If you’re an MSP, there’s a good chance you’re already doing compliance work—even if that’s not yet a service line you’ve formalized. This might look like helping a client fill out a security questionnaire, documenting MFA adoption, reviewing access controls before an insurance renewal, or responding to a customer's evidence request.
The problem is that this work is typically treated as a project: a client has a requirement, your team scopes it, delivers it, and moves on. That approach comes at a real cost—not just revenue left on the table, but delivery inefficiency, inconsistent scoping, margin erosion, and manual effort rebuilt from scratch with every new request. The real risk is that every compliance engagement becomes a custom project, with no clear path to turning it into something repeatable and scalable.
Whether it's a formal certification, an insurance requirement, or maintaining the security practices your clients depend on, these obligations don't end when the first deliverable ships. The recurring need is already there.
In this article, we'll explore the one-off compliance project trap, why compliance work is inherently ongoing, and how to build a compliance program that generates recurring revenue from your very first engagement.
The One-Off Compliance Project Trap
Many MSPs treat their first compliance engagement as a project when it should be treated as the foundation for a larger compliance program.
| Compliance as a Project | Compliance as a Program |
|---|---|
| Assess → Action → Document → Submit → Close | Assess → Action/Remediate → Document → Monitor → Report → Refresh/Update → Prepare for Renewal |
Compliance work requires significant upfront effort, including defining the scope of the engagement, establishing an evidence baseline, aligning controls with a framework (if you’re working towards a specific certification), and creating documentation for policies and procedures. Once the foundation is in place, the ongoing work—maintaining practices/protocols, reassessments and evidence refreshes—takes a fraction of the original effort.
Building your compliance program with the next engagement in mind means the same upfront cost becomes an investment of recurring revenue rather than a sunk cost. It's the difference between compliance work that resets with every client and a practice that compounds.
Of course, there are real reasons to proceed with caution when starting a compliance program. Failing to meet requirements can cause real issues, such as a poorly executed assessment or a missed control. Those mistakes can have real-world consequences and even cause the loss of client relationships you were striving to cultivate.
That’s why we recommend starting on a small scale. But there’s a difference between starting small and limiting yourself—the goal is to create the kind of foundation that will allow you to grow your practice, not keep you stuck.
Compliance Is an Ongoing Responsibility
The reason it makes sense to build with ongoing support in mind is that most compliance requirements are already set up this way. A client who lapses out of compliance can lose a contract, lose cyber insurance coverage, or lose the ability to serve certain customers altogether. That's the recurring service model built into these frameworks. Here's a breakdown of the most common frameworks, who they apply to, and the recurring cadence each requires.
Framework Requirements at a Glance
| Framework | Who It Applies To | Recurring Cadence* |
|---|---|---|
| SOC 2 Type 2 | SaaS companies, financial services, or other organizations that store, process, or transmit customer data on behalf of other businesses | Annual |
| CMMC Level 2 | Defense contractors (defense industrial base) | Triennial C3PAO assessment plus annual self-assessment |
| NIST CSF | Federal contractors, critical infrastructure sectors (energy, utilities, financial services, healthcare), and any organization using it as a voluntary security baseline | No mandated cadence, but it is widely treated as annual |
| HIPAA | Healthcare organizations and the vendors and service providers that handle patient data on their behalf, including MSPs | Ongoing annual risk assessment is the best practice |
| HITRUST | Healthcare organizations and their business associates and vendors, including MSPs, that handle protected health information; increasingly requested by health plans and larger healthcare systems as a condition of doing business | Certification cycle every 2 years (r2), with an interim assessment required at the 1-year mark |
| CIS Controls | Organizations that need a practical, prescriptive security baseline but don't have a mandated framework, commonly used in financial services, manufacturing, retail, and state or local government, and increasingly cited by cyber insurers | No mandated cadence; typically annual review |
At the end of the day, recurring compliance work isn't a business model you're layering onto your existing client relationships. It's already written into the obligations your clients are trying to meet for their own requirements.
How to Approach GRC as an Ongoing Program
1. Start the Discussion With Clients
The first compliance conversation with a client isn't really a sales pitch—it's a diagnostic. Leading with framework names like CMMC, SOC 2, or ISO 27001 can trigger hesitation rather than commitment, because clients don't buy frameworks. They buy outcomes, and they act when they recognize a pressure they're already feeling.
A more effective approach is to start with questions that surface what your client is already experiencing:
- "Have you had to fill out a security questionnaire for a customer or vendor recently?"
- "Has your cyber insurance renewal gotten more detailed in the last year or two?"
- "Are any of your contracts starting to include new security or data-handling language?"
These questions work because they're not inventing a problem—they're naming one the client already has. Once a client recognizes the pattern, the conversation tends to shift naturally from "Do I need this?" to "What do I do about it?"
2. Scope Your Work for Continuity
As we’ve discussed, the scope of most compliance work does not end at the certification point. Your clients will still need to maintain that certification—or risk losing important contracts, insurance coverage, or other opportunities.
It’s important to clearly set these expectations at the scoping stage. This is the ideal time to educate your client on why ongoing compliance is necessary, if they’re not yet aware. By signing on to a recurring service agreement, they get your support on an ongoing basis—allowing them to maintain their certifications without having to take on the work themselves.
3. Price Your Work as an Ongoing Service
That's not to say that your agreement needs to look exactly the same from month-to-month. Depending on the framework, it may make more sense to front-load the initial certification work before tapering down to a maintenance schedule. The important thing is to set it up as a named, priced recurring service from the beginning—not a project that will need to be re-scoped and re-sold every time your client faces a renewal.
For example: instead of selling a one-time HIPAA assessment, an MSP might package an initial assessment, quarterly evidence reviews, policy updates, vendor risk checks, an annual risk reassessment, and executive reporting into a single recurring compliance service—scoped once, delivered continuously.
Most MSPs offering ongoing compliance settle on one of two structures: a monthly retainer that covers continuous monitoring, evidence collection, and check-ins, or a bundled fixed price that covers the full cycle—certification, all interim check-ins, and the annual evaluation. Either way, be clear on what's included: whether you're handling remediation alongside assessment and reporting, how many hours per month you're committing to, and what the client is responsible for. That clarity prevents scope creep and makes it easier to price consistently as you grow.
4. Decide How to Manage Work on a Rolling Basis
The key to making a continuous service model sustainable—and to justifying your monthly fee—is treating compliance activities as part of ongoing operations, not as preparation that only kicks in when an assessment is approaching. When evidence collection, policy reviews, and control monitoring happen continuously, your clients aren't scrambling before audits. They're already ready. That's the value your recurring fee is delivering, and it's worth making that explicit in how you communicate with them.
In practice, the right cadence depends on the client. A tiered approach helps: lighter engagements might cover quarterly compliance checks and an annual reassessment, while more involved clients may need quarterly roadmap reviews and remediation support, or even monthly executive reporting and full GRC program management. Packaging these into named tiers—rather than scoping each engagement from scratch—makes your service easier to sell, easier to deliver, and easier to scale.
From One-Off Engagement to Recurring Program
If a client needs a certification because a vendor or insurer mandates it, that client relationship doesn't end when the report ships. Their obligation renews every year, and so does the opportunity sitting in front of you.
Building a compliance program doesn't require a complete overhaul of how you run your MSP. It requires treating the framework you've chosen, the evidence you've gathered, and the client you already have as the foundation of a program—not the end of a project.
MSPs who integrate compliance into their regular operations, rather than treating it as a one-time project, are already working the way these frameworks are designed to be followed. This approach allows you to deepen your GRC expertise and build recurring revenue while maintaining the client relationships you've worked hard to build.
ControlMap is built to help MSPs structure exactly this kind of engagement from the first client on, turning a one-time engagement into a repeatable service model