
Compliance framing
Cyber Essentials Enabler
Map Trustholm capabilities to your assessor program with honest Shipped/Gap rows-not vendor certification claims.
- Reproduce audit export in trial
- Download trust pack for binders
- Regional hub cross-links
United Kingdom Cyber Essentials and NCSC-aligned remote access evidence.
United Kingdom buyers use Trustholm for user access control and script integrity enablers-Cyber Essentials certification applies to the organisation, not the SaaS product.
Framework evidence framing before detailed tables below.

Compliance framing
Map Trustholm capabilities to your assessor program with honest Shipped/Gap rows-not vendor certification claims.
This page describes product capabilities for your control matrix. Trustholm does not hold SOC 2, ISO 27001, IRAP, Essential Eight, CMMC, Cyber Essentials, NIS2, or framework certification badges.
United Kingdom organisations often reference Cyber Essentials and NCSC guidance when evaluating remote access tools used by MSPs. Cyber Essentials certification applies to an organisation's implementation-not to a SaaS product badge.
Trustholm contributes evidence for user access control, secure configuration narratives, and malware protection themes where script signing reduces unsigned execution risk.
User access control: Portal MFA and RBAC for administrators. Technicians authenticate through your configured IdP where SSO is enabled. Avoid shared break-glass accounts across customer tenants-tenant-scoped administration is the default model.
Secure configuration: Tenant security settings document signing policy, audit logging toggles, and agent polling credential requirements. Endpoint secure configuration-patch cadence, application control, macro policies-remains customer and MSP-operated. Trustholm documents agent footprint and signing enforcement, not workstation imaging standards.
Malware protection: Signed PowerShell policy before execution complements-but does not replace-organisational AV and application control programs. Document Trustholm as a script integrity enabler in your security case, not as certified anti-malware.
Patch management: OS and third-party patching on managed endpoints is outside product scope. MSPs continue incumbent RMM patch workflows; Trustholm standardizes script governance and audit export.
When buyers ask whether the vendor holds Cyber Essentials certification, answer no-provide technical artifacts: audit export sample, MFA configuration screenshot, IAM role matrix, and subprocessors list. MSPs serving UK regulated clients include vendor evidence in customer assurance packs while the customer pursues Cyber Essentials or CE Plus with their assessor.
Pair this page with SOC 2 evidence framing for international buyers and UK-specific trust download materials at /trust/downloads. Engage security@trustholm.com during trial for mapping discussions scoped to your deployment model.
Limitations: We do not operate your email filtering, macro policies, or fleet patch compliance. Cyber Essentials maturity is measured at the organisation boundary-Trustholm supplies supporting vendor inputs only.
Assessor workshop tip: Bring one exported audit JSON file and your IdP group membership screenshot to Cyber Essentials readiness reviews-reproducible artifacts beat marketing PDFs. Download the UK vendor pack at /trust/downloads.
| Topic | Evidence | Status | Notes |
|---|---|---|---|
| Secure configuration | Tenant security settings; agent polling credential model | Shipped | Endpoint baseline remains customer-operated |
| User access control | Portal MFA and RBAC for administrators | Shipped | - |
| Malware protection | Script signing policy; not AV replacement | Partial | - |
| Cyber Essentials certification | Organisation certifies; vendor holds no Cyber Essentials badge | Gap | - |
No. Cyber Essentials certifies organisations. We provide vendor evidence for access control and secure configuration narratives.
Most directly user access control (MFA, RBAC) and secure configuration documentation. Malware protection is partial via signing-not AV replacement.
MSPs include vendor evidence in customer assurance. NCSC themes for remote access align with MFA, logging export, and execution integrity.
Yes. Export JSON/CSV from the security audit plane for review windows. Store in your GRC toolchain with retention matching policy.
Patch management, macro policies, application control, email filtering, and organisational Cyber Essentials certification pursuit.
See /trust/downloads for UK Cyber Essentials vendor pack and general trust materials.