CERTIFIED MANAGED COMPLIANCE PROVIDER
The Certified Managed Compliance Provider credential is issued by Digital Hands and delivered in partnership with Kaseya. It attests that you have passed the CMCP certification assessment — an evaluation of applied competence in governance, risk and compliance practice, scored against a fixed standard.
Certification is valid for one year and is maintained by annual reassessment.
Practitioners at managed service providers who deliver compliance work for clients — scoping engagements, collecting and packaging evidence, managing a POA&M, and preparing clients for audit.
Registration is open beyond MSP staff, and there's nothing you need to buy or license first — the course can be completed without any platform access.
Yes. The eight-module curriculum is built for entry-level professionals moving into the GRC space, and what it teaches — scoping, control mapping, evidence, POA&M governance, audit readiness — transfers to whatever platform you work in.
If you have access to a Kaseya Compliance Manager instance you can work alongside it from Module 3 onward, which adds knowing where things live in a real tool to knowing the concepts. It isn't required, and the Kaseya knowledge base covers the same ground if you don't have an instance.
No. You can sit the standalone certification exam directly, at any time, with no prerequisites, no prior credential, and no Compliance Manager license required.
That route exists for practitioners who want independent validation of capability they already have, rather than instruction. It is the same 70-item assessment at the same 75% standard, and it produces the same certification. The difference is what you do beforehand, no what you're held to.
What you'd miss is the hands-on dimension. Module 3 focuses on Kaseya Compliance Manager, and covers integrations across VSA, IT Glue, PSA, Microsoft 365 and AWS. Without an instance, you cover the material as discussed rather than tangibly following along with it — you're still eligible for the course and its content, but you will lose the practical enrichment that turns discussion into hands-on familiarity for execution.
Contact Kaseya to learn more about the Kaseya ecosystem and what's available in it.
Compliance Manager is where GRC delivery actually happens, so Module 3 focuses on it specifically and the modules after it draw on it — and working with an instance open alongside the course is much the best way to take that material in. Following along turns described procedures into screens you have actually opened and records you have actually read. The course is written so the material stands on its own if your instance isn't in place yet, and the Kaseya knowledge base documents the same screens and workflows in the meantime.
One detail worth knowing if Compliance Manager isn't part of your stack yet: it's a separate product from VSA, IT Glue and the rest of the suite. It's licensed through your own organization's channel. Contact your Kaseya representative for pricing and acquisition details.
View access to one client record is plenty — enough to see that client's framework configuration, integration settings, role assignments, scan results and POA&M.
The exercises are look-and-locate: nothing is created, changed or run. You don't need elevated rights, and your organization chooses which client record to use, so it's an easy thing for an owner to approve.
A desktop or laptop computer. The course isn't designed for phones or tablets — several modules use detailed tables and diagrams that need a full-size screen.
Pop-ups allowed for the course site — lessons open in a new window.
You log in directly at the CMCP site. Single sign-on and external identity providers aren't supported at this time.
Multi-factor authentication is enforced for every user, so you'll set that up on first login.
Where your organization purchased seats for a team, your login details come from your company's designated Learner/Admin. If you bought your own seat, you set your own credentials at registration.
Not at this time. If you have questions before purchasing, please email grcteam@digitalhands.com.
CMCP is a learning path you enroll in once. It contains several modules and a certification exam that sits inside the same path
Around 75 hours for the full required path and is self-paced to accommodate your work schedule.
Deep-dive framework courses are supplemental and add their own time on top: most take two to three hours, the longest four to five.
Self-paced, and modules are completed in order — each builds on the one before it, so you work through them sequentially rather than picking and choosing.
Ask the Expert sessions are available as part of the CMCP learning path.
Scenario-based and multiple choice. You work through realistic client situations — a discovery call, a scoping dispute, an auditor's request — and decide what a practitioner should do.
From Module 3 onward, the exercises are written so you can follow along in a live Compliance Manager instance if you have one — locating framework configuration, integration settings, scan results and a POA&M in the real tool rather than only reading about them. Without an instance, the Kaseya knowledge base documents the same screens and workflows, and you work through the material that way.
Each lesson closes with a knowledge check.
Kaseya Compliance Manager isn't included in any of these. It's licensed separately — contact your Kaseya representative for pricing and acquisition details.
There's no separate volume discount at this time — the structure does the work instead. The first purchase carries the course; every seat after that is USD 1,200.
Buying one seat now and more later costs the same as buying them all at once, so there's nothing lost by starting small.
No. All sales are final and we don't offer refunds or cancellations. Please check the system requirements and the twelve-month access period above before you buy.
If you're unsure how to stage a purchase around your team's onboarding, email grcteam@digitalhands.com before you buy. It's a much easier conversation beforehand.
The credential lapses and has to be earned again. Once it has expired the recertification exam is no longer available to you, so re-earning it means sitting the standalone certification exam at USD 1,500 rather than the renewal exam at USD 1,000.
You don't have to retake the course.
Access periods, and what happens if something interrupts you.
Access ends and the learner record is cleared. To take the course again you purchase a new twelve-month access period, and the course begins again from the first module. There is no discounted continuation.
The window is designed to be comfortable — around 75 hours across a full year.
If you already passed the certification exam before your access expired, your credential is unaffected: it runs for a year from the date you certified, separately from course access.
No, on both counts. Compliance Manager is a Kaseya product, licensed separately by your organization, and entirely separate from the learning platform where the course and your progress live — so a gap there doesn't touch your progress.
And it doesn't block you. Because the course can be completed without Compliance Manager, you can keep working through Module 3 and everything after it. What you lose while access is down is the ability to follow along in the tool, not the ability to continue.
Your course access period keeps running in the meantime, since the twelve months run from the date of purchase. Worth knowing if you were pacing the course around when your platform access returns — there's no need to wait.