COMMENTARY: DSPM tells you where controlled unclassified information is exposed. That's useful, but it's not the same as fixing it. The actual compliance work - restricting access, enforcing classification policies, building the audit trail a CMMC assessor wants to see - happens in the protection layer, after discovery. For MSPs and MSSPs working with defense contractors, that's the real opportunity. The clients who've run DSPM already know their problem. They need a partner to help them solve it.
I talk to channel partners every week who are sitting on a goldmine and do not realize it. They have clients in the Defense Industrial Base who have already deployed DSPM. The scans are done. The dashboards are live. Leadership has seen the gap reports. CUI is everywhere where it should not be—shared with the wrong people, stored in unapproved locations, transmitted through ungoverned channels.
And now those clients are stuck. They know exactly how bad the problem is. They have no idea how to fix it. Their DSPM vendor cannot help them, because DSPM was never designed to fix it.
That is your opening. And if you are not walking through it, someone else will.
The DSPM Ceiling Is Your Floor
DSPM has had a strong run in the CMMC market. These tools solve a real problem: defense contractors cannot protect CUI they have not found, and most of them are genuinely shocked by what DSPM discovers. Files shared with “Everyone.” Engineering drawings in personal cloud folders. Export-controlled data sitting in SaaS apps with zero encryption.
But here is what the DSPM sale does not include: the platform that protects that data. DSPM identifies overexposed CUI. It does not build the secure enclave where CUI should live. It does not enforce FIPS 140-3 encryption. It does not govern how CUI is shared with primes, subs, and government agencies. It does not generate the immutable audit trails that CMMC assessors demand.
Every DSPM deployment produces a gap report. That gap report is essentially a requirements document for the Kiteworks platform. The client has already paid a vendor to identify the problem. Now they need a partner to solve it. The question is whether that partner is you.
The Math That Should Get Your Attention
When you sell DSPM alone, you are selling a diagnostic. The engagement has a natural ceiling: deploy, scan, report, and possibly some ongoing monitoring. It is a solid deal, but it is a finite deal.
When you sell DSPM plus a protection platform, you are selling the diagnostic and the treatment. The deal size grows because you are now covering two layers of the CMMC stack instead of one. You are adding a secure CUI enclave, governed file sharing and email, managed file transfer, FIPS-validated encryption, and audit logging across every data exchange. That is not an incremental upsell. It is a fundamentally larger engagement.
But the deal size is only part of the story. The real revenue advantage is what happens after deployment. DSPM is largely a set-it-and-monitor-it tool. A
protection platform is an operational infrastructure that the client runs every day—every file shared with a subcontractor, every email containing CUI, every managed file transfer to a government agency flows through it. That creates ongoing managed services revenue for MSPs and MSSPs that a standalone DSPM deployment never will.
I have watched partners go from mid-five-figure DSPM engagements to six-figure combined deals by adding the protection layer. And the managed services tail on those deals extend for years, because CMMC compliance is not a one-time event. It is a continuous obligation.
The Conversation You Should Already Be Having
If your client has DSPM deployed, the conversation almost writes itself. They have the gap report. They can see that CUI is scattered across file shares, email, and cloud storage. They know they have compliance gaps around encryption, access controls, and audit logging. They just sat through a presentation that told them exactly how exposed they are.
Walk in and say: “Your DSPM told you what’s wrong. Let me show you how to fix it.”
If your client is evaluating DSPM, position yourself as the partner who delivers the complete solution from day one. Too many DIB organizations buy DSPM, thinking it will get them to certification, then realize six months later that discovery without enforcement leaves them short. You save them those six months and the painful realization. You also lock in a larger initial engagement instead of coming back later for the second half.
If your client has neither, you have the opportunity to architect the full CMMC compliance stack from scratch. That is the most valuable engagement of all, because you are not retrofitting—you are building it right the first time. Scope both layers together. Deploy in parallel or sequence based on the client’s readiness. Either way, you own the relationship across the entire compliance journey.
Why This Matters More for MSPs and MSSPs
Resellers capture the initial sale. MSPs and MSSPs capture the long game. And the long game on CMMC compliance is substantial.
DSPM requires periodic scans, monitoring, and policy updates. That is manageable recurring revenue. But a protection platform like Kiteworks is production infrastructure—it handles secure email, file sharing, managed file transfer, and API-based data exchanges for the client’s most sensitive workflows. Managing that environment, monitoring audit logs, responding to policy violations, maintaining encryption configurations, and ensuring continuous compliance readiness is a managed services engagement that renews year after year.
There is also the supply chain multiplier. Your client shares CUI with dozens of subcontractors. Every one of those subcontractors has the same CMMC compliance obligations. Every one of them needs the same discovery-plus-protection stack. One client relationship in the DIB can lead to five, ten, or twenty downstream opportunities if you position yourself as the partner who understands the full picture.
The Window Is Open: It Will Not Stay Open
CMMC 2.0 rulemaking is finalized. Assessments are ramping up. DIB organizations that have been kicking the can are now under real deadlines with real contract consequences. The demand for partners who can deliver end-to-end CMMC solutions—not just a piece of the puzzle—is accelerating fast.
Partners who sell only DSPM will capture the assessment layer. Partners who sell only a protection platform will capture the enforcement layer. Partners who sell both will own the client relationship, command larger deal sizes, and build managed services revenue streams that compound over time.
Your clients already have the gap report. They are looking at it right now, wondering what comes next. Be the partner who answers that question.
MSSP Alert Perspectives columns are written by trusted members of the managed security services, value-added reseller and solution provider channels or MSSP Alert's staff. Do you have a unique perspective you want to share? Check out our guidelines here and send a pitch to [email protected].