When is Compliance Scorecard the better pick?
Compliance Scorecard is built around policy work. You get customized policy creation, revision control, e-signature tracking and a risk register in one place (Compliance Scorecard). For an MSP that's been keeping client policies in a SharePoint folder of Word files, that's a real step up.
It covers more frameworks than we do, too: 30+, updated monthly, and you can build your own (Compliance Scorecard). Each client gets its own program, and running it on your own MSP is free on any paid plan (Compliance Scorecard).
It's also run by people who know the channel. CEO Tim Golden is a 20-year compliance veteran, and Bellini Capital, led by ConnectWise co-founder Arnie Bellini, backs the company (Compliance Scorecard).
In December 2024 it bought PrivacyMSP and started a professional services team (press release). So if you'd like someone to run the program with you, or for you, that option's there. There's also a Peer Group at $299 a month, with weekly GRC calls and workshops for your whole team (Compliance Scorecard). That's the Peer Group's price, not the platform's.
If your service is "we keep your policies and risk register current, and we report on it every quarter," Compliance Scorecard's a good fit.
What does using Cyber Verify look like?
UCS (the Unified Certification Standard) is the standard: 72 requirements across 5 domains, with the full text free at mspalliance.com/ucs. UCS has been around since 2004. Cyber Verify launched in 2023 and uses it as the framework for its certification program.
Cyber Verify is the certification you earn against UCS, and the platform where you do the work, first for your own MSP and then for your clients. MSPAlliance runs the program. An independent audit firm, pre-approved by MSPAlliance, performs the audit.
Here's what you'll do, step by step:
Assess. You answer the guided assessment (CVAT). It takes under an hour and scores you across the 5 UCS domains (MSP Verify).
Fix. You get a gap list sorted by impact and effort, plus templates for missing policies. Most MSPs close their critical gaps in 60 to 120 days (MSP Verify).
Prove. You upload evidence, and your compliance sherpa reviews it before the auditor does.
Get certified. The audit is part of certification. You get a written report signed by the audit firm, plus a seal to use in marketing and sales. Most MSPs finish in three to six months, and you renew each year.
Add frameworks. Certification is the foundation for this step. SOC 2, ISO 27001, CMMC and others sit on the same platform and reuse the evidence you've collected. Each framework's auditor still decides what they'll accept.
Sell it to clients. Each client gets its own tenant and white-labeled reports. We bill you per client, and you set the client's price and bill them yourself. For client audits, we connect you to CPA firms, ISO registrars and C3PAOs, and that firm works under its own engagement with you or your client.
When is Cyber Verify the better pick?
Compliance Scorecard helps you govern your clients. UCS holds your own MSP to a standard, and it looks at your business as well as your security.
The audit asks whether you've been profitable in 6 of the last 12 months, or have a year of funding (requirement 10.01). It checks your insurance (10.05). It wants a written plan for handing a client to a new provider if you ever part ways (02.08). A client can't check any of that from outside, which is why an independent audit carries weight.
Neil Holme, Founder and CEO of Impact Business Technology, describes the result:
“MSPAlliance helps you prove you're well-run, making your company stronger, more efficient, and profitable.”
Once you're certified, you run the same assess, fix and prove steps inside each client's tenant.