The MSP guide

How to price and package compliance services

You already do the security work. The patching, the MFA, the backups. But if your invoice says "managed services" and nothing else, you are giving the most valuable part away for free. This guide shows how MSPs turn Essential 8 and SMB1001 work into named, priced services: the revenue models, the packaging, the sales conversation, and the delivery rhythm.

One honesty note before we start: there is no published market rate for compliance services, and we will not invent one. This guide gives you the models and the maths. The price is yours to set.

Why compliance pricing is different from per-seat support

Per-seat support pricing is under pressure from two directions: AI resolves more of the tickets you bill for, and clients using AI hire fewer people. Compliance runs on different fuel. The client pays because something they want is at stake: a contract that demands proof of security, an insurance renewal, a tender, a big customer's questionnaire. That value does not shrink when headcount does.

That changes three things about how you price it. You price per client, not per seat. You price against the value at stake, not the hours spent. And you keep it as a named line item, because compliance buried inside an all-inclusive bundle becomes invisible work you can never charge for.

The four revenue models, and when each applies

1. The readiness project (fixed fee, one-off)

Take one client from where they are to a named tier: SMB1001 Bronze, Silver or Gold, or an Essential 8 maturity level. Scope it like any project: scan, close the gaps, write the policies, prepare the attestation for the director to sign. Fixed fee beats hourly here, because the platform does the assessment in minutes that used to take days, and a fixed fee lets you keep that efficiency instead of billing fewer hours.

2. Compliance-as-a-service (monthly, per client)

The annuity. Re-scan on a schedule, fix drift, keep the evidence current, and answer any questionnaire that lands within days instead of weeks. This is the model that compounds: every client added is recurring revenue, and the work per client falls as your delivery gets practised.

3. Annual recertification (yearly, per client)

SMB1001 certificates last one year and the standard is updated annually, so recertification is built-in repeat business. Put every client’s certificate expiry in your calendar and quote the renewal before they ask. A client who certified once rarely wants to let it lapse, because the customers who asked for proof will ask again.

4. Upgrade and event projects (quotable, as they arise)

Each step up a tier is a project. So is each trigger event: a new standard edition (the 2027 update adds AI governance and device management), an insurer tightening requirements, a client chasing a government tender that needs Essential 8 evidence. These arrive on their own schedule, and the MSP already holding the evidence wins them without competition.

A healthy compliance line uses all four: the project lands the client, the monthly service keeps them, the recertification repeats every year, and the events add quotable work on top.

Packaging: map your tiers to the standard's tiers

The packaging problem is already solved for you: SMB1001 comes in tiers, so your packages can mirror them. Three packages is plenty.

Baseline

SMB1001 Bronze or Silver

Entry package for every client. The foundational controls, certified by director self-attestation, with the evidence kept for one year. The point of this package is that every client can say yes to it.

Standard

SMB1001 Gold

The flagship. Gold is the highest tier a director can self-attest, which means you deliver it end to end without an external certifier. Includes the policies, the incident response plan and the AI usage policy the standard expects.

Contract-ready

Essential 8 ML1/ML2 evidence

For clients chasing government work, DISP or enterprise contracts that name Essential 8. Priced highest, because the value at stake is a contract, and scoped as evidence per control, which is exactly what the tender asks for.

Name the packages after outcomes, not frameworks, on your own price list. Your client buys "contract-ready", not a standard number.

The maths, with real numbers where we have them

Your delivery cost has two parts: platform and people. The platform side is public: CYBERWHITE MSP plans run from $199 AUD per month for 1 to 5 client tenants to $1,499 AUD per month for 21 to 50. At the Portfolio tier that is roughly $30 per client per month.

The people side is where the platform changes the economics. A manual Essential 8 ML2 assessment runs 45 to 62 hours per client. The scan does the technical checking in about 5 minutes, and AutoFix deploys 48 of the 151 mapped remediation actions in one click, with snapshot and rollback. Your engineer's time goes into the judgement calls and the client conversation, not the spreadsheet.

Worked example, with your price as the variable: an MSP with 30 clients on a compliance service at P dollars per client per month earns 30 × P × 12 per year, against roughly $30 per client per month in platform cost plus your delivery time. At any sensible P, the margin lives or dies on delivery efficiency, which is exactly what the automation buys you. Plug your own numbers into the MSP revenue calculator to see your version.

How to sell it

Do not sell compliance. Sell the moment. Clients buy when something they want is blocked: an insurance renewal with new questions, a supplier questionnaire from their biggest customer, a tender that names Essential 8. Your job is to be there before the moment, so that when it arrives, the conversation is short.

The opening line that works

"When your insurer or your biggest customer next asks you to prove your security, what will we send them?" Then stop talking. Every business owner knows that question is coming, and almost none of them has an answer.

The objection: "aren't we already paying you for security?"

"You are paying us to do the work. This is about being able to prove it to the people who ask, with a certificate and evidence, control by control. The work and the proof are different products." This is also why compliance must be a named line item: if it is invisible inside the bundle, this objection wins.

A page you can forward today

We keep a plain-English page written for your clients, not for you: Why SMB1001 matters for your business. Paste it into the next client email and let it start the conversation.

How to deliver it without drowning

1

Sort the client base once

List every client with their target tier and the trigger most likely to hit them (insurance renewal date, main customer, tender season). This list is your pipeline, in order.

2

Run the first scan in the sales meeting

Connect the tenant read-only and scan while you talk, about 5 minutes. A ranked gap list for their own business closes better than any slide deck.

3

Fix in one pass, evidence as you go

Deploy the one-click fixes with snapshot and rollback, schedule the rest, and generate the policy documents. The evidence pack builds itself as the controls close.

4

The director signs, you file the date

Prepare the attestation; the client director signs it. Never sign for them, and never pre-fill what has not been done. Then put the renewal date in your calendar: that is next year’s revenue.

The five pricing mistakes that kill the service line

  • Pricing per seat. Compliance value does not scale with headcount, and seat counts are shrinking.
  • Folding it into the all-inclusive bundle. Invisible work cannot be valued, raised, or defended.
  • Selling a one-off project with no renewal. Certificates expire yearly; price the relationship, not the event.
  • Billing hourly for automated work. Fixed fees let you keep the efficiency the platform creates.
  • Guaranteeing certification. The director signs the attestation, not you. Prepare everything; promise preparation, not outcomes.

Common questions

How much should an MSP charge for compliance services?

There is no published market rate, and anyone quoting one is guessing. Price from the value at stake for the client (the contract, the insurance renewal, the tender) and your cost to deliver. Most MSPs land on a fixed-fee readiness project to reach a tier, a monthly per-client fee to keep evidence current, and an annual recertification fee.

Should compliance be priced per seat or per client?

Per client. Compliance effort scales with the number of tenants and certifications, not headcount, and per-client pricing protects you when AI and automation shrink client seat counts. It also matches how the client experiences the value: one certificate per business.

Should compliance go inside the managed services bundle?

Keep it as a separate, named line item. Compliance buried inside an all-inclusive bundle becomes invisible work you cannot charge more for. A named service with its own fee is visible, valued, and easier to raise as scope grows.

Can an MSP guarantee a client gets certified?

No, and your agreement should say so. For SMB1001 Bronze, Silver and Gold the company director signs the attestation, and for the top tiers an independent certifier assesses. The MSP prepares the controls and the evidence; the client owns the certification decision. Put that boundary in writing.

What does it cost an MSP to deliver compliance with CYBERWHITE?

CYBERWHITE MSP plans run from $199 AUD per month for 1 to 5 client tenants up to $1,499 AUD per month for 21 to 50. At the Portfolio tier that is roughly $30 per client per month in platform cost, against a compliance service you price and invoice under your own brand.

See the delivery side for yourself

Book a proof check: we scan one client tenant with you and show the ranked gaps and the evidence an assessor would ask for. Bring a hardened tenant if you want to test us.