Certify your practice.
Win more business.
The Certified Managed Compliance Provider (CMCP) program gives your MSP the credential, the skills, and the platform mastery to deliver compliance services your customers are already asking for.
The CMCP program is available exclusively through Digital Hands on behalf of KASEYA.
Compliance is no longer a nice-to-have.
Your customers are facing pressure from upstream enterprise clients, cyber insurance underwriters, and regulators who want proof of security and a strong compliance posture.
The MSPs who can deliver compliance services credibly and confidently — with a structured approach, the right tooling, and a recognized credential — will win those engagements.
New services, better margins, immediate value based on high market demand
Compliance services are among the highest-margin offerings an MSP can deliver. CMCP gives you the skills and the credential to charge for them confidently.
A designation your customers recognize
The CMCP is awarded to your organization — not just an individual. Display it to prospects and customers as proof that your practice is structured, verified, and audit-ready.
Differentiate in a crowded market
Most MSPs claim they can do compliance. CMCP-certified MSPs can prove it — with a recognized credential backed by a structured curriculum and platform-aligned delivery skills.
What the CMCP credential is.
The Certified Managed Compliance Provider (CMCP) is an organization-level designation — awarded to your MSP as a business, not to an individual employee.
It signals to every prospect and customer you engage that your practice has been trained, tested, and verified to deliver compliance services using a structured, auditable methodology built on the K Compliance Manager platform.
LMS-based, self-paced program with gated assessments at every module
Your organization — requires at least one user to complete and pass the full program
KASEYA Compliance Manager — the platform your practice already uses or is investing in
Add framework-specific deep-dive modules as your customer base and practice grow
What you will learn.
Eight progressive modules build your practice from the ground up — from compliance fundamentals and platform configuration through client delivery, reporting, and advanced multi-framework engagements.
GRC Foundations
Walk into any compliance conversation with confidence — explain what GRC means, why your customers care, and exactly what your role is as their compliance partner.
Framework Scoping & Control Mapping
Accurately scope any compliance engagement, map controls across frameworks, and build unified evidence strategies that serve multiple standards at once.
Compliance Manager Configuration
Configure KASEYA Compliance Manager for any client environment — activate frameworks, integrate your tool stack, set up role-based access, and validate scan results from day one.
Evidence Collection & Validation
Collect and package audit-ready evidence that satisfies auditor standards — across both automated platform outputs and manual collection — so nothing gets kicked back.
POA&M Governance
Build and run a remediation tracking program your clients can see, understand, and act on — turning compliance gaps into a managed, accountable process.
Executive Reporting & Audit Readiness
Produce the reports your clients show their boards and the evidence packages their auditors accept — and guide clients through the audit itself without surprises.
Delivery QA & Continuous Governance
Operate your compliance practice with consistency and quality — detect drift between audit cycles, score your own delivery, and keep every client on track.
Advanced Framework Delivery
Handle the most complex engagements — multi-framework clients, CMMC and HIPAA nuances, overlapping evidence requirements — with the depth and precision your clients need.
Pass all 8 modules + final certification exam
Framework deep dives.
Once you have earned your CMCP designation, Module X is available as an advanced add-on. Each lesson delivers practitioner-level mastery of a single framework — going well beyond the foundational coverage in the core program. Purchase individual lessons for the frameworks your customers need most.
17 practices, FAR 52.204-21, SPRS scoring, self-assessment methodology, and False Claims Act exposure for defense contractors.
110 practices, NIST SP 800-171, C3PAO assessment preparation, CUI scoping, SSP development, and POA&M remediation at scale.
All six core functions including the new Govern function, profile development, implementation tiers, and gap analysis methodology.
93 Annex A controls across four themes, ISMS clause structure, Statement of Applicability, risk treatment planning, and certification audit support.
All 18 Controls, 153 Safeguards, Implementation Groups 1–3, MSP tool stack alignment, and attack-prioritized defense rationale.
AICPA Trust Services Criteria, all 9 Common Criteria groups, evidence sourcing, CPA audit process, sampling standards, and report interpretation.
Required and addressable safeguards, ePHI detection, OCR-compliant risk analysis, BAA requirements, and breach notification protocols.
Who we are.
Digital Hands is a cybersecurity and risk advisory firm specializing in managed security, Unified Security Posture Management, and GRC services. We built the CMCP program because we saw firsthand what happens when MSPs try to deliver compliance services without a structured foundation — inconsistent delivery, client dissatisfaction, and missed revenue.
The CMCP is not a generic GRC course. It was purpose-built for MSPs operating within the KASEYA ecosystem, aligned to the KASEYA Compliance Manager platform, and designed by practitioners who deliver these services every day.
- Built for MSPs — not enterprise compliance teams or internal IT departments
- Platform-aligned — curriculum maps directly to KASEYA Compliance Manager workflows
- Organization-level credential — your business earns the designation, not just one employee
- Gated progression — every module requires demonstrated competency before advancing
- Exclusive — Digital Hands is KASEYA’s only authorized CMCP certification partner
- Expandable — add framework deep-dive modules as your practice grows
Accessible at every stage of building your practice.
The CMCP program is designed to be accessible at any stage of building your compliance practice — from your first certification to a fully expanded multi-framework, multi-user program.
CMCP Certification (Base)
12-month access: core curriculum (Modules 1–8), 1 user license, knowledge exam, and CMCP organization credential upon passing. Includes one monthly live Ask-the-Expert session with a Digital Hands GRC practitioner.
Contact Us →Module X • Framework Lessons
12-month access: individual Module X lessons — choose one or more frameworks (CMMC L1/L2, NIST CSF, ISO 27001, CIS Controls, SOC 2, HIPAA). Prerequisite: CMCP certification or completed Knowledge Exam.
Contact Us →Additional User License
Per-seat license for each additional staff member completing the program within your organization.
Contact Us →Knowledge Exam (Standalone)
Exam-only access for staff who have completed training through an alternate path and seek CMCP designation.
Contact Us →Recertification Exam
Annual or renewal exam to maintain your active CMCP designation as frameworks and requirements evolve.
Contact Us →The CMCP program is available exclusively through Digital Hands on behalf of KASEYA.
Earn your CMCP designation.
Enroll directly through the CMCP portal — or look through the program first.