CERTIFICATION PROGRAM
The Certified Managed Compliance Provider program gives your MSP the credential, the skills, and the platform mastery to deliver the governance, risk and compliance services your customers are already asking for.
THE MARKET SHIFT
Compliance is no longer a nice-to-have — it is a buying requirement. Your customers face pressure from upstream enterprise clients, cyber-insurance underwriters, and regulators who want proof of a strong security and compliance posture.
The MSPs who deliver compliance credibly — with a structured approach, the right tooling, and a recognized credential — win those engagements. The ones who can't refer them out, or lose them.
Compliance is among the highest-margin services an MSP can sell — CMCP gives you the skills and credential to charge for it.
The CMCP is awarded to your organization, not an individual — proof that your practice is structured, verified, and audit-ready.
Most MSPs claim they can do compliance — CMCP-certified MSPs prove it with a credential and platform-aligned skills.
What Makes CMCP Different
Not enterprise teams or internal IT
Prove competency before advancing
Maps to Kaseya Compliance Manager
Add framework deep-dives as you grow
The business earns it, not one employee
Kaseya's only authorized CMCP partner
What The Certification Is
The CMCP is awarded to your MSP as a business. It signals to every prospect and customer that your practice has been trained, tested, and verified to deliver compliance services using a structured, auditable methodology built on the Kaseya Compliance Manager platform.
Self-paced LMS-based program with gated assessments after every module
Your organization — requires at least one user to complete and pass the full program
Kaseya Compliance Manager, the platform your practice already uses or is investing in
Add framework-specific, deep-dive modules as your customer base and practice grow
Core Certification · Modules 1–8
Eight progressive modules build your practice from the ground up — from compliance fundamentals and platform configuration through client delivery, reporting, and advanced multi-framework engagements. Every module is gated: you advance when you can prove you're ready.
Lead any compliance conversation with confidence: explain what GRC means, why customers care, and your role as their compliance partner.
Scope any engagement accurately, map controls across frameworks, and build unified evidence strategies that serve multiple standards at once.
Configure Kaseya Compliance Manager for any client: activate frameworks, integrate your tool stack, set role-based access, and validate scans from day one.
Collect and package audit-ready evidence that meets auditor standards across automated outputs and manual collection so nothing gets kicked back.
Run a remediation-tracking program clients can see, understand, and act on — turning compliance gaps into a managed, accountable process.
Produce board-ready reports and auditor-accepted evidence packages to guide clients through the audit itself without surprises.
Operate with consistent quality: detect drift between audit cycles, score your own delivery, and keep every client on track.
Handle the most complex engagements — multi-framework clients, CMMC and HIPAA nuances, overlapping evidence — with depth and precision.
The CMCP designation is awarded once all modules are complete and every certification gate is passed.
Go Further with Module X Sold Separately
Once you have earned your CMCP designation, each Module X lesson delivers practitioner-level mastery of a single framework — well beyond the core program's foundational coverage. Purchase individual lessons for the frameworks your customers need most.
17 practices, FAR 52.204-21, SPRS scoring, self-assessment methodology.
110 practices, NIST SP 800-171, C3PAO prep, CUI scoping, SSP development.
All six core functions including Govern, profile development, gap analysis.
93 Annex A controls, ISMS clause structure, Statement of Applicability.
18 Controls, 153 Safeguards, Implementation Groups 1–3, tool-stack alignment.
Trust Services Criteria, evidence sourcing, sampling standards, report interpretation.
Required and addressable safeguards, ePHI detection, risk analysis, BAAs, breach notification.
Why Digital Hands
Digital Hands is a cybersecurity and risk-advisory firm specializing in managed security, Unified Security Posture Management, and comprehensive risk management services. We built the CMCP program after seeing what happens when MSPs deliver compliance without a structured foundation — inconsistent delivery, unhappy clients, and missed revenue.
CMCP is not a generic GRC course. It is purpose-built for MSPs in the Kaseya ecosystem, aligned to the Kaseya Compliance Manager platform, and designed by practitioners who deliver these services every day.
The CMCP program is available exclusively through Digital Hands in partnership with Kaseya.