Three Thresholds, Three Weeks
Three thresholds were written down in three different parts of the MSP business.
Start with ChannelLife, and start with a caveat, because this one is a byline. Scott Frew — who founded and runs iAsset, a company that sells channel lifecycle software — writes that Microsoft has cut its global distributor base from about a hundred and eighty companies down to roughly sixty. Two out of every three, gone. To stay in, a distributor now has to clear thirty million US dollars in Cloud Solution Provider revenue over twelve months, in each region it’s authorized for. A million, if you’re a direct bill partner. Frew calls what that leaves behind a lifecycle execution problem — with fewer parties in the middle and ownership shifting between them, tracking who owns which renewal and who is answerable for it gets harder for everyone downstream. Which is the diagnosis you would expect from a man whose product manages lifecycles, and the numbers are his — I could not confirm them anywhere else.
Then Managed Services Journal. Their reporting says regulated buyers are disqualifying managed service providers whose remote monitoring and management platform does not carry FIPS 140-3 validated cryptography. FIPS 140-3 is the U.S. federal standard for validated cryptographic modules. It is not a claim a vendor makes about its own encryption; it is a certificate issued after testing, and a product either holds one or it doesn’t. The publication is careful to say that having the validation does not by itself make a provider compliant with anything. The buyers are using its absence anyway, to take providers out of consideration.
And then Technology Reseller, out of the UK. A company called CompareIT has launched what it bills as the country’s first AI-powered platform for comparing managed service providers. Businesses use it to search, compare and monitor more than eight thousand MSPs, across up to a hundred and ninety-seven data points per provider. Giacom is behind it as a strategic supporter, and on the other side of the platform, CompareIT sells MSPs access to the leads it generates. Eight thousand providers. A hundred and ninety-seven fields each.
Three announcements. One of them sits in the supply chain, one sits in the tool stack, one sits in a database in another country. In each case somebody wrote down a number that separates the providers who qualify from the providers who don’t, and then published it.
Three parties who don’t talk to each other, reaching for the same instrument in the same month. That’s not coincidence, and it isn’t conspiracy either.
Cheaper Than A Conversation
A threshold is what a large party uses when it has too many small parties to talk to.
That is the whole of it, and you can watch it work by following what happens to one of them after it gets set. Take the cryptography requirement. Kaseya is not arguing with it. In October, according to ITPro and ChannelPro, Datto RMM gets FIPS 140-3 validated cryptography and native Apple device management, and both arrive at no additional cost. Think about why a vendor gives that away. A platform whose partners are being disqualified by their buyers loses the partners, so the platform absorbs the requirement rather than letting anyone fail it. And once it is absorbed, clearing that bar costs a provider one account-level setting. Which means clearing it distinguishes nobody. Only failing it does anything at all. A threshold never really gets negotiated. It gets absorbed, and absorption is what converts it from an advantage into a floor.
Now the same logic running the other direction, on the supply side. CyberFOX makes privileged access management, a password manager, and DNS filtering, all built for MSPs. This month it signed a North American distribution agreement with Ingram Micro, putting those products on Ingram’s platform in front of more than a hundred and sixty-five thousand channel partners and resellers. Channel Dive describes the deal as scaling beyond the MSP market. Look at the shape of that decision. Not recruit providers one at a time. Sign once, with the party that already holds all of them.
And the party holding them keeps getting thicker. TD SYNNEX — and this is TD SYNNEX describing its own platform — has expanded PartnerFirst with AI assistants, lifecycle analytics, quoting tools and accounting integrations, says customers transacting regularly across its digital offerings are growing nearly thirty percent on average, outpacing the ones who aren’t. That is the company’s own number about its own product. But the direction is what matters: the middle layer is absorbing the tracking of renewals and ownership.
So nobody decided to exclude anybody. A threshold is just what scale reaches for instead of a conversation, and every one of these is held by a party that got bigger by not having the conversation.
And not one of those decisions produces a phone call.
You’ll Never Get The No
You do not lose these. You are never told.
An industry has grown up around the fields that decide it. Two examples landed in the last week, both companies announcing their own products, so take each for what it is.
The first is a product called SCOUTz, from a company called RYTHMz, currently in open beta. What it sells an MSP is dated, outside-in evidence about a prospect’s environment, assembled before the first sales meeting, plus a read-only review of that prospect’s Microsoft 365 tenant afterward. It lists at two hundred and seventy-nine dollars a month. Self-announced launch, no independent coverage, so weigh the product accordingly. The price is the part that matters. Somebody can buy the outside-in view of your prospect for two hundred and seventy-nine dollars a month. Somebody can buy the view of you for the same.
The second is Senteon and SPECTRA, who announced a partnership this month pairing Senteon’s automated endpoint hardening with SPECTRA’s certification and warranty service. The two companies position it as a way for an MSP to prove its security controls to an insurer or a regulated buyer. Again, that is the two of them describing their own arrangement. But look at what is being sold. Not the hardening. The attestation — proof of your own eligibility, purchasable from a third party, because asserting it yourself no longer clears anything.
That is a category now, with vendors and prices in it. Categories like that become somebody’s job, or they stay nobody’s.
Not every light quarter is a disqualification. But a disqualification looks exactly like one, and that is the problem — the only way to tell them apart is to go check the fields yourself.
So here is the choice. Give the fields an owner. One person who knows what tier you sit in with every distributor you buy through, which of your platforms carry which validations and when those expire, and what the public record returns about your business when a machine scores it — and who re-runs that check every quarter, the way a buyer would.
Or leave it where it lives now, which is nowhere, and learn you were taken out of a market the only way a silent disqualification ever tells you: a quarter that came in light, with no losses in it to explain why.
All of which you can go check on Monday, which is the part that makes it awkward.
Because the provider who wins the next regulated deal will not be the one who sold it better — it will be the one who happened to be eligible when the list got cut, and eligibility is now checkable before anybody makes a call. The separator has moved in front of the pitch. Find out which lists you are on and which ones you have already fallen off, and you will know exactly who you are still competing against.
The provider who wins this doesn’t win it by being lucky. They win it because somebody in that shop made eligibility a deliberate thing, once — and now they get shortlisted in rooms they never walked into.
What to Consider
Ask your RMM vendor for the certificate number, not the marketing sentence. There is a difference between a vendor saying it uses FIPS-validated cryptography, a vendor handing you the certificate number for the cryptographic module inside the product you run, findable on NIST’s validated modules list, where it stays active for five years, and a procurement officer knows which one they asked for. Get that in writing before October — because once the requirement ships free inside the major platforms, being unable to produce a number stops being a gap and becomes the only signal left.
Find out whether your distributor is one of the sixty. Call whoever holds your Cloud Solution Provider agreement and ask directly where they land after the cut and what revenue threshold now applies to your volume. This is a competitive question, not an administrative one: if your distributor is on the way out, the provider quoting against you next quarter gets continuity while you get a migration, and neither of you chose that.
Go look yourself up. If you sell to buyers with UK exposure, search the comparison platform for your own business and read what comes back. Searching is free and takes no account, and providers get listed by claiming a profile — so finding nothing at all is also an answer. The useful part is not your score — it is the shape of the set you were ranked inside, because the providers listed beside you are who the buyer believes your competitors are, and that is frequently not who you believe they are.
If this trend continues, by the middle of 2027, the opening section of a regulated RFP will be a list of validation certificate numbers rather than a description of your service, and the shortlist will be assembled before anyone reads a word you wrote.

