MSP SALES & GROWTHILLUSTRATIVE
SCOUTz product evidence supporting Qualify Before You Quote: The MSP Client Scorecard
What is MSP client qualification?

It is the process of deciding, before pricing, whether a prospect will be profitable and safe to serve, using observable signals about their environment and their willingness to accept a standard stack and documented accountability.

100-POINT CLIENT SCORECARD

Set the decision thresholds before the logo wins the argument.

0–49NODo not quote without a different case.
50–64CONDITIONALQuote with a written remediation plan.
65–100GOFits the operating model and appetite.
EndpointLoggingProcessesPoliciesIncident responseMail authAutomationOwnershipIdentityTraining
The weighting is a starting point for an MSP to tune, not a universal benchmark.
SCOUTz raccoon mascot leaning against a boundary with folded arms

Short answer: MSP qualification is the decision, made before pricing, about whether a prospect will be profitable to serve. Score every prospect on observable signals (mail authentication, identity hygiene, exposed services, executive ownership of security decisions, willingness to accept a standard stack) and set thresholds: go, conditional with a remediation plan, or no. The evidence for most of the score is visible from outside the tenant, which means you can qualify before the first meeting rather than after the third.

Every MSP owner has one. The logo that looked great on the slide and cost money every month of the contract. No security champion, exceptions on every control, a manual-only mindset, and a ticket queue that never stopped. Revenue and growth are not the same thing, and the gap between them is almost always a qualification decision somebody skipped.

The margin for that mistake is shrinking. Kaseya's 2026 State of the MSP Report found the share of MSPs whose typical customer spends $25,000 or more a year fell from 75 percent to 41 percent, and the share reporting they are not yet profitable doubled from 5 percent to 10 percent. Smaller contracts leave less room to absorb a client who costs more to serve than they pay. The cure is a qualification discipline built on objective signals, and much of it can run before anyone signs an NDA.

Where you are decides what "good" means

An early-stage MSP should take almost any client who pays on time and accepts the scope, because volume teaches delivery and funds the tools. A mature MSP has a higher bar: the client fits the operating model, accepts the standard stack, and signs risk exceptions when they decline a control.

Be honest about which one you are. Qualification rules for a forty-person MSP will starve a four-person MSP. The scorecard below is for the MSP that has enough clients to be choosy and not enough margin to be wrong.

The 100-point scorecard

Build a weighted 100-point card and set the thresholds before you score anyone, so the number decides rather than your mood that week. A reasonable starting point: 65 and above is go, 50 to 64 is conditional with a written remediation plan, below 50 is no. Weight the categories for your own stack and appetite. The categories worth scoring:

  • Endpoint coverage: unified, centrally managed, integrated with monitoring. Mixed unmanaged devices is a no-go signal.
  • Centralized logging and retention: exists, includes email telemetry, retained long enough to investigate.
  • Documented processes: versioned procedures for triage and escalation, or at least drafts.
  • Security policies: approved within twelve months and attested by staff.
  • Incident response plan: written, roles assigned, tested within the year.
  • Mail authentication: SPF present and DMARC at enforcement, or a credible path to it within ninety days.
  • Automation posture: willing to let policy-guided automation act, with an exception list, versus manual-only.
  • Executive ownership: a named person who can say yes and sign a risk register.
  • Identity hygiene: MFA enforced across privileged and standard accounts.
  • Awareness training: a program that runs and is tracked.

Half of that list can be scored from the outside before you ever ask a question. That is the part most MSPs miss.

What you can score before the first meeting

Mail authentication is public. SPF, DKIM and DMARC records live in DNS. SCOUTz scores it with one rule: a domain is spoofable if it has no SPF, or if DMARC is absent or set to p=none; it is enforcing only at quarantine or reject. Apply that rule to a prospect and you have a scored line before the call.

Exposed services are public. An indexed remote-management console, a self-hosted VPN portal on an old version, a remote-desktop gateway that answers to anyone. Those tell you about patch discipline and about who is watching.

Lookalike domains are public. If three near-matches to the prospect's domain were registered in the last quarter, you have both a finding and an opener.

Cloud identity is partly public. The identity provider, the mail platform, the filtering gateway in front of it. Enough to know what stack conversation you are walking into.

Executive ownership, automation posture and policies require a conversation. The point of scoring the public half first is that you walk into that conversation already knowing which half of the card is at risk.

Discovery moves that de-risk the price

Run discovery before you quote, never after. Three moves cover most of it: a look back at what is already sitting in the mailboxes, a mail-authentication review with a dated enforcement plan, and a demonstration of what your automation will do and what it will not. Price against the real work those three reveal, not against the prospect's description of their environment. The prospect's description is always cleaner than the tenant.

Add a fourth move that precedes all three: show the prospect the outside-in findings and watch how they respond. An owner who says "fix it" is a different client from one who says "our guy handles that." The scorecard cannot capture that reaction. You can.

Put the risk in the contract

The contract is where margin gets protected or given away. If the client declines a recommended control, document it in an exception register with an executive signature, state in the MSA that costs and fines tied to that decision are the client's, and align the cyber-insurance language so a declined control that raises their premium is their delta to pay.

Then price behavior instead of hope. An exception multiplier that recedes as controls close. Two rates for DMARC enforcement, one if they hit the date and one if they do not. A manual-only surcharge tied to measured hours. None of this is punitive. It is the only pricing structure that keeps the incentives pointed at remediation, which is the reason you were hired.

The takeaway

Qualification is a trust decision in both directions. The client is deciding whether to trust you at 3 a.m. You are deciding whether their environment, and their attitude toward it, will let you keep that promise at a margin that lets you stay in business. Score it. Write it down. Walk away from the ones below fifty, and put the conditional ones on a remediation plan with a date.

Frequently asked questions

What is MSP client qualification?

The process of deciding, before pricing, whether a prospect will be profitable and safe to serve, using observable signals about their environment and their willingness to accept a standard stack and documented accountability.

What signals predict a bad MSP client?

Weak or absent mail authentication, mixed unmanaged endpoints, no centralized logging, no named security owner, refusal to run basic discovery, and a manual-only attitude toward automation. That pattern shows up later as technician burnout, noisy tickets and flat recurring revenue.

Can an MSP qualify a prospect before the first meeting?

Partly, and the public part is significant. SPF and DMARC status, indexed remote-access services, lookalike domain registrations and the cloud identity provider are all observable without credentials.

What score should an MSP use to accept a client?

A workable starting point: 65 or above proceed, 50 to 64 proceed with a written remediation plan and dates, below 50 decline. Adjust the weights to your own stack and risk appetite.

How should an MSP price a client who declines security controls?

Document the exception with an executive signature, assign the resulting costs and fines to the client in the MSA, and attach a monthly uplift that recedes as the control is closed.

How SCOUTz gets you there

SCOUTz is prospect intelligence for MSPs, and qualification is where it earns its keep. Point it at a prospect's domain and the public half of the scorecard fills in before the first meeting: mail authentication scored against a clear enforcement rule, exposed and indexed services, lookalike domains, cloud identity, connected apps and shadow SaaS. With a read-only Microsoft 365 connection after the prospect says yes, the rest of the card follows: identity hygiene, license waste, credential hygiene and grant creep, with every finding tied to the evidence behind it. The output is a branded report and a work plan in your MSP's name, deterministic rather than guessed, so you price the real environment instead of the described one. Point it at any client and walk out with a deal. The open beta is free for thirty days at scoutzsecurity.io.