W
Reviewed by Jacob Whitmore, Whito · Fact-checked for accuracy

Last Updated on September 8, 2026

Your entire proposition is that a business should not simply trust its own judgement about security. It should have somebody independent check. Then most MSP websites ask to be trusted on exactly that basis.

There are two free, public, independent checks in this sector. Publishing yours and teaching buyers to run them is the cheapest differentiation available.

Check one: the ICO register

ICO registration and the data protection fee are statutory, made under the Data Protection (Charges and Information) Regulations 2018. The register is public and searchable by registration reference, organisation name or postcode, and a full register of fee payers can be downloaded. Controllers are officially registered from the date payment is received.

TierWhoFee
Tier 1, microMaximum turnover of £632,000 or no more than 10 members of staff£52
Tier 2, small and mediumMaximum turnover of £36 million or no more than 250 staff£78
Tier 3, largeEveryone above tier 2£3,763

There is an automatic £5 discount for direct debit. Public authorities are assessed on staff numbers only, and charities and small occupational pension schemes pay tier 1.

The penalties are where it becomes a conversation with a client:

TierFixed penalty for non-payment
Tier 1£400
Tier 2£600
Tier 3£4,000
Statutory maximum£4,350 where a controller fails to provide enough information to determine the right fee

Those are issued under section 155 of the Data Protection Act 2018, and the ICO can issue a notice of intent 28 days after expiry. A £52 obligation carrying a £400 penalty is a good, small, concrete compliance point, and checking a prospect’s registration before a meeting is a legitimate and useful thing to do.

Check two: the Cyber Essentials certificate search

IASME is the NCSC’s official Cyber Essentials delivery partner, working through a network of over 400 certification bodies. Published certification fees, all excluding VAT:

Organisation sizeCyber Essentials fee
Micro, 0 to 9 employees£320 plus VAT
Small, 10 to 49£440 plus VAT
Medium, 50 to 249£500 plus VAT
Large, 250 plus£600 plus VAT

Cyber Essentials Plus is a technical audit of your IT systems, priced according to the size and complexity of your network, and its cost is not published. NCSC corroborates the £320 entry price and adds that organisations under £20 million turnover achieving full certification receive free cyber liability insurance.

Volumes, from NCSC’s own brochure: the 200,000th certificate was awarded by 2024, and between 1 April 2024 and 31 March 2025 there were 37,298 Cyber Essentials certificates and 11,950 Cyber Essentials Plus certificates issued, a 19 per cent year-on-year increase.

The twelve month window, which is the interesting bit

IASME’s public certificate search lets anyone search by name or certificate number for organisations holding a certificate issued in the last 12 months. It also states plainly that the search is solely for checking certification and must not be used for marketing, data research or any other purpose.

Two consequences. First, a lapsed certificate disappears entirely, so appearing in that search is a live signal rather than a historic claim, which makes it worth more than most credentials. Second, respect the marketing restriction. Scraping that search for prospects is both against the stated terms and a bad look for a firm selling security.

How to publish yours

  1. ICO registration number, as text, with a link to the register search.
  2. Cyber Essentials or Plus, the date achieved, and a link to the IASME search so the buyer can confirm it is current.
  3. ISO 27001 if held, with the certification body named and the certificate number. UKAS accredits certification bodies rather than companies and publishes a free searchable list of them.
  4. NCSC Cyber Advisor status if you hold it, which is assured to provide general cyber security advice and support.
  5. Your own insurer and cover level for professional indemnity and cyber liability.

Then write the page that teaches a buyer to run those checks on anybody. It is genuinely useful content, it costs you nothing, and it sets a standard that a less rigorous competitor will quietly fail.

What is not a register, and should not be presented as one

Three honest limits.

PCI DSS is contractual, not statutory. The PCI Security Standards Council states that whether an entity must comply or validate compliance is at the discretion of organisations managing compliance programmes, such as a payment brand or acquirer. It applies to entities storing, processing or transmitting cardholder data. It is not a licence.

ISO 27001 has no published certification cost from ISO, which sells the standard document itself for 155 Swiss francs. That is a document price in a foreign currency and must never be presented as the cost of certification.

The NCSC CHECK scheme page returned an error when we tried it, so nothing about CHECK is stated in this guide.

What is coming

The Cyber Security and Resilience (Network and Information Systems) Bill was introduced in the Commons on 12 November 2025 and expands the regulations to include managed service providers, defined in the Commons Library briefing as organisations that provide third-party IT services to other businesses.

We could not confirm the Bill’s current stage: the briefing we opened was last updated on 8 July 2026 and lists report stage and third reading for 10 June 2026. The number of MSPs expected to be in scope is not published in that briefing.

So the honest position is that MSPs are currently unregulated as MSPs, and that is on course to change. A provider that is already publishing its registrations and certificates will find the transition considerably easier than one that is not.

Common questions

Does an MSP have to be registered with the ICO?

If it processes personal data as a controller it will generally need to pay the data protection fee, which is statutory. Fees are £52, £78 or £3,763 by tier, with fixed penalties for non-payment of £400, £600 and £4,000 under section 155 of the Data Protection Act 2018.

How much does Cyber Essentials cost?

£320 plus VAT for 0 to 9 employees, £440 for 10 to 49, £500 for 50 to 249 and £600 for 250 plus. Cyber Essentials Plus is priced by network size and complexity and is not published.

Can I check whether a supplier holds Cyber Essentials?

Yes, free, through IASME’s certificate search by name or certificate number, covering certificates issued in the last 12 months. IASME states the search must not be used for marketing or data research.

Where does your own business stand?

The structural checks behind this research run on any website in about twenty seconds. Enter yours and read the full result on the page. Free, and we do not ask for your email.

Run the free Visibility Check
author avatar
Whito
Whito is an independent UK research bureau. We ask the AI engines what they recommend, then check the businesses they name against Companies House and the sector registers. Figures we publish carry the date they were checked. Companies cannot pay to appear or to rank.