Blog › Article
Cyber Essentials for MSPs: selling it as a service
Most MSPs treat Cyber Essentials as a once-a-year job: help the client through the questionnaire, invoice, move on. The fourteen-day rule and the current question set make that a harder way to work and an easier service to sell.
Your own certificate comes first
Before selling Cyber Essentials, an MSP should hold it. Clients increasingly ask their suppliers for it, and an MSP's own accounts — the ones used to manage client systems — sit inside every client's scope. An MSP that isn't certified is asking clients to trust access it hasn't had assessed.
Holding a certificate doesn't make an MSP a certification body; certificates are issued by certification bodies licensed through IASME. Many MSPs partner with one, prepare clients for assessment and handle the submission.
The one-off model and its problem
The traditional package is preparation and submission for a fixed fee. It works, but it has two weaknesses. Each year starts from scratch, because nobody tracked the estate in between. And it leaves the MSP exposed: if a client's certificate turns out to be untrue after an incident, the MSP that prepared it is the first place anyone looks.
The continuous model
The alternative is to sell the year, not the day:
- Onboarding: scope, gap analysis, remediation and first certification.
- Monthly: tracking the controls that drift — update age, antivirus, firewall, admin accounts, MFA on cloud services — and fixing issues as they appear.
- Reporting: a regular summary for the client showing the state of each control over the period.
- Renewal: a formality, because the evidence already exists.
For the client, it replaces an annual scramble with a predictable monthly cost. For the MSP, it turns a one-off job into recurring revenue, and gives a monthly reason to be in touch with the client about security.
What makes it work
- Measurement, not assumption. "We patch everything" isn't a service. Knowing how far behind each machine is, every day, is.
- Honest limits. Endpoint monitoring doesn't cover MFA on cloud services or the boundary firewall. Say so, and cover those some other way.
- Evidence the client can use. Dated reports they can put in front of an assessor or a customer.
- A clear line on responsibility. The client signs the declaration. The MSP's job is to make sure what they sign is true.
The fourteen-day rule is a monitoring requirement in disguise. No client can meet it reliably by checking once a year. That's the gap a continuous service fills, and why it's easier to sell now than it was before the question set changed.
Quick answers
Can an MSP issue Cyber Essentials certificates?
Only if it's a certification body licensed through IASME. Most MSPs prepare clients and work with a certification body for the assessment.
Should an MSP have Cyber Essentials itself?
Yes. Its accounts and access sit inside every client's scope, and clients increasingly ask.
What should an MSP charge?
The market varies. Many price the first certification as a project and the ongoing work as a monthly service, sized to the number of devices.