Skip to content

MSPs are your supply chain. We should be verifying them like one

19 May 20262 min read
Guest Insights
MSPs are your supply chain. We should be verifying them like one

Mit Patel

Founder, Assurix

Paper certificates do not secure supply chains; live evidence does. That is the direction that UK policy is moving towards with the upcoming Cyber Security and Resilience Bill.

The current model is stranger than it seems. An IT provider holds your domain admin credentials, sits inside your identity stack, runs your backup systems, and even controls your EDR console. In practical terms, they are your security team. And the way that buyers check that any of this is run safely is an audit that takes place once a year.

Trust is the default. It shouldn't be.

This is how almost every UK buyer verifies their supplier today. A self-attestation form. A logo on a slide. A point-in-time certification based on an annual audit.

Supply chain risk does not behave like a certificate; controls drift between audits, technicians come and go, customer environments are onboarded with shortcuts, tooling gets misconfigured. Procurement, insurers, and regulators are left taking trust as evidence.

What good actually looks like

Continuous, evidence-based verification has three properties. It runs all the time, not once a year. Evidence is read directly from the supplier's environment, not gathered into a questionnaire. When a control fails, the supplier is told to fix it and if they don't, the certification is suspended, in public.

A trustmark, certification, or status that does not move when the underlying posture moves shows that a supplier once met the standard, not that they do today. If assurance is going to be load-bearing, public suspension when standards drop must be part of it. The buyer needs to be able to see, today, whether their supplier still meets the bar, not what an auditor wrote down last quarter.

Where this is already working

Assurix is a continuous, live evidence trustmark for UK IT suppliers. It sits on a defined set of operational and security controls, aligned with the NCSC Cyber Assessment Framework. Evidence is read continuously from the supplier's environment, not from a self-completed form. If something falls out of tolerance, there is a thirty-day window to fix it. Past that, it is publicly suspended. Buyers, insurers, and regulators can check the status of an IT provider whenever they need to, not the moment its auditor was last in the building.

The same logic applies further up the supply chain. Defence sub-contractors, clinical software vendors, payroll providers, shared services platforms: all of them hold privileged access into customer environments, and all of them are verified today by point in time certifications. The IT provider market is where the model is being proven first, because the risk is most concentrated and the buyer is least equipped to interrogate it. But wherever a third party holds the keys, we must be able to verify whether they are keeping their systems secure today.

The model exists. The work now is to take it from the leading edge of the UK IT provider market into the rest of the supply chain.