Cyber Essentials for MSPs Offering VDI or Hosted Desktop Services
Published 17 August 2026
The MSP scoping problem
MSPs run a mixture of their own infrastructure, shared infrastructure used by multiple customers, and infrastructure owned by individual customers. CE scope follows operational control – what you patch, who you give admin to, whose certificate it would breach if it failed. Drawing those lines clearly is the difference between a clean certificate and a misleading one.
What is in the MSP's scope
- Provider-owned VDI infrastructure (broker, gateway, image management, profile services)
- Hypervisors and management consoles operated by the MSP
- Hosted network used to deliver the service
- Administrator endpoints (engineer laptops, jump boxes)
- MSP-side privileged accounts, including any "support" account that can reach customer systems
- Backup, monitoring and patching tools that touch in-scope systems
What is normally in the customer's scope
- End-user devices (laptops, thin clients, BYOD) used to launch sessions
- Customer-owned admin accounts and self-service consoles
- Customer data inside the hosted environment
- Customer identity provider (where the customer operates it)
See the wider responsibility split in customer devices vs provider infrastructure.
Privileged access – the riskiest control
MSP engineers typically have wide privileged access into customer environments. CE expects:
- MFA on every privileged account
- Separation between day-to-day and privileged accounts
- Documented joiner/mover/leaver process for engineers
- Privileged access only from managed admin endpoints
- Just-in-time elevation where practical
Customer-facing claims to get right
Acceptable: "MSP Ltd is Cyber Essentials certified for our hosted desktop platform, administrator endpoints and supporting infrastructure."
Not acceptable: "All of our customers are Cyber Essentials certified through our service." For the marketing-language detail, see how providers can market CE honestly.
Common MSP scoping mistakes
- Excluding RMM and PSA tools that have privileged access into customer estates
- Forgetting backup platforms holding customer data
- Implying customer environments are certified by association
- Engineer laptops not enrolled in management because "they're just admin"
- Support accounts without MFA
The longer-term path for MSPs
CE is a baseline for MSPs. Operational maturity, supplier obligations and tender expectations usually push MSPs toward Cyber Assurance or ISO 27001 within 12–18 months. Treat CE as the foundation, not the destination.
