Your Cyber Essentials Certificate Does Not Cover Your Customers
Published 19 August 2026
The two directions of the misconception
Direction 1: "My provider is certified, so I am covered"
The provider's certificate covers the infrastructure they operate. It does not certify your laptops, your administrator accounts, your identity tenant or the data you put into their platform. Buyers who rely on a supplier's certificate to skip their own assessment are mis-reading the scheme.
Direction 2: "We are certified, so our customers are too"
If you are a SaaS, VDI or MSP provider, your certificate covers your scope. It says nothing about how each customer manages their endpoints, identity or data. Marketing copy that implies otherwise is misleading.
Practical implications for buyers
- You still need to scope and certify your own IT estate
- You still need to evidence MFA, patching, secure config and access control on the systems you control
- You still need to apply the CE controls to the device you use to access the supplier's platform
- You can rely on the supplier's certificate as assurance for the infrastructure side only
For the responsibility split, see customer devices vs provider infrastructure.
Practical implications for providers
- Your scope statement must explicitly say what is excluded (e.g. "customer-owned end-user devices")
- Your marketing must reflect the certificate scope, not over-extend it
- Tender responses should attach the certificate and quote the scope wording verbatim
- Sales teams should be briefed on what they cannot say
For the wording detail, see how providers can market CE honestly.
Sectors where this confusion bites
- VDI / hosted desktop: customer endpoints are theirs to certify
- SaaS: customer admin accounts and identity sit in the customer's scope
- MSPs: support and engineer access is provider-side; everything customer-owned remains the customer's
- Cloud hosting: tenant configuration and admin accounts are customer-side
- Outsourced IT: the outsourcer's certificate covers their scope; you still need your own
How to evidence cleanly in a tender response
- Attach your own CE/CE+ certificate with the scope visible
- Attach key suppliers' certificates separately, again with scope visible
- Provide a one-page shared responsibility matrix showing who covers what
- Avoid any "all-encompassing" wording about supplier certificates covering the whole chain
For the wider supplier assurance approach, see supplier cyber assurance without overcomplicating it.
