Accredited and recognised


Why this lands on your desk
An MSP rarely goes looking for Cyber Essentials work. It arrives, usually as a client forwarding an email from their insurer, their largest customer or a tender portal, with some version of "we need this by the end of the month, can you sort it?"
From there the options are all mildly unsatisfying. You can tell them to find a certification body themselves, which sends your client shopping and occasionally introduces them to somebody who also sells managed IT. You can take it on and discover the questions are about your estate as much as theirs. Or you can subcontract to whoever answers the phone and hope the turnaround holds.
The two ways partners work with us
Referral
You introduce the client and we contract with them directly. You are paid a commission on each completed assessment. No invoicing, no support burden, and no involvement in the assessment unless you want it. Suits an MSP who wants the client looked after without adding a line of business.
Reseller
You buy at partner rates and sell at your own price. You contract with the client, you set the margin, and the client need never deal with us at all. Suits an MSP who already sells compliance and wants Cyber Essentials inside their own stack and their own invoice.
Plenty of partners run both, depending on the account.
Placing the work or becoming a Certification Body yourself is a real fork, and the answer is not always us.
Preferential rates under IASME pricing
Partners pay less than the published direct price, against IASME's own fee bands. We do not put the numbers on this page, for two reasons worth stating rather than hiding.
The first is that they are not one number. Terms move with volume and with which route you take, and an MSP placing steady work through the year should not be on the same terms as one placing a single certificate. The second is that a partner rate published on a public page is a partner rate every direct buyer also finds, which is unfair to the partners who negotiated it.
So: tell us roughly how many clients you expect to certify in a year and what mix they are, and you get the actual figures back in writing. No call required unless you want one.
The question every MSP asks first
Do we compete with you? No. Solusec is a specialist certification body and penetration testing provider. We do not sell managed IT, helpdesk, hardware, licensing or monitoring, and we are not set up to. If your client asks us who should be running their IT, the answer is you.
That is a structural position rather than a promise. A certification body that also sells managed services has a reason to look closely at the incumbent provider's estate. We have no such reason, because we do not want the contract.
What you are placing the work with
- An appointed IASME Certification Body. The certificate is issued by us directly, with nobody else in the chain, so the turnaround is ours to commit to rather than something we are waiting on.
- Assessment within one business day of submission as standard, and the same day with the urgent option where the submission lands before midday.
- A human assessor. Submissions are reviewed by a qualified, certified assessor and never fed to a model. If you are putting your own brand on the outcome, that distinction is yours as much as ours.
- Room past Cyber Essentials. IASME Cyber Assurance Levels 1 and 2 today, Cyber Essentials Plus from late October 2026, CREST-accredited penetration testing available white-labelled under your brand and report template, and Defence Cyber Certification Level 0 for clients holding MoD contracts.
The gap analysis is where you make your margin
Cyber Essentials is pass or fail against five technical controls. A client whose estate you already manage to a standard will usually pass first time. A client you inherited last quarter, with unmanaged laptops, local administrator rights everywhere and multi-factor authentication on about half the cloud services, will not.
A gap analysis before submission tells you which one you are dealing with. For an MSP that is not a pass-rate exercise, it is a scoped piece of remediation work you are the obvious person to deliver, and it is usually worth more than the certificate. Partners who lead with it certify more clients and argue about failures less.
The DCC deadline is worth a call on its own
Any of your clients holding a Ministry of Defence contract, or supplying someone who does, has been told to reach Defence Cyber Certification Level 0 by 31 December 2026. Cyber Essentials is a prerequisite at every DCC level, including Level 0, under Def Stan 05-138 Issue 4. You will see it written elsewhere that Level 0 needs no Cyber Essentials. That is not what the standard says, and planning around it leaves your client short.
If you have defence suppliers in your book, that is a conversation to have with them this quarter rather than in December.
Should you place this work, or become a Certification Body yourself?
Tick what is true. This is a real fork and the answer is not always us.
Further reading on this site
Four guides going deeper than this page does. All free, no sign-up.
- Referral or reseller? Take the two routes apart firstIt reads like a binary choice about commission. It is really three separate questions about contracting, cash and support, and they do not have to move together.
- You built the estate. Should you also be the one assessing it?This is not an accusation about the quality of your work. It is an awkward structural fact that you did not create, and it is easier to handle if you name it first.
- Getting a client base ready, not one client at a timeCertifying clients one by one means solving the same five problems repeatedly and billing for none of them. Solved once across the estate, it becomes a product.
- Should you become a certification body yourself?For most MSPs the answer is no, and for a few it is clearly yes. The difference is volume, and a fixed annual burden that does not care how many certificates you issue.