When is Compliance Manager GRC the better pick?
Its big strength is automated evidence. It collects data from the network, the cloud and each computer. Then it scores every control and sends tasks to the people who own them (Kaseya). It builds a policy and procedure manual for each standard you manage, plus evidence reports and plans of action (Kaseya).
Kaseya bought RapidFire Tools, the maker of Network Detective, in September 2018 (Kaseya). It launched the product as Compliance Manager GRC in March 2022 (Kaseya).
Compliance Monitor arrived in March 2025 at no additional cost. It keeps checking each device's settings against CIS Benchmarks mapped to CMMC, HIPAA, NIST and other standards (Kaseya). In June 2026 Kaseya previewed automatic remediation of those findings through Datto RMM (Kaseya).
It connects to VSA, Datto RMM, IT Glue, Autotask and Kaseya's backup and security tools, so data you already collect flows in (Kaseya). One note: we didn't find it listed among the components of Kaseya 365 Endpoint, Ops or User (Endpoint, Ops, User), so plan to budget for it on its own.
Kaseya also helps you sell it. Its MSP page suggests charging "20-50% more than your base managed services" for these security services (Kaseya).
Say you run Kaseya tools, and your clients need HIPAA, CMMC or cyber insurance proof from many sites. Then Kaseya's tool is a strong fit.
What does using Cyber Verify look like?
UCS (the Unified Certification Standard) is the standard: 72 requirements across 5 domains, with the full text free at mspalliance.com/ucs. UCS has been around since 2004. Cyber Verify launched in 2023 and uses it as the framework for its certification program.
Cyber Verify is the certification you earn against UCS, and the platform where you do the work, first for your own MSP and then for your clients. MSPAlliance runs the program. An independent audit firm, pre-approved by MSPAlliance, performs the audit.
Here's what you'll do, step by step:
Assess. You answer the guided assessment (CVAT). It takes under an hour and scores you across the 5 UCS domains (MSP Verify).
Fix. You get a gap list sorted by impact and effort, plus templates for missing policies. Most MSPs close their critical gaps in 60 to 120 days (MSP Verify).
Prove. You upload evidence, and your compliance sherpa reviews it before the auditor does.
Get certified. The audit is part of certification. You get a written report signed by the audit firm, plus a seal to use in marketing and sales. Most MSPs finish in three to six months, and you renew each year.
Add frameworks. Certification is the foundation for this step. SOC 2, ISO 27001, CMMC and others sit on the same platform and reuse the evidence you've collected. Each framework's auditor still decides what they'll accept.
Sell it to clients. Each client gets its own tenant and white-labeled reports. We bill you per client, and you set the client's price and bill them yourself. For client audits, we connect you to CPA firms, ISO registrars and C3PAOs, and that firm works under its own engagement with you or your client.
When is Cyber Verify the better pick?
Kaseya's tool gets you ready for an auditor. Kaseya is upfront that a successful scan doesn't guarantee compliance on its own (Kaseya). That's true of every readiness tool. With Cyber Verify, the audit of your own MSP is part of certification.
UCS also checks things no scanner can reach, because they live in your contracts and books. It looks for signed MSAs with your clients and accurate invoices (requirements 09.01 and 09.02). It checks that your MSP carries insurance (10.05). A prospect can't see any of that from outside, so an audit is how you show it.
And the process is built to get you through. Your compliance sherpa checks evidence before it's sent. Then an independent audit firm, pre-approved by MSPAlliance, does the audit. Neil Holme, Founder and CEO of Impact Business Technology, described MSPAlliance's approach like this:
“It's a friendly audit. They really want you to get through this and they will help you do it.”