Solusec: Solutions for Cyber Security

Operated by Solusec Ltd
CREST accredited · IASME Certification Body

For MSPs and IT providers

Penetration testing for MSPs

A client asks for a penetration test and you have three bad options and one good one. The good one is a specialist who has no interest in the rest of their IT.

Accredited and recognised

CREST accredited penetration testing providerCREST AI-Enabled Penetration Testing accreditationCREST member company

Three bad options and one good one

A client forwards you an email. Their insurer wants a penetration test, or a customer has sent a security questionnaire, or a tender has a clause in it. They ask you to sort it, because you are the people who look after their IT.

From there the options are familiar. You can tell them to find a testing firm themselves, which sends your client shopping and occasionally introduces them to somebody who also sells managed services. You can quote it yourself and subcontract to whoever answers the phone, which works until the report arrives with somebody else's logo on it. You can decline, which is honest and loses you the remediation work that follows.

Or you can have terms with a testing specialist who does not sell managed IT, so the report can carry your brand and the client never meets a competitor.

We do not do the IT side, and cannot

This is the first thing every partner asks, so it goes near the top. Solusec is a specialist penetration testing provider and certification body. We do not sell managed IT, helpdesk, hardware, licensing, monitoring or projects. We are not set up to, and we have no plans to be.

That is a structural position rather than a promise, which is the only kind worth anything here. A testing firm that also sells managed services has a commercial reason to look closely at the incumbent provider's estate and a reason to be available when the client wonders whether they are well served. We have neither, because we do not want the contract.

If your client asks us who should be running their IT, the answer is you.

Placing testing for a client and not sure what white-label actually covers? The five checks below are the ones that decide whether it runs smoothly.

What white-label actually means in practice

The phrase gets used loosely, so here is what it means with us.

That last point matters more than it sounds. A client whose tender names CREST needs a report that satisfies the clause. Putting your brand on the cover does not change who did the work, and any partner arrangement that pretends otherwise is one you should walk away from.

Liability, insurance and the question your client will ask

If you are reselling, your client's contract is with you, which means their questions about cover land on your desk rather than ours. Worth having the answers.

Solusec carries professional indemnity to £1,000,000, public liability to £6,000,000 and employers liability to £10,000,000. Certificates are available to partners on request, and to your client through you if their procurement asks.

The other document that matters is the authorisation and rules of engagement. It is what makes the engagement lawful, and on a resold test it has to be signed by somebody at the end client who can commit them, not by you on their behalf. That is the single most common thing that delays a partner-placed test, because it depends on a person who is not in the conversation yet.

Banked days, for partners placing work regularly

Quoting each test separately is fine for one or two a year. Past that it is administrative friction on both sides and it makes short-notice work harder than it needs to be.

The alternative is a block of testing days bought up front and drawn down across multiple clients and projects. It prices better than per-test quoting, it mobilises faster because the commercial conversation has already happened, and it lets you say yes to a client with a three-week deadline without a procurement cycle in the middle. We already run this with SaaS clients where we sit close to the release cycle, and it translates directly to a partner placing work across a book of clients.

The remediation is where you make your money

A penetration test produces findings. Somebody has to fix them, and on a client whose estate you run, that somebody is you.

This is the part partners sometimes miss when they treat testing as a pass-through at a small margin. The test is the smaller half of the engagement. The remediation work it generates, and the retest that evidences closure, is scoped, justified by an independent document, and obviously yours to deliver. Partners who position it that way sell more testing, not less, because the conversation stops being about the cost of a report and starts being about a programme of work with a beginning and an end.

What we need from you

  1. A description of the target, or an introduction to somebody at the client who can give one. Named applications, URLs or IP ranges rather than "their systems".
  2. What is actually driving it. An insurer, a tender, a customer questionnaire or a board. That decides what the test needs to cover and often makes it smaller than expected.
  3. Credentials on day one if it is an authenticated test, working and tested by somebody on your side before the window opens.
  4. A named signatory at the client for the authorisation and rules of engagement.
  5. Your branding pack, if the report is going out under your name. Template, logo, the wording you use for severity ratings if you have house conventions.

None of that is difficult. It is sequential, and every item that surfaces late costs days on an engagement that usually has a deadline attached.

What else you can place with us

Cyber Essentials and IASME Cyber Assurance Levels 1 and 2, issued directly because we are an appointed IASME Certification Body. Cyber Essentials Plus from late October 2026. Defence Cyber Certification Level 0 for clients holding Ministry of Defence contracts, where the deadline for industry partners is 31 December 2026 and Cyber Essentials is a prerequisite at every level under Def Stan 05-138 Issue 4.

Plenty of partners start with one test and end up placing certification as well, because it turns out the same client asking for a penetration test has a tender clause about Cyber Essentials three paragraphs further down.

Can you white-label this cleanly?

Tick what is already true. These are the five things that decide whether a resold test runs smoothly or becomes your problem.

Further reading on this site

Four guides going deeper than this page does. All free, no sign-up.

Ask about white-label terms

Tell us roughly how many tests a year you expect to place and what your clients look like. You will get partner terms back in writing, usually within one business day. No call unless you want one, and no obligation either way.

Your details are handled by a real person, never fed into AI.