Skip to content
Compliance

Cyber Essentials with Outsourced IT: Who Does What?

Your MSP can complete the Cyber Essentials self-assessment for you. Learn what your organisation must review, authorise and sign off before submission.

A person installing a graphics card into a co

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

8 min read

Share

You can get Cyber Essentials certification when your IT is outsourced. Your managed service provider (MSP) can complete the self-assessment on your behalf, provided your organisation reviews and authorises the submission and provides its sign-off in the Cyber Essentials assessment portal. Your business remains responsible for its application. A certificate held by your provider does not automatically certify your organisation.

A customer asks for your Cyber Essentials certificate. You forward the request to the company that manages your laptops and email. They confirm that they can help, but need you to answer questions about your business first.

This is where a clear division of work matters. Your provider understands the systems it manages. You understand how the business operates, which services staff use and what the customer has requested. Bringing those two views together makes the application easier to complete accurately.

This guide explains how to organise that work with an existing provider, whether it is a managed service provider (MSP), an IT support company or an external consultant.

Section 01

Does your IT provider's Cyber Essentials certificate cover you?

No, not automatically. Check which legal entities and systems the certificate actually covers. Buying IT support from a certified provider is not evidence that your own business has been assessed.

IASME's April 2026 scheme update explains that the legal entities included in an assessment must be identified. If someone says your business is already covered, ask for the certificate and its scope, and confirm that your organisation is included. A provider's logo or sales statement is not enough.

If your customer requires a certificate for your organisation and you are not included in an existing certified scope, you will need to arrange the appropriate assessment. Start by confirming whether the customer has requested Cyber Essentials or Cyber Essentials Plus.

Section 02

Can your MSP complete the self-assessment for you?

Yes. Your MSP can complete the self-assessment on your organisation's behalf. Your organisation must review the completed answers, authorise submission and provide its own sign-off in the Cyber Essentials assessment portal.

The declaration must be approved by a board member or equivalent from your organisation. If you are a sole trader, that is you. IASME's guide to starting Cyber Essentials explains the assessment-platform process and this declaration requirement. The MSP completing the questionnaire does not replace your organisation's review and sign-off.

Your business, your IT provider and the certification body have different roles. IASME's guidance on working with a third-party IT provider makes clear that outsourcing IT does not transfer the applicant's responsibility for meeting the requirements.

The following is a practical allocation of work. Agree it with your provider before starting; it is not an additional scheme requirement or a substitute for your service contract.

WhoRole in your application
Your businessConfirm the customer requirement and business details, review the completed answers, authorise submission and provide the required sign-off in the assessment portal. Approve expenditure and own the renewal date.
Your IT providerComplete the self-assessment on your behalf where agreed, explain the systems it manages and carry out agreed fixes. Confirm any work or services outside its support agreement.
Certification bodyAgree the assessment scope, assess the application and explain its findings. Award certification when the applicable requirements are met.

Name one person inside the business to coordinate the application. Give that person a named technical contact at the provider. A shared list of unanswered questions is easier to manage than separate email threads between sales, finance and IT.

Section 03

What should you ask your IT provider to prepare?

Ask for information about your environment, with a date and a clear description of what it covers. A general statement that the provider follows good security practice will not tell you whether a particular answer is accurate for your business.

IASME publishes free assessment questions that you can use before purchasing an assessment. For applications purchased from 27 April 2026, the question set is called Danzell and the technical requirements are version 3.3. Use the version applicable to your application.

As a preparation exercise, ask your provider for:

  • Its coverage: which devices, networks and cloud services it manages for you, and which it does not.
  • Its technical answers: responses to the relevant current assessment questions, with an explanation wherever the answer depends on how your business works.
  • Supporting information: relevant configuration reports, service records or other information that helps you understand those answers.
  • Outstanding work: anything still to be checked or corrected, who will do it and the expected completion date.
  • Commercial arrangements: whether preparation, fixes and responses to assessor queries are included in your support agreement or charged separately.

These are suggested working records, not a mandatory evidence pack in a prescribed format. Cyber Essentials is a verified self-assessment; the certification body can request further information where needed. Keep sensitive technical records in an agreed secure location and share only what is needed for the assessment.

IASME also provides a question list for third-party IT providers. It is a useful conversation starter, used alongside the current assessment documents.

Section 04

Check the boundary of your provider's service

The list of services on your IT support invoice may not describe everything your business uses. Before sending the questionnaire to your provider, ask each department about the tools it has purchased or adopted independently.

For example, an IT company might manage your laptops and email while your finance team administers accounting software and your sales team manages a separate customer database. Record who can answer for each service. This is an illustrative scenario, not a customer case study.

The NCSC requirements, section D, make several distinctions relevant to outsourced IT:

  • Cloud services hosting your organisation's data or services must be included in scope.
  • Accounts your organisation owns remain in scope when a provider uses them to support your infrastructure.
  • Devices your organisation owns and lends to a third party are in scope. Devices owned by an external MSP and used by its administrators are outside your assessment scope.
  • You must still confirm appropriate configuration for third-party devices interacting with your data or services, including those outside the assessment scope.

Ask the certification body to resolve uncertainty about your arrangements before assessment begins. This is particularly useful where several suppliers share responsibility for a service.

Section 05

Turn assurances into answers you can review

You do not need to become a systems administrator to coordinate certification. You do need to understand what your provider has confirmed and whether anything remains unresolved.

Three follow-up questions can make the discussion more useful:

“Which services does that answer cover?” If the provider confirms multi-factor authentication for your email system, ask who will check the other cloud services. Under the current scheme, MFA must be implemented for cloud services where it is available, including paid options. See IASME's explanation of the April 2026 changes.

“Has the work been completed?” Keep proposed changes separate from settings already in place. Ask for a completion date and confirmation after the work is done, rather than treating an accepted quotation as evidence of implementation.

“What is outside our support agreement?” Agree who will investigate a service the provider does not manage. An unresolved ownership question can otherwise remain unnoticed until the application needs an answer.

Avoid rewriting a technical answer merely to make it sound more reassuring. Where the evidence and the proposed answer differ, resolve the underlying issue with the provider.

Section 06

A briefing you can send to your IT provider

Adapt the following message to your circumstances. It is an original working template, not an IASME form.

We are preparing a Cyber Essentials application for [legal entity]. Our customer has requested [Cyber Essentials or Cyber Essentials Plus] by [date]. Please confirm your availability to support preparation and respond to assessment queries.

Please review the applicable question set against the services you manage for us. Identify what you can answer, what information you need from us and any systems outside your support agreement.

For any outstanding work, please provide a proposed owner, cost and completion date. Please distinguish controls already implemented from changes that are still planned.

Our internal coordinator is [name]. Please confirm whether you will complete the self-assessment on our behalf. We will review the completed answers, authorise submission and provide the required sign-off in the Cyber Essentials assessment portal. Please also confirm how we should share supporting information securely.

Send the provider the actual customer requirement as well as your summary. If it specifies Plus, the provider will also need to coordinate access and availability for technical testing with the assessor.

Section 07

What changes if the customer requires Cyber Essentials Plus?

Cyber Essentials Plus assesses the same controls but adds independent technical testing. Outsourcing IT does not, by itself, determine which level you need. Check the customer's stated requirement and your assurance objectives. IASME's assessment FAQs explain the distinction.

For Plus, arrange a planning discussion between your provider and the certification body. Confirm the agreed scope, testing arrangements, technical contacts and how any disruption will be managed. Your provider should understand the access the assessor needs before the appointment.

For a fuller comparison, see our guide to Cyber Essentials and Cyber Essentials Plus.

Section 08

Before you submit, complete a business review

Read the application with the person who will sign it. IASME requires a senior declaration confirming the answers; its current scheme also makes the obligation to maintain the controls throughout the certification period explicit. IASME's declaration guidance explains this responsibility.

Use these final checks to organise that review:

1. The business named in the application is the one that needs certification.

2. The description of how your organisation works matches reality, including services managed outside the main IT agreement.

3. Questions passed between your team and the provider have been resolved.

4. Work described as complete has actually been completed.

5. The organisation has authorised submission, and the board member or equivalent understands the answers and has provided the required sign-off in the Cyber Essentials assessment portal.

After certification, put the renewal date in your business calendar and agree how your provider will report relevant changes or problems. Cyber Essentials certificates expire after 12 months; IASME confirms the renewal requirements. Certification does not guarantee that an organisation is free from vulnerabilities, as the scheme terms make clear.

Section 09

Arrange your Cyber Essentials assessment with Fig

You can retain your existing IT provider and use Fig for certification. Fig Compliance Ltd, part of Fig Group, is an IASME-licensed certification body; see our licence information.

If you are ready to apply, view Cyber Essentials certification options. If responsibilities or scope are still unclear, contact Fig with your organisation name, the certification level requested and your deadline. That gives us a practical starting point for discussing your assessment.

Keep preparation time separate from assessment turnaround when planning a customer commitment. Any technical fixes, information gathering and provider scheduling need to be allowed for before a complete application can be assessed.

Sources checked on 4 September 2026. This guide addresses preparation with outsourced IT; use the official requirements and question set applicable to your assessment.

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.