Thursday, 1 October 2026

Where technology leaders come to think out loud

ColumnThe Channel

Assurix’s first certified MSP shows where due diligence is heading

Assurix has certified its first UK MSP against a mark checked continuously, not once a year. But the badge will only pay partners who turn it into contract terms customers can enforce

Nick Haley, founder and managing director of Little Big Tech
Image: Little Big Tech
In brief
  • Small and medium businesses outsource cybersecurity heavily but rarely review the suppliers they hand it to, so continuous independent evidence fills a real gap.
  • Pressure for supplier proof is likely to reach mid-market MSPs through customers signing the government’s Cyber Resilience Pledge before regulation reaches them.
  • Partners should judge any privately run mark by what it verifies and who can see the result.

On 19 May 2026 Assurix, a UK startup that runs a trustmark for managed service providers, named London-based Little Big Tech as the first MSP to earn its mark. Ingenio Technologies became the second, according to IT Europa. Assurix says more than 80 UK MSPs have now committed to the standard, most of them already in assessment.

MSPs must pass 64 controls covering security and operational maturity, and the status is suspended publicly if standards slip, IT Channel Oxygen reported. Assurix said compliance is monitored continuously rather than through periodic reviews, and that its controls are mapped to the National Cyber Security Centre’s Cyber Assessment Framework (CAF), IT Europa reported. Assurix’s own case study of Little Big Tech presents the mark as independently verified evidence rather than claims.

Two certified firms is a small number in a large market. Assurix founder and chief executive Mit Patel, who ran an MSP for 20 years, told IT Channel Oxygen at the scheme’s launch in October 2025 that the UK has about 13,000 MSPs, and Assurix set a target of 1,500 members within five years. At launch, the publication reported that Assurix verifies controls through integrations with tools MSPs already use, including Microsoft 365, professional services automation (PSA), remote monitoring and management (RMM) and backup, and that MSPs out of compliance for more than 30 days would be suspended automatically. But the direction matters more than the count.

Many small businesses have handed their security to outside providers, and few check it. Continuous, independent evidence offers them a way to check, and the partners who write it into their contracts are likely to win work their competitors lose.

The buyer who doesn’t check

The government’s Cyber Security Breaches Survey 2025/2026, published on 30 April, shows how far smaller firms lean on outside help. Almost two-thirds (64%) of small businesses and 70% of medium businesses outsource cybersecurity, and the share of micro businesses doing so rose from 39% to 44% in a year.

Few of them look hard at what they have outsourced. Only 12% of micro businesses and 22% of small businesses formally review the cyber risks posed by their immediate suppliers. Across all businesses, 11% require suppliers to hold any standard or accreditation, and just 3% ask for Cyber Essentials. The survey’s interviews found MSPs were commonly used, especially by smaller organizations and often because of capacity constraints, with round-the-clock access seen as a significant advantage.

That is a lot of trust placed with very little evidence. Patel told IT Channel Oxygen that at the MSP Show 10 small businesses came to the Assurix stand unhappy with their MSPs, and that they saw the scheme as “a whole new way to understand how to choose an MSP”. A buyer who will never send a security questionnaire can still look at a live status page.

Pressure from the top of the supply chain

The pull will not come from small customers alone. On 12 May the government urged organizations to sign a Cyber Resilience Pledge, launching later in 2026, one of whose three actions is to require Cyber Essentials certification across their supply chains. Ministers have written to some of the UK’s leading companies inviting them to sign. Patel acknowledged to IT Channel Oxygen at launch that the Cyber Security and Resilience Bill, which continues through Parliament, would at first cover only the largest MSPs.

Regulation will take time to reach the MSP serving 50-person firms. Customer pressure may arrive sooner. When a pledge signatory asks its suppliers for proof, and those suppliers ask their own, an MSP serving the mid-market will face the question its smaller clients never put. A status that is checked continuously answers it faster than a folder of policies.

The contract behind the badge

For partners, the commercial value of a trustmark does not sit in a website footer. It sits in the contract. An MSP with live assurance can offer what a rival with a once-a-year certificate cannot: a service schedule that commits to keeping the mark, sets out what happens if it is suspended and gives the customer the right to check status whenever it likes. That turns evidence into a reason to pay more, and a reason not to switch.

There are limits. Any privately run mark is only as credible as its independence, its governance and the number of firms that hold it, and buyers will reasonably ask who checks the checker. Assurix’s model, with a paid waitlist, depends on MSPs choosing to join. Partners should judge it, and any rival scheme, on what is verified and who can see the result, not on the badge.

The certificate on the wall told customers that an MSP once passed a test. The next customer will want to know whether it is passing today.

AdvertisementZoomInfo

Get The VETTDD BriefingThe week in the technology channel, every week.

Subscribe free
Sources
  1. IT Europa, “Little Big Tech becomes first MSP to achieve Assurix trustmark”, 19 May 2026. https://www.iteuropa.com/news/little-big-tech-becomes-first-msp-achieve-assurix-trustmark
  2. IT Channel Oxygen, “MSP trustmark founder claims ‘90% get it’ as it verifies first MSP”, 19 May 2026. https://itchanneloxygen.com/msp-trustmark-founder-claims-90-get-it-as-it-verifies-first-msp/
  3. Assurix, “From ‘Trust My Story’ to ‘Here’s the Proof.’”, Little Big Tech case study (undated; sitemap last modified 6 May 2026). https://assurix.com/customers/little-big-tech
  4. Assurix, “Assurix Launches: A New Standard of Proof for the UK MSP Industry” (launch event 2 October 2025). https://assurix.com/resources/assurix-launch
  5. IT Channel Oxygen, “‘It’s easier to be an MSP than a hairdresser,’ MSP trustmark founder claims”, 2 October 2025. https://itchanneloxygen.com/its-easier-to-be-an-msp-than-a-hairdresser-msp-trustmark-founder-claims/
  6. DSIT and DCMS, “Cyber security breaches survey 2025/2026”, official statistics, 30 April 2026. https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026
  7. DSIT, “Government steps up action to strengthen cyber defences as UK cyber industry continues to grow”, press release, 12 May 2026. https://www.gov.uk/government/news/government-steps-up-action-to-strengthen-cyber-defences-as-uk-cyber-industry-continues-to-grow
About the author

Editor

The VETTDD editorial desk. Interviews, analysis, columns and news on the decisions shaping UK B2B technology.

More from Editor →