Choosing a Cyber Essentials Certified MSP in the UK
If you need an MSP that is itself Cyber Essentials certified (and can help you achieve it), this guide explains what "CE-certified MSP" really means and how to evaluate one.

Section 01
Choosing a Cyber Essentials Certified MSP in the UK
"Cyber Essentials certified MSP" is a phrase that gets thrown around loosely. Some providers mean they hold the certificate themselves. Some mean they are a licensed IASME certification body. Some mean neither - they simply know their way around the question set and will hold your hand through a submission to a third party. All three can be useful, but they are not the same thing, and choosing the wrong kind can cost you weeks of rework at renewal.
If you are a UK business scoping an MSP on the basis of their Cyber Essentials credentials, this guide walks you through what the badge should actually tell you, the questions that separate real certified partners from the marketing noise, and how to verify a claim in under two minutes.
Section 02
The three types of "CE-certified MSP"
The phrase collapses three distinct things that it pays to keep separate.
Type one: the MSP holds Cyber Essentials itself. This means the named organisation passed a verified self-assessment for its certified scope on the issue date. It does not prove that every current operational control remains effective or that a client's estate is covered. Verify the entity, scope, level and expiry through the IASME certificate search, then ask for current operational evidence relevant to your service.
Type two: the MSP or a related legal entity is a licensed certification body. Check the actual legal entity and its current IASME permissions for Cyber Essentials and, separately, Cyber Essentials Plus before assuming it can deliver both. Fig Compliance Ltd holds the relevant Fig Group licences; the IASME body directory and Fig Group licence evidence identify the licensed entity. Fig Group's six-working-hour Basic commitment has specific complete-submission and cutoff terms; Plus testing has a separate schedule.
Type three: the MSP provides preparation support. It may help inventory the estate, prepare answers and remediate gaps, while a separately licensed body makes the assessment decision. Ask who submits the senior declaration, who contracts with the certification body and whether preparation is included in the quoted fee.
These roles can overlap, but one credential does not establish the others. Confirm each claim against the appropriate record and agreement.
Section 03
Questions to ask before signing
Five questions will cut through almost all of the marketing language.
"Do you hold Cyber Essentials yourself - and can I see the certificate?" Check the certificate search, entity, certified scope and expiry. A parent company's certificate may have a different scope; ask how the contracting entity and service are covered.
"Are you a licensed IASME certification body, or do you sub-contract certification?" Either answer is fine; a vague answer is not. A licensed body will name the IASME licence. A sub-contracting provider will name its certification-body partner. Anyone who dodges the question is hoping you will not ask it.
"What is your turnaround time from submission to decision?" Ask for the written start condition, business-day cutoff, clarification process and any remedy. Fig Group's Basic commitment is six working hours after receipt of a complete, compliant submission before midday UK time on a UK business day, subject to terms.
"How many feedback rounds and resubmissions are included?" Check the current provider terms and distinguish assessor feedback, resubmissions and Plus retests. Do not assume a universal entitlement applies to every package.
"Who runs the CE Plus technical assessment?" Check the named body's Plus licence and the technical assessor's role. Basic and Plus may use different licensed bodies; agree evidence handover, sampling and schedule before ordering.
Section 04
The IASME directory - use it
IASME is the NCSC's delivery partner for Cyber Essentials. Use the certificate search for an organisation's award, then the separate certification-body directory for a claimed licence. Match the legal entity, scope, level and dates to the service you are buying. If a lookup fails, ask the issuing body or IASME to verify the claim before drawing a conclusion.
This single check defeats most of the weaker marketing claims in the market.
Section 05
What an MSP with a real CE capability adds
A capable MSP can help keep devices, access controls and evidence current between assessments. Annual renewal still requires a complete submission under the applicable account version; no fixed two-hour shortcut is implied.
That looks like enforced MFA across every cloud app you use, not just Microsoft 365. It looks like a live asset register that flags out-of-support operating systems automatically. It looks like patch-cadence dashboards that show the oldest critical patch currently unapplied across the estate. It looks like monthly evidence-readiness reports that catch regressions before the auditor does.
Without that operational backbone, a "CE-certified MSP" is just an MSP that paid for its own certificate once. It may not help your renewal at all.
Section 06
Where Fig Group sits
The Fig Group certificate holder and the licensed assessment entity should be checked separately. Fig Compliance Ltd holds the relevant IASME licences. Fig Group's MSP-facing platform can support asset, MFA and patch evidence workflows, subject to each customer's configured integrations and scope; an MSP should verify live coverage before claiming continuous readiness.
That combination - holder, certifier, and enabler - is unusual. It exists because the same team that was tired of late-stage remediation scrambles built the platform that prevents them.
Section 07
Next steps
If you are scoping an MSP relationship and Cyber Essentials is part of the requirement, start with the five questions above and the IASME directory check. Then, if you want to see what continuous CE readiness looks like from the MSP side, have a look at the Fig Group MSP compliance platform or the published pricing for certification if you need the certificate directly.
Talk to a certified assessor → | See MSP compliance-as-a-service → | View published pricing →
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Guides
Cyber Essentials Exeter: a practical certification guide
Cyber Essentials can help an Exeter organisation demonstrate a defined baseline of technical security. Before starting, establish whether you are responding to a contractual requirement or choosing certification as part of your own improvement programme. That decision affects the deadline and evidence a buyer expects, but not the national control standard.
Read articleCompliance
UK Cyber Essentials Certification Bodies Compared (2026)
There are dozens of IASME-licensed Cyber Essentials certification bodies. This guide compares them on price, turnaround, technology, and specialism to help you pick the right one.
Read articleCompliance
Do I Need DCC for MOD Contracts? MOD Asks Suppliers for DCC Level 0 by End of 2026
The MOD's Director of Cyber Defence and Risk, Eleanor Fairford, has asked all industry partners to achieve Defence Cyber Certification (DCC) Level 0 by 31 December 2026, including Cyber Essentials for business-critical systems. This guide explains what the MOD has actually said, who it affects, how DCC levels map to your contract, and what suppliers should do now - with the primary gov.uk sources.
Read article

