Most MSPs Sell Security Awareness Training Wrong. Here’s How to Actually Make Money on It.
Most MSPs sell security awareness training wrong. The playbook for positioning it as a real service line, capturing renewal revenue, and protecting margin.

A playbook for MSP owners who want training to be a real service line, not a margin-killing afterthought. Every MSP says they sell security. Most of them don’t actually sell security awareness training.
According to Barracuda’s 2024 MSP report, only 38% of managed service providers include security awareness training in their service stack. That number is going up, but slowly. Meanwhile, cybersecurity is the fastest-growing segment of MSP services, expanding at 18% annually through 2026. The customers are buying. They’re asking for it on cyber insurance applications. They’re asking for it during compliance audits. They’re asking for it after their first phishing incident. The MSPs that don’t have an answer are losing those conversations to the ones that do.
Here’s the uncomfortable part. Plenty of MSPs technically offer training, but the way they offer it actively hurts their business. Reselling a big-name platform at a thin markup makes you a commodity. Handing the customer a login and walking away guarantees the customer never associates the value with you. Bundling it into the security stack at no incremental cost means you’re absorbing a real expense for free. None of these is what “offering training” is supposed to look like.
This post is the playbook. How to position it, how to bundle it (or not), how to capture renewal revenue, how to handle the objections, and how to make sure the customer thinks of you, not the training vendor, when they think about who keeps their team safe.
Diagnosis: why most MSPs do this wrong
Three patterns account for almost all of the failed approaches.
Pattern one: The thin reseller. The MSP signs a partner agreement with a big-name training platform, gets a 10 to 15% reseller margin, and resells at retail or near it. The customer sees a third-party login screen with the vendor’s logo. The MSP never touches the implementation. When the customer renews, half the time they renew direct with the vendor and the MSP loses the line item entirely. There’s no defensible margin, no relationship lock-in, and no story to tell. The MSP is a billing intermediary.
Pattern two: The included-for-free play. The MSP folds training into the security stack at no incremental charge, hoping it adds perceived value to the bundle. It doesn’t. The customer doesn’t see the training as separate value because it’s not separately priced. The MSP eats the wholesale cost on every seat. At scale, this is a meaningful margin hit on a service line that should be one of your highest-margin offerings. “Free” never actually means free.
Pattern three: The buy-it-once-and-forget-it. The MSP sells the customer a one-time training rollout, runs the team through a single course, and then the engagement dies. There’s no recurring revenue, no recertification trigger, no reason to come back. Training becomes a project sale instead of a managed service. Worst of all, the customer’s team doesn’t actually become more secure, because one-time training doesn’t change behavior. Eighteen months later they get phished and the customer asks why you didn’t catch it.
All three of these patterns share the same root cause. Training is being treated as an add-on to sell, not as a managed service to deliver. The MSPs winning at this have flipped that.
Prescription: how to actually run training as a service line The model that works has five specific characteristics. Get these right and training becomes one of the stickiest, highest-margin lines in your stack.
Position it as a managed service, not a software resale. The customer isn’t buying access to a training platform. They’re buying outcomes: a trained team, audit-ready documentation, certified completion, and a partner who runs the program for them. Same way they don’t buy a firewall, they buy managed network security. The pitch isn’t “we’ll give you a login,” it’s “we’ll make sure your people are trained, certified, and current every quarter, and you’ll have the records to prove it.”
White-label everything the customer sees. Your brand on the platform. Your colors. Your subdomain. The customer’s team logs into something that looks like it was built by you. When the CFO asks the office manager who handles security awareness training, the answer should be your company’s name, not a training vendor they’ve never heard of. White-label is the difference between a service line and a billing intermediary. In leiu of your brand, you may want an option to brand the platform for the customer.
Price it as its own line item. Whether you bundle it or break it out, it has its own price tag the customer sees. Bundling at zero is the pattern that destroys margin. Bundling with a separately stated price (“your security stack includes training, valued at $X per user per year”) communicates value and protects you on renewal. Break it out as its own line item if your customers are price-sensitive and you want flexibility on the security stack price. Either works. “Included for free” doesn’t.
Make recertification automatic. The reason training has to be ongoing is the reason it’s a managed service in the first place. Annual training doesn’t change behavior. Quarterly does. Each course expires after a year, the system automatically re-issues it, and the customer’s team takes the new module without anyone having to think about it. Recertification is your renewal mechanism. It’s also your story for why customers can’t walk away at the 12-month mark — the program is designed to be continuous.
Capture the records. When the cyber insurance carrier asks for proof of training, you produce it in a click. When the auditor wants to verify a specific certificate, they hit a public verification page. When the customer’s board asks how the security awareness program is going, you send them a portfolio-level report. The records are the evidence trail that justifies the entire service line. They’re also what stops the customer from ever wondering whether they should run this in-house.
The sales conversation that actually closes
How the conversation goes when the customer asks about security awareness training.
When the customer surfaces the question. Most often, it surfaces during a cyber insurance renewal (“the carrier is asking if we have annual training and phishing simulations”), a compliance event (“we’re going through a SOC 2 audit” or “we just got pulled into a CMMC requirement from one of our DoD primes”), or right after an incident (“one of our people just clicked something they shouldn’t have”). All three are golden moments. The customer is asking, the urgency is real, and they’re not price-shopping yet. They want a problem solved.
The pitch. Two sentences, then stop talking. “We run that as a managed service for our customers. Quarterly training, automatic recertification, with audit-ready records you can hand to the carrier or the auditor.” That’s it. The customer’s next question tells you what they care about most. Pricing? You quote it. Implementation? You walk them through it. Don’t lead with features. Lead with outcomes and let them pull on the thread that matters to them.
Handling the most common objection. “We already use [legacy vendor] for training.” The wrong response is to attack the competitor. The right response is to ask one question: “How’s that going?” Almost every honest answer reveals a problem. Their team isn’t completing it. The reporting is hard to pull. They’re paying more than they thought. They can’t actually find their certificates when the auditor asks or there are none to begin with. The competitor sold them a platform but didn’t solve the underlying problem of running an actual program. That’s your opening. “We run it as a service. Same training requirement satisfied, but you don’t have to manage it.”
Pricing positioning. If the customer is comparing on a per-user basis, you’ll could look more expensive at retail than what they’d pay direct to a low-cost SaaS vendor. The frame is total cost of running a program. Your price includes the platform, the content, the recertification cadence, the reporting, and the management. Their existing per-user price is just the platform. If they’re running it themselves, the real cost includes someone’s internal time, the audit risk if records are incomplete, and the cost of an incident if training isn’t actually moving the needle. Reframe the comparison and you stop looking expensive.
The economics, briefly
ClickCerts gives MSPs a wholesale discount off published retail pricing. Specific numbers and tier breakdowns are in the partner program details. The headline is that the margin between wholesale and what you charge your customer is large enough to make this a real service line, not a thin reseller play.
A few model points worth understanding. Your own internal team trains free up to 50 employees. You set your end-customer pricing. ClickCerts doesn’t sign a contract with your customer; you do, you bill them, we bill you. Customer support comes from you first, with platform escalation to us. The 12-month commitment passes through to your customers, which gives you predictable revenue and protects the program from the train-and-dump pattern. If you want the actual wholesale numbers, email sales@clickcerts.com or schedule a 15-minute partner call.
Compliance angle worth flagging briefly: customers in regulated industries (defense contractors hitting CMMC, healthcare touching HIPAA, financial services under GLBA, anyone subject to NIST 800-171) need documented, recurring security awareness training as an explicit control requirement. If your customer base includes any of those, the training conversation gets easier because the customer doesn’t need convincing on whether they need it, only on who delivers it. Our deeper post on CMMC walks through the AT-family controls in detail if that’s your wedge.
What the right partner relationship looks like
Quick checklist for evaluating any training platform you’d resell, not just ours.
Your brand goes on the customer-facing platform, or theirs. If the customer’s team logs into something with the vendor’s name on it, you’re a billing intermediary, not a partner.
You sign the customer contract, not the vendor. If the vendor signs the customer, you’re a referral source. The day the customer grows enough to negotiate direct, you’re out.
Wholesale margin is enough to be a real service line. The training segment should be one of the better-margin lines in your stack, not the worst.
Content is current and refreshed continuously. Training written in 2022 is teaching customers’ employees to spot phishing techniques attackers have moved on from. AI-generated phishing in particular has rewritten the rules in the last 18 months. If the platform’s content hasn’t been refreshed in the last year, walk away.
Records are exportable and verifiable. Certificates with serial numbers, completion records by user, public verification pages for individual certificates. If you can’t hand a customer’s carrier or auditor a clean report on demand, the platform is going to fail you at the moment that matters.
Tier-1 support is yours, tier-2 is theirs. The customer should call you first. You should escalate to the platform vendor only for genuine platform issues. Any vendor whose support model bypasses the MSP is one that will eventually compete with you for the customer.
+++++
38% of MSPs offer security awareness training. The other 62% are leaving margin on the table while their customers ask the question and quietly look elsewhere. That number is going to change fast over the next two years as cyber insurance, compliance frameworks, and incident frequency all keep pushing customers to ask. The MSPs that build the service line right are going to keep those customers and capture the renewals. The ones that bolt it on as a thin resale are going to lose those conversations to the ones who didn’t.
Security training as a managed service is one of the cleanest, highest-margin, stickiest lines you can add to a stack. The work is in setting it up the right way, not the wrong way.
Email sales@clickcerts.com if you’re ready to talk wholesale terms or if you want a copy of our MSP partner sheet with full pricing. Related reading: “Your MSP Sells Security. Are You Actually Selling It?” for the broader case for adding training to your stack, and “CMMC and Security Awareness Training: What the Framework Actually Requires” for MSPs whose customers include defense contractors.



