Blog | CMS Distribution

Your customers don't read the NCSC. They read you.

Written by CMS Distribution | Oct 1, 2026, 12:21:03 PM

A client rings you, their managed service provider (MSP), in October because a contract they want requires Cyber Essentials, and asks how long it takes. You tell them not long. You have run their systems for six years and you know what is in there.

The government's own survey says you are right to be confident. When it asked UK businesses where their cyber security advice came from, 27% named an external IT or cyber provider, 4% named any government source, and 1% named the National Cyber Security Centre (NCSC). That is the Cyber Security Breaches Survey 2025/26 from the Department for Science, Innovation and Technology (DSIT), of 2,112 businesses. You are not competing with official guidance for your customers' attention. You have it already. You may not have anything that shows it.

The assessment

No client of ours is in what follows. The scheme rules inside it are exact.

Cyber Essentials is a self-assessment. Your client registers, which opens an assessment account, and that creation date decides which version of the rules they are marked against. Accounts opened from 27 April 2026 get the revised ones, with no transition period. Theirs is opened in October.

You work through the questionnaire. It asks whether multi-factor authentication (MFA) is enforced on every cloud service that offers it. MFA is on email. It is on the file sharing. It is not on the remote access tool, set up in 2021 by somebody who has since left and untouched since, because it has worked every day for five years.

You answer honestly, and you submit.

The fail

Under the revised rules that single gap is an automatic fail. It is not a score, and it is not a list of recommendations with a window to put them right. No assessor weighs six years of careful work against one tool nobody had a reason to open.

Your client asks you why.

Controls without the certificate

The government's breaches survey, the one where 1% of businesses named the NCSC, found something else. 24% of UK businesses already have all five of the scheme's technical controls, but only 5% hold the certificate. That means four in five firms with the controls have nothing that shows it.

Your client is typical of those firms. They were not careless, and neither were you. In six years nothing had asked anyone to prove the controls were in place, so one tool nobody had a reason to open stayed unchecked until the assessment. Some of your other clients are likely to be in the same position, and you can find their gaps before an assessor does.

Before you submit

There are two checks worth making, and both are free.

Which side of 27 April 2026 was the assessment account opened? That date decides which ruleset applies. Then: is MFA enforced on every cloud service that offers it, including whichever one nobody has opened since 2021?

Both checks take a morning per client. It is worth being plain about what passing gets your client. The certificate is not evidence that they are safer. It is their director's signed word, checked by an qualified assessor, that the controls are in place and will be kept that way for the year. That is a smaller claim than safety, and your work as their MSP is what makes it true.

We sell the fix

The trusted adviser and the seller of the remedy are the same party. That is the structural position of everyone in this channel, distributors included. The peer-reviewed work that established IT companies as the main advice route for micro and small firms says in the same breath that they "can also be part of the problem" (Cartwright, Cartwright and Edun, 2023).

The evidence that the advice works is thinner than we would like. A study of 5,872 UK firms across four survey waves found awareness of Cyber Essentials and the 10 Steps went with more secure practice, but found no evidence that firms implementing the recommended measures were less likely to be breached or harmed. One study, on data ending in 2021, and an absence of proof is not proof of absence. It is still the best there is.

What moves behaviour

Awareness is not what moves it, on the evidence of other trades. Front-seat belt wearing in the UK sat at around 40% through years of campaigning and reached around 95% after the law of 31 January 1983. That is an analogy rather than evidence about cyber, but the shape recurs: behaviour moves when advice becomes a condition of trade.

Those conditions are already arriving, and the April 2026 rules are one of them. The Cyber Security and Resilience Bill, which reached Grand Committee in the Lords on 1 September and is not law, would make a defined minority of MSPs regulated in their own right. If it passes, those providers would face the same question your client did: can you show it?

CMS vendors in this area

  • Acronis: patch management and endpoint protection for MSPs, managed from one console.
  • Barracuda: firewalls and email protection for businesses, and the same range packaged for MSPs to manage across their clients.
  • DrayTek: routers and firewalls for small and medium-sized businesses.
  • ESET: endpoint protection against malware, and multi-factor authentication.
  • SolarWinds: patch management and IT monitoring tools.
  • Swissbit: hardware security keys for multi-factor sign-in.

CMS Distribution distributes the vendors listed here. They appear alphabetically, and none paid for placement or reviewed this article.

Figures come from DSIT's Cyber Security Breaches Survey 2025/26 (2,112 businesses, fieldwork August to December 2025, self-reported, 13% adjusted response rate). The assessment process and the April 2026 changes come from the IASME Consortium's (Information Assurance for Small and Medium Enterprises) and the NCSC's published guidance; the April 2026 changes also made breaching the pre-existing 14-day rule on high and critical patches an automatic fail. Research findings are cited to their authors. The client is an illustration; the scheme rules and dates are exact. The photograph is generated rather than taken. No real person appears in it. The Cyber Security and Resilience Bill's status is taken from our source of record rather than from commentary: it is before the Lords, and Royal Assent is forecast rather than dated.