Three episodes, one throughline: MSPs catch flak for the compliance decisions their clients refuse to make. This roundup pulls the practical takeaways from our latest run of Get NIST-y — the podcast where we skip the framework LARP and talk about what actually works in a client environment on a Tuesday afternoon.
If you missed any of these, here’s the short version along with the full podcast link:
Episode 1: Shared responsibility gets ugly
The setup: A medical client’s cyber insurer wants annual security policies. The doctors want the front desk to handle it. You, the MSP, are being nominated for the unpaid compliance department.
This is the trap. Shared responsibility only works when the client actually holds up their end, and “the front desk will do it” is not holding up their end. A receptionist might be able to gather answers, chase signatures, and format documents. What they cannot do is own the policy. Policy authority needs an executive sponsor or a real practice manager — someone with the standing to say “yes, this is how we do things here” and make it stick when it’s inconvenient.
Where MSPs go sideways:
Absorbing decisions that aren’t yours. Review vendor risk and lay out options — don’t accept risk on the client’s behalf. OCR settlements in healthcare show what owning the outcome costs when it goes wrong.
Letting the exec carve themselves out. The moment leadership exempts itself from MFA, training, or the AUP, you’ve taught the whole company what actually matters. The Verizon 2025 DBIR is clear: privileged users are the highest-value targets and the most frequent root cause of serious breaches.
Confusing recurring service with project work. Ongoing compliance help belongs in MRR. Sprint work — new attestation, emergency insurer audit, full risk assessment — is a project. Price it that way or you’ll be doing it for free by month three.
The move: put a shared-responsibility matrix in every compliance-adjacent contract. Two columns: “MSP does” and “Client does.” Sign it. Reference it when the front desk gets nominated to write HIPAA policy.
Episode 2: CMMC Level 2 without lighting money on fire
The setup: A small defense-adjacent client hears “CMMC” and starts pricing a full GCC High migration for the whole company. That’s the monster. Nine times out of ten, the monster is bad scoping.
CMMC Level 2 is aligned with NIST SP 800-171 — 110 controls protecting Controlled Unclassified Information (CUI). The assessment only applies to the people and systems that actually touch CUI. If three people in a 40-person shop handle CUI, scope an enclave around those three, isolate it, and leave the rest of the business outside the boundary. You do not need to launch the whole company into GCC High to satisfy a DoD prime.
Where MSPs earn their fee:
Map data flows first. Before buying anything, know where CUI enters, lives, and leaves. The DoD’s CMMC Assessment Guide for Level 2 treats scope as the first-order decision — scope creep is why small-company CMMC budgets triple.
Scope the enclave tight. A bounded CUI enclave (dedicated tenant or GCC High subset, dedicated devices, dedicated identity boundary) shrinks the assessment from “the whole company” to “these seven people and these three systems.” That’s the difference between a six-figure and a five-figure project.
Operationalize, don’t just purchase. Buying an EDR doesn’t check a control. Running it, tuning it, reviewing alerts weekly, and documenting that you did checks the control. Tools without operational discipline are the top finding C3PAOs report at Level 2.
The move: before the client signs, deliver a scoping memo — data flow diagram, in-scope assets, out-of-scope assets with justification, and a controls-mapping table. That memo determines whether the project costs $40k or $400k.
Episode 3: AI usage and the new shadow IT
The setup: Half your clients are treating AI like a productivity cheat code. The other half blocked ChatGPT at the firewall and consider the problem solved. Both are wrong.
The blockers create shadow AI — users pasting client data into personal ChatGPT accounts on their phones, or standing up unsanctioned Copilot Studio flows that nobody inventoried. (We wrote about the downstream identity risk this creates last week.) The permissive clients get output-quality problems, data-leakage problems, and eventually a lawsuit when someone acts on a hallucinated answer.
The middle path is the only one that survives contact with actual users.
What actually works:
Sanction a tool. Publish the rules. Give users an approved AI option (Microsoft Copilot with data-processing controls, an enterprise ChatGPT tenant, a private-hosted model — whatever the risk profile supports) and a plain-English acceptable-use policy. Users create shadow AI when official channels are slower or dumber than the personal alternative. Fix that gap.
AI output is a draft, not a decision. Your client’s team still owns the result. Legal, medical, financial, and safety-adjacent outputs need human review before they leave the building. Bake that into the AUP and the training.
If the process is broken, AI just breaks it faster. If nobody can explain how a workflow is supposed to run, adding AI doesn’t fix it — it accelerates the mess and adds plausible deniability. Fix the process first.
Find shadow SaaS by walking the money. The fastest way to inventory unsanctioned AI and SaaS is still the oldest trick: get close to accounting. Expense reports and corporate-card statements show every $20/month tool the security team never approved. Pair that with a browser-extension inventory and an OAuth-grant audit in the identity provider, and you’ll surface 80% of the shadow footprint in a week.
The move: productize a Shadow AI & SaaS Discovery — expense-report review, OAuth grant audit, browser extension inventory, and a one-page AUP the client can actually enforce. Small engagement, big surface area, natural upsell into ongoing governance.
The through-line
Every one of these episodes lands on the same principle: compliance is a shared responsibility, and shared means both sides show up. MSPs get in trouble when they absorb decisions the client should be making — policy authority, risk acceptance, scope definition, tool operationalization, AI governance. Clients get in trouble when they treat the MSP as an outsourced conscience.
The fix in all three cases is the same: write the scope down, sign it, and price it. Sprint work as projects, recurring work as MRR, exec-level decisions as exec-level decisions. That’s how you stay out of the unpaid compliance department — and how the client actually gets compliant.
Catch the full episodes wherever you get podcasts, and if you want the shared-responsibility matrix template, the CMMC scoping memo template, or the AI acceptable-use starter, reply to this newsletter and we’ll send them over.
FAQ
Q: Who owns compliance decisions in an MSP–client relationship?
A: The client owns risk acceptance, policy authority, and scope definition. The MSP owns advice, execution of agreed controls, evidence collection, and options analysis. If the client won’t name an executive sponsor for compliance decisions, you’re being set up to absorb accountability you can’t legally hold — walk the contract back before it burns you.
Q: How do I keep CMMC Level 2 costs from spiraling for a small client?
A: Scope the CUI enclave tightly before you buy anything. Map data flows, identify the minimum set of people and systems that touch CUI, and isolate them in a bounded environment (dedicated tenant, devices, and identity boundary). Everything outside that boundary is out of scope. Scoping determines whether the project lands in five figures or six.
Q: Do I have to move the whole company to GCC High for CMMC Level 2?
A: Almost never. If CUI is handled by a small subset of the workforce, a properly bounded enclave — sometimes in a GCC High partition, sometimes in a dedicated commercial tenant — satisfies the assessment without moving the entire company. Confirm with a C3PAO or qualified CMMC RPO before finalizing the enclave-versus-full-tenant call.
Q: How should an MSP handle client AI usage without banning everything?
A: Sanction a defensible tool, publish a clear AUP, require human review for legal, medical, and financial outputs, and audit monthly via expense reports, OAuth grants, and browser extensions. Blocking creates shadow AI; unrestricted access creates data leakage. Approved tools plus enforced guardrails is the only path that survives.
Q: What’s the fastest way to find shadow IT and shadow AI?
A: Walk the money. Expense reports and corporate-card statements reveal every SaaS and AI tool the security team never approved. Layer in an OAuth grant audit in the identity provider (Entra ID, Okta, Google Workspace) and a browser-extension inventory across managed endpoints — you’ll surface most of the shadow footprint inside a week.


