Building a recurring cyber governance offer
How to move from one-off audits to a cyber governance subscription: scope, deliverables, pricing, and industrialising the service so the margin holds.
Most IT service providers already sell security. Few sell governance. The difference is not a matter of wording: it separates a one-off engagement, renegotiated every single time, from monthly revenue backed by an obligation the client cannot postpone.
This article describes how to structure that offer — scope, deliverables, price, industrialisation.
Why does the one-off audit hit a ceiling?#
The audit sold by the unit has four structural flaws.
It is renegotiated every time. Every engagement starts again from a full commercial justification.
It is seasonal. It comes after an incident, a customer request or an insurance deadline. In between, nothing.
It does not accumulate. The same client's second audit largely redoes the first, for want of any state kept between the two.
It does not build company value. Project revenue is valued poorly; contracted recurring revenue is valued well. For an MSP owner considering a sale in the medium term, that gap is decisive.
Governance fixes all four: it is a state to maintain, so it is a subscription.
What does a recurring cyber governance offer contain?#
A credible offer holds four deliverables, each attached to a cadence.
1. The initial diagnostic and its repeat. The way in. A single framework — ANSSI's 42 cyber hygiene measures, from France's national cybersecurity agency, do the job well — a score, a list of gaps, a costing.
Repeated every year, it becomes the demonstration of progress that justifies renewing the contract.
2. The tracked action plan. Every gap becomes an action with an owner, a deadline and a cost. The plan is reviewed at each periodic meeting. That is what separates a report from actual steering.
3. The evidence register. The most underrated deliverable, and the most defensible commercially. Every measure applied comes with dated evidence: a configuration screenshot, a restore-test record, a training certificate, a signed policy.
It is that register which lets you answer a customer questionnaire in 48 hours instead of three weeks — and it is exactly what will be asked for by a client subject to the NIS2 supply chain security obligation.
4. The management report. One to four times a year depending on the tier: score, trend, incidents, actions completed, budget committed, recommendations. One page, written for the company's leadership.
That document is what makes the service visible. An invisible governance service is a service cancelled at the first budget review.
How many tiers should the offer have, and what goes in each?#
Three tiers are enough. Beyond that, the client compares line items instead of choosing an outcome.
| Essential | Steering | Compliance | |
|---|---|---|---|
| Diagnostic | annual | half-yearly | quarterly |
| Action plan | yes | monthly tracking | monthly tracking |
| Evidence register | — | yes | yes |
| Management report | annual | half-yearly | quarterly |
| Answering customer questionnaires | — | 2 / year | unlimited |
| ISO 27001 / NIS2 preparation | — | — | yes |
| User awareness training | — | annual | continuous |
The top tier is not meant to be the one that sells most: it exists to make the middle tier look reasonable. It is the most reliable anchoring mechanism there is in B2B selling.
How do you price a governance subscription?#
The price rests on four decisions.
Index it on the number of users. The number of users is the variable the client understands, does not dispute, and which tracks their growth. Billing by number of servers or sites leads to sterile technical arguments.
Position against the cost avoided, not the hourly rate. A governance subscription for a forty-person business compares to a cyber insurance deductible, to three days of business interruption, or to a regulatory penalty — not to a day rate.
Bill the initial diagnostic separately. Two reasons: it represents a real non-recurring workload, and a client who has paid for their diagnostic commits far more to the action plan that follows. The free diagnostic is invariably the least acted on.
Do not include remediation. Governance steers; it does not execute. Including remediation in the subscription makes the margin unpredictable and turns a steering service into an unlimited support package. The actions in the plan are billed as they come — and that is the main source of additional revenue the offer generates.
How do you industrialise the offer so the margin survives?#
A governance offer becomes profitable the moment the twentieth client does not cost twenty times the first. Four conditions.
One framework for the whole portfolio. A framework per client rules out any comparison and any reuse.
Reports that are generated, not written. If producing a management report takes half a day, the offer will never scale. That is the first task to automate.
A portfolio view. Being able to see on one screen which clients have a falling score, a late action or expired evidence. Without that view, follow-up degrades from about ten clients onwards.
Evidence collected automatically wherever possible. Part of the security posture — MFA enabled, endpoints patched, backups run — can be read straight from the tools already in place. What is collected automatically is never asked of the client again.
What do you answer to the most common objections?#
"My client won't pay for reporting." They are not paying for reporting, they are paying not to have to answer a customer questionnaire, an insurer or an authority themselves. The reporting is the medium, not the product.
"I already do all of that, for free." That is the most frequent case — and the most expensive. The work exists, it is simply neither tracked nor billed. Formalising it does not change the workload, it changes the invoice.
"I don't have compliance expertise." The 42 cyber hygiene measures call for no legal expertise. For ISO 27001 and NIS2, the competence is acquired on the first few engagements — and the final audit is subcontracted.
Read next
Answering cyber insurance questionnaires
Why cyber insurance questionnaires have got tougher, what they always check, and how an MSP turns answering them into billable work.
Proving compliance over time, not just once
A screenshot proves nothing to an auditor, who wants evidence that a control held all year. What auditors mean by evidence, and how to build it.
ReCyF, NIS2, ISO 27001: the mapping table
ReCyF's 20 objectives mapped to NIS2 Article 21 and to ISO/IEC 27001:2022 controls — and what such a mapping does and does not tell you.