Skip to main content
    NixInfinity-AI
    MSPs and Providers

    Cyber Essentials for MSPs Offering VDI or Hosted Desktop Services

    Published 17 August 2026

    The MSP scoping problem

    MSPs run a mixture of their own infrastructure, shared infrastructure used by multiple customers, and infrastructure owned by individual customers. CE scope follows operational control – what you patch, who you give admin to, whose certificate it would breach if it failed. Drawing those lines clearly is the difference between a clean certificate and a misleading one.

    What is in the MSP's scope

    • Provider-owned VDI infrastructure (broker, gateway, image management, profile services)
    • Hypervisors and management consoles operated by the MSP
    • Hosted network used to deliver the service
    • Administrator endpoints (engineer laptops, jump boxes)
    • MSP-side privileged accounts, including any "support" account that can reach customer systems
    • Backup, monitoring and patching tools that touch in-scope systems

    What is normally in the customer's scope

    • End-user devices (laptops, thin clients, BYOD) used to launch sessions
    • Customer-owned admin accounts and self-service consoles
    • Customer data inside the hosted environment
    • Customer identity provider (where the customer operates it)

    See the wider responsibility split in customer devices vs provider infrastructure.

    Privileged access – the riskiest control

    MSP engineers typically have wide privileged access into customer environments. CE expects:

    • MFA on every privileged account
    • Separation between day-to-day and privileged accounts
    • Documented joiner/mover/leaver process for engineers
    • Privileged access only from managed admin endpoints
    • Just-in-time elevation where practical

    Customer-facing claims to get right

    Acceptable: "MSP Ltd is Cyber Essentials certified for our hosted desktop platform, administrator endpoints and supporting infrastructure."

    Not acceptable: "All of our customers are Cyber Essentials certified through our service." For the marketing-language detail, see how providers can market CE honestly.

    Common MSP scoping mistakes

    • Excluding RMM and PSA tools that have privileged access into customer estates
    • Forgetting backup platforms holding customer data
    • Implying customer environments are certified by association
    • Engineer laptops not enrolled in management because "they're just admin"
    • Support accounts without MFA

    The longer-term path for MSPs

    CE is a baseline for MSPs. Operational maturity, supplier obligations and tender expectations usually push MSPs toward Cyber Assurance or ISO 27001 within 12–18 months. Treat CE as the foundation, not the destination.

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions