Likely required by regulation
Laws and rules that may apply to the work you described, such as HIPAA, CMMC, GDPR, NIS2, or the FTC Safeguards Rule. Read these first.
Tell the Compliance Navigator where you operate, which industry you serve, and what work and data you handle. It returns a prioritized list of the regulations you likely have to follow, the assurance your customers tend to ask for, and the security frameworks worth adopting, each mapped to the MSPAlliance Unified Certification Standard.
About 2 minutes. No cost, no download, nothing saved to your profile.
Example results
Grouped in priority order
Likely required by regulation
FTC Safeguards Rule
Why it applies, your role, what you'd need
Your customers might ask for
SOC 2
Why it applies, your role, what you'd need
Optional, but useful
NIST CSF 2.0
Why it applies, your role, what you'd need
What you get
Compliance reading lists are long because they are written for everyone. The Navigator narrows a catalog of 15 regulations, assurance programs, and security frameworks down to the ones your answers point to, then splits them into three groups.
Laws and rules that may apply to the work you described, such as HIPAA, CMMC, GDPR, NIS2, or the FTC Safeguards Rule. Read these first.
Assurance and attestation work that buyers, insurers, and prime contractors request during procurement, such as SOC 2 or the MSPAlliance UCS audit.
Security frameworks you can adopt voluntarily to structure the work, such as NIST CSF 2.0, CIS Controls v8.1, ISO/IEC 27001, or Essential Eight.
Inside a result
A framework name on its own is not useful. Each result opens into the context you need to decide whether it is worth your time.
The specific answer you gave that surfaced this item, written in plain language rather than a rule citation.
Whether your MSP is likely in scope directly, as a vendor to a covered client, or as the party being asked to provide evidence.
The kind of work the item generally expects, so you can scope it before talking to counsel, an auditor, or a client.
The MSPAlliance Unified Certification Standard domains that cover similar ground, so overlapping work can be done once.
A link to the regulator or standards body that publishes the requirement, plus the date the entry was last reviewed.
Related services your MSP may be able to deliver for clients who fall under the same requirement.
Who it is for
You need to know which rules touch your own business before a client, insurer, or prime contractor asks.
You scope compliance work for clients across several industries and want a repeatable first pass.
You keep meeting security questionnaires mid-deal and want to understand what is being asked and why.
How it works
Select the countries and regions where your MSP works or serves customers. Geography decides which privacy and cybersecurity laws are even in play.
Pick the industry that matches your MSP or the client you are reviewing. Healthcare, defense, finance, and retail each pull in different rules.
Select the services you deliver, the data you hold, and the contracts you sign. Results appear immediately, grouped in priority order.
What it covers today
Depending on your answers, the Navigator can point you toward references like these, explain why each one surfaced, and link you to the body that publishes it.
Coverage is not exhaustive. A framework name appearing here does not mean it applies to you, and a rule can apply even if it is not in the catalog.
Mapped to the UCS
Every result carries an indicative mapping to the domains of the Unified Certification Standard, the MSPAlliance standard written for managed and cloud service providers. Where several requirements land on the same UCS domain, the underlying work is often shared rather than repeated.
The mapping is a research aid. It is not a UCS audit result and does not mean a requirement has been satisfied.
Read about the UCSWhat it is not
Use the results to ask better questions, read the primary sources, and decide where you need qualified help.
MSP compliance FAQ
MSP compliance is the work of meeting the legal, contractual, security, and industry requirements that affect a managed service provider and its clients. The right requirements depend on where you operate, who you serve, and what data or systems you handle.
There is no single answer for every MSP. Common examples include CMMC for parts of the US defense supply chain, HIPAA for protected health information, PCI DSS for payment-card data, GDPR and NIS2 for covered work in Europe, the FTC Safeguards Rule for covered financial institutions, and frameworks such as SOC 2, NIST CSF, CIS Controls, or ISO 27001 for security and assurance. Applicability always depends on the facts.
You answer three short questions about geography, industry, and business activities. The tool then shows regulations, assurance expectations, and security frameworks that may be worth reviewing, grouped in priority order, with a plain-language reason for each result, an indicative mapping to the MSPAlliance Unified Certification Standard, and a link to the official source.
No. It is a research starting point, not legal advice, an audit, a certification, or a compliance decision. A missing result does not mean that no requirement applies.
A checklist assumes the requirements already apply to you. The Navigator works the other way around: it starts from your geography, industry, and activities and narrows a general list down to the items worth reading first, with the reason each one appeared.
Each result includes an indicative mapping to the UCS domains that cover similar ground. The UCS is the MSPAlliance standard written specifically for managed and cloud service providers, so the mapping shows where one body of work may support several requirements. The mapping is indicative only and is not a UCS audit result.
The Compliance Navigator is available to approved MSPAlliance members and is included at no cost. MSP membership is free, and every application is reviewed by the MSPAlliance team.
No. The current version evaluates your answers for that visit and does not save them to your member profile.
Included with membership
Three questions, about two minutes, and a research list you can take into your next client conversation.
Membership is free for managed service providers. Every application is reviewed by the MSPAlliance team.