NCSC MSP Due Diligence Checklist for UK SMEs
The NCSC's MSP due diligence checklist helps UK SMEs evaluate managed service providers. This guide breaks down each checkpoint in plain English.
Quick summary
- The NCSC has published an MSP due diligence checklist to help you ask better questions.
- Questions are easy to ask; the answers can be impossible to verify if you are not technical.
- This article gives you plain-English questions and explains what "good" looks like.
- Assurix helps move from promises to proof with independent, ongoing verification.
If you run a UK SME, your IT provider now has more power over your business than almost anyone else. When their systems fail or their security is weak, your staff cannot work. Orders stall. Your reputation can take a hit in hours, not weeks.
The UK's National Cyber Security Centre (NCSC) - the government body that deals with cyber security - has published guidance and an MSP due diligence checklist to help you ask better questions of managed service providers (MSPs). The challenge is simple: questions are easy to ask, but the answers can be almost impossible to verify if you are not technical.
This article turns that checklist into plain-English questions, examples and steps you can actually use with your current or future MSP, and explains how Assurix helps you move from promises to proof. By the end, you will know exactly which questions to ask and what "good" looks like from an MSP.
1. What the NCSC is really trying to protect you from
The NCSC guidance is not about turning you into a cyber expert. It is about stopping some very specific business problems. In practice, that means avoiding things like:
- Long outages where your team cannot work because systems are down.
- Ransomware or data breaches that hit both your reputation and cashflow.
- MSPs who "sound" good in meetings but do not run solid security behind the scenes.
- You, as a director, being left unable to show insurers, regulators or customers that you took reasonable steps.
Criminals now target MSPs because breaking into one provider can open doors into dozens or hundreds of SMEs. The NCSC checklist recognises this and asks you to apply a bit more healthy scepticism when you choose or review an MSP.
The Core Question
Is this MSP actually keeping us safe and resilient, or are we just hoping for the best?
2. What the NCSC MSP guidance really means in plain English
The formal NCSC MSP due diligence checklist is broken into four broad areas: choosing an MSP, services to request, contract and agreement considerations, and risk and responsibility.
Underneath the detail, it is really helping you do five things. Think of it as a buyer's guide for your IT provider.
1. Avoid blind trust
Move from "we get on well with our IT guy" towards "we have seen clear proof the basics are being done properly."
2. Be clear on who does what
Your contract should spell out which systems are covered, what your MSP looks after, and what still sits with you.
3. Make sure the basics are solid
Timely security updates, working backups, tested restore procedures, MFA, incident response - the dull but vital basics.
4. Check your MSP looks after its own house
The NCSC wants your MSP to manage risks from its own suppliers, train staff properly and have its own tested recovery plans.
5. Plan for bad days as well as good ones
If something serious happens, you need to know what will actually happen in the first few hours and days, not just what a policy document says.
You do not need to memorise the checklist. You just need to turn these ideas into practical questions and a short, focused conversation.
3. What "good" looks like when you talk to an MSP
When you start asking tougher questions, the way an MSP responds tells you as much as the words themselves.
How strong MSPs behave
Signs of a solid MSP:
- Give clear, concrete answers without drowning you in jargon.
- Translate technical detail into business impact: "Here is what this means for uptime, data loss and your obligations."
- Show real evidence: reports, dashboards, test results, third-party checks.
- Use specific examples: "In March a client had X issue; here is how we found it and how long it took to fix."
- Be honest about gaps and trade-offs: "We do A and B now; we recommend adding C within six months."
Warning signs and weak answers
Red flags to watch for:
- Hide behind technical language and acronyms when you ask simple questions.
- Fall back on "trust us, we have it covered" without showing anything concrete.
- Blame your size or budget for everything: "We would do that if you were bigger or paid more."
- Struggle to show you when they last tested backups, restored data, or ran an incident exercise.
- Get defensive or uncomfortable when you ask about their own suppliers and internal security.
You do not need to "catch them out". Just notice whether the conversation leaves you with more clarity and confidence, or more question marks.
4. Questions that separate solid MSPs from smooth talkers
Here are seven practical questions you can copy and paste into an email or meeting invite for your MSP. They are aligned with the spirit of the NCSC MSP due diligence checklist.
You can ask them even if you are not technical. Focus on the shape of the answer, not the jargon.
1) How do you keep our systems up to date with security patches, and how can you show us that this is working each month?
✓ Reassuring answer: They describe a regular process, mention timeframes for critical patches, and offer simple reports or dashboards showing patch coverage for your devices.
✗ Red flag: "Windows updates are automatic; you do not need to worry about it" with no data or reporting.
2) What does our backup and recovery setup look like in practice, and when did you last test restoring our data?
✓ Reassuring answer: They can tell you where backups are stored, how long data is kept, and when they last did a test restore (including how long it took).
✗ Red flag: "Backups run every night" but they cannot tell you when they last proved they could restore from them.
3) If we had a serious incident on a Monday morning (for example, ransomware), what would the first four hours look like from our side?
✓ Reassuring answer: They talk through a clear incident response plan, who contacts whom, expected communication frequency, and realistic recovery expectations.
✗ Red flag: "We would jump on it straight away" with no mention of roles, timeframes, or how they keep you informed.
4) Who has administrator-level access to our systems (both in your team and ours), and how do you control and review that access?
✓ Reassuring answer: They maintain an access list, use multi-factor authentication (MFA) on admin accounts, review access regularly and remove it promptly when people change roles or leave.
✗ Red flag: "Only trusted staff have access" but there is no formal list, no reviews and no mention of MFA.
5) Which security standards or certifications do you follow (for example Cyber Essentials Plus or ISO 27001), and how does that show up in how you run our account?
✓ Reassuring answer: They can name the frameworks or certifications they use and explain, in plain English, how that turns into controls and checks you benefit from.
✗ Red flag: "We are working towards something" or "we follow best practice" with no specifics or clear link to your service.
6) What regular reporting could you give our board so we can see that patching, backups, monitoring and incidents are under control?
✓ Reassuring answer: They suggest a simple monthly or quarterly pack or dashboard with a small number of clear metrics, such as patch compliance, backup success, key alerts and incident summaries.
✗ Red flag: "You can always ask us if you want to know anything" but nothing systematic you could show to directors, insurers or customers.
7) If we ever decide to switch provider, how would you hand everything over and remove your access safely?
✓ Reassuring answer: They have a documented offboarding process, including handing over documentation, transferring admin accounts and confirming that their access has been removed.
✗ Red flag: Vague answers about "helping where we can" or no clear process to cleanly separate.
You do not need to ask all of these at once. Even picking two or three will tell you a lot about how mature and transparent your MSP really is.
5. How to use the NCSC checklist without getting overwhelmed
You do not need to turn this into a major project or a fifty-page audit. Treat it as a short, focused review of one of your most important suppliers.
Here is a simple way to use the NCSC MSP checklist and the questions above:
Monthly Review Checklist
- Book a 30-minute review with your MSP. Make it clear this is about assurance, not blame.
- Send three to five of the questions in advance. Let them know you want plain-English answers and examples.
- Ask for one or two pieces of real evidence. Start with basics like a patching report or backup success report.
- After the meeting, decide: stay as you are, ask your MSP to raise their game, or start exploring alternatives.
- Put MSP assurance on the agenda twice a year alongside insurance renewal and budget reviews.
This is exactly how the NCSC expects SMEs to use its checklist: not as a tick-box exercise, but as a way to have better conversations and make clearer decisions.
6. From promises to proof: where Assurix fits in
The NCSC checklist helps you ask better questions. Assurix is designed to help your MSP provide better, ongoing answers.
Assurix is an independent trustmark and governance platform for MSPs. To become an Assurix Trusted MSP, a provider has to evidence day to day controls around things like patch compliance, backups, multi-factor authentication, security monitoring, incident response, supplier management and staff training. These checks are aligned with UK government frameworks such as the Cyber Assessment Framework (CAF) and, crucially, they run continuously rather than as a one-off audit.
Continuous monitoring, not annual audits
Third-party verification you can trust
Non-technical dashboards for boards
In practice, that means:
- The same areas the NCSC tells you to ask about are monitored and measured in the background.
- Your MSP can show your board and your insurer structured, repeatable evidence that they are doing what they say they are doing.
- Assurix treats the NCSC checklist as a baseline and then adds extra depth around governance, roles and operational discipline over time.
For you as an SME, you do not need to learn the technical detail. You get simple, non-technical views of whether your MSP is meeting agreed security and operational standards, and where there are gaps.
Independent Proof
If your current MSP does not use Assurix, you can still borrow the mindset. Ask them how they would show, in a clear dashboard or short report, that they are on top of patching, backups, access control, monitoring and incident response.
7. Choose one question this week
You do not have to fix everything this week. Start small.
Pick one question from this article and ask your MSP in the next seven days. See how they respond and how you feel afterwards.
Then:
- Keep a copy of the NCSC MSP checklist and this set of questions with your IT contracts and board papers, so they do not disappear into a drawer.
- Add "MSP assurance" as a standing topic on your leadership or risk agenda at least twice a year.
- Include one simple line when you book your MSP review: "Are you Assurix Trusted, or planning to be?"
Looking for an Assurix Trusted MSP?
Our directory helps SMEs find IT providers who can prove they meet the standards the NCSC recommends.
Find a Trusted MSPAppendix: For SMEs and MSPs who want the detail on how Assurix maps to the NCSC MSP checklist
If you are an SME leader who wants to see "what is under the bonnet", or an MSP who wants to understand the wiring in more depth, this appendix is for you. It shows, at a high level, how the Assurix framework lines up with the NCSC MSP due diligence checklist, so you can see how the practical questions in the main article map to specific controls and checks.
The aim is simple: when NCSC-style questions come up, you can point to a structured, independently verified framework rather than just assurances.
For MSPs and detail-minded SMEs, this appendix is your shortcut: if you are Assurix-aligned, you can confidently say, "Yes, we meet these standards, and here's the evidence."