CMMC Scores Hit Five-Year High as Contractor Confidence Drops 24 Points

CMMC for MSPs

Something strange showed up in the defense industrial base this month. Contractors are reporting the best cybersecurity scores in the history of the program — and simultaneously trusting those scores less than they ever have. CyberSheath’s 2026 State of the DIB report, published August 20, found the average self-reported Supplier Performance Risk System score climbed […]

Why MSPs Fall Behind on Compliance Management

MSP compliance as as service CaaS

MSP compliance management sits at the intersection of expanding regulations and limited operational capacity. Every new framework your clients fall under adds documentation, controls, and audit cycles to your plate. This article breaks down the root causes behind these operational bottlenecks and shows how a Compliance-as-a-Service model can reduce your team’s workload. Blacksmith InfoSec helps […]

8 MSP Compliance Bottlenecks to Fix Before You Scale

compliance bottlenecks for MSPs

Countless MSPs have hit the same wall. Their first few compliance clients felt like careful, custom work. Their next ten felt like they were drowning. By client thirty, the MSP was pulling technicians off billable work every audit cycle, drafting the same policy from scratch for the fourth time, watching their margin evaporate into the […]

7 Policy Automation Facts MSPs Should Know in 2026

policy automation for MSP compliance

Managing compliance for one client is a process. Managing it for twenty, fifty, or one hundred clients is an operational challenge. Policies need to be assigned, reviewed, updated, acknowledged, and connected to the risks and controls they are meant to support. Evidence needs to be organized before an audit request arrives — not assembled from […]

9 Policy Management Features That Matter in 2026

MSP policies and compliance

Regulated organizations generate more policies than ever, and most of those policies live in shared folders, inboxes, or outdated wikis where no one can track what’s current, who approved it, or whether anyone read it. For MSPs delivering compliance management software services to clients in healthcare, finance, and government, helping those clients get policy management […]

8 GRC Capabilities MSPs Need in 2026

8 GRC Capabilities MSPs Need in 2026

Regulatory pressure on your clients keeps climbing. So does the demand for you to prove their security posture to auditors, insurers, and upstream vendors. Blacksmith InfoSec helps MSPs turn that pressure into a structured, scalable compliance-as-a-service offering. But whether you use Blacksmith or another platform, certain GRC capabilities separate tools that help you scale from tools that become bottlenecks. […]

Get NIST-y Roundup: The Compliance Trap, the CMMC Monster, and the AI Wild West

Three episodes, one throughline: MSPs catch flak for the compliance decisions their clients refuse to make. This roundup pulls the practical takeaways from our latest run of Get NIST-y — the podcast where we skip the framework LARP and talk about what actually works in a client environment on a Tuesday afternoon. If you missed […]

Blacksmith Launches GTIA Cybersecurity Trustmark Framework Support for MSPs and Solution Providers

GTIA trustmark Blacksmith Infosec compliance MSP

Managed service providers and solution providers need practical ways to turn cybersecurity standards into repeatable operational workflows. Blacksmith’s new support for the GTIA Cybersecurity Trustmark framework is built to do exactly that, giving partners a more streamlined path to manage, operationalize, and demonstrate progress toward the Trustmark inside the Blacksmith platform.  This launch reflects a collaboration between Blacksmith and the Global […]

The Checkbox Isn’t the Point: Does Speed Undermine Compliance Credibility?

msp compliance solution

A new piece of research landed recently that should make any MSP concerned with cybersecurity and compliance stop and think. According to a June 2026 study⁽¹⁾ by business resilience specialists IO — conducted among 251 senior UK cybersecurity managers — 87% of respondents believe the speed at which compliance certification is achieved affects its credibility . […]

Compliance as a Service: Turning Red Tape into Client Value

msp compliance tracking tool

Most MSPs talk about security as a way to “keep you safe.” That’s fine, but it misses the reason your clients are suddenly paying attention to compliance: their ability to win business, keep contracts, and stay insurable now depends on being able to prove they’re safe to work with. Compliance frameworks are not just about […]

Check Out Our Compliance Podcast on Spotify!