Shared Responsibility
Customer Devices vs Provider Infrastructure: Who Is Responsible for Cyber Essentials?
Published 18 August 2026
The principle: control determines responsibility
Cyber Essentials follows operational control. Whoever patches, configures, holds the admin password and would be at fault if it failed owns that control for CE purposes. That is true whether the technology is on-prem, virtualised or cloud-hosted.
Responsibility matrix
| Element | Provider (MSP / VDI / SaaS) | Customer |
|---|---|---|
| Hosted infrastructure | Yes | No |
| Hypervisors (provider-operated) | Yes | No |
| Hosted network and segmentation | Yes | No |
| Management plane / tenant console | Provider-side | Customer-side |
| Engineer / support administrator accounts | Yes | No |
| End-user devices (laptop, thin client, BYOD) | No | Yes |
| Customer identity provider | No* | Yes |
| Customer administrator accounts | No | Yes |
| User session activity / data inside session | No | Yes |
| Backups of customer data | Depends on contract | Depends on contract |
*Unless the provider operates the IdP on the customer's behalf, in which case it joins their scope.
Where responsibility commonly gets confused
- Admin endpoints: the provider's engineer laptop is the provider's responsibility; the customer's IT admin laptop is the customer's.
- Identity: if the provider hosts the IdP, it is theirs; if the customer brings their own (e.g. Entra ID tenant), it is theirs.
- Backups: contract language decides. Make sure the contract is explicit – assume nothing.
- Patching of VDI desktops: the provider patches the gold image; the customer is responsible for what users do in persistent sessions if persistence is offered.
What this means for your certificate
Each party needs their own certificate covering their own scope. The provider's certificate does not cover the customer – see why a supplier certificate does not cover customers. The customer's certificate does not cover the provider's infrastructure.
How to evidence responsibility cleanly
- Maintain a written shared responsibility matrix between provider and customer
- Reference it in contracts and onboarding documents
- Refresh it at every contract renewal or scope change
- Reflect it accurately in both parties' CE scope statements
If you provide hosted services commercially, see CE for MSPs offering VDI.
