United Kingdom organisations pursuing Cyber Essentials or Cyber Essentials Plus certification-and MSPs serving UK regulated clients-evaluate remote access tools against NCSC-aligned themes: user access control, secure configuration, malware protection, and patch management. Cyber Essentials certifies organisations, not SaaS product badges.
Trustholm is a remote script orchestration platform that contributes honest enabler evidence for user access control, secure configuration documentation, and partial malware protection via script signing. We do not claim Cyber Essentials certification for the product, NCSC product endorsement, or "CE compliant platform" marketing language.
When UK buyers ask whether the vendor holds Cyber Essentials certification, the accurate answer is no-follow with technical artifacts: audit export samples, MFA configuration screenshots, IAM role matrices, and subprocessors transparency. MSPs include vendor evidence in customer assurance packs while the customer pursues certification with their assessor.
This resource supports procurement narrative alongside /compliance/uk/cyber-essentials for control mapping and trust hub downloads.
NCSC themes and remote script orchestration
Remote management planes that execute PowerShell sit inside organisational security cases when MSPs administer UK client estates. Assessors and Cyber Essentials assessors ask whether administrative access is controlled, configuration is documented, and execution reduces unsigned tampering risk.
Trustholm concentrates evidence on management-plane controls-not workstation imaging, email filtering, or fleet patch compliance.
User access control
Portal MFA and RBAC: Administrators authenticate through JWT sessions with MFA flows available per tenant policy. Users and roles UI supports separation between script authors, approvers, and operators where workflows require it.
SSO integration: OIDC and SAML SSO delegates identity lifecycle to your IdP-your team owns joiner-mover-leaver procedures and periodic access reviews.
Tenant-scoped administration: Avoid shared break-glass accounts across customer tenants. Default model scopes administration to tenant context with JWT tenant binding returning 403 on mismatch for portal users.
Document Security Center screenshots and role matrices in customer assurance packs. Reproduce cross-tenant API tests in trial for assessor confidence.
Secure configuration
Tenant security settings: Signing policy, audit logging toggles, and agent polling credential requirements are configurable and documented in Security Center. Export configuration evidence for Cyber Essentials secure configuration narratives tied to remote management tooling.
What remains customer-operated: Endpoint secure configuration-patch cadence, application control, macro policies, browser hardening-is outside product scope. MSPs continue incumbent RMM workflows for fleet baseline; Trustholm standardizes script governance and audit export.
Honest scoping prevents assessor pushback when buyers expect a vendor to certify workstation standards.
Malware protection (partial enabler)
Signed PowerShell policy: Tenant signing enforcement blocks unsigned execution when required-addressing script integrity for remote PowerShell. This complements organisational AV and application control programs; it does not replace certified anti-malware or full endpoint allowlisting.
Use phrasing such as: "Trustholm enables script integrity via signing policy before remote execution." Avoid: "malware protection certified" or implying CE malware control satisfaction from the vendor alone.
Patch management-explicitly out of scope
OS and third-party patching on managed endpoints is customer and MSP-operated. Cyber Essentials patch requirements flow from your RMM, WSUS, or Intune programs-not from Trustholm. Your security case should map patch mitigations to incumbent tools while mapping logging and signing to Trustholm without double-counting.
Cyber Essentials Plus and technical verification
CE Plus adds hands-on technical verification by an assessor. Vendor marketing cannot substitute for organisational tests. Prepare customers with: (1) audit export for script lifecycle events; (2) MFA evidence for portal admins; (3) signing policy demonstration; (4) limitations appendix naming patch, macro, and SIEM gaps as customer-operated or backlog.
UK MSPs serving finance, legal, and public sector clients should maintain version-controlled vendor diligence folders updated when trust hub Shipped/Gap rows change.
Procurement language for UK RFPs
Good: "Trustholm provides MFA, RBAC, signing enforcement, and audit export supporting Cyber Essentials user access control and secure configuration narratives for remote script orchestration; organisational CE certification remains customer-owned."
Avoid: Cyber Essentials product certification slogans, NCSC approved language, or maturity scores attributed to the vendor.
Pair with SOC 2 evidence framing articles for international buyers and UK-specific trust downloads at /trust/downloads.
MSP workshop agenda for UK assurance teams
Ninety-minute session: (1) map Cyber Essentials controls to tools in stack; (2) mark Trustholm enabler rows for access control and signing; (3) mark customer-operated rows for patch, macros, email; (4) draft customer assurance pack template; (5) assign quarterly audit export owner. Revisit when ACSC-equivalent UK guidance updates or regulated clients onboard.
Pairing Trustholm with incumbent UK RMM stacks
Many UK MSPs retain Datto, NinjaOne, or similar for patch and inventory. Trustholm standardizes script governance evidence for assessor windows. Customer narratives should show complementary tooling-not redundant control claims.
Trust hub cross-reference
See /compliance/uk/cyber-essentials for control tables and /trust/downloads for UK Cyber Essentials vendor pack materials. Product Cyber Essentials certification is not claimed.
Appendix: evidence reproduction steps
Assign a reviewer to open trial tenant, navigate documented UI paths, and capture screenshots with timestamps. Export audit JSON for same session.
Store in immutable GRC folder. Compare results to this article quarterly.
When Shipped/Gap rows change in trust hub, re-run reproduction within ten business days. Attach limitations memo for WORM audit and Sentinel connector backlog.
Include DB operator access policy from hosting provider. Pair technical evidence with customer governance documents-policies, pentest summaries, IR runbooks.
Never substitute marketing copy for reproduced checks in front of assessors. Treat this appendix as a living runbook section owned by security engineering, not a one-time audit artifact.
Schedule annual refresh aligned with trust hub version stamps and major product releases. Link each reproduction run to a change ticket for traceability.
Distribute updated article PDFs to customer-facing teams when dateModified changes. Archive prior versions for twelve months to support assessor lookback questions.
When citing this article externally, include dateModified and pillar metadata in footnotes so readers know content freshness. Internal enablement should link pillar tags to trust hub sections for consistent customer messaging.
Add article slug to internal wiki index for sales engineering quick lookup during live questionnaire calls.