Free for MSPAlliance members

Answer 3 Questions. See Which Compliance Rules Actually Apply to Your MSP.

Tell the Compliance Navigator where you operate, which industry you serve, and what work and data you handle. It returns a prioritized list of the regulations you likely have to follow, the assurance your customers tend to ask for, and the security frameworks worth adopting, each mapped to the MSPAlliance Unified Certification Standard.

About 2 minutes. No cost, no download, nothing saved to your profile.

Example results

Grouped in priority order

3 groups

Likely required by regulation

FTC Safeguards Rule

Why it applies, your role, what you'd need

Your customers might ask for

SOC 2

Why it applies, your role, what you'd need

Optional, but useful

NIST CSF 2.0

Why it applies, your role, what you'd need

Illustration only. Your results depend entirely on your answers.

What you get

A Short List, Sorted by What to Deal With First

Compliance reading lists are long because they are written for everyone. The Navigator narrows a catalog of 15 regulations, assurance programs, and security frameworks down to the ones your answers point to, then splits them into three groups.

1

Likely required by regulation

Laws and rules that may apply to the work you described, such as HIPAA, CMMC, GDPR, NIS2, or the FTC Safeguards Rule. Read these first.

2

Your customers might ask for

Assurance and attestation work that buyers, insurers, and prime contractors request during procurement, such as SOC 2 or the MSPAlliance UCS audit.

3

Optional, but useful

Security frameworks you can adopt voluntarily to structure the work, such as NIST CSF 2.0, CIS Controls v8.1, ISO/IEC 27001, or Essential Eight.

Inside a result

Every Item Explains Itself

A framework name on its own is not useful. Each result opens into the context you need to decide whether it is worth your time.

Why it applies

The specific answer you gave that surfaced this item, written in plain language rather than a rule citation.

Your role

Whether your MSP is likely in scope directly, as a vendor to a covered client, or as the party being asked to provide evidence.

What you'd need

The kind of work the item generally expects, so you can scope it before talking to counsel, an auditor, or a client.

UCS mapping

The MSPAlliance Unified Certification Standard domains that cover similar ground, so overlapping work can be done once.

Official source

A link to the regulator or standards body that publishes the requirement, plus the date the entry was last reviewed.

Service opportunities

Related services your MSP may be able to deliver for clients who fall under the same requirement.

Who it is for

Built for the People Who Get Asked First

MSP owners and operators

You need to know which rules touch your own business before a client, insurer, or prime contractor asks.

vCISO and compliance leads

You scope compliance work for clients across several industries and want a repeatable first pass.

Sales and account teams

You keep meeting security questionnaires mid-deal and want to understand what is being asked and why.

How it works

Three Questions, Then Your List

  1. Where you operate

    Select the countries and regions where your MSP works or serves customers. Geography decides which privacy and cybersecurity laws are even in play.

  2. Which industry

    Pick the industry that matches your MSP or the client you are reviewing. Healthcare, defense, finance, and retail each pull in different rules.

  3. What work and data you touch

    Select the services you deliver, the data you hold, and the contracts you sign. Results appear immediately, grouped in priority order.

What it covers today

15 Regulations, Assurance Programs, and Security Frameworks

Depending on your answers, the Navigator can point you toward references like these, explain why each one surfaced, and link you to the body that publishes it.

CMMCHIPAA Security RuleSOC 2NIST CSF 2.0ISO/IEC 27001PCI DSS 4.0.1GDPRNIS2DORAFTC Safeguards RuleCIS Controls v8.1UK GDPRPIPEDAAustralia Privacy ActEssential Eight

Coverage is not exhaustive. A framework name appearing here does not mean it applies to you, and a rule can apply even if it is not in the catalog.

Mapped to the UCS

See Where the Work Overlaps

Every result carries an indicative mapping to the domains of the Unified Certification Standard, the MSPAlliance standard written for managed and cloud service providers. Where several requirements land on the same UCS domain, the underlying work is often shared rather than repeated.

The mapping is a research aid. It is not a UCS audit result and does not mean a requirement has been satisfied.

Read about the UCS

What it is not

A Starting Point, Not a Compliance Decision

  • It does not tell you that your MSP or your client is compliant.
  • It is not legal advice and does not replace counsel who knows your contracts.
  • It is not an audit, an assessment, or a certification of any kind.
  • Coverage is not exhaustive. A requirement can apply even if it never appears in your results.

Use the results to ask better questions, read the primary sources, and decide where you need qualified help.

MSP compliance FAQ

Straight Answers Before You Start

What is MSP compliance?

MSP compliance is the work of meeting the legal, contractual, security, and industry requirements that affect a managed service provider and its clients. The right requirements depend on where you operate, who you serve, and what data or systems you handle.

Which compliance frameworks apply to MSPs?

There is no single answer for every MSP. Common examples include CMMC for parts of the US defense supply chain, HIPAA for protected health information, PCI DSS for payment-card data, GDPR and NIS2 for covered work in Europe, the FTC Safeguards Rule for covered financial institutions, and frameworks such as SOC 2, NIST CSF, CIS Controls, or ISO 27001 for security and assurance. Applicability always depends on the facts.

How does the MSP Compliance Navigator work?

You answer three short questions about geography, industry, and business activities. The tool then shows regulations, assurance expectations, and security frameworks that may be worth reviewing, grouped in priority order, with a plain-language reason for each result, an indicative mapping to the MSPAlliance Unified Certification Standard, and a link to the official source.

Does the Navigator tell me that my MSP is compliant?

No. It is a research starting point, not legal advice, an audit, a certification, or a compliance decision. A missing result does not mean that no requirement applies.

How is this different from a compliance checklist I can download?

A checklist assumes the requirements already apply to you. The Navigator works the other way around: it starts from your geography, industry, and activities and narrows a general list down to the items worth reading first, with the reason each one appeared.

How does it relate to the Unified Certification Standard?

Each result includes an indicative mapping to the UCS domains that cover similar ground. The UCS is the MSPAlliance standard written specifically for managed and cloud service providers, so the mapping shows where one body of work may support several requirements. The mapping is indicative only and is not a UCS audit result.

Who can use the Compliance Navigator?

The Compliance Navigator is available to approved MSPAlliance members and is included at no cost. MSP membership is free, and every application is reviewed by the MSPAlliance team.

Does the Navigator save my answers?

No. The current version evaluates your answers for that visit and does not save them to your member profile.

Included with membership

Find Out What Applies to You

Three questions, about two minutes, and a research list you can take into your next client conversation.

Membership is free for managed service providers. Every application is reviewed by the MSPAlliance team.