NCSC MSP Due Diligence Checklist for UK SMEs

The NCSC's MSP due diligence checklist helps UK SMEs evaluate managed service providers. This guide breaks down each checkpoint in plain English.

Quick summary

If you run a UK SME, your IT provider now has more power over your business than almost anyone else. When their systems fail or their security is weak, your staff cannot work. Orders stall. Your reputation can take a hit in hours, not weeks.

The UK's National Cyber Security Centre (NCSC) - the government body that deals with cyber security - has published guidance and an MSP due diligence checklist to help you ask better questions of managed service providers (MSPs). The challenge is simple: questions are easy to ask, but the answers can be almost impossible to verify if you are not technical.

This article turns that checklist into plain-English questions, examples and steps you can actually use with your current or future MSP, and explains how Assurix helps you move from promises to proof. By the end, you will know exactly which questions to ask and what "good" looks like from an MSP.

1. What the NCSC is really trying to protect you from

The NCSC guidance is not about turning you into a cyber expert. It is about stopping some very specific business problems. In practice, that means avoiding things like:

Criminals now target MSPs because breaking into one provider can open doors into dozens or hundreds of SMEs. The NCSC checklist recognises this and asks you to apply a bit more healthy scepticism when you choose or review an MSP.

The Core Question

Is this MSP actually keeping us safe and resilient, or are we just hoping for the best?

2. What the NCSC MSP guidance really means in plain English

The formal NCSC MSP due diligence checklist is broken into four broad areas: choosing an MSP, services to request, contract and agreement considerations, and risk and responsibility.

Underneath the detail, it is really helping you do five things. Think of it as a buyer's guide for your IT provider.

1. Avoid blind trust

Move from "we get on well with our IT guy" towards "we have seen clear proof the basics are being done properly."

2. Be clear on who does what

Your contract should spell out which systems are covered, what your MSP looks after, and what still sits with you.

3. Make sure the basics are solid

Timely security updates, working backups, tested restore procedures, MFA, incident response - the dull but vital basics.

4. Check your MSP looks after its own house

The NCSC wants your MSP to manage risks from its own suppliers, train staff properly and have its own tested recovery plans.

5. Plan for bad days as well as good ones

If something serious happens, you need to know what will actually happen in the first few hours and days, not just what a policy document says.

You do not need to memorise the checklist. You just need to turn these ideas into practical questions and a short, focused conversation.

3. What "good" looks like when you talk to an MSP

When you start asking tougher questions, the way an MSP responds tells you as much as the words themselves.

How strong MSPs behave

Signs of a solid MSP:

Warning signs and weak answers

Red flags to watch for:

You do not need to "catch them out". Just notice whether the conversation leaves you with more clarity and confidence, or more question marks.

4. Questions that separate solid MSPs from smooth talkers

Here are seven practical questions you can copy and paste into an email or meeting invite for your MSP. They are aligned with the spirit of the NCSC MSP due diligence checklist.

You can ask them even if you are not technical. Focus on the shape of the answer, not the jargon.

1) How do you keep our systems up to date with security patches, and how can you show us that this is working each month?

✓ Reassuring answer: They describe a regular process, mention timeframes for critical patches, and offer simple reports or dashboards showing patch coverage for your devices.

✗ Red flag: "Windows updates are automatic; you do not need to worry about it" with no data or reporting.

2) What does our backup and recovery setup look like in practice, and when did you last test restoring our data?

✓ Reassuring answer: They can tell you where backups are stored, how long data is kept, and when they last did a test restore (including how long it took).

✗ Red flag: "Backups run every night" but they cannot tell you when they last proved they could restore from them.

3) If we had a serious incident on a Monday morning (for example, ransomware), what would the first four hours look like from our side?

✓ Reassuring answer: They talk through a clear incident response plan, who contacts whom, expected communication frequency, and realistic recovery expectations.

✗ Red flag: "We would jump on it straight away" with no mention of roles, timeframes, or how they keep you informed.

4) Who has administrator-level access to our systems (both in your team and ours), and how do you control and review that access?

✓ Reassuring answer: They maintain an access list, use multi-factor authentication (MFA) on admin accounts, review access regularly and remove it promptly when people change roles or leave.

✗ Red flag: "Only trusted staff have access" but there is no formal list, no reviews and no mention of MFA.

5) Which security standards or certifications do you follow (for example Cyber Essentials Plus or ISO 27001), and how does that show up in how you run our account?

✓ Reassuring answer: They can name the frameworks or certifications they use and explain, in plain English, how that turns into controls and checks you benefit from.

✗ Red flag: "We are working towards something" or "we follow best practice" with no specifics or clear link to your service.

6) What regular reporting could you give our board so we can see that patching, backups, monitoring and incidents are under control?

✓ Reassuring answer: They suggest a simple monthly or quarterly pack or dashboard with a small number of clear metrics, such as patch compliance, backup success, key alerts and incident summaries.

✗ Red flag: "You can always ask us if you want to know anything" but nothing systematic you could show to directors, insurers or customers.

7) If we ever decide to switch provider, how would you hand everything over and remove your access safely?

✓ Reassuring answer: They have a documented offboarding process, including handing over documentation, transferring admin accounts and confirming that their access has been removed.

✗ Red flag: Vague answers about "helping where we can" or no clear process to cleanly separate.

You do not need to ask all of these at once. Even picking two or three will tell you a lot about how mature and transparent your MSP really is.

5. How to use the NCSC checklist without getting overwhelmed

You do not need to turn this into a major project or a fifty-page audit. Treat it as a short, focused review of one of your most important suppliers.

Here is a simple way to use the NCSC MSP checklist and the questions above:

Monthly Review Checklist

This is exactly how the NCSC expects SMEs to use its checklist: not as a tick-box exercise, but as a way to have better conversations and make clearer decisions.

6. From promises to proof: where Assurix fits in

The NCSC checklist helps you ask better questions. Assurix is designed to help your MSP provide better, ongoing answers.

Assurix is an independent trustmark and governance platform for MSPs. To become an Assurix Trusted MSP, a provider has to evidence day to day controls around things like patch compliance, backups, multi-factor authentication, security monitoring, incident response, supplier management and staff training. These checks are aligned with UK government frameworks such as the Cyber Assessment Framework (CAF) and, crucially, they run continuously rather than as a one-off audit.

Real-time

Continuous monitoring, not annual audits

Independent

Third-party verification you can trust

Plain English

Non-technical dashboards for boards

In practice, that means:

For you as an SME, you do not need to learn the technical detail. You get simple, non-technical views of whether your MSP is meeting agreed security and operational standards, and where there are gaps.

Independent Proof

If your current MSP does not use Assurix, you can still borrow the mindset. Ask them how they would show, in a clear dashboard or short report, that they are on top of patching, backups, access control, monitoring and incident response.

7. Choose one question this week

You do not have to fix everything this week. Start small.

Pick one question from this article and ask your MSP in the next seven days. See how they respond and how you feel afterwards.

Then:

Looking for an Assurix Trusted MSP?

Our directory helps SMEs find IT providers who can prove they meet the standards the NCSC recommends.

Find a Trusted MSP


Appendix: For SMEs and MSPs who want the detail on how Assurix maps to the NCSC MSP checklist

If you are an SME leader who wants to see "what is under the bonnet", or an MSP who wants to understand the wiring in more depth, this appendix is for you. It shows, at a high level, how the Assurix framework lines up with the NCSC MSP due diligence checklist, so you can see how the practical questions in the main article map to specific controls and checks.

The aim is simple: when NCSC-style questions come up, you can point to a structured, independently verified framework rather than just assurances.

For MSPs and detail-minded SMEs, this appendix is your shortcut: if you are Assurix-aligned, you can confidently say, "Yes, we meet these standards, and here's the evidence."

Related reading