Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security

White-Label Compliance and Penetration Testing for MSPs: How to Deliver Without Building a Team

Direct answer: An MSP delivers SOC 2, ISO 27001, penetration testing and vCISO work to its clients without building a specialist team by bringing in a partner that does the work under the MSP's brand (white-label), alongside it as a named specialist (co-branded), or directly on referral. The MSP keeps the client relationship and sets its own margin. What makes it work is the paperwork: a clear scope, a mutual NDA, a non-solicit covering the MSP's clients, defined ownership of the deliverables, and an honest line on independence where an audit or a test is involved.

Why MSPs get asked for this work

Your clients' customers send security questionnaires. Their insurers ask about MFA, backups and incident response. Their enterprise buyers ask for a SOC 2 report or an ISO 27001 certificate. Their boards ask who is accountable for security. The client's first call is to the people who already run their IT, which is you.

The difficulty is that this work is specialist and lumpy. A SOC 2 readiness project needs someone who knows what an auditor accepts. A penetration test needs testers with offensive experience. A vCISO needs a senior person who can sit in front of a board. None of those is a full-time hire for most MSPs, and saying no leaves a gap in a relationship you have spent years building.

The three delivery models

White-label

The partner works under your brand: your email domain, your templates, your status updates. Your client sees your team. You hold the contract, set the price and keep the renewal. This suits work that sits naturally inside your managed relationship, such as readiness projects, policy sets, ongoing compliance upkeep and fractional security leadership under your name.

Co-branded

The partner is introduced as your specialist for a defined area. Useful when the credential itself matters to the client or their buyer, such as AI security, a named security leader, or work that an auditor or enterprise customer will scrutinize.

Direct referral

You refer the work and the partner contracts with your client directly, while you keep the managed services relationship. The cleanest model when the scope is far outside your usual book, or when independence rules make it better for the partner to hold the contract.

Pick per engagement, not once for the whole partnership. The same MSP might white-label a readiness project, co-brand a vCISO, and refer an internal audit.

Sold it and cannot staff it? We deliver SOC 2, ISO 27001, testing and vCISO work under your brand or ours, and the client relationship stays yours. MSP partners

What each service looks like delivered through an MSP

SOC 2 and ISO 27001 readiness

Readiness runs in two phases. Phase 1 is a fixed-price gap analysis that sets scope and produces a ranked findings register. Phase 2 is remediation, scoped and priced from those findings: policies, controls, evidence, auditor selection and support through fieldwork. Much of the technical remediation, such as MFA, device management, logging and backups, is work your team already does. A good partner will hand you those items as tickets rather than doing them itself, which keeps the work and the revenue with you.

The audit itself is always done by an independent party: a licensed CPA firm for SOC 2, an accredited certification body for ISO 27001. Neither you nor the readiness partner can sign it, and you should be wary of any arrangement that blurs that line.

Penetration testing

Testing is the service where independence matters most. If your team built and runs the environment, your client's customer will want to know the test was performed by someone else. White-label testing is common, but the report should state who performed it in terms the client's buyer will accept, and attestation letters should be accurate about the tester. We deliver penetration testing with our testing partners and put one standard report and attestation letter behind it, with retests of the fixes.

vCISO

Fractional security leadership is the most natural white-label service, because it is a relationship. A named senior person attends the client's leadership or board meetings, owns the security roadmap, answers questionnaires and represents the client to buyers. Under your brand it extends what you sell from operations to governance.

CyberSecure Canada

For Canadian small and medium clients, CyberSecure Canada certification against CAN/DGSI 104 is a natural fit for an MSP, because many of its controls are things you already operate: patching, anti-malware, MFA, backups, firewalls and access control. The certification itself is issued by an accredited certification body. The readiness work and the evidence pack are where a partner adds value. See our CyberSecure Canada certification guide.

Independence: the line you cannot cross

Some work cannot be white-labelled by the people who run the environment, whatever the contract says:

  • Audits and certifications are always by an independent CPA firm or certification body.
  • ISO 27001 internal audits must be objective and impartial, so the people who operate the controls cannot audit them. If you run the client's ISMS, refer the internal audit out.
  • Penetration tests carry more weight with buyers when performed independently of the team that built the environment, and the report should be clear about who tested.

Get this right and it becomes a selling point: you deliver the operations, a partner delivers the independent assurance, and the client gets both through one relationship.

Free weekly email

Get The Compliance Brief every Tuesday

One email a week from Jacob Masse: the security and compliance stories that changed something that week, and what each one means if you sell software to enterprise buyers. Five stories, a take on each, five minutes to read.

Free. Unsubscribe in one click, and replies reach Jacob directly. Read the latest issue or browse the archive.

The contract that protects you

  • Mutual NDA covering your client list and their data.
  • Non-solicit on your clients, so the partner does not approach them directly later.
  • Scope and deliverables agreed before you commit to your client, including what the partner needs from your team.
  • Ownership of the deliverables, templates and any workspace the client uses.
  • Communication rules: who talks to the client, in whose name, and through which tools.
  • Data handling: least-privilege access, where client data lives, and when the partner's access is removed.
  • Which entity signs, and under which province's law.

Pricing and margin

You set your own price to the client. The partner's price to you should be published or agreed per service before you quote, so your margin is known rather than discovered. Our published starting prices are SOC 2 readiness from $3,000, ISO 27001 from $3,500, penetration testing from $3,500 and vCISO from $2,500 a month. Each compliance price is for the Phase 1 gap analysis; remediation is priced from the findings, which is also how you should quote it to your client. Quoting a full SOC 2 project before anyone has seen the gaps is how margin disappears.

Starting with one engagement

Do not build a full partner programme before the first job. Start with one client who has asked for something specific, such as a SOC 2 gap analysis or a penetration test for a customer questionnaire. Agree the model, the scope and the price for that engagement, run it, and see how the handoffs work in practice: who chases the client for evidence, who joins which calls, how status reaches your account manager, and how fixes that fall to your team are ticketed.

After two or three engagements you will know which services you want to resell routinely, which you would rather refer, and which you might eventually bring in house. That is a better basis for a standing agreement than a rate card negotiated in the abstract.

Timing on compliance work depends on the gaps found and on the auditor's or certification body's schedule, so agree the start date and deliverables with the partner before you commit to the client, and be honest with the client that the audit date is not yours to promise.

Questions to ask a white-label partner

  • Which services do you deliver yourselves, and which with partners?
  • Can you show completed engagements in Canada, and provide references on request?
  • Will you work in our tools, under our domain, with our templates?
  • Is remediation priced before or after the gap assessment?
  • How do you handle independence for audits, internal audits and testing?
  • What are the practitioner's credentials beyond a baseline certification?
  • Where does engagement data live, and what happens to it at the end?

Frequently asked questions

Will our client know a partner is involved?

Only if you choose a co-branded or referral model. Under white-label, the work is delivered under your brand, and the terms say how, or whether, the partner communicates with your client.

Can we resell the partner's services at our own price?

Yes. You hold the contract and set the margin. Agree the partner's price per service before you quote.

Can our MSP do the SOC 2 audit if we partner with a readiness firm?

No. A SOC 2 report is issued by a licensed CPA firm, independent of the organization and of whoever prepared it. ISO 27001 certificates are issued by accredited certification bodies.

What if our team runs the client's environment and they need a pentest?

Have the test performed by testers independent of your operations team, and make sure the report says who tested. That is what the client's buyer will check.

Clients asking for compliance or testing you cannot staff? Tell us the scope, the client profile and whether you want us white-labelled.

MSP partnersOr see published prices

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on vulnerability management. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
Zero
Exceptions on a SOC 2 Type II built from nothing in-house

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.