Cyber Essentials for MSPs › Becoming a certification body
Every MSP that places more than a handful of Cyber Essentials certificates a year eventually asks the question. If we are doing the readiness work, the remediation and most of the hand-holding anyway, why are we paying someone else to mark the answers?
It is a fair question and it deserves a proper answer rather than a defensive one. Sometimes the right answer is that you should license. Here is what it involves and how to work out which side of the line you are on.
What licensing actually requires
A trained and examined assessor
At least one person has to complete assessor training and pass the examination. That is a real technical qualification, not a form. It has to be somebody senior enough to make judgement calls on scope and evidence, which in a small MSP means one of the people you can least afford to take off billable work.
One assessor is also a single point of failure. If that person is on holiday, ill or leaves, your assessment capability stops. Most licensed bodies end up training a second, which doubles that part of the cost.
An IASME licence
IASME runs the Cyber Essentials scheme on behalf of the NCSC, and certification bodies operate under licence from IASME. There is an application, a set of criteria to meet and an annual licence to maintain. Terms and fees come from IASME rather than from us, and they are the part of this exercise you should get in writing directly before you do anything else.
A documented quality management system
This is the piece MSPs consistently underestimate, because it is the least like the work they already do. You need documented procedures covering how assessments are conducted, how decisions are recorded, how impartiality and conflicts of interest are managed, how appeals and complaints are handled, how assessor competence is maintained and evidenced, and how records are retained and secured.
If you already hold ISO 27001 or ISO 9001, you have a frame to hang this on and the work is materially smaller. If you do not, you are writing a management system from scratch, and honest estimates for that run into weeks of somebody’s time rather than days.
An audit, and then another one
The quality management system is audited. Not read: audited, with evidence that the documented procedures were actually followed on real assessments. That means the system has to survive contact with the way your business genuinely operates, which is a higher bar than having good documents.
Keeping all of it current
This is the cost that catches people out, because it is the one that recurs whether or not you issue a single certificate. The scheme changes. Question sets are revised, and the technical requirements move with them. Assessors need continuing development. The management system needs reviewing, records need retaining, and the audit comes round again.
The arithmetic, honestly
Set the fixed annual burden against the contribution per certificate, and the answer falls out. Neither of those numbers is one we can publish for you, but the shape is easy to see.
On the revenue side, the ceiling is what a client will pay, and the published direct market gives you that. Ours runs from £320 plus VAT for one to nine staff to £600 plus VAT at two hundred and fifty and over. You cannot charge a great deal more than the prevailing direct price for the certificate itself, because clients can and do compare. So your contribution per certificate is that figure less your delivery cost, and your delivery cost includes assessor time, which for a thorough review of a non-trivial submission is not trivial.
On the cost side sits the fixed annual burden: the licence, the assessor training and continuing development, the management system maintenance, the audit, and the professional time absorbed by all of it. That number does not fall when you issue five certificates instead of fifty.
Divide the second by the first and you have your break-even volume. For most MSPs it lands somewhere above thirty certificates a year, and comfortably above that once you account for the management time you have not costed. Below about thirty the arithmetic rarely works. Above fifty it often does, particularly if the assessor is a person you would have employed regardless.
| Points towards licensing | Points towards placing the work |
|---|---|
| Fifty or more certificates a year, or a clear path to it | Fewer than thirty, with no reason to expect growth |
| Compliance is a defined line of business with its own revenue target | Cyber Essentials arrives when clients are asked for it |
| An existing ISO management system to build on | No formal management system and no appetite to build one |
| Two people who could hold assessor qualification | One person who could, who is also your most billable |
| Clients who value buying everything from one supplier | Clients in tenders or insurance renewals who benefit from third-party assessment |
| Willingness to separate assessment from delivery internally | A small team where everybody touches every estate |
Independence does not disappear, it moves inside
Licensing does not remove the awkwardness of assessing estates you built. It relocates it into your quality management system, which is exactly where the impartiality and conflict of interest procedures earn their place.
In practice that means the person assessing a client cannot be the person who configured that client’s estate, and you have to be able to demonstrate that separation to an auditor. In a firm of fifteen where three engineers touch everything, that is a genuine operational constraint and it needs thinking about before you apply, not after. It is also, incidentally, the argument some licensed MSPs use for continuing to place a portion of their work externally: the accounts where the conflict is sharpest go to somebody else.
Cyber Essentials Plus is a separate question
Worth flagging because it changes the calculation for some firms. Cyber Essentials Plus involves a technical audit with hands-on testing rather than a reviewed questionnaire, and it carries its own requirements and its own assessor competence. Licensing for the self-assessed certification does not give you the Plus capability. If a meaningful share of your clients need Plus, model the two separately rather than assuming one licence covers both. We assess Cyber Essentials Plus from late October 2026.
A go or no-go in five questions
- What is your actual certificate count over the last twelve months? Not your forecast. The count.
- Who is the assessor, by name, and what does their time cost you? If you cannot name them, you are not ready to apply.
- Do you have a management system an auditor could examine? If the honest answer is a folder of documents, add several weeks.
- Can you separate assessment from delivery and evidence it? In a small team this is harder than it sounds.
- What does the fixed annual burden come to, in full, including your own time? Then divide it by your realistic contribution per certificate.
If that last division gives you a number below your current volume, license. If it gives you a number well above it, place the work and revisit in a year. If it lands close, the deciding factor is usually whether you want compliance to be a business rather than a service, because licensing commits you to the first.
What we would tell you
We are a certification body, so the obvious commercial incentive is to talk you out of this. We would rather be useful. If you are issuing at volume, if compliance is a product line with its own target, and if you have the management system and the people, licensing is likely the better outcome for you and we will say so.
If you are not there yet, partner terms will serve you now and they do not stop you licensing later. Nothing about placing work with a certification body creates a commitment that makes the other route harder, and a couple of years of placing work is a reasonable way to find out what your real volume looks like before you commit to a fixed annual burden.
Either way, get IASME’s current licensing criteria and fees directly from IASME before you make the decision. They are the only accurate source for that part, and the arithmetic above is only as good as the numbers you put into it.
How long does it take to become a certification body?
Plan in months rather than weeks. The assessor training and examination is the shortest part. Writing and implementing a quality management system from nothing, then running enough real assessments through it to have evidence an auditor can examine, is what sets the timeline. Firms with an existing ISO management system move considerably faster.
Can we license and still place some work with another certification body?
Yes, and some licensed MSPs deliberately do. The usual reason is impartiality: accounts where the same people built and run the estate go to an independent body, while the rest are assessed in house. Capacity is the other reason, particularly around a deadline when one assessor is the constraint.
Does becoming a certification body let us issue Cyber Essentials Plus?
No. Cyber Essentials Plus is a hands-on technical audit rather than a reviewed questionnaire, with its own requirements and its own assessor competence. Treat it as a separate decision with separate arithmetic. If a large share of your clients need Plus, that may change which side of the line you fall on.
What happens to our existing clients if we license later?
Nothing awkward. A certificate is valid for its term regardless of which body issued it, and a client can be certified by a different body at renewal without penalty. Placing work now does not lock you in, which is part of why partnering first is a reasonable way to test your real volume before committing to a fixed annual cost.
We will tell you which side you are on
Send us your actual certificate count and what your team looks like. If the answer is that you should be licensing rather than partnering, we will say so, and point you at IASME rather than sell around it.