What MSPs Are Actually Selling
The current wave, and the compliance instrument that generates more pipeline than any campaign.
The five pillars
Most mid‑market MSPs organise their catalogue into roughly the same five categories. Knowing them lets you read any MSP's website — or answer "where are you strongest?" in an interview — in the vocabulary they already use.
| Pillar | Typically covers |
|---|---|
| Cybersecurity | Endpoint and detection, email security, identity protection, awareness training, audit and uplift work |
| Network & communications | LAN/WAN, SD‑WAN, wireless, connectivity, firewalls |
| Cloud & infrastructure | Public cloud, private/hosted infrastructure, virtualisation, backup and DR, data centre |
| Microsoft modern workplace & 365 | Identity, device management, collaboration, migration and adoption |
| UC & video | Voice platforms, contact centre, meeting rooms and video conferencing |
The current wave
Time‑stamped, because this section will date faster than the rest of the manual — which is the point of noticing it:
- Virtualisation migrations. A large volume of small and mid‑size customers moving off VMware to Hyper‑V, driven by licensing and cost changes rather than by any technical dissatisfaction. Licensing upheaval at a major vendor reliably becomes an MSP project pipeline.
- The Microsoft modern‑workplace stack. Intune, Entra, hybrid identity, device management, SharePoint. Rarely one project — usually a sequence.
- Security uplift, almost always triggered by a framework or an insurer rather than by an incident.
- AI, as a conversation. The easy first transaction is Copilot licences. The substantive conversation is what the tool actually gives them and what controls sit around it — data governance, what leaves the tenancy, what the staff are already pasting into a chatbot.
- Data sovereignty. Customers increasingly require data to stay in‑country, which shapes which platforms an MSP can even propose.
Compliance as the sales motion
The cleanest pipeline instrument in managed services is a framework audit. In Australia that's the Essential Eight; in the UK, Cyber Essentials; in the US, NIST or CMMC depending on sector. The mechanic is the same everywhere and it's worth understanding properly, because it's the rare piece of security selling that isn't fear‑based:
- The customer agrees to an audit against a published, independent standard
- You produce a maturity scorecard — met, partially met, not met, control by control
- Every "not met" line is a discrete, scopeable, priceable piece of work
- The gaps are the customer's own, measured against a standard you didn't write
You are not manufacturing urgency; you're measuring against something a government agency published. That's why it converts, and it's why an MSP with a credible audit offering has a pipeline problem that solves itself. If you're new to a practice, learning to run and read the local framework audit is the fastest way to become immediately useful.