Written by Charles Weaver, co-founder of MSPAlliance
MSP registration is finally here. We’ve been talking about this for a long time, and it’s finally here. MSPAlliance has encouraged discussion within our professional community for many years on the role of government in regulating MSPs. While we will undoubtedly have more to say on this matter in the coming months, we now have an actual law to analyze and discuss as a community.
MSP Registration for State Public Bodies
Louisiana Act 117 - Senate Bill 273 (see below for full text), recently signed into law by the governor, goes into effect February 1, 2021. The law requires MSPs who manage infrastructure or end-user systems for “public bodies” to register with the state. These terms are defined in the text of the law and seem relatively clear about their use. What is slightly less clear is the guidance on what “public bodies” means. Again, definitions are provided in the text, but these could become further defined over time.
MSP Disclosure of Cyber Incidents & Ransomware Payments
The law also requires those registered MSPs to notify the state in the event of a cyber incident, including any ransomware payments. While all 50 states (including Louisiana) already have data breach notification laws on the books, this law appears to be further clarifying this rule by requiring MSPs who have made payments to ransomware actors to disclosure such incidents to the states. Previously, data breach disclosure rules have primarily been made to the “impacted parties,” namely, the data owner.
MSP Impact & Analysis
Louisiana will not be the last state to act in this way towards MSPs; there will be others! Almost since the beginning of the MSPAlliance we have been telling MSPs that governmental regulation could come if specific actions were not taken. While the MSP professional community (in general) and the MSPAlliance (in particular) have been proactive in developing rules of behavior, professional standards, and models for interacting with clients, we have vigorously asked the government to stay out of our professional activities. There are too many examples of governmental interference with MSPs that would have harmed the general public, and not helped them. The California anti-spyware bill from the early 2000s is a good example.
Authors Note: MSPAlliance is not anti-regulation. While we have been against licensure for MSPs, regulatory efforts impacting MSPs happen all the time and MSPAlliance has been supportive of many of those efforts. What we have opposed, in the past, are legislative or regulatory efforts attempting to regulate without the input from the MSP professional community.

