Compliance used to be something MSPs worried about only when a healthcare or financial services client asked for it. That’s no longer the case. Cyber insurance carriers are demanding proof of security controls before they’ll issue or renew a policy. State privacy laws are spreading well beyond California. And clients in construction, manufacturing, and professional services are increasingly asking their MSP the same question: “Can you show me we’re secure?”
For MSPs, compliance frameworks aren’t just a checkbox for regulated clients anymore but are becoming the common language for proving security value across your entire book of business. The challenge is that there are a lot of frameworks, they overlap in confusing ways, and most MSPs don’t have a compliance officer on staff to sort it all out.
This post breaks down the compliance frameworks that matter most for MSPs and their clients, explains how they relate to one another, and shows where Augmentt fits into the picture, especially through its Microsoft 365 security posture and CIS benchmark reporting.
Why compliance frameworks matter for MSPs, not just their clients
A compliance framework is a structured set of security controls and best practices; things like requiring multi-factor authentication, encrypting data at rest, logging administrative activity, or restricting who can access sensitive systems. Frameworks exist so that a business (and its customers, regulators, or insurers) can point to a recognized standard and say, “we followed this.”
For an MSP, frameworks show up in three ways:
- Client requirements. A healthcare client needs HIPAA. A defense contractor needs CMMC. A software client’s enterprise customers demand SOC 2. If you manage their IT environment, you’re implicated in whether they pass an audit.
- Cyber insurance underwriting. Insurers increasingly use frameworks like the NIST Cybersecurity Framework or CIS Controls as the baseline for what they’ll ask about on an application, and what they’ll use to deny a claim if it wasn’t in place.
- Your own differentiation. MSPs that can speak fluently about compliance, and back it up with reporting, win more security-conscious deals and justify higher-margin security services.
The good news: most of these frameworks share a large common core of controls. You don’t need to master ten separate rulebooks — you need to understand the handful that come up most often and recognize how they overlap.
The frameworks MSPs run into most often
NIST Cybersecurity Framework (CSF)
The NIST CSF, maintained by the U.S. National Institute of Standards and Technology, is less a checklist than an organizing structure. Version 2.0 groups activities into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. It’s voluntary and not industry-specific, which is exactly why it’s so widely adopted. It works as a common vocabulary that other frameworks (and many cyber insurance questionnaires) map back to.
For MSPs, NIST CSF is often the framework you use to structure a client’s overall security program, even if a more specific framework governs a particular compliance obligation.
CIS Controls and CIS Benchmarks
The Center for Internet Security (CIS) publishes two related things MSPs should know apart: the CIS Critical Security Controls, a prioritized list of 18 safeguards (things like inventory and control of assets, access control management, and continuous vulnerability management), and CIS Benchmarks, which are prescriptive, product-specific configuration guides, including one built specifically for Microsoft 365.
CIS Benchmarks are popular with MSPs because they’re actionable in a way broader frameworks aren’t. Instead of “protect access to systems,” a CIS Benchmark tells you the exact tenant setting to change. Because CIS controls are deliberately cross-mapped to NIST CSF, ISO 27001, PCI DSS, CMMC, HIPAA, and GDPR, hardening a client’s environment to the CIS Microsoft 365 Foundations Benchmark also moves the needle on most other frameworks a client might need.
This is where Augmentt is most directly useful. Augmentt’s security posture checks and MFA reporting are mapped to specific controls in the CIS Microsoft 365 Foundations Benchmark v2.0.0; things like identifying admin accounts without MFA, blocking legacy authentication, monitoring Microsoft Purview audit log status, enforcing idle session timeouts, and alerting on risky sign-ins or role changes outside of Privileged Identity Management. The Security Posture Report shows a Posture Score, flags each check as compliant, partially compliant, or not compliant, and lets you export a branded PDF for a client who doesn’t have Augmentt access, turning a compliance conversation into something you can show, not just describe.
HIPAA
The Health Insurance Portability and Accountability Act governs how healthcare providers, insurers, and their business associates (which can include an MSP) protect patient health information. HIPAA’s Security Rule requires administrative, physical, and technical safeguards; access controls, audit controls, encryption, and breach notification procedures among them.
If you support any healthcare client, you’re very likely a HIPAA “business associate,” which means you need a signed Business Associate Agreement and a genuine security program behind it, not just a promise. Many of the technical safeguards HIPAA requires (access control, audit logging, encryption of data in transit, session timeouts) overlap directly with the CIS Microsoft 365 controls Augmentt already monitors.
SOC 2
SOC 2 is an attestation, not a government regulation. A CPA firm audits a company against the AICPA’s Trust Services Criteria (security, availability, processing integrity, confidentiality, and privacy) and issues a report. SOC 2 matters to MSPs in two directions: clients in SaaS and professional services increasingly need a SOC 2 report to win their own enterprise customers, and MSPs themselves are sometimes asked by clients to prove their own SOC 2 compliance, since the MSP has privileged access to client systems.
Notably, Augmentt has undergone its own SOC 2 Type 2 audit as a vendor, giving its MSPs even more peace of mind.
CMMC (Cybersecurity Maturity Model Certification)
CMMC applies to companies in the Department of Defense supply chain, and it’s built on NIST SP 800-171. It has tiered levels of maturity, and unlike some frameworks, third-party or government assessment is required at the higher levels. If you have clients who are defense contractors or subcontractors, CMMC compliance isn’t optional, and the underlying controls (access control, audit and accountability, incident response, configuration management) again overlap heavily with what CIS-aligned Microsoft 365 hardening already covers.
PCI DSS
The Payment Card Industry Data Security Standard applies to any organization that stores, processes, or transmits cardholder data. It’s prescriptive about things like network segmentation, encryption, and access restrictions. MSPs supporting retail, hospitality, or e-commerce clients will run into PCI DSS regularly, particularly around securing the systems and email accounts that touch payment workflows.
ISO/IEC 27001
ISO 27001 is an international standard for information security management systems (ISMS). It’s less common among small and mid-sized MSP clients in North America than SOC 2, but it shows up often with clients that do business internationally or with enterprise customers overseas. Like the others, its control set (access control, cryptography, operations security) overlaps substantially with CIS and NIST.
GDPR and state privacy laws
The EU’s General Data Protection Regulation applies to any organization processing the personal data of EU residents, which catches more MSP clients than people expect, especially those with any European customers, employees, or web traffic. In the U.S., a growing patchwork of state privacy laws (California, Colorado, Virginia, and others) imposes similar obligations around data access, deletion rights, and breach notification. These aren’t security control frameworks in the same technical sense as NIST or CIS, but they create legal requirements around how quickly and thoroughly a client (and their MSP) can respond to a data request or breach, which is where good audit logging and access reporting (the kind Augmentt’s alerting provides) becomes evidence rather than just good practice.
How the frameworks relate to each other
The reason this list feels overwhelming at first is that most MSPs try to treat each framework as a separate project. In practice, the frameworks share a large overlapping core:
Access control and MFA enforcement appear in every single one of them, just under different names — NIST CSF calls it PR.AC, SOC 2 addresses it under CC6.1, HIPAA covers it in the Access Control standard, ISO 27001 handles it in Annex A.9, and CMMC maps it to the AC domain. The same is true of audit logging, encryption, and incident response.
That means the highest-leverage work an MSP can do is harden the common core — strong MFA, tight admin access, audit logging turned on, legacy authentication blocked, DLP and sharing policies configured correctly — and treat framework-specific requirements as the smaller layer on top. This is exactly the approach the CIS Microsoft 365 Foundations Benchmark takes, and it’s why it functions as a practical starting point regardless of which specific framework a given client ultimately needs to satisfy.
Where Augmentt fits
Augmentt isn’t a compliance certification body, and it won’t issue you a HIPAA or SOC 2 attestation. What it does is give MSPs continuous visibility into the Microsoft 365 security controls that sit underneath nearly every framework on this list:
- Security posture checks mapped directly to the CIS Microsoft 365 Foundations Benchmark v2.0.0, covering MFA enforcement, legacy authentication, conditional access, Purview audit logging, mailbox auditing, DLP policies, Sharepoint and Teams sharing settings, and more.
- The Security Posture Report, which scores a tenant’s compliance status (compliant, partially compliant, not compliant, resolved, or risk-accepted) against those checks, ties each item to its Microsoft Secure Score impact, and exports as a branded PDF for clients.
- Alerting on risky sign-ins, role and permission changes, self-service password reset activity, and mail forwarding rule changes — the kind of continuous monitoring that HIPAA, SOC 2, and CMMC all expect to see in place, not just configured once and forgotten.
- Scheduled reporting, so posture and compliance status can go out to clients automatically on a recurring cadence rather than requiring a manual pull before every QBR.
For an MSP juggling multiple clients with different compliance obligations, that combination — one dashboard mapped to a benchmark that overlaps with nearly every other framework, plus reporting you can hand to a client or auditor — turns compliance from a once-a-year scramble into an ongoing, demonstrable process.
Getting started
If you’re not sure where a given client stands, the fastest starting point is usually the same regardless of which framework they ultimately need to satisfy: run a CIS Microsoft 365 Foundations Benchmark assessment, close the highest-impact gaps (MFA, legacy auth, audit logging, admin role hygiene), and build reporting into your regular client cadence so compliance becomes a running conversation instead of a fire drill. From there, layer in the framework-specific requirements — a signed BAA for HIPAA clients, evidence collection for a SOC 2 audit, NIST 800-171 documentation for CMMC — on top of that hardened baseline.
Compliance will keep getting more complicated as more frameworks and state laws come online. But the underlying security work barely changes. Get the fundamentals right once, and you’re most of the way to satisfying whatever framework comes up next.
Want to check your own clients’ security posture? Try Augmentt for free!
Cover Photo by Jakub Żerdzicki on Unsplash
