m365expertise MICROSOFT SECURITY EXPERTISE
Home · Blog · MSP
MSP

Building a recurring audit offer rather than a one-off audit

m365expertise·14 July 2026·8 min

A one-off audit is a good sale and a bad business. The same work, structured as a sequence with a follow-up audit and a quarterly committee, turns a fee into a subscription — and produces better security outcomes, which is why clients accept it.

Why the one-off audit disappoints everyone

The pattern is familiar. You deliver a hundred findings, the client is impressed, three months later nothing has changed and neither party wants to mention it. The audit was accurate and useless, for a structural reason: a photograph does not fix anything, and nobody was accountable for the interval between two photographs.

The recurring model exists because remediation, not measurement, is where the value is — and remediation takes quarters, not days.

The sequence

Framing — half a day

Create the client record, agree the perimeter in writing, and choose the baseline from a normative template: CIS for a technical debrief, MCSB for a client already aligned with Defender for Cloud, NIS2 or DORA when the stake is regulatory. Then request the access — and this is the critical path, so start it here rather than the week before.

Initial audit — one day

Run it, pin it as the reference run, attach a context note. Export the framework report as HTML and the same audit as JSON, which gives you time-stamped evidence that costs nothing to keep.

Debrief — two hours, and the order matters

Open with the picture — the attack path graph on Active Directory. Then the maturity level, which is a sentence rather than a number. The percentage comes third, or not at all. Leave the executive report as a PDF and the remediation plan as a spreadsheet.

Remediation — the client's quarter

They fix, in the order the maturity model gives. You stay available for arbitration rather than doing the work — the moment you take the remediation, you have sold a project, not a subscription, and the next audit becomes an audit of your own work.

Follow-up audit — half a day

Same baseline, same perimeter. The value is in the drift comparison: the resolved findings prove the quarter's work object by object, and the new findings show what appeared meanwhile. That second list is what justifies the next quarter without you having to argue for it.

Quarterly committee — one hour

Score, trend, what regressed before what improved, the five priorities. Then the cycle repeats.

What makes it profitable

LeverEffect
The audit itself is automatedThe billable time is the debrief and the arbitration, not the data collection. That is the only reason the economics work.
The baseline is reusableFraming is paid once per client, then amortised over every subsequent run.
One record per clientHistory, connector and report branding are separated per client, so a portfolio does not become a spreadsheet problem.
Reports carry your brandThe client sees your firm, not a tool vendor. That is what makes it an offer rather than a resale.
Two perimetersThe same client can be audited on the tenant and the directory — two engagements from one framing conversation.

How to price it without guessing

The two variables that actually move are the number of perimeters and the number of committees per year. Everything else — number of controls, number of resources — costs you almost nothing extra, because the run is automated. Which means the honest structure is a framing fee, then a recurring fee per perimeter per quarter, rather than a day rate that would punish you for being fast.

The trap to avoid: pricing per finding, or per remediated item. It aligns your revenue against the client's improvement, and clients notice. Price the cadence, not the damage.

What to promise, and what not to

Promise a measured posture, a documented scope, a prioritised plan and dated evidence of progress. Do not promise compliance — no audit grants NIS2, ISO 27001 or SOC 2 status, and a client who heard otherwise will be unhappy at exactly the wrong moment. Do not promise continuous monitoring either: an audit is a photograph taken deliberately, and saying so plainly is what makes the quarterly cadence make sense in the first place.

All articles
23 articles on Microsoft security auditing.
Back to the blog →