Cyber Essentials for MSPs
Your clients are being asked for it by their insurers, their customers and their tenders. You can hand that work to a certification body that has no interest in the rest of their IT.
Ask about partner rates
Tell us roughly how many clients you expect to certify in a year and what sort of estates they run. You will get the actual partner figures back in writing, usually within one business day. No call unless you want one, and no obligation either way.
An appointed IASME Certification Body: certificates are issued directly by Solusec. Verify our credentials on the BlockMark registry, and find us listed on the IASME website.
Why this lands on your desk
An MSP rarely goes looking for Cyber Essentials work. It arrives, usually as a client forwarding an email from their insurer, their largest customer or a tender portal, with some version of "we need this by the end of the month, can you sort it?"
From there the options are all mildly unsatisfying. You can tell them to find a certification body themselves, which sends your client shopping and occasionally introduces them to somebody who also sells managed IT. You can take it on and discover that the assessment questions are about your estate as much as theirs. Or you can subcontract it to whoever answers the phone and hope the turnaround holds.
The alternative is a certification body you have terms with, that issues the certificate itself, and that has no interest in the rest of the client's IT.
The two ways partners work with us
Referral
You introduce the client and we contract with them directly. You are paid a commission on each completed assessment. No invoicing, no support burden, no involvement in the assessment itself unless you want it. Suits an MSP who wants the client looked after without adding a line of business.
Reseller
You buy at partner rates and sell at your own price. You contract with the client, you set the margin, and the client need never deal with us. Suits an MSP who already sells compliance and wants Cyber Essentials to sit inside their own stack and their own invoice.
The full model, including how it works for penetration testing, is on the partnerships page. This page is about the Cyber Essentials side of it.
Preferential rates under IASME pricing
Partners pay less than the published direct price, against IASME's own fee bands. We do not put the numbers on this page, for two reasons worth stating rather than hiding.
The first is that they are not one number. Terms move with volume and with which route you take, and an MSP placing steady work through the year should not be on the same terms as one placing a single certificate. The second is that publishing a partner rate on a public page means every direct buyer finds it too, which is unfair to the partners who negotiated it.
So the arrangement is simple: tell us roughly how many clients you expect to certify in a year and what mix they are, and you get the actual figures back in writing. No call required unless you want one.
What you are actually buying into
- An appointed IASME Certification Body. The certificate is issued by us directly. Nobody else is in the chain, so the turnaround is ours to commit to.
- Assessment within one business day of submission as standard, and the same day with the urgent option where the submission lands before midday.
- A human assessor. Submissions are reviewed by a qualified, certified assessor, never fed to a model. If a partner is putting their own brand on the outcome, that distinction matters.
- No channel conflict. We do not sell managed IT, helpdesk, licensing or monitoring, so there is nothing of yours for us to cross-sell into.
- Room to grow past Cyber Essentials. IASME Cyber Assurance Levels 1 and 2 now, Cyber Essentials Plus from late October 2026, CREST-accredited penetration testing available white-labelled, and Defence Cyber Certification Level 0 for clients with MoD contracts.
The gap analysis is where partners make their margin
Cyber Essentials is pass or fail against five technical controls. A client whose estate you already manage to a standard will usually pass first time. A client you inherited last quarter, with unmanaged laptops, local admin rights everywhere and multi-factor authentication switched on for about half the cloud services, will not.
A gap analysis before submission tells you which one you are dealing with. For an MSP that is not just a pass-rate exercise, it is a scoped piece of remediation work you are the obvious person to deliver, and it is usually worth more than the certificate. Partners who lead with it certify more clients and argue about failures less.
Who this suits, and who it does not
It suits an MSP or IT provider with a handful of clients a year being asked for Cyber Essentials, who would rather place the work with a specialist than either turn it away or become a certification body. It suits anyone whose clients are drifting into insurance renewals and tender requirements and who wants a straight answer on timing.
It does not suit an MSP certifying at real volume, who should probably look at becoming an IASME Certification Body directly. If that is you, say so on the form and we will tell you what is involved rather than sell around it.
Common questions
What rates do MSPs actually get?
Preferential rates against IASME’s published fee bands, set by volume and by which route you take. We do not publish the numbers because they move with commitment and because an MSP placing steady work should not be on the same terms as one placing a certificate a year. Tell us roughly how many clients you expect to certify in a year and you will get the actual figures back, not a brochure.
Do you compete with us for the managed services work?
No, and it is the first thing most partners ask. Solusec is a specialist certification body and penetration testing provider. We do not sell managed IT, helpdesk, hardware, licensing or monitoring, and we do not want to. If your client asks us who should run their IT, the answer is you. That is a commercial position rather than a promise, because we are not set up to deliver managed services and have no plans to be.
Who holds the client relationship?
Whichever way you want it. On a referral you introduce and we contract with the client directly, with your commission paid on completion. On a reseller arrangement you contract with the client, we contract with you, and the client need never deal with us at all. Some partners run both depending on the account.
Who issues the certificate?
We do. Solusec is an appointed IASME Certification Body, so the certificate comes directly from us with no third party in the chain. That matters for a partner because it means the turnaround is ours to commit to rather than something we are waiting on somebody else for.
Should we just become a Certification Body ourselves?
Possibly, and it is worth looking at honestly. It means assessor training and examination for at least one person, an IASME licence, a documented quality management system, an audit, and then keeping all of that current. For an MSP certifying a handful of clients a year the arithmetic rarely works. For one certifying fifty it might. We will tell you which side of that line you look like you are on, including when the answer is that you do not need us.
What else can we place with you?
Cyber Essentials and IASME Cyber Assurance Levels 1 and 2 today. Cyber Essentials Plus from late October 2026. CREST-accredited penetration testing, which can be white-labelled under your brand and report template. Defence Cyber Certification Level 0 for any of your clients holding MoD contracts, where the deadline is 31 December 2026.
How fast is the assessment?
Within one business day of submission as standard, and the same day with the urgent option where the submission arrives before midday. What that clock does not cover is the part that actually takes time, which is getting the client’s five controls right before they answer the questionnaire. Partners who run a gap analysis first pass first time far more often.
What happens if a client fails?
They get told exactly what failed and why, and under the current scheme rules there is one free resubmission inside a limited window. We would rather find the problem at gap analysis than at assessment, which is the whole argument for doing one on any client whose estate you have not already standardised.
Related
Solusec
Typically replies within one business day
Had an incident, or need a penetration test or Cyber Essentials at short notice?
Tell us what you're dealing with and we'll come back to you.
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day
Ready to talk?
No sales team to get past. Send the numbers and you will get partner rates back in writing, usually within one business day.