Compliance
Tabletop Exercises for MSPs: How to Build and Sell Incident Response Testing as a Compliance Service in 2026
September 17, 2026 · 8 min read · Brett Coffin
TLDR: Every compliance framework your clients need — SOC 2, HIPAA, PCI DSS, NIST CSF 2.0, CMMC — explicitly requires testing the incident response plan, not just having one. Most MSPs have helped clients write IR plans. Almost none have productized the testing. A tabletop exercise generates the one deliverable no auditor will skip: a dated, signed after-action report proving the plan was executed. That report is billable, recurring, and impossible to produce without your involvement.
The global average cost of a data breach reached $4.99 million in 2026 — a 12% jump from the prior year — with US organizations averaging $11.5 million per incident, more than double the global figure ([IBM Cost of a Data Breach Report 2026](https://www.ibm.com/reports/data-breach)). The difference between organizations that recover quickly and those that suffer prolonged business disruption is rarely whether they had an incident response plan. It is whether that plan had ever been tested before the incident occurred.
IBM's 2025 Cost of a Data Breach research found that organizations with a regularly tested IR plan reduced breach costs by an average of $2.66 million and identified breaches 54 days faster than those without tested plans ([JumpCloud, citing IBM, 2025](https://jumpcloud.com/blog/incident-response-statistics)). Tested plans also produce documented evidence of a working response function — which regulators and insurance carriers explicitly look for when assessing penalty exposure and coverage eligibility.
Every major compliance framework now distinguishes between having an incident response plan and having tested one. That distinction is where the MSP service opportunity lives.
What Every Major Framework Requires
SOC 2 — CC7.5 and CC3.1
SOC 2 Trust Services Criteria CC7.5 requires that incident response procedures be executed and that the organization evaluates the effectiveness of its response. CC3.1 requires that risk assessments consider threats to achieving objectives — which auditors read as evidence that response capabilities have been validated, not just documented.
In practice, SOC 2 Type II auditors expect to see at least one tabletop exercise per year with a written record of the scenario, participants, findings, and resulting plan updates ([PreparedEx, 2024](https://preparedex.com/utilizing-tabletop-exercises-validate-soc-2-incident-response-plan-compliance-requirements/)). A client with a written IR plan but no exercise history will produce a SOC 2 finding. See the [SOC 2 compliance checklist for MSPs](/blog/soc-2-compliance-checklist-msp-2026) for the full evidence inventory auditors request.
HIPAA — § 164.308(a)(7)(ii)(D)
The HIPAA Security Rule explicitly requires covered entities and business associates to implement procedures for periodic testing and revision of their contingency plans (45 CFR § 164.308(a)(7)(ii)(D)). HHS's December 2024 proposed Security Rule updates specifically named tabletop exercises as an acceptable testing method and proposed moving testing from an addressable to a required implementation specification.
For MSPs serving healthcare clients — clinics, dental practices, behavioral health providers, telehealth platforms — this is direct evidence of required testing. An OCR desk audit will request contingency plan test records. Without them, the client fails the audit and the MSP loses a compliant client relationship.
NIST CSF 2.0 — RS.AN and RS.MA
NIST CSF 2.0's Respond function includes RS.AN (Incident Analysis) and RS.MA (Incident Management) — both of which call for exercise and training programs to validate that response activities can actually be executed under simulated conditions ([NIST, 2024](https://www.nist.gov/cyberframework)). NIST SP 800-84 provides the federal standard for IT contingency planning exercises and explicitly recommends tabletop exercises as the minimum exercise type for all organizations.
For MSPs using NIST CSF as a baseline across their client portfolio — which is increasingly common given its industry-agnostic coverage — annual tabletop exercises are the primary mechanism for demonstrating RS.AN and RS.MA maturity.
PCI DSS v4.0 — Requirement 12.10.4
PCI DSS v4.0.1 Requirement 12.10.4 requires that personnel responsible for incident response be trained at least annually, and Requirement 12.10.6 requires that the incident response plan be reviewed and tested at least annually with updates made as needed. For any client that processes, stores, or transmits cardholder data — retail, restaurant, healthcare — this is a mandatory annual deliverable.
Cyber Insurance Carriers
In 2026, cyber insurance underwriters have moved beyond asking "do you have an incident response plan?" to "when did you last test it and what did you find?" Carriers including Chubb, Coalition, and Beazley now include IR plan testing in underwriting questionnaires, and some require documented exercise records as a condition of coverage renewal (cyber insurance compliance checklist for MSPs). An untested plan is increasingly a coverage gap, not just a compliance gap.
The Four Scenarios MSP Clients Face Most
A tabletop is only as useful as the scenario it tests. For a typical SMB client portfolio, four scenarios cover the highest-probability incidents and the widest range of compliance requirements:
1. Ransomware with business-critical system encryption. Tests detection, isolation, backup restoration, and business continuity decision-making. Satisfies HIPAA contingency testing, SOC 2 CC7.5, and PCI DSS 12.10. The most requested scenario by insurance carriers.
2. Business email compromise and wire fraud attempt. Tests phishing response, account containment, financial process controls, and law enforcement notification procedures. Common in SMBs; relevant to FTC Safeguards Rule clients (accountants, auto dealers).
3. Data exfiltration / insider threat. Tests logging and monitoring effectiveness, HR and legal escalation paths, and regulatory notification timelines (HIPAA breach notification, state breach laws). Directly tests the notification procedures every HIPAA-covered client must maintain.
4. Vendor/supply-chain compromise. Tests third-party risk response: how the client identifies affected systems, communicates with the vendor, notifies affected parties, and invokes backup service relationships. Relevant to SOC 2 CC9.2 and NIST CSF GV.SC (Cybersecurity Supply Chain Risk Management).
How to Structure the Exercise
A well-run tabletop takes two to three hours and produces an after-action report the same day. The structure:
Pre-exercise (one to two weeks before):
- Confirm participants: a tabletop requires executive sponsor, IT lead, department heads, and (for healthcare) compliance officer
- Select and customize the scenario — inject client-specific details (their backup vendor, their primary application, their notification obligations)
- Distribute the IR plan to participants and assign roles
Exercise (two to three hours):
- Facilitator introduces the scenario in injects — discrete events that unfold over simulated time
- Participants verbalize what they would do at each decision point; the facilitator records gaps, workarounds, and decisions
- No laptops or actual systems — the exercise tests the decision process, not execution speed
After-action report (same day):
- What worked: confirmed capabilities the plan accurately reflects
- What didn't: gaps between the written plan and how participants actually responded
- Action items: plan updates, training needs, tool gaps, notification procedure corrections with assigned owners and due dates
This report is the compliance artifact. Dated, signed by the executive sponsor, filed with audit evidence. A SOC 2 auditor, an OCR investigator, and a cyber insurance underwriter all accept it.
Packaging This as a Recurring MSP Service
The business model is straightforward: annual tabletop required by every framework, quarterly optional for high-compliance verticals (healthcare, defense contractors), one exercise generates one billable deliverable.
Service tiers:
- **Annual Tabletop:** Scenario design, facilitation, after-action report, plan update recommendations. Suitable for SOC 2, HIPAA, PCI DSS compliance evidence. Recommended pricing: $1,500–$3,500 per engagement depending on client size and scenario complexity.
- **Quarterly Program (add-on):** Four exercises per year with rotating scenarios, progress tracking against prior findings, compliance evidence package for each framework the client is assessed against.
- **Board/Executive Reporting (add-on):** Executive summary version of the after-action report formatted for board presentation or insurance carrier submission.
The recurring case: once a client has one exercise on record, missing the next one creates a compliance gap they cannot explain to their auditor. The service renews itself.
Running the Evidence Pipeline with Nuronus
The compliance value of a tabletop exercise goes up when it is connected to a client's live compliance posture. If an exercise reveals that the client's backup restoration process takes 48 hours when their HIPAA contingency plan specifies 24 — that gap needs to be reflected in their compliance assessment, their risk register, and their next QBR.
Nuronus maps each client's security controls — including incident response and contingency planning — against all 11 compliance frameworks simultaneously. When an exercise produces findings, you update the client's assessment in Nuronus and the gap appears across every framework it affects (HIPAA, SOC 2, NIST CSF, cyber insurance). The white-label compliance report for the client's next audit reflects the current state, not a snapshot from when the IR plan was written.
Start free for up to two clients — no credit card required. Build the tabletop program on your pilot clients, generate the after-action reports from your first two exercises, and use the compliance reporting to demonstrate value at QBR.
Getting Started This Quarter
Pick your two or three most compliance-sensitive clients — healthcare, financial services, or anyone with an active SOC 2 or cyber insurance requirement. Offer them a ransomware tabletop as a compliance deliverable, not an IT drill. Position it as the annual exercise their auditor requires. Schedule it before their next audit or insurance renewal.
The scenario design, facilitation, and after-action report are the service. You already have the compliance framework knowledge. The playbook and the evidence artifact are all that stands between a client with an IR plan and a client with a tested, compliant IR program.
Every compliance checklist your clients hand you has "test your incident response plan" on it. Most MSPs nod along. The ones building durable compliance practices are the ones who show up with a scenario, run the exercise, and hand the client a signed after-action report they can put in front of an auditor. That is the service. It is annual. It is billable. And it starts with the incident response plan your client already has.
Ready to Add Compliance Services to Your MSP?
Free forever for 2 clients. All features included. No credit card required.
Get Started Free
Brett Coffin
Founder, Nuronus
20+ years in IT infrastructure and security. Built Nuronus after watching MSPs leave compliance revenue on the table because the tooling made it impossible to deliver profitably.