Two clarifications save a lot of confusion. SOC 2 and ISO 27001 produce a real, third-party attestation or certificate you can show customers; HIPAA, by contrast, has no official government certification — any vendor claiming to be “HIPAA certified” is using marketing language, not a recognized credential. And most frameworks overlap heavily at the control level, so meeting one well puts you most of the way toward the next.
The MSP role
What an MSP actually does for compliance
A compliance-capable MSP does far more than install antivirus. Its work spans the technical controls, the paperwork that proves them, and the ongoing operation that keeps you compliant between audits. These are the six things the right provider brings.
Risk assessment & gap analysis
Maps your current state against the framework that applies to you and produces a prioritized list of gaps. Most frameworks require a documented risk assessment as a starting point.
Implementing technical controls
Deploys and operates the safeguards auditors look for: MFA, EDR/MDR, encryption, email security, patching, and least-privilege access across your environment.
Policies & documentation
Drafts and maintains the written policies, procedures, and an incident-response plan that frameworks demand. This paperwork is what most businesses lack and what auditors check first.
Continuous monitoring & SIEM
Runs logging, alerting, and often a 24/7 security operations center, so controls keep working between audits and you can detect and respond to incidents.
Audit evidence & reporting
Collects and organizes the logs, configurations, and reports an assessor will ask for, so audit season is a document hand-off rather than a scramble.
Training, BAAs & vendor management
Delivers security awareness training, signs a business associate agreement (BAA) where PHI is involved, and helps manage the security of your other vendors.
What an MSP cannot do is sign your name on the compliance attestation or assume your liability. It also cannot replace the independent auditor: a SOC 2 report or PCI assessment is issued by a qualified third party, never by the MSP that built your controls. The provider gets you ready; an external assessor certifies the result.
The common core
The security controls auditors expect
Frameworks differ in wording, but they converge on the same core safeguards. Put these in place well and you are most of the way to satisfying almost any standard you are likely to face. This is also the layer cyber-insurance underwriters now require before they will write a policy.
| Control | What it is | Why frameworks require it |
|---|---|---|
| Multi-factor authentication (MFA) | A second factor beyond a password on every account | The single most effective control against account takeover; now near-universal |
| EDR / MDR | Endpoint detection and response, often managed 24/7 | Detects and contains threats antivirus misses; expected by insurers and auditors |
| Encryption | Protecting data at rest and in transit | Required for PHI, cardholder, and financial data; limits breach impact |
| Logging & monitoring (SIEM) | Centralized, retained logs with alerting | Most frameworks require audit trails and the ability to detect incidents |
| Access control & least privilege | Role-based access and periodic access reviews | Limits who can reach sensitive data; a core requirement everywhere |
| Patch & vulnerability management | Timely updates and regular vulnerability scans | Closes known weaknesses attackers exploit; explicitly required by most rules |
| Backup & disaster recovery | Tested, isolated backups with a recovery plan | Supports availability and resilience requirements and ransomware recovery |
| Security awareness training | Regular staff training and phishing simulations | People are the top attack vector; many frameworks mandate documented training |
Notice how little of this is exotic. The same controls that lower your cyber-insurance premium, reduce your breach risk, and satisfy an enterprise customer’s security questionnaire are the controls that map onto HIPAA, PCI DSS, SOC 2, and CMMC. Good security and good compliance are built on the same foundation; compliance simply adds the requirement to document and prove it.
By sector
Compliance by industry
Your industry usually decides your primary framework. Here is how the obligations and the typical MSP scope line up across the sectors that face the most scrutiny — the same verticals where a specialist provider is most worth paying for.
| Industry | Primary frameworks | Typical MSP scope |
|---|---|---|
| Healthcare | HIPAA / HITECH | PHI safeguards, BAA, risk assessment, audit logging, staff training |
| Financial services | GLBA, FTC Safeguards, FINRA, SEC | Written security program, encryption, access control, monitoring, reporting |
| Defense & aerospace | CMMC, NIST 800-171 | CUI controls, system security plan, evidence for assessment readiness |
| Retail & e-commerce | PCI DSS | Cardholder-data segmentation, scanning, logging, and self-assessment support |
| SaaS & technology | SOC 2, ISO 27001 | Control implementation, evidence collection, audit readiness for the report |
| Legal & professional | Client & ethics requirements, state privacy law | Confidentiality controls, encryption, access governance, training |
If your business sits in one of these sectors, look for a provider with direct, referenceable experience in your specific framework rather than a generalist. You can shortlist regional specialists from our rankings for healthcare, financial services, and defense contractors — the three verticals where compliance experience separates the credible providers from the rest.
The investment
What compliance support costs
Compliance work sits on top of standard managed IT, so it costs more than a baseline plan. Think of it in three layers: a higher recurring rate for the heavier control set, one-time assessment and remediation, and the separate fees paid to an independent auditor. These are typical 2026 ranges, not quotes.
| Compliance service | Typical 2026 range | What it covers |
|---|---|---|
| Compliance-focused managed IT | $250–$300 / user / mo | The heavier control, documentation, and monitoring set regulated firms need |
| Risk assessment / gap analysis | $5,000–$25,000 one-time | The documented assessment most frameworks require to begin |
| Remediation project work | Project-based | Closing the gaps the assessment finds; scoped to your environment |
| vCISO / compliance advisory | $1,500–$5,000 / mo | Ongoing strategy, policy ownership, and audit liaison; sometimes bundled |
| Independent audit / attestation | Paid to a third party | SOC 2, PCI, or ISO assessment fees go to the auditor, not the MSP |
For context, standard fully managed IT typically runs $75 to $200 per user per month; the compliance-heavy tier reaches $250 to $300 because of the added controls, evidence collection, and advisory work. The full breakdown of MSP pricing models lives in our MSP pricing guide. The one cost to never confuse is the audit itself — a SOC 2 or PCI assessment is performed and signed by an independent firm, so those fees are separate from anything your MSP charges.
Due diligence
How to choose a compliance-capable MSP
Most MSPs claim compliance experience; fewer can prove it. Run any provider that will touch regulated data through this checklist before you sign, and ask for specifics rather than reassurance.
- Direct experience in your framework. Ask for referenceable clients in your industry and your specific standard — HIPAA, PCI DSS, SOC 2, or CMMC — not generic “security” experience.
- Willingness to sign a BAA or data-protection terms. If they handle PHI, a signed business associate agreement is non-negotiable; for other frameworks, equivalent contractual terms.
- Evidence and documentation as a deliverable. Confirm they produce the policies, reports, and audit evidence in writing, not just operate tooling quietly in the background.
- Continuous monitoring, not point-in-time. Compliance is ongoing; look for logging, alerting, and periodic reviews rather than a one-time setup.
- Their own security posture. A credible compliance partner can speak to its own controls — many hold SOC 2 themselves. Ask.
- A clear scope statement. Insist on a written split of which controls they own and which remain yours, so accountability is unambiguous.
For the broader vendor-selection process beyond compliance — references, SLAs, pricing, and contract terms — pair this with our guide on how to choose an MSP and the six-factor Trust Score methodology behind every provider we rank.
The path
The compliance journey, step by step
Compliance is a program, not a project with an end date. With the right MSP, the path from “we have an obligation” to “we can prove it, and keep proving it” follows a predictable sequence.
- Determine what applies. Confirm which frameworks govern your data and customers. Many businesses fall under more than one, and scope errors here are expensive later.
- Run a gap assessment. Measure your current controls and documentation against the requirements to produce a prioritized, evidence-based gap list.
- Build a remediation roadmap. Sequence the fixes by risk and effort, with owners and timelines, so the work is fundable and trackable.
- Implement the controls. Deploy MFA, EDR, encryption, logging, access control, and the rest, and configure them to the standard’s requirements.
- Document policies and procedures. Write the security policies, incident-response plan, and procedures the framework requires — the evidence auditors check first.
- Monitor continuously. Operate logging, alerting, and reviews so controls keep working and drift is caught between audits.
- Complete the audit or attestation. Hand the assembled evidence to an independent assessor for the SOC 2 report, PCI assessment, or readiness review.
- Maintain and re-assess. Re-test, retrain, and update as your environment, the threats, and the rules change. Most attestations renew annually.
Watch out
Compliance red flags
A few patterns reliably signal a provider that will leave you exposed at audit time or in front of a regulator. Treat any of these as a reason to keep looking.
- “We’ll make you compliant” or “certified.” No MSP can guarantee compliance or issue a certification, and HIPAA has none to issue. This promise reveals either a misunderstanding or a sales tactic.
- Refusing to sign a BAA. If a provider handling PHI will not sign a business associate agreement, it is not a serious healthcare compliance partner.
- Conflating security with compliance. A provider that says “we have you secured, so you’re compliant” misses the documentation and evidence half of the job.
- No documentation deliverables. If policies, reports, and audit evidence are not in the scope of work, you will be exposed when an assessor asks for them.
- Treating compliance as one-time. A setup-and-forget approach fails, because frameworks require continuous monitoring and annual re-assessment.
- No clear scope or its own security story. A partner that cannot say in writing which controls it owns, or speak to its own posture, cannot be relied on for yours.
Questions
MSP compliance FAQs
An MSP can make you audit-ready and operate the controls a framework requires, but it cannot “make you compliant” in a legal sense or assume your accountability. Compliance is a shared responsibility: the provider builds, runs, and evidences the safeguards you contract it to manage, while the obligation to the regulator, card brands, or customer remains yours.
The practical value is real — a specialist MSP implements MFA, encryption, logging, and documentation faster and more credibly than most internal teams. Just treat any promise of “guaranteed compliance” as a red flag.
No. There is no official government HIPAA certification, so any vendor advertising itself as “HIPAA certified” is using marketing language rather than a recognized credential. What matters instead is demonstrable HIPAA experience, a willingness to sign a business associate agreement (BAA), and the ability to implement and document the required safeguards.
This differs from SOC 2 or ISO 27001, which do produce a genuine third-party attestation or certificate. For HIPAA, judge a provider on evidence and references, not on a certification claim.
Security is whether your data is actually protected; compliance is whether you can prove, with documentation and evidence, that you meet a defined standard. They overlap heavily — the same controls underpin both — but they are not identical.
A business can be reasonably secure yet fail an audit because it cannot produce the required policies, logs, and reports. That is why a good MSP treats documentation and evidence collection as core deliverables, not an afterthought to the technical work.
The most common are HIPAA (healthcare), PCI DSS (any business taking card payments), SOC 2 (SaaS and service firms holding customer data), CMMC and NIST 800-171 (defense contractors), GLBA and the FTC Safeguards Rule (financial institutions), and GDPR or CCPA (handling EU or California resident data). ISO 27001 and the NIST Cybersecurity Framework are widely used baselines.
Your industry, customers, and the data you handle decide which apply, and many businesses fall under more than one. The good news is that the frameworks overlap at the control level, so meeting one well advances the others.
A business associate agreement (BAA) is a HIPAA-required contract between a healthcare organization and any vendor that can access protected health information (PHI). If your MSP manages systems that hold patient data, you need a signed BAA before they begin — it defines each party’s safeguards and responsibilities.
A provider that handles PHI but will not sign a BAA is not a serious healthcare partner. For non-healthcare frameworks, the equivalent is a data-protection or security addendum with comparable terms.
Compliance-focused managed IT typically runs $250 to $300 per user per month — above the $75 to $200 standard range — because of the heavier control set, documentation, and monitoring. On top of that, expect a one-time risk assessment or gap analysis in the $5,000 to $25,000 range, remediation billed as project work, and optional vCISO advisory at roughly $1,500 to $5,000 per month.
The independent audit itself — a SOC 2, PCI, or ISO assessment — is performed and signed by a separate qualified firm, so those fees are paid to the auditor, not to your MSP. See the MSP pricing guide for the full picture.
Despite different wording, frameworks converge on a common core: multi-factor authentication (MFA), endpoint detection and response (EDR/MDR), encryption of data at rest and in transit, centralized logging and monitoring, role-based access control with least privilege, patch and vulnerability management, tested backups and disaster recovery, and documented security awareness training.
These are the same controls cyber-insurance underwriters require and the same ones that satisfy enterprise security questionnaires, which is why implementing them well advances security and compliance at the same time.
Look for direct, referenceable experience in your specific framework rather than generic security claims; a willingness to sign a BAA or equivalent data-protection terms; documentation and audit evidence as explicit deliverables; continuous monitoring rather than a one-time setup; a clear written statement of which controls they own versus which stay with you; and a credible account of their own security posture, ideally including their own SOC 2.
Shortlist specialists from our rankings for healthcare, financial services, and defense contractors, then compare them with our how to choose an MSP guide.
Find a compliance-ready provider
Compliance experience you can verify.
Browse independently scored MSPs across dozens of US cities and 20 industry verticals, including the regulated sectors where compliance depth matters most. Every provider is measured against the same six-factor Trust Score — no paid placements.