Compliance Frameworks Every MSP Should Know

Table of Contents

Compliance used to be something MSPs worried about only when a healthcare or financial services client asked for it. That’s no longer the case. Cyber insurance carriers are demanding proof of security controls before they’ll issue or renew a policy. State privacy laws are spreading well beyond California. And clients in construction, manufacturing, and professional services are increasingly asking their MSP the same question: “Can you show me we’re secure?”

For MSPs, compliance frameworks aren’t just a checkbox for regulated clients anymore but are becoming the common language for proving security value across your entire book of business. The challenge is that there are a lot of frameworks, they overlap in confusing ways, and most MSPs don’t have a compliance officer on staff to sort it all out.

This post breaks down the compliance frameworks that matter most for MSPs and their clients, explains how they relate to one another, and shows where Augmentt fits into the picture, especially through its Microsoft 365 security posture and CIS benchmark reporting.

Why compliance frameworks matter for MSPs, not just their clients

A compliance framework is a structured set of security controls and best practices; things like requiring multi-factor authentication, encrypting data at rest, logging administrative activity, or restricting who can access sensitive systems. Frameworks exist so that a business (and its customers, regulators, or insurers) can point to a recognized standard and say, “we followed this.”

For an MSP, frameworks show up in three ways:

  1. Client requirements. A healthcare client needs HIPAA. A defense contractor needs CMMC. A software client’s enterprise customers demand SOC 2. If you manage their IT environment, you’re implicated in whether they pass an audit.
  2. Cyber insurance underwriting. Insurers increasingly use frameworks like the NIST Cybersecurity Framework or CIS Controls as the baseline for what they’ll ask about on an application, and what they’ll use to deny a claim if it wasn’t in place.
  3. Your own differentiation. MSPs that can speak fluently about compliance, and back it up with reporting, win more security-conscious deals and justify higher-margin security services.

The good news: most of these frameworks share a large common core of controls. You don’t need to master ten separate rulebooks — you need to understand the handful that come up most often and recognize how they overlap.

The frameworks MSPs run into most often

NIST Cybersecurity Framework (CSF)

The NIST CSF, maintained by the U.S. National Institute of Standards and Technology, is less a checklist than an organizing structure. Version 2.0 groups activities into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. It’s voluntary and not industry-specific, which is exactly why it’s so widely adopted. It works as a common vocabulary that other frameworks (and many cyber insurance questionnaires) map back to.

For MSPs, NIST CSF is often the framework you use to structure a client’s overall security program, even if a more specific framework governs a particular compliance obligation.

CIS Controls and CIS Benchmarks

The Center for Internet Security (CIS) publishes two related things MSPs should know apart: the CIS Critical Security Controls, a prioritized list of 18 safeguards (things like inventory and control of assets, access control management, and continuous vulnerability management), and CIS Benchmarks, which are prescriptive, product-specific configuration guides, including one built specifically for Microsoft 365.

CIS Benchmarks are popular with MSPs because they’re actionable in a way broader frameworks aren’t. Instead of “protect access to systems,” a CIS Benchmark tells you the exact tenant setting to change. Because CIS controls are deliberately cross-mapped to NIST CSF, ISO 27001, PCI DSS, CMMC, HIPAA, and GDPR, hardening a client’s environment to the CIS Microsoft 365 Foundations Benchmark also moves the needle on most other frameworks a client might need.

This is where Augmentt is most directly useful. Augmentt’s security posture checks and MFA reporting are mapped to specific controls in the CIS Microsoft 365 Foundations Benchmark v2.0.0; things like identifying admin accounts without MFA, blocking legacy authentication, monitoring Microsoft Purview audit log status, enforcing idle session timeouts, and alerting on risky sign-ins or role changes outside of Privileged Identity Management. The Security Posture Report shows a Posture Score, flags each check as compliant, partially compliant, or not compliant, and lets you export a branded PDF for a client who doesn’t have Augmentt access, turning a compliance conversation into something you can show, not just describe.

HIPAA

The Health Insurance Portability and Accountability Act governs how healthcare providers, insurers, and their business associates (which can include an MSP) protect patient health information. HIPAA’s Security Rule requires administrative, physical, and technical safeguards; access controls, audit controls, encryption, and breach notification procedures among them.

If you support any healthcare client, you’re very likely a HIPAA “business associate,” which means you need a signed Business Associate Agreement and a genuine security program behind it, not just a promise. Many of the technical safeguards HIPAA requires (access control, audit logging, encryption of data in transit, session timeouts) overlap directly with the CIS Microsoft 365 controls Augmentt already monitors.

SOC 2

SOC 2 is an attestation, not a government regulation. A CPA firm audits a company against the AICPA’s Trust Services Criteria (security, availability, processing integrity, confidentiality, and privacy) and issues a report. SOC 2 matters to MSPs in two directions: clients in SaaS and professional services increasingly need a SOC 2 report to win their own enterprise customers, and MSPs themselves are sometimes asked by clients to prove their own SOC 2 compliance, since the MSP has privileged access to client systems.

Notably, Augmentt has undergone its own SOC 2 Type 2 audit as a vendor, giving its MSPs even more peace of mind.

CMMC (Cybersecurity Maturity Model Certification)

CMMC applies to companies in the Department of Defense supply chain, and it’s built on NIST SP 800-171. It has tiered levels of maturity, and unlike some frameworks, third-party or government assessment is required at the higher levels. If you have clients who are defense contractors or subcontractors, CMMC compliance isn’t optional, and the underlying controls (access control, audit and accountability, incident response, configuration management) again overlap heavily with what CIS-aligned Microsoft 365 hardening already covers.

PCI DSS

The Payment Card Industry Data Security Standard applies to any organization that stores, processes, or transmits cardholder data. It’s prescriptive about things like network segmentation, encryption, and access restrictions. MSPs supporting retail, hospitality, or e-commerce clients will run into PCI DSS regularly, particularly around securing the systems and email accounts that touch payment workflows.

ISO/IEC 27001

ISO 27001 is an international standard for information security management systems (ISMS). It’s less common among small and mid-sized MSP clients in North America than SOC 2, but it shows up often with clients that do business internationally or with enterprise customers overseas. Like the others, its control set (access control, cryptography, operations security) overlaps substantially with CIS and NIST.

GDPR and state privacy laws

The EU’s General Data Protection Regulation applies to any organization processing the personal data of EU residents, which catches more MSP clients than people expect, especially those with any European customers, employees, or web traffic. In the U.S., a growing patchwork of state privacy laws (California, Colorado, Virginia, and others) imposes similar obligations around data access, deletion rights, and breach notification. These aren’t security control frameworks in the same technical sense as NIST or CIS, but they create legal requirements around how quickly and thoroughly a client (and their MSP) can respond to a data request or breach, which is where good audit logging and access reporting (the kind Augmentt’s alerting provides) becomes evidence rather than just good practice.

How the frameworks relate to each other

The reason this list feels overwhelming at first is that most MSPs try to treat each framework as a separate project. In practice, the frameworks share a large overlapping core:

Access control and MFA enforcement appear in every single one of them, just under different names — NIST CSF calls it PR.AC, SOC 2 addresses it under CC6.1, HIPAA covers it in the Access Control standard, ISO 27001 handles it in Annex A.9, and CMMC maps it to the AC domain. The same is true of audit logging, encryption, and incident response.

That means the highest-leverage work an MSP can do is harden the common core — strong MFA, tight admin access, audit logging turned on, legacy authentication blocked, DLP and sharing policies configured correctly — and treat framework-specific requirements as the smaller layer on top. This is exactly the approach the CIS Microsoft 365 Foundations Benchmark takes, and it’s why it functions as a practical starting point regardless of which specific framework a given client ultimately needs to satisfy.

Where Augmentt fits

Augmentt isn’t a compliance certification body, and it won’t issue you a HIPAA or SOC 2 attestation. What it does is give MSPs continuous visibility into the Microsoft 365 security controls that sit underneath nearly every framework on this list:

  • Security posture checks mapped directly to the CIS Microsoft 365 Foundations Benchmark v2.0.0, covering MFA enforcement, legacy authentication, conditional access, Purview audit logging, mailbox auditing, DLP policies, Sharepoint and Teams sharing settings, and more.
  • The Security Posture Report, which scores a tenant’s compliance status (compliant, partially compliant, not compliant, resolved, or risk-accepted) against those checks, ties each item to its Microsoft Secure Score impact, and exports as a branded PDF for clients.
  • Alerting on risky sign-ins, role and permission changes, self-service password reset activity, and mail forwarding rule changes — the kind of continuous monitoring that HIPAA, SOC 2, and CMMC all expect to see in place, not just configured once and forgotten.
  • Scheduled reporting, so posture and compliance status can go out to clients automatically on a recurring cadence rather than requiring a manual pull before every QBR.

For an MSP juggling multiple clients with different compliance obligations, that combination — one dashboard mapped to a benchmark that overlaps with nearly every other framework, plus reporting you can hand to a client or auditor — turns compliance from a once-a-year scramble into an ongoing, demonstrable process.

Getting started

If you’re not sure where a given client stands, the fastest starting point is usually the same regardless of which framework they ultimately need to satisfy: run a CIS Microsoft 365 Foundations Benchmark assessment, close the highest-impact gaps (MFA, legacy auth, audit logging, admin role hygiene), and build reporting into your regular client cadence so compliance becomes a running conversation instead of a fire drill. From there, layer in the framework-specific requirements — a signed BAA for HIPAA clients, evidence collection for a SOC 2 audit, NIST 800-171 documentation for CMMC — on top of that hardened baseline.

Compliance will keep getting more complicated as more frameworks and state laws come online. But the underlying security work barely changes. Get the fundamentals right once, and you’re most of the way to satisfying whatever framework comes up next.

Want to check your own clients’ security posture? Try Augmentt for free!

Cover Photo by Jakub Żerdzicki on Unsplash

Author
Gavin Garbutt
Co-Founder & Chairman of Augmentt

FAQ

Using our GDAP tool & Magic Link, setting up is easy! You can integrate with your CSP partner portal in minutes
Augmentt uses a combination of Microsoft Secure Score best practices as well as industry standards such as NIST & CIS. You can use the out of box templates to get started right away and even build your own custom templates to match your client requirements.
Out of box, Augmentt comes pre-configured to not be noisy. Very few Microsoft alerts are critical in nature so you will be receiving tickets for account breaches and not minor user log related events. That said, everything is customizable and you can turn alerts on & off to match your clients’ needs.
No. You can choose to schedule alerts to any stakeholder you want and at the frequency you want or manually download reports when you need them.
Regardless of how MFA is managed across your tenants, we have you covered. Augmentt supports Conditional Access Policies, Security Defaults, Entra ID per user (Legacy) MFA as well as 3rd party MFA services like DUO.
No. You can use Augmentt to monitor and manage all clients regardless of their licensing. For environments with no premium licensing you can still provide alerts and monitoring for account breaches and configure security best practices. For environments with premium licensing, you can leverage Microsoft’s premium alerts and premium security configurations such as Conditional Access Policies.
Augmentt is one of the few vendors SOC 2 Type II, and GDPR compliant.
Site licenses to make sure you can deliver standardized service across all clients very affordably.

SUBSCRIBE for more resources

Related Content

Policy Sprawl Is Killing MSP Efficiency
Policy sprawl is quietly draining your margins, creating security gaps, and eroding client trust. The good news? Standardization is the cure.
Does Microsoft Secure Score Tell the Whole Story?
Do you have a complete understanding of your security? See why MSPs need to understand the role licensing plays in Secure Score results.
Top 10 M365 Security Best Practices for MSPs
Here are the top M365 security best practices to help you enhance protection, ensure compliance, and stay ahead of emerging threats.