
Here is a number that should unsettle any MSP or MSSP selling compliance-shaped security services: 83% of SMBs report having a cybersecurity strategy, and their incident rates are statistically identical to the companies that have none. The documents exist. The policies passed review. The protection never materialized. That gap between paper and protection is the predictable output of a specific way of structuring engagements, one where the deliverable is evidence for an auditor rather than a working security program, and it is worth examining before your practice builds its next service tier around a framework checklist.
Most of Your MSP Clients Are Not Compliance-Driven
Start with a question about your own base: how many of your clients face a regulatory requirement with actual teeth? Cynomi’s Chief Evangelist Tim Coach has been asking that question in rooms full of practitioners, and when he polled 150 security professionals at an industry event, almost nobody described a client base that was majority compliance-driven. His field estimate lands somewhere under 20–25% of partner clients with a formal compliance need, and the pattern holds wherever the question gets asked: outside healthcare, payments, defense contracting, and a handful of other regulated corners, most SMBs face customer expectations and insurance questionnaires, and no regulator at all.
Sit with what that means for a compliance-led practice: if frameworks are your front door, you have structured your security business around the needs of a fifth of your clients, and the other 75–80% get either a program shaped like someone else’s obligations or no program at all. They still get breached. They still need posture, visibility, and a roadmap. They just never had an auditor to make the conversation urgent, so the conversation never happened.
None of this means compliance demand is soft. Among MSPs and MSSPs surveyed for the State of the vCISO report, 86% report high or moderate demand for compliance readiness, up 14 points in a year, with strategic cybersecurity planning right beside it at 85%. Both lines are growing for the same underlying reason: clients feel exposed. The question this piece is actually about is what you build to answer that feeling, because the two demand signals resolve into one delivery model or two entirely different ones.
What a Compliance-First Security Engagement Produces
A compliance-first engagement has a shape, and the shape is a project. There is a framework, a gap assessment against it, a remediation push, an audit or attestation, and a certificate. Then there is an end. The revenue ends with the project, the client’s attention ends with the auditor’s departure, and the controls start aging the day after the celebration email. When the client’s real environment changes three months later, nothing in the engagement structure notices, because the engagement is over. New SaaS tools get adopted, staff turn over, an acquisition brings in an unassessed network, and the policy binder now describes a company that no longer exists.
The deeper problem is what the shape optimizes for. When the deliverable is audit evidence, the work bends toward what the auditor will examine, and the practitioner consensus has a name for the result: compliant but still exposed. The controls exist where the framework looks and thin out where it does not. This is how 83% of SMBs end up with a strategy document and an unchanged incident rate, and it is why compliance and risk management differ in ways that matter operationally, well beyond the definitional distinction.
You have seen the client-side version of this. The company that passed its SOC 2 attestation and then failed a basic phishing simulation the following quarter. The practice that shipped 40 policy documents nobody inside the client’s business has read since. A certificate is a snapshot taken through the auditor’s lens on the auditor’s date; it says nothing about next Tuesday. Your clients half-know this already, which is why the ones who bought a compliance project rarely renew it as one: from their side, they paid for a document, the document arrived, and the file is closed until someone reopens it for them.
What a Security-First Engagement Produces for Your Practice
Run the same client through a security-first structure and the shape changes from a project to a program. The engagement starts with a posture assessment across the client’s actual environment, produces a risk-prioritized roadmap, and settles into a cadence: tasks get done, posture gets remeasured, the roadmap gets updated, and the client sees the movement. The unit of value shifts from a document set to a visible trajectory. What SMB owners respond to, in the field experience Cynomi’s partners report, is exactly that visibility: “I can see where my security sits, I can see what we are doing next, and I can budget for it.” That is concreteness without an audit deadline as the forcing function.
Compliance then becomes what it always should have been: an output. A client running a real program already operates most of the controls any framework will ask about, so when the SOC 2 request or the insurance questionnaire or the customer security review arrives, the work is mapping and evidence, and much of the evidence already exists because the program generates it continuously. The standards bodies themselves have been drifting toward this reading of the world; NIST CSF 2.0 added an entire Govern function precisely because point-in-time control checking was not producing governed, continuous security management.
The economics follow the shape. A project bills once and competes on price against every other project shop. A program bills monthly, compounds trust, generates the posture data that feeds the next quarter’s conversation, and survives the audit date. For the practice director deciding what the service catalog looks like, that difference is the whole game: one structure produces revenue events, the other produces recurring revenue with a defensible reason to exist every month. For the partner making payroll, that is the difference between chasing the next project fee and building monthly recurring revenue, the number a practice actually plans headcount and tooling around.
The client conversation changes register too, and your account team will feel it before your P&L does. A compliance engagement runs on the auditor’s questions, so the client experiences your practice as a cost of doing business with someone else’s requirements. A program engagement runs on the client’s own environment, so the quarterly conversation becomes “here is where your posture moved, here is what we are doing next, and here is what it protects.” One of those conversations gets shopped against cheaper providers at renewal. The other one gets budget added to it, because the client can see what they are buying and can watch it improve. Practice directors who have made the switch describe the same pattern: fewer procurement-style renewals, more advisory-style planning meetings, and clients who bring the next problem to you before it becomes a request for proposal.
Take the Compliance Ask, Deliver the Security Program
The objection every practice director will raise is sequencing, and it deserves a straight answer. Clients do not call asking for a security program. They call because a customer demanded SOC 2, an insurer sent a questionnaire, or a competitor’s breach made the news, and they budget against that deadline. Leading the conversation with posture philosophy while the client is staring at an audit date is a losing pitch, and selling compliance without consequences behind it is a losing pitch of a different kind.
So take the ask, every single time, because the play is to keep the client’s vocabulary and invert the delivery underneath it. The engagement that starts with “we need SOC 2” begins with a posture assessment anyway, because gap analysis against a real baseline is better audit preparation than a framework checklist in the first place. The remediation work gets prioritized by risk, which substantially overlaps what the attestation needs and covers what it misses. And when the audit passes, the client is holding a roadmap with the next two quarters on it, and you are holding a recurring engagement that a compliance-first shop would have closed out.
The client who arrived through the compliance door gets a security program with an attestation as its first milestone. The 80% who were never going to arrive through that door get offered the program directly, on the strength of what it shows them about their own environment. One delivery model serves both, which is the practical meaning of compliance as byproduct: you never stop selling compliance work, you stop letting it define what the engagement is.
Restructuring Your Security Practice Around the Program
Making this real is an operations problem more than a philosophy problem, and it comes down to what your delivery system produces by default. If assessments are bespoke consulting exercises, running them across every client is unaffordable and the program model dies of labor cost. The practices that operate security-first at scale standardize the layer underneath: a consistent security posture assessment baseline across every client, risk-prioritized task generation from it, and framework requirements handled as cross-mappings from controls already in place rather than as separate projects per framework.
This is the delivery model Cynomi was built around as a Security Growth Platform: continuous posture management first, with compliance readiness generated from it, across every client at every maturity level. The platform assesses the environment, produces the prioritized roadmap your team walks the client through, and maps the same control set across the frameworks a client will eventually need, so the SOC 2 ask lands as a mapping exercise instead of a fire drill. Compliance is an outcome the system produces on demand because security is the thing it manages all the time.
Getting there does not require rebuilding the practice in a quarter. Most partners start by conducting the posture baseline assessment across their existing compliance clients first, because those clients already expect assessment work and the delta is immediately visible: the same engagement that was producing audit evidence starts producing a roadmap, and the renewal conversation changes on its own. The 80% follow from there, one entry-level assessment at a time, using the posture story rather than a framework mandate as the reason to start.
The practice-level question to sit with is blunt: if your biggest compliance client passed their audit tomorrow, what would you be billing them for next month? If the answer is nothing, the checkbox was the program, and the engagement was always going to end. Structure the program so compliance is one of its outputs, and the engagement stops having an expiration date. See how Cynomi runs the program beyond the checkbox: security your whole team can deliver, with compliance ready whenever the auditor arrives.