Skip to main content
    NixInfinity-AI
    Shared Responsibility

    Customer Devices vs Provider Infrastructure: Who Is Responsible for Cyber Essentials?

    Published 18 August 2026

    The principle: control determines responsibility

    Cyber Essentials follows operational control. Whoever patches, configures, holds the admin password and would be at fault if it failed owns that control for CE purposes. That is true whether the technology is on-prem, virtualised or cloud-hosted.

    Responsibility matrix

    ElementProvider (MSP / VDI / SaaS)Customer
    Hosted infrastructureYesNo
    Hypervisors (provider-operated)YesNo
    Hosted network and segmentationYesNo
    Management plane / tenant consoleProvider-sideCustomer-side
    Engineer / support administrator accountsYesNo
    End-user devices (laptop, thin client, BYOD)NoYes
    Customer identity providerNo*Yes
    Customer administrator accountsNoYes
    User session activity / data inside sessionNoYes
    Backups of customer dataDepends on contractDepends on contract

    *Unless the provider operates the IdP on the customer's behalf, in which case it joins their scope.

    Where responsibility commonly gets confused

    • Admin endpoints: the provider's engineer laptop is the provider's responsibility; the customer's IT admin laptop is the customer's.
    • Identity: if the provider hosts the IdP, it is theirs; if the customer brings their own (e.g. Entra ID tenant), it is theirs.
    • Backups: contract language decides. Make sure the contract is explicit – assume nothing.
    • Patching of VDI desktops: the provider patches the gold image; the customer is responsible for what users do in persistent sessions if persistence is offered.

    What this means for your certificate

    Each party needs their own certificate covering their own scope. The provider's certificate does not cover the customer – see why a supplier certificate does not cover customers. The customer's certificate does not cover the provider's infrastructure.

    How to evidence responsibility cleanly

    1. Maintain a written shared responsibility matrix between provider and customer
    2. Reference it in contracts and onboarding documents
    3. Refresh it at every contract renewal or scope change
    4. Reflect it accurately in both parties' CE scope statements

    If you provide hosted services commercially, see CE for MSPs offering VDI.

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions