CERTIFIED MANAGED COMPLIANCE PROVIDER

What you need to know before you enroll

CMCP is a GRC certification for practitioners delivering compliance work inside managed service providers. There are three routes to it — pick the one that describes you.

 

New to GRC

Take the full eight-module course, then the certification exam.

 

Already experienced

Sit the standalone exam. No course, no prerequisites.

 

Already certified

Take the annual recertification exam to stay current.

Is this for you

CMCP is built for people delivering governance, risk and compliance services to clients — not for compliance theory in the abstract.

What is the CMCP certification?

The Certified Managed Compliance Provider credential is issued by Digital Hands and delivered in partnership with Kaseya. It attests that you have passed the CMCP certification assessment — an evaluation of applied competence in governance, risk and compliance practice, scored against a fixed standard.

Certification is valid for one year and is maintained by annual reassessment.

Who is it designed for?

Practitioners at managed service providers who deliver compliance work for clients — scoping engagements, collecting and packaging evidence, managing a POA&M, and preparing clients for audit.

Registration is open beyond MSP staff, and there's nothing you need to buy or license first — the course can be completed without any platform access.

I'm new to GRC, is the full course the right starting point?

 

Yes. The eight-module curriculum is built for entry-level professionals moving into the GRC space, and what it teaches — scoping, control mapping, evidence, POA&M governance, audit readiness — transfers to whatever platform you work in.

If you have access to a Kaseya Compliance Manager instance you can work alongside it from Module 3 onward, which adds knowing where things live in a real tool to knowing the concepts. It isn't required, and the Kaseya knowledge base covers the same ground if you don't have an instance.

I've done this work for years, do I have to take the course?

 

No. You can sit the standalone certification exam directly, at any time, with no prerequisites, no prior credential, and no Compliance Manager license required.

That route exists for practitioners who want independent validation of capability they already have, rather than instruction. It is the same 70-item assessment at the same 75% standard, and it produces the same certification. The difference is what you do beforehand, no what you're held to. 

We don't run Kaseya products, can I still take this?

 

What you'd miss is the hands-on dimension. Module 3 focuses on Kaseya Compliance Manager, and covers integrations across VSA, IT Glue, PSA, Microsoft 365 and AWS. Without an instance, you cover the material as discussed rather than tangibly following along with it — you're still eligible for the course and its content, but you will lose the practical enrichment that turns discussion into hands-on familiarity for execution.

Contact Kaseya to learn more about the Kaseya ecosystem and what's available in it.

Before you start

What to have in place before you begin, and what makes the platform modules land.

How does Kaseya Compliance Manager fit into the course?

 

Compliance Manager is where GRC delivery actually happens, so Module 3 focuses on it specifically and the modules after it draw on it — and working with an instance open alongside the course is much the best way to take that material in. Following along turns described procedures into screens you have actually opened and records you have actually read. The course is written so the material stands on its own if your instance isn't in place yet, and the Kaseya knowledge base documents the same screens and workflows in the meantime. 

One detail worth knowing if Compliance Manager isn't part of your stack yet: it's a separate product from VSA, IT Glue and the rest of the suite. It's licensed through your own organization's channel. Contact your Kaseya representative for pricing and acquisition details. 

What Compliance Manager settings work best for the course?

 

View access to one client record is plenty — enough to see that client's framework configuration, integration settings, role assignments, scan results and POA&M.

The exercises are look-and-locate: nothing is created, changed or run. You don't need elevated rights, and your organization chooses which client record to use, so it's an easy thing for an owner to approve.

What do I need to run the course?

A desktop or laptop computer. The course isn't designed for phones or tablets — several modules use detailed tables and diagrams that need a full-size screen.

Pop-ups allowed for the course site — lessons open in a new window.

How do I log in? Can we use our company sign-on?

You log in directly at the CMCP site. Single sign-on and external identity providers aren't supported at this time.

Multi-factor authentication is enforced for every user, so you'll set that up on first login.

Where your organization purchased seats for a team, your login details come from your company's designated Learner/Admin. If you bought your own seat, you set your own credentials at registration.

Is there a preview or sample I can look at?

Not at this time. If you have questions before purchasing, please email grcteam@digitalhands.com.

 

What it involves

Self-paced, designed to fit around client work, and better still if you can follow along in your own Compliance Manager instance.

How is the course structured?

 

CMCP is a learning path you enroll in once. It contains several modules and a certification exam that sits inside the same path

 

How much time should I budget?

 

Around 75 hours for the full required path and is self-paced to accommodate your work schedule.

Deep-dive framework courses are supplemental and add their own time on top: most take two to three hours, the longest four to five.

Is it self-paced? Do I have to take the modules in order?

 

Self-paced, and modules are completed in order — each builds on the one before it, so you work through them sequentially rather than picking and choosing.

Ask the Expert sessions are available as part of the CMCP learning path.

What are the exercises like?

 

Scenario-based and multiple choice. You work through realistic client situations — a discovery call, a scoping dispute, an auditor's request — and decide what a practitioner should do.

From Module 3 onward, the exercises are written so you can follow along in a live Compliance Manager instance if you have one — locating framework configuration, integration settings, scan results and a POA&M in the real tool rather than only reading about them. Without an instance, the Kaseya knowledge base documents the same screens and workflows, and you work through the material that way.

Each lesson closes with a knowledge check.

What it costs

All prices are in USD and exclude applicable tax, which is added at checkout.

What are the prices?

What You're Buying Price
Course and first user license — includes the certification exam USD 6,750
Each additional seat for a colleague USD 1,200
Standalone certification exam — no course USD 1,500
Annual recertification exam USD 1,000
Deep-dive framework course — unlimited copies for your team USD 750

Kaseya Compliance Manager isn't included in any of these. It's licensed separately — contact your Kaseya representative for pricing and acquisition details.

 

Is there a discount for putting a team through?

There's no separate volume discount at this time — the structure does the work instead. The first purchase carries the course; every seat after that is USD 1,200.

Seats Total Per Person
1 USD 6,750 USD 6,750
5 USD 11,550 USD 2,310
10 USD 17,550 USD 1,755
20 USD 29,550 USD 1,478

Buying one seat now and more later costs the same as buying them all at once, so there's nothing lost by starting small.

 

How do I pay? Can we be invoiced?

Credit card, processed through Stripe. We aren't able to accept purchase orders or issue invoices for payment at this time.

You'll receive a credit card receipt issued to the purchaser.

We aren't able to accept a VAT or business tax registration number at checkout at this time.

Can I get a refund?

No. All sales are final and we don't offer refunds or cancellations. Please check the system requirements and the twelve-month access period above before you buy.

 

If you're unsure how to stage a purchase around your team's onboarding, email grcteam@digitalhands.com before you buy. It's a much easier conversation beforehand.

How you certify

One certification, one standard, three routes to it.

What is the exam like?

70 questions, drawn two per lesson so every part of the curriculum is covered in every sitting.
 
Pass mark 75%.
Open book and un-proctored.
Unlimited attempts, no waiting period, within your access period.
 
Questions are drawn from a continually updated bank, so the assessment tracks framework changes rather than freezing at the version it was written against.

 

Why is the exam open book?

Because that's how the work is done. Compliance delivery is reference-based — practitioners consult the framework, the control catalog and their own documentation constantly — so an exam that permits the same measures the capability that matters.
 
CMCP attests that you can locate and correctly apply the right guidance. It does not attest to unaided recall, and it is not a proctored examination.

What if I don't pass first try?

Take it again. There's no limit on attempts and no waiting period between them — retake as many times as you need to learn the material properly. That's the intent.

Attempts are unlimited within your twelve-month access period.

Is the platform itself tested?

No. Kaseya Compliance Manager is not part of the assessment — platform configuration is Kaseya's domain and varies from one MSP to another, so testing it would examine your environment rather than your competence.

The exam covers governance, risk and compliance judgment, because that's what transfers across every framework, every client and every toolset.

After you certify

The credential is yours to keep and to advertise, and it stays current through annual reassessment.

What do I receive?

Two things:
 
A CMCP diploma naming both you and your employer, with the date you earned it. The award is to both of you.
 
The Kaseya Certified Managed Compliance Provider badge — the orange shield mark. Both you and your firm can display it: your LinkedIn profile and email signature, and your company's website, proposals and capability statements.
 
If something on the diploma is wrong — a misspelling, or details that don't match your record — email grcteam@digitalhands.com and we'll issue a corrected one. If your circumstances change later, that's different: the organization shown is the one you earned it with at the time and it stays that way, in the same way a degree certificate names the institution rather than where you work now.
 

 

How long is it valid, and how do I stay current?

Certification is valid for one year from the date you complete the certification exam.

To stay current, take the annual recertification exam — USD 1,000, unlimited attempts, and no Compliance Manager access needed. We'll remind you about ten months after you certify.

There's no continuing-education requirement: the annual exam is how the credential stays current.

What happens if I let it lapse?

 

The credential lapses and has to be earned again. Once it has expired the recertification exam is no longer available to you, so re-earning it means sitting the standalone certification exam at USD 1,500 rather than the renewal exam at USD 1,000.

You don't have to retake the course.

If I change employers, does it come with me?

Yes — your certification stays with you if you move, and you don't need to keep Compliance Manager access to hold it, since the renewal exam doesn't require the platform.

Your diploma continues to name the employer you were with when you certified. That record doesn't change, in the same way a degree certificate names the institution rather than where you work now.

What can I tell clients about it?

How you present your certification is up to you. If it's useful, here's how to describe it accurately.

The award is to both you and your employer. So "our firm is a Certified Managed Compliance Provider" and "our team includes CMCP-certified practitioners" are both accurate. The diploma names both.
 
It's issued by Digital Hands and delivered in partnership with Kaseya. Both marks are associated with the program and you're welcome to display either — including the orange Kaseya badge you receive on certifying.
 
It isn't an accreditation, so "CMCP-accredited" isn't accurate in any form.
 
It doesn't qualify anyone to issue an audit opinion or certify a client's controls. That boundary is taught in the curriculum itself, and it's worth being clear about it with clients.

Where can I use the badge?

Anywhere you'd reasonably show a professional credential — LinkedIn, an email signature, a conference bio — and anywhere your firm presents its capabilities: website, proposals, capability statements, tender responses.

The award is to both the individual and the employer, so "our firm is a Certified Managed Compliance Provider" and "our team includes CMCP-certified practitioners" are both accurate.

Display it while the certification is current. It runs for a year from the date of certification, and the annual recertification exam keeps it live.

Practical matters

Access periods, and what happens if something interrupts you.

How long do I have access?

Twelve months from the date of purchase — counted from the purchase date shown against your order, not from when you first log in or start a module.

Note that certification and access run on separate clocks: your access period runs from purchase, and your certification runs for a year from the date you pass the exam. Pacing the course doesn't shorten your certification.
 

 

What if I don't finish within the twelve months?

Access ends and the learner record is cleared. To take the course again you purchase a new twelve-month access period, and the course begins again from the first module. There is no discounted continuation.

 

The window is designed to be comfortable — around 75 hours across a full year.

If you already passed the certification exam before your access expired, your credential is unaffected: it runs for a year from the date you certified, separately from course access.

Our Compliance Manager access lapsed part-way through. Am I stuck?

 

No, on both counts. Compliance Manager is a Kaseya product, licensed separately by your organization, and entirely separate from the learning platform where the course and your progress live — so a gap there doesn't touch your progress.

And it doesn't block you. Because the course can be completed without Compliance Manager, you can keep working through Module 3 and everything after it. What you lose while access is down is the ability to follow along in the tool, not the ability to continue.

Your course access period keeps running in the meantime, since the twelve months run from the date of purchase. Worth knowing if you were pacing the course around when your platform access returns — there's no need to wait.

I've logged in but there's no course to open

Your account exists but you haven't been enrolled yet. Where your organization bought the seats, enrollment is a separate step your company's Learner/Admin completes once a license is assigned to you — until then you can log in but won't see a course to click on.

Nothing is wrong with your account. Contact your Learner/Admin, who can enroll you.

I can't get in — forgotten password or lost my authenticator

Did someone at your company set up your account for you?

Yes — contact your organization's Learner/Admin. They can reset your password and your MFA device.
 
No, I bought my own seat — email grcteam@digitalhands.com and we'll help you back in.
 

Deep dives

Ten supplemental framework courses, for going deeper on the topics your clients are asking about.

What are the deep-dive courses?

Supplemental, voluntary courses for deeper engagement on a framework relevant to your business. Ten are available and more frameworks will be added:

CIS Controls v8.1
CMMC Level 1 · CMMC Level 2
HIPAA Security and Privacy Rules
ISO/IEC 27001:2022 — Information Security Management Systems
ISO/IEC 42001:2023 — AI Management System
NIST SP 800-53 Rev. 5
NIST AI 600-1 — AI Risk Management Framework: Generative AI Profile
NIST CSF 2.0
SOC 2 Type II
 
Most take two to three hours; the longest four to five. Each closes with a self-assessment that isn't scored — deep dives are enrichment and have no bearing on your certification or recertification.

What do they cost, and what do I get?

 USD 750 per framework, and copies for the rest of your team are free — so a five-person team works out at USD 150 a head.

On finishing you receive a certificate of completion naming the framework. It records completion of a supplemental course and is not a certification.

Access runs twelve months from purchase, and completion is recognized for one year from the date you finish. Recognition renews by working through the course again, which needs active access — so if your access period has ended, renewing means purchasing the course again.
 
 

Want to learn more?