Selling Compliance Without Fear Using vCIO Meetings
Listen to this article
Browser text-to-speech
Selling Compliance Without Fear: How MSPs Use vCIO Meetings to Grow MRR
By Carrie Richardson, Co-Founder, Fox & Crow Group January 9, 2026
Executive Summary
Many MSPs struggle with selling compliance to existing clients. The challenge is rarely the value of compliance itself. It is how and when compliance is introduced inside trusted client relationships.
The most effective way for MSPs to sell compliance is not through one time pitches or fear based messaging. It is through ongoing vCIO and account management conversations that focus on governance, growth, and operational maturity. When compliance is positioned in context, it becomes a natural extension of the advisory role MSPs already play.
This post explores how MSPs can use quarterly meetings to sell compliance and grow MRR without chasing net new logos. It also explains why this approach aligns with how trust based compliance programs are meant to be delivered.
For MSP leaders who want to see how this works in practice, we will be discussing it live in an upcoming fireside chat with Blacksmith InfoSec.
Register for the webinar Using Quarterly Meetings to Boost MRR
Questions This Post Answers
-
Is this webinar only about compliance for MSPs?
-
Do MSPs need to already offer compliance services to benefit from this webinar?
-
Who at an MSP should attend this webinar?
-
Will this webinar teach MSPs how to sell compliance without being pushy?
-
How do MSPs sell compliance to existing clients?
-
Why is selling compliance difficult for MSPs?
-
What is compliance as a service for MSPs?
-
How do vCIO meetings help MSPs grow MRR?
-
Is compliance better sold as a recurring service by MSPs?
The January 2026 Growth Problem for MSPs
January has a way of narrowing focus for MSPs. Planning conversations tend to revolve around pipeline targets, outbound activity, and the pressure to land net new logos quickly.
That instinct is understandable. Growth targets are real and competition is intense. Prospecting feels like the most obvious lever to pull.
What often gets overlooked is that many MSPs are sitting on meaningful expansion opportunities inside their existing client base. Those opportunities do not look like traditional sales motions. They live inside quarterly conversations, long term planning discussions, and governance reviews.
This is especially true when it comes to selling compliance. Many MSPs know compliance is important, but struggle to introduce it without disrupting trust or sounding alarmist. The result is hesitation, stalled conversations, or compliance being deferred indefinitely.
Why Selling Compliance Is Hard for MSPs
Selling compliance is difficult for MSPs because it is often framed as an interruption rather than a continuation of the relationship.
-
Compliance conversations frequently show up reactively.
-
A customer receives a vendor questionnaire.
-
An insurer tightens requirements.
-
A prospect asks about certifications.
Suddenly compliance feels urgent and uncomfortable.
When compliance is introduced this way, it is easy for it to feel transactional or fear driven. That creates resistance, especially when the MSP has already established itself as a trusted advisor rather than an enforcer.
The challenge is not the importance of compliance. Focusing on positioning leads to better sales outcomes.
Blacksmith Infosec has several resources for MSPs exploring how to position compliance to their existing and prospective customers.
Learn more about Compliance as a Service in the "Forging Trust" ebook sample from Blacksmith Infosec
Buy the "Forging Trust" book by Jared Crasner and Michael Zbarsky on Amazon
Why vCIO and Account Management Are the Right Sales Motion
Selling compliance works best for MSPs when it is part of an ongoing governance conversation, not a one time event.
vCIO and account management meetings create the conditions that make this possible. Quarterly discussions shift the focus away from tickets and tools and toward outcomes, risk, and readiness. They provide continuity and context. They establish a cadence where new topics can be introduced gradually and responsibly.
In this environment, selling compliance does not feel like a surprise. It feels like a logical next consideration based on changes in the business.
This is where Fox & Crow focuses its work with MSPs. Not on teaching compliance frameworks, but on helping MSPs structure conversations that naturally support cross selling and recurring revenue growth.
Join the fireside chat to hear real world examples of how MSPs structure these conversations
How Mature MSPs Sell Compliance in Quarterly Meetings
Mature MSPs rarely announce compliance as a new offering. Instead, compliance emerges from a series of connected conversations.
As MSP clients grow, their risk profile changes. As they take on new vendors, customers, or markets, expectations increase. As insurance, contracts, and partnerships become more formal, questions about controls and governance follow.
Quarterly meetings provide MSPs with a place to connect those dots. Rather than selling compliance directly, the MSP helps the client understand what has changed and what typically comes next at this stage of maturity.
Over time, selling compliance becomes less about closing a deal and more about stewardship.
Selling Compliance as a Service, Not a One Time Event
When compliance is positioned correctly, it naturally lends itself to a recurring model.
Selling compliance as a service for MSPs is not about packaging audits or checklists. It is about ongoing alignment between a client’s operations, risk tolerance, and business goals. That alignment cannot be achieved in a single project.
This approach avoids fear based selling and supports long term trust. It also creates predictable recurring revenue for MSPs who are already well positioned to deliver governance focused services alongside their existing offerings.
This philosophy aligns closely with how Blacksmith InfoSec approaches compliance programs in practice.
Register to hear how selling compliance as a service fits into a quarterly meeting strategy
Growing MRR Without New Logos
Cross selling to existing clients is consistently more efficient for MSPs than acquiring new ones. Trust already exists. The MSP already understands the environment. Billing relationships are established.
Selling compliance through vCIO conversations strengthens that relationship rather than straining it. It deepens account engagement, increases stickiness, and aligns revenue growth with client success.
For MSPs planning their 2026 growth strategy, this approach reduces reliance on constant prospecting and shifts focus toward maturing existing accounts.
Join the Fireside Chat on Selling Compliance Through Quarterly Meetings

Fox & Crow Group Founder Ian Richardson will join Jared Casner and Michael Zbarsky, founders of Blacksmith InfoSec, for a fireside chat on how MSPs can plan and execute cross sell campaigns using quarterly vCIO and vCISO meetings.
This conversation will focus on how selling compliance actually works inside real MSP client relationships, and how to do it without fear based tactics or one time pushes.
Using Quarterly Meetings to Boost MRR
January 21, 2026 1:00 PM ET Hosted by: Blacksmith InfoSec
Want to Learn More About Effective Account Management for MSPs?
If you want to explore how to strengthen account management, improve vCIO conversations, and grow MRR without relying on constant prospecting, you can schedule a call with Ian Richardson, Co Founder of Fox & Crow Group.
Schedule a call with Ian Richardson
Frequently Asked Questions
Is this webinar only about compliance for MSPs?
No. This webinar is designed for MSPs who want to grow recurring revenue through better account management and quarterly meetings. Compliance is discussed as one example of how MSPs can cross sell additional services in a trust based way.
Do MSPs need to already offer compliance services to benefit from this webinar?
No. MSPs do not need to currently offer compliance services to benefit. The webinar focuses on how MSPs can position and sell services through vCIO and vCISO conversations, regardless of whether compliance is already part of their portfolio.
Who at an MSP should attend this webinar?
This webinar is best suited for MSP owners, vCIOs, account managers, and sales leaders at MSPs who are responsible for account growth and recurring revenue.
Will this webinar teach MSPs how to sell compliance without being pushy?
Yes. This webinar is specifically designed to help MSPs understand how to sell compliance and other services without fear based or high pressure tactics.
People Also Ask
How do MSPs sell compliance to existing clients?
MSPs sell compliance most effectively when it is introduced through ongoing vCIO or account management conversations. By tying compliance to governance, risk, and business growth, MSPs can position it as a natural next step rather than a disruptive sales pitch.
Why is selling compliance difficult for MSPs?
Selling compliance is difficult for MSPs when it is positioned as a one time requirement or introduced reactively. MSPs see better results when compliance is framed as part of long term operational maturity.
What is compliance as a service for MSPs?
Compliance as a service for MSPs refers to delivering compliance support as an ongoing managed offering rather than a single project. This model aligns with how MSPs already provide recurring services.
How do vCIO meetings help MSPs grow MRR?
vCIO meetings help MSPs grow MRR by creating regular opportunities to identify new needs, align services with business outcomes, and introduce additional offerings in context.
Is compliance better sold as a recurring service by MSPs?
Yes. Compliance is better sold as a recurring service by MSPs because it requires ongoing alignment and oversight as a client’s business evolves.
