February 1, 2021, marks the day the Louisiana MSP registration law goes into effect. MSPs have known about this law since early 2020, and it is now a reality for those MSPs practicing in that state.
The MSP professional community has had a lot of time to contemplate this law and what it means for us. Speaking personally, I have talked to the people intimately involved in the law. Today, I have a much better understanding of their "legislative intent," which can inform our thinking about how other legislative and regulatory bodies may approach this similar issue.
Speaking for myself, I believe the Louisiana law should be the template for all future MSP regulations. I will explain why.
Why the need for MSP regulation?
According to my understanding of Louisiana's motives, the state wanted to safely continue its use of outsourcing to MSPs and address the risk associated with operating any device connected to the Internet.
Assuming this analysis is correct, the state's motives are genuinely favorable to the cause of MSPs everywhere. A "hostile legislative" act towards MSPs would have made it much more difficult for the state (and its respective agencies and departments) to maintain their IT assets with MSPs' assistance. The MSP registration law attempts to make it easier for the state to outsource to MSPs...safely!
Not everyone agrees with our assessment of this law, perhaps out of ignorance or perhaps out of genuine dislike for the law's text. Those of you on Reddit who have expressed dismay and doubt about the Louisiana law seem to be focused on the perceived burdens of such regulation and the increased difficulty in conducting business as an MSP. As a staunch advocate for the cause of outsourced managed IT services for over 20 years, I can assure you I am as pro-MSP as you can get. In my opinion, the Louisiana law does not aim to hinder the cause of managed services within the state. Quite the opposite is true.
Yet, as MSPs have increased in their prominence worldwide, customers like Louisiana (Louisiana is acting as a managed services client in this law) are increasingly aware of Cybersecurity risks and the need for professional-grade MSPs in mitigating those security risks. If you view the law in this context, it should make sense why the state acted as they did.

