When is Apptega the better pick?
Apptega covers a lot of ground. It supports over 30 frameworks, including NIST, SOC 2, ISO 27001, HIPAA and PCI, and you can create custom ones (Apptega). Crosswalking lets you run a multi-framework program as one.
It's built for scale. Apptega says you can "manage hundreds of clients from one centralized dashboard" (Apptega), and you can configure integrations per client, based on the tools each one uses (Apptega).
You can also try it before you talk to sales. The 14-day trial needs no card (Apptega).
If you're an MSSP with clients spread across many frameworks, and you'd like a branded GRC console, Apptega's a strong fit.
What does using Cyber Verify look like?
UCS (the Unified Certification Standard) is the standard: 72 requirements across 5 domains, with the full text free at mspalliance.com/ucs. UCS has been around since 2004. Cyber Verify launched in 2023 and uses it as the framework for its certification program.
Cyber Verify is the certification you earn against UCS, and the platform where you do the work, first for your own MSP and then for your clients. MSPAlliance runs the program. An independent audit firm, pre-approved by MSPAlliance, performs the audit.
Here's what you'll do, step by step:
Assess. You answer the guided assessment (CVAT). It takes under an hour and scores you across the 5 UCS domains (MSP Verify).
Fix. You get a gap list sorted by impact and effort, plus templates for missing policies. Most MSPs close their critical gaps in 60 to 120 days (MSP Verify).
Prove. You upload evidence, and your compliance sherpa reviews it before the auditor does.
Get certified. The audit is part of certification. You get a written report signed by the audit firm, plus a seal to use in marketing and sales. Most MSPs finish in three to six months, and you renew each year.
Add frameworks. Certification is the foundation for this step. SOC 2, ISO 27001, CMMC and others sit on the same platform and reuse the evidence you've collected. Each framework's auditor still decides what they'll accept.
Sell it to clients. Each client gets its own tenant and white-labeled reports. We bill you per client, and you set the client's price and bill them yourself. For client audits, we connect you to CPA firms, ISO registrars and C3PAOs, and that firm works under its own engagement with you or your client.
When is Cyber Verify the better pick?
A branded console shows a prospect how you'll manage their compliance. A UCS certification shows them your own MSP passed an audit first.
UCS was written for MSPs, so it asks about parts of your business a prospect can't see from outside. Do you have a written plan for handing a client to a new provider (requirement 02.08)? Have you been profitable in 6 of the last 12 months, or do you have a year of funding (10.01)?
Apptega's Audit Manager gets you ready for an audit. Cyber Verify takes you through one. Your sherpa checks evidence before it's submitted, and an independent audit firm, pre-approved by MSPAlliance, does the audit. Mike Deskin, President of Dresner Group, certified since 2015, put it this way:
“Cyber Verify has allowed us to win millions of dollars in work over the last 10 years. I personally think it's a small amount of money to pay for what we've gotten out of it.”
Client work runs on the same platform once you're certified, with your own client prices.