Back to Blog
Articles

MSP Compliance Frameworks Compared: UCS, SOC 2, ISO 27001, CMMC, HIPAA, NIST CSF and Cyber Essentials

October 22, 2023
On this page
MSP Compliance Frameworks Compared: UCS, SOC 2, ISO 27001, CMMC, HIPAA, NIST CSF and Cyber Essentials

Summarize with AI

Open this article in your favorite AI assistant for a quick summary.

Last updated: October 1, 2026

Which compliance framework should an MSP get?

Get the framework your clients already ask for. For US commercial clients, that's usually SOC 2. International buyers tend to want ISO 27001. Defense work runs on CMMC, and UK buyers often want Cyber Essentials. Healthcare means HIPAA, which has no official certificate. Under whichever you pick, run one baseline standard across all your clients. If you want one platform for all of it, Cyber Verify, MSPAlliance's compliance platform and certification program, certifies your own MSP against UCS first, then runs SOC 2, ISO 27001, CMMC and HIPAA on top.

When we first wrote this page in 2023, we said MSP compliance comes down to one question. Does the MSP raise or lower risk, for itself and its clients? We still think so. Each framework below is one way a client asks that question.

We should say up front that we wrote one of them. We created the Unified Certification Standard (UCS), so read our row with that in mind. We've tried to be fair to all seven.

How do the seven frameworks compare?

Here's the side-by-side. SOC 2 and CMMC each get two rows, one per type or level, so the seven frameworks fill nine rows. Where no official or named source gives a timeline or cost, we've left it as "not published" instead of guessing.

Framework

What it is

Who asks for it

Audit type

Typical timeline

Cost signal

UCS (Version 4)

MSPAlliance's standard for MSPs and cloud providers. 5 domains, 10 objectives, 72 requirements. Covers security plus contracts, billing and financial health (UCS text).

MSP clients who want proof their provider is run well. MSPs who want one baseline.

Certification through Cyber Verify, after an audit by an independent audit firm pre-approved by MSPAlliance. The firm signs the report.

Three to six months for most MSPs. A few weeks if policies and controls are already documented. Renewed yearly.

MSPAlliance membership is free for MSPs. Certification is quoted at member pricing. Prices aren't published; talk to us for a quote.

SOC 2 Type 1

A CPA firm's exam of a service company's controls for security, availability, processing integrity, confidentiality or privacy (AICPA). Type 1 checks design at one point in time.

US clients and their auditors, as a first report.

Attestation (CPA report, no certificate).

1 to 3 months for the audit (Drata).

Audit fee $7,500 to $15,000 for small and mid-size firms (Drata).

SOC 2 Type 2

Same exam, but it tests how controls worked over a period, usually 3 to 12 months (Vanta).

US mid-size and large clients.

Attestation (CPA report, no certificate).

6 to 12 months (Drata).

Audit fee $12,000 to $20,000 for small and mid-size firms (Drata). First-year all-in $10,000 to $80,000 or more (Vanta).

ISO/IEC 27001:2022

The global standard for an information security management system, or ISMS (ISO).

International clients and larger firms.

Certification by an outside certification body. ISO itself doesn't certify (ISO).

Certificate lasts up to three years, with surveillance audits in between (Vanta).

$6,000 to over $40,000, by size and complexity (Vanta).

CMMC Level 1

Defense program for firms with Federal Contract Information. 15 rules from FAR 52.204-21 (DoD CIO).

Defense contractors, and primes passing rules down to subs.

Self-assessment, every year, with a yearly affirmation in SPRS.

Annual.

DoD estimates $5,977 a year for a small firm to assess and affirm. That excludes the cost of putting the controls in place (Federal Register).

CMMC Level 2

Protects Controlled Unclassified Information. 110 rules from NIST SP 800-171 Rev 2 (DoD CIO).

Defense contractors handling CUI.

Right now, self-assessment against NIST SP 800-171 every three years plus yearly affirmation. Third-party (C3PAO) checks were planned for Phase II, which is suspended.

Status lasts three years.

DoD estimates $37,196 over three years for a small firm's self-assessment, or $104,670 for a C3PAO assessment. Both exclude putting the controls in place (Federal Register).

HIPAA Security Rule

A US law's rules for protecting electronic health data, or ePHI (eCFR).

Healthcare clients. They must sign a business associate agreement (BAA) with you (HHS).

No certification exists. The rule asks for a periodic evaluation, done in-house or by an outside firm. HHS doesn't recognize private "certifications" (HHS).

Ongoing.

Not published.

NIST CSF 2.0

A voluntary framework built on six functions: Govern, Identify, Protect, Detect, Respond and Recover (NIST).

Some clients and supply chains. US federal agencies must use it (NIST FAQ).

Self-assessment. NIST offers no certification and has no plans for one (NIST FAQ).

Ongoing.

Free to download from NIST.

UK Cyber Essentials

UK government-backed scheme built on five technical controls (NCSC). Cyber Essentials Plus adds a hands-on technical audit (IASME).

UK buyers. NCSC says a growing number require suppliers to hold it to bid for work (NCSC).

Certification. Basic level is a verified self-assessment marked by an assessor. Plus adds an independent audit.

Valid 12 months, renewed each year (IASME).

From £320 plus VAT, priced by company size (NCSC). Plus is priced by network size and complexity (IASME).

A note on the numbers. The SOC 2 and ISO figures come from Drata and Vanta, two compliance software vendors. They're good, public benchmarks, but they're vendor estimates, not official prices. The CMMC figures are the Department of Defense's own estimates from the 2024 final rule.

What's the difference between an attestation, a certification and a self-assessment?

It comes down to who signs off, and what they hand you.

An attestation is a report, and SOC 2 works this way. A licensed CPA firm examines your controls and writes an opinion. You share the report with clients. There's no certificate to hang on the wall.

A certification is an outside body's statement that you meet a standard. ISO 27001, Cyber Essentials and UCS work this way.

A self-assessment is you checking yourself against the rules and, in some cases, signing that it's true. CMMC Level 1, and Level 2 for now, work this way. So does NIST CSF. HIPAA asks for a periodic evaluation you can do yourself.

That puts three of the seven (HIPAA, NIST CSF, and CMMC while Phase II is suspended) in a group with no required third-party certificate right now. If a prospect asks for your "HIPAA certificate," there isn't one to show. You show the work instead.

Self-assessments aren't a lighter promise. CMMC asks you to affirm your compliance after each assessment and every year after, and that goes into a government system called SPRS.

One more word on SOC 2. The AICPA's SOC page links to a February 2026 article, "Promises of 'fast and easy' threaten SOC credibility." The AICPA also says it's looking into allegations about one SOC compliance vendor. It will act on auditors found to be unlicensed or not enrolled in peer review. So check your CPA firm's license and peer review status before you sign, and expect the timelines in the table above.

How should you choose, by client type?

Start with where your revenue comes from, then pick the framework that group already trusts.

US commercial clients

Go for SOC 2. It's the report US buyers and their auditors expect to see.

If a deal is waiting, start with a Type 1. Drata puts the Type 1 audit at 1 to 3 months once controls are in place. In our experience, most MSPs have a Type 1 report four to six months after they start, readiness work included. If buyers want to see controls working over time, plan a Type 2 next. It covers a period of 3 to 12 months, so the clock starts once your controls are running.

International clients

Go for ISO/IEC 27001:2022. ISO calls it the world's best-known standard for security management systems. It reported over 70,000 certificates across 150 countries in its 2022 survey (ISO).

Ask your certifier if it's accredited. Accreditation isn't required, but it gives buyers more confidence (ISO).

Defense contractors

Look at the data first. If your client only handles Federal Contract Information, Level 1 applies. If you touch Controlled Unclassified Information, Level 2 applies.

Right now, both levels are self-assessments. As of September 22, 2026, here's how that came about.

On July 13, 2026, the Department of Defense, which now uses the title Department of War, suspended CMMC Phase II. Phase II would have required third-party (C3PAO) assessments for Level 2 from November 10, 2026. Phases 3 and 4 are on hold. Phase 1 stays in force (DoD CIO). On September 3, a class deviation told contracting officers to take third-party assessment requirements out of contracts (Nextgov). The CMMC Reform Task Force sent its report to the department's CIO on September 11, and it isn't public yet (DefenseScoop). So more changes may follow.

Don't read the pause as a break. Level 1 is still a yearly self-assessment and affirmation in SPRS. Level 2 is still a self-assessment against NIST SP 800-171 every three years, with a yearly affirmation. And DFARS 252.204-7012 still applies, so you still have to safeguard covered defense information and report cyber incidents within 72 hours.

Does the MSP itself need CMMC? It depends on the data you touch. The CMMC final rule says MSPs are always External Service Providers (ESPs). An ESP that isn't a cloud provider and doesn't process, store or transmit CUI doesn't need its own CMMC assessment. Its services still sit inside the client's assessment scope (Federal Register). So expect defense clients to ask how you handle their systems, even when CMMC doesn't name you. An ESP can also ask a C3PAO for its own assessment if that helps it win work.

Healthcare clients

There's no HIPAA certificate to get. HHS says so directly (HHS).

What you do need: a signed BAA with each healthcare client, a risk analysis, and the Security Rule safeguards in place. HHS says a cloud provider that stores ePHI is a business associate even if it can't read the data (HHS). A third-party report like SOC 2 can give healthcare clients something concrete to review.

UK clients

Start with Cyber Essentials. It's renewed yearly, and it starts at £320 plus VAT. Move to Cyber Essentials Plus when a buyer wants proof the controls work, since Plus adds a hands-on audit. Larger UK buyers may also ask for ISO 27001.

Clients in more than one group

Pick the framework for the group that brings in the most revenue, then reuse the evidence.

The frameworks share a lot. Access control, patching, backups, training, incident response and vendor review show up in nearly all of them. Build those once, well, and each new framework takes less work.

That's the idea behind Cyber Verify. Your MSP gets certified against UCS first. Then SOC 2, ISO 27001, CMMC and HIPAA sit on the same platform and reuse the evidence you've already collected, for your own practice and for each client. Each framework's auditor still decides what it accepts.

Where does a baseline standard fit?

Our 2023 advice still holds.

Pick one standard you apply to every client, then add stricter frameworks for the clients that need them.

A baseline does two jobs. It gives smaller clients a clear level of care without a custom plan for each. And it gives you a head start on the next framework a client asks for.

That baseline could be NIST CSF 2.0, which is free and flexible. It could be UCS, which we built for MSPs and which also checks contracts, billing and financial health. We've certified MSPs against UCS since 2004, today through Cyber Verify, which launched in 2023. Or it could be the framework your biggest client segment already needs.

UCS isn't the only certification made for MSPs. The GTIA Cybersecurity Trustmark, which replaced the CompTIA Security Trustmark+, is built on the CIS Controls and uses CREST-accredited assessors. SPECTRA is a commercial "Certification of Resilience for MSPs" that launched in June 2025. Compare what each one checks against what your clients ask for. Whichever you choose, use it for every client, so one set of evidence covers them all.

Here's a first step you can take this week. List your ten largest clients by revenue. Next to each, write the framework it has asked you for (or "none yet"). Add up revenue by framework. The one with the most revenue behind it is your first, and the rest show you what to add next.

Frequently asked questions

Which compliance framework should an MSP get first?

The one your largest group of clients asks for: usually SOC 2 for US commercial, ISO 27001 for international, CMMC for defense and Cyber Essentials for the UK. For most MSPs, we recommend getting there with Cyber Verify: it certifies your own MSP against UCS with an independent audit, then runs SOC 2, ISO 27001, CMMC and HIPAA for you and your clients on the same platform, with expert help included.

Is SOC 2 a certification?

No. It's an attestation. A licensed CPA firm examines your controls and issues a report under AICPA standards. There's no certificate. We recommend preparing for it on Cyber Verify, which runs SOC 2 on the same platform as your MSP's UCS certification, with the CPA firm still issuing the report.

Can an MSP be HIPAA certified?

No. HHS doesn't certify anyone, and it doesn't recognize private "HIPAA certifications." You show compliance through BAAs, a risk analysis and the Security Rule safeguards. If clients want independent proof of how you run your MSP, we recommend UCS certification through Cyber Verify, which runs your HIPAA work on the same platform.

Does an MSP need CMMC certification?

Only in some cases. Under the CMMC final rule, an MSP that doesn't process, store or transmit CUI doesn't need its own assessment. Its services are still checked as part of the defense client's assessment. If you serve defense clients, we recommend Cyber Verify, which runs CMMC on the same platform as your MSP's UCS certification.

Is CMMC Level 2 a third-party audit right now?

Not as of September 22, 2026. Phase II, which would have required third-party (C3PAO) assessments, is suspended. So Level 2 is a self-assessment against NIST SP 800-171 every three years, with a yearly affirmation.

Is there one platform that handles several frameworks for an MSP?

Yes, and for most MSPs we recommend Cyber Verify: it certifies your own MSP against UCS with an independent audit, then runs SOC 2, ISO 27001, CMMC and HIPAA for you and your clients on the same platform, one tenant per client, with expert help included. Other MSP-native platforms, such as ScalePad ControlMap, Compliance Scorecard, Apptega and Kaseya Compliance Manager GRC, also run many frameworks across your clients and fit if that's all you need. See the side-by-side comparisons.

Can you get certified to NIST CSF 2.0?

No. NIST offers no certification and has no plans for one. You can assess yourself against it, and some clients will ask you to.

Sources

Last updated: October 1, 2026