Solusec: Solutions for Cyber Security

Operated by Solusec Ltd
CREST accredited · IASME Certification Body

For MSPs and IT providers

Cyber Essentials for MSPs

Your clients are being asked for it by their insurers, their customers and their tenders. You can place that work with a certification body that has no interest in the rest of their IT.

Accredited and recognised

Cyber Essentials Certification BodyIASME Cyber Assurance Certification Body

Why this lands on your desk

An MSP rarely goes looking for Cyber Essentials work. It arrives, usually as a client forwarding an email from their insurer, their largest customer or a tender portal, with some version of "we need this by the end of the month, can you sort it?"

From there the options are all mildly unsatisfying. You can tell them to find a certification body themselves, which sends your client shopping and occasionally introduces them to somebody who also sells managed IT. You can take it on and discover the questions are about your estate as much as theirs. Or you can subcontract to whoever answers the phone and hope the turnaround holds.

The two ways partners work with us

Referral

You introduce the client and we contract with them directly. You are paid a commission on each completed assessment. No invoicing, no support burden, and no involvement in the assessment unless you want it. Suits an MSP who wants the client looked after without adding a line of business.

Reseller

You buy at partner rates and sell at your own price. You contract with the client, you set the margin, and the client need never deal with us at all. Suits an MSP who already sells compliance and wants Cyber Essentials inside their own stack and their own invoice.

Plenty of partners run both, depending on the account.

Placing the work or becoming a Certification Body yourself is a real fork, and the answer is not always us.

Preferential rates under IASME pricing

Partners pay less than the published direct price, against IASME's own fee bands. We do not put the numbers on this page, for two reasons worth stating rather than hiding.

The first is that they are not one number. Terms move with volume and with which route you take, and an MSP placing steady work through the year should not be on the same terms as one placing a single certificate. The second is that a partner rate published on a public page is a partner rate every direct buyer also finds, which is unfair to the partners who negotiated it.

So: tell us roughly how many clients you expect to certify in a year and what mix they are, and you get the actual figures back in writing. No call required unless you want one.

The question every MSP asks first

Do we compete with you? No. Solusec is a specialist certification body and penetration testing provider. We do not sell managed IT, helpdesk, hardware, licensing or monitoring, and we are not set up to. If your client asks us who should be running their IT, the answer is you.

That is a structural position rather than a promise. A certification body that also sells managed services has a reason to look closely at the incumbent provider's estate. We have no such reason, because we do not want the contract.

What you are placing the work with

The gap analysis is where you make your margin

Cyber Essentials is pass or fail against five technical controls. A client whose estate you already manage to a standard will usually pass first time. A client you inherited last quarter, with unmanaged laptops, local administrator rights everywhere and multi-factor authentication on about half the cloud services, will not.

A gap analysis before submission tells you which one you are dealing with. For an MSP that is not a pass-rate exercise, it is a scoped piece of remediation work you are the obvious person to deliver, and it is usually worth more than the certificate. Partners who lead with it certify more clients and argue about failures less.

The DCC deadline is worth a call on its own

Any of your clients holding a Ministry of Defence contract, or supplying someone who does, has been told to reach Defence Cyber Certification Level 0 by 31 December 2026. Cyber Essentials is a prerequisite at every DCC level, including Level 0, under Def Stan 05-138 Issue 4. You will see it written elsewhere that Level 0 needs no Cyber Essentials. That is not what the standard says, and planning around it leaves your client short.

If you have defence suppliers in your book, that is a conversation to have with them this quarter rather than in December.

Should you place this work, or become a Certification Body yourself?

Tick what is true. This is a real fork and the answer is not always us.

Further reading on this site

Four guides going deeper than this page does. All free, no sign-up.

Ask about partner rates

Tell us roughly how many clients you expect to certify in a year and what sort of estates they run. You will get the actual partner figures back in writing, usually within one business day. No call unless you want one, and no obligation either way.

Your details are handled by a real person, never fed into AI.