The dominant mechanism addressed is the development of a self-regulatory framework for IT service providers, specifically as Texas A&M University's Global Cyber Research Institute (GTIA) launches the Consortium for Responsible IT Services (CRITS). This signals a move toward organized self-governance and standard-setting within the MSP sector, in contrast to direct government-imposed regulation. The initiative is designed to shift the industry from fragmented standard adoption toward collective risk and professional accountability, using academic infrastructure and industry funding as its operational backbone.
According to statements from Cole Knuth, GTIA’s facilitation of CRITS involves university-hosted development and company funding, with the intention to produce a publication outlining operational and cybersecurity standards for IT service providers. The university has committed both its name and financial resources, making CRITS a formal legal construct enabled by Texas A&M’s research arm. The initial executive sponsors are large industry players—New Charter, Pax8, and The 20—but there is not yet independent MSP participation under 25 employees. The first member meeting is scheduled to occur alongside the GCRI Summit in October.
The episode contrasts CRITS with prior efforts to establish industry standards, noting previous initiatives by the MSP Alliance, NSITSP, and GTIA’s own Cybersecurity Trustmark, none of which achieved broad acceptance or regulatory recognition. Cole Knuth attributes this lack of traction to fragmented grassroots approaches or top-down lobbying, asserting that CRITS aims for a “middle out” model by aggregating MSP voices to build legitimacy and influence before external regulation is enacted. The consortium’s design includes the possibility of recognizing existing certifications rather than displacing them, and emphasizes eventual inclusion of smaller and independent MSPs in governance.
For MSPs and IT leaders, the practical implications include increased pressure to participate in the development and adoption of industry standards to mitigate liability risk and avoid externally imposed rules. Operational challenges are likely to include the need for resource allocation to compliance initiatives, cost uncertainties regarding participation and auditing, and navigating evolving governance requirements as standards are defined. Smaller MSPs face the risk of exclusion unless explicit mechanisms are created for their input and representation, and the structure of CRITS may lead to new layers of compliance complexity and scrutiny, particularly as the consortium transitions from initial large-member funding to broader industry engagement.
Supported by:
💼 All Our Sponsors
MSP Radio is supported by our partners:
ABC Solutions · CometBackup · GoTo · Guardz · Opentext · Pax8 · Rythmz · ScalePad · TimeZest · Transit AI
Supporting the IT services community through insights, analysis, and transparency.
🚀 Join Business of Tech Plus
Get exclusive access to investigative reports, vendor analysis, leadership briefings, and more.
👉 https://businessof.tech/plus
🎧 Subscribe to the Business of Tech
Want the show on your favorite podcast app or prefer the written versions of each story?
📲 https://www.businessof.tech/subscribe
📰 Story Links & Sources
Looking for the links from today’s stories?
Every episode script — with full source links — is posted at:
🎙 Want to Be a Guest?
Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:
💬 https://www.podmatch.com/hostdetailpreview/businessoftech
🔗 Follow Business of Tech
LinkedIn: https://www.linkedin.com/company/28908079
YouTube: https://youtube.com/mspradio
Bluesky: https://bsky.app/profile/businessof.tech
Instagram: https://www.instagram.com/mspradio
TikTok: https://www.tiktok.com/@businessoftech
Facebook: https://www.facebook.com/mspradionews
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
[00:00:01] Dave Sobel here reporting from the floor of Channel Con in San Diego. I'm sitting down with Cole Knuth. Cole is the Associate Director of Entrepreneurship at Texas A&M University, where he helped build the Consortium for Responsible IT Services, that's CRITS, which Texas A&M's Global Cyber Research Institute and GTIA announced here this week.
[00:00:24] It's an effort to write the first widely accepted professional, operational and cybersecurity standards for IT service providers and to stand up a self-regulatory body for the profession. So I've got two disclosures here. I couldn't get to Cole's session, so this is me learning in real time the same way you are as a viewer. And I have argued on this show repeatedly that this industry needs exactly this. So I want this one to work.
[00:00:52] That's why I'm going to press the way I am. Cole, welcome to the show. Absolutely. Thanks for having me. So let's start out. Start at the beginning. What is the Consortium and what exactly did you announce this week? The Consortium is primarily going to be the university hosting and developing an architect and framework for us to operate with. So think about it this way. The university is going to host it. Companies are going to fund it in and through GTI.
[00:01:20] And the intended outcome is for us to be able to take an artifact, probably a publication, and use that as the way that we operate as an industry. Because we have to find a way to organize before we professionalize, before we regulate. And so the first step of this is to define what that looks like, and then for us to start to change. Change the way we function, change the way we meet, change the way we communicate, right? Because self-regulatory organizations are grouped forming for single purpose first, well before they get to anything related to regulation.
[00:01:47] But it creates a bigger voice, right? You aggregate all the minds and creativity of the industry, and it gives you a precursor to be able to influence the people who write our legislation or write our laws. So today, is there something actionable that an MSP can do today by sending announcements? No. So this announcement basically, we actually announced the intention to do this at CCF, so the councils and forum that GTIA does.
[00:02:17] And then Paxi Beyond, they announced their support and investment in it. This is us launching it. So basically from today, it's official. The university made it official in the last couple months, and that just means that the Department of Research has accepted it. They've agreed to put their name next to it, and they've agreed to finance it and let the consortium operate in the university. Because it is a legal construct, right? Bylaws and all.
[00:02:44] Right. Okay, so GTIA's release says GTIA will be the future SRO resulting from this work. Now my understanding is a self-regulatory organization normally exists because a government delegated authority to it. The example being FINRA has the SEC behind it. So is there a delegating authority here for this organization? No, no, no. This would match more like how the Bar Association came into fruition, right?
[00:03:06] Which I watched your podcast from 2020. It's more like us coming together because we need some organization and we've got too much fragmentation in our channel. Okay. And the economic and even geopolitical forces are moving quicker than we are. And the longer we stay independent, the more, I think, more liability we create for ourselves. So prior to the CompTIA split to be conformed in GTIA, the advocacy and public policy groups went over to the public policy. Like that isn't in this organization.
[00:03:35] So my understanding is nobody in the channel really has the legislative muscle to do this. Who carries this to a legislature? Well, so Texas A&M won't necessarily do it all the way to the finish line for us. But one of the reasons we, I say we, I now work for the university. One of the reasons Texas A&M was where a lot of this idea went from concept to practice was the different investment areas that A&M has and how large it is.
[00:04:02] So I'll start kind of with early 2000s, George Bush Senior picked Texas A&M as its presidential library. With that, it also endowed a school of government. That school of government public policy has a lot of masters and graduate degrees and PhDs that are developed about creating policy. It's actually the largest single aggregate of graduate students in D.C. is Texas A&M University. And so that was kind of one of it. The other was, I think, maybe early 2010s. Don't quote me on the date. Texas A&M purchased a law school.
[00:04:32] And they put that law school with the school of government to have presence in D.C. as well. And so you have a lot of students that go and work in internships and different things. And so the university is very well practiced at helping influence legislators to write law. And they're very, very plugged in. A lot of it's the military background and things like that. And so that is the big difference here, right? Huge engineering school most people know A&M for.
[00:04:54] But it's the other areas that they've developed over the last 20 or 30 years that I think actually gives us the differentiation and maybe even, I think, makes me feel comfortable. So I'm a decade veteran in the space. Makes me feel comfortable letting them steward us through this change. Okay. That makes sense. So MSP Alliance has audited MSP against their unified certification standard back since 2000. The NSI-TSP has been at this attempt for five years now.
[00:05:22] GTIA itself has the cybersecurity trust mark. Three attempts. None have become a standard so far. What's different about the four? Fantastic question. So the way I've kind of looked at this is like we have been very good at the grassroots efforts, like new framework, new methodology, new approach, right? And we have not participated in it, but there's been people that have already attempted to influence government. And we know that, you know, the likes of Microsoft and others spend a lot of money on lobbying.
[00:05:49] What we've never done is organized in a way where we can actually recognize the different methodologies and the different frameworks and also have a voice that's big enough to be heard by the large companies and lobbyists so that we can represent ourselves. And so this is really a middle out approach. You think about the ones you just referenced. Those have operated much like a grassroots. It's every company at one at a time, right? No matter how much money you put it, you still have to do it one at a time. The other way is just like, well, let's just, you know, throw some money at it, see if we can get a law written and then they'll just be forced down, right?
[00:06:18] Where it's done to us and it's actually quite detrimental. And it's a huge liability for the organization if that happens. This is an attempt for us to kind of go middle out, right? Where we get together as a group and form and even let MSPs because, you know, self-regulatory organization will primarily almost exclusively be operated by MSPs. We haven't designed it yet, but I'm pretty sure that the professors that are in the School of Law and Economics will recommend that MSPs are the president of their state chapters and that they represent the role of secretary and treasurer.
[00:06:48] And they meet, it'll be without us, it'll be without the media, without vendors, it'll be managed service writers or IT service writers. That collective voice creates an aggregation point that is, I think, a one to many and creates scale for us to do this right this time. Is the vision Crits replaces the trust mark? No. Sits above it, becomes a third badge, like what's the vision of how it fits together? I think the trust mark and others become recognized by Crits. Now, Crits, it has a start and a stop, right? Okay.
[00:07:18] So when it's done, that recommendation and that publication will tell us as an industry how to operate. And when the self-regulation starts to function where you have leaders, you know, leading the SRO function, they will decide if they need to add a new framework. Let's say in 2030, somebody's like, hey, we have a new way to do this and we want to participate. And it's like, okay, fine, we'll add you. You'll be the fifth one. You'll be the fifth one to be able to recognize as a group or a different accreditation, right?
[00:07:47] So it's meant to be inclusive, but to define, right? Saying all these things are good, right? Right. You know, it's like the Bar Association accepts degrees from accredited universities that give out JDs, right? Mm-hmm. It's the same concept. It's now maybe not university level is the way we do that, but we do need a way to form and recognize the different frameworks and pieces that already exist. We'll be right back after this message. This episode is brought to you by Control Map.
[00:08:15] Drawing MSPs are using Control Map to build recurring revenue by expanding their GRC services. Starting now, Control Map is offering a free plan for MSPs looking to get started with providing compliance as a service. Create a free account and run an assessment. Track key items like policies, risks, and evidence in one place. It's a practical way to prove value to a client before deciding to expand your compliance offering. Try Control Map for free today.
[00:08:43] Visit scalepad.com slash Dave to get started. That's scalepad.com slash Dave. So, the named executive members are the 20, New Charter, and Pax8. Two aggregators and a distributor. Mm-hmm. So, is there an independent MSP under 25 people at the table today? Not yet. Okay. Now, we need to, I think, be very intentional in how we design the next group because we do plan on it being about 15 to 20 members.
[00:09:13] But we need the foundation. You know, the university, as much as it is there for creating, you know, science-backed decisions, they don't do things for free. Right? And so, we have to fund the research. We have to fund the researchers. And so, we need the support of some of our, you know, larger participants in the industry. But we also need the voice to be heard, like, all the way through the smaller MSP. Right? And I'm not talking about small, small at any size. Right? Like, anyone that I think has the right approach and perspective, they should participate.
[00:09:42] And so, we're going to create different ways to do that. Whether that's, you know, giving, you know, awarding a few seats, advisory seats to directly influence me. Or maybe it's also having, you know, another committee or a committee that kind of starts to govern this so that MSPs can participate in that. Now, it might be too early for this, but I want to ask for completion. Like, a six-person MSP to pay to be compliant. Fees, auditing, tooling, staff time. Like, who is intended to pay that cost? I don't know yet. Okay. I really don't.
[00:10:11] This is not meant to be a, it's meant to be obviously something they need to go through a process. And the cost is probably people. Like, you lose time with people doing it. And the first one will be the hardest, right? The change management will be extreme. It'll be complicated. But that's part of the design that the consortium will do, right? So, the consortium is a research initiative. Okay. But instead of individually research projects, the consortium is designed to have one big mission and have a bunch of research initiatives that plug into it.
[00:10:41] And that will be one of them. Okay. Now, make the argument I haven't made. Like, why is an industry writing its own rules better for the buyer than a state legislature doing it for them? That's a good question. I think this is our attempt to try to do it that way. Like, you know, it quickly gets tied into regulation because everyone gets that question very, very quickly. Like, you spend five minutes talking about it and they're like, well, what about the regulation? Like, people are talking about this.
[00:11:09] There's already groups formed by and for the government that are talking about this. It's like, yes, we will influence regulators. However, the primary purpose of this is to create a collection and almost a muster point, which is ironic that I use that because muster is a big part of our history at Texas A&M. But, you know, it's this muster point for us all to come together as an industry because if we can collect and aggregate, it creates more transparency for the buyer, right?
[00:11:37] And it keeps them from becoming defrauded by somebody who's selling something that's nefarious. Yes. So, let's make this actionable with the last question. The first member meeting is October alongside the GCRI Summit. Yes. Between now and then, what should an owner listening or watching this show actually do and what should they refuse to do? The best way for a local, we'll call them the broad side of the MSP industry, the best thing for them to do is to join GTIA.
[00:12:07] And I say that because like the big reason why GTIA is facilitating is because they have all these spaces and places for us to meet and talk, right? And so, they are a really good way for us to take research done in a small room in a university and bring it to the masses through keynotes and breakout sessions and even, you know, inviting people to come give feedback and challenge, you know, some of the initial research.
[00:12:31] More broadly, what we're going to need between now and then is the rest of the participants who can and want to support the initiative. We're going to need them to raise their hand and volunteer their time and financial support of the consortium. Well, there's your action items. Paul, thank you so much for joining me today. Yeah, absolutely. That was fantastic. What would you fix in your business with the right playbook?
[00:12:54] Small Biz Thoughts members get a library of templates and operational resources, recorded member calls, and classes through IT Service Provider University. Operational education built specifically for independent MSPs. Start at smallbizthoughts.org. Interested in advertising? Head to mspradio.com slash engage. The Business of Tech is written and produced by me, Dave Sobel,
[00:13:22] under ethics guidelines posted at businessof.tech. Thanks for listening. I'll see you on the next episode. Produced by Picture This Video, part of the MSP Radio Network.

