Accredited and recognised



Three bad options and one good one
A client forwards you an email. Their insurer wants a penetration test, or a customer has sent a security questionnaire, or a tender has a clause in it. They ask you to sort it, because you are the people who look after their IT.
From there the options are familiar. You can tell them to find a testing firm themselves, which sends your client shopping and occasionally introduces them to somebody who also sells managed services. You can quote it yourself and subcontract to whoever answers the phone, which works until the report arrives with somebody else's logo on it. You can decline, which is honest and loses you the remediation work that follows.
Or you can have terms with a testing specialist who does not sell managed IT, so the report can carry your brand and the client never meets a competitor.
We do not do the IT side, and cannot
This is the first thing every partner asks, so it goes near the top. Solusec is a specialist penetration testing provider and certification body. We do not sell managed IT, helpdesk, hardware, licensing, monitoring or projects. We are not set up to, and we have no plans to be.
That is a structural position rather than a promise, which is the only kind worth anything here. A testing firm that also sells managed services has a commercial reason to look closely at the incumbent provider's estate and a reason to be available when the client wonders whether they are well served. We have neither, because we do not want the contract.
If your client asks us who should be running their IT, the answer is you.
Placing testing for a client and not sure what white-label actually covers? The five checks below are the ones that decide whether it runs smoothly.
What white-label actually means in practice
The phrase gets used loosely, so here is what it means with us.
- The report is yours. Delivered in your template, under your brand, with your contact details on it. We already work this way, including delivering under another consultancy's brand and report template.
- You decide who is on the call. Some partners want us present as their testing team, introduced by name. Some want us invisible and take the technical questions themselves. Both work, but decide before the kick-off rather than during it.
- You own the client relationship and the invoice. You contract with the client at your price, we contract with you at partner terms.
- The testing is not white-labelled. The work is done by a CREST-registered tester at a CREST-accredited company, and if your client asks whether the testing firm behind you is accredited, the honest answer is yes and it is verifiable. What is branded is the deliverable, not the credential.
That last point matters more than it sounds. A client whose tender names CREST needs a report that satisfies the clause. Putting your brand on the cover does not change who did the work, and any partner arrangement that pretends otherwise is one you should walk away from.
Liability, insurance and the question your client will ask
If you are reselling, your client's contract is with you, which means their questions about cover land on your desk rather than ours. Worth having the answers.
Solusec carries professional indemnity to £1,000,000, public liability to £6,000,000 and employers liability to £10,000,000. Certificates are available to partners on request, and to your client through you if their procurement asks.
The other document that matters is the authorisation and rules of engagement. It is what makes the engagement lawful, and on a resold test it has to be signed by somebody at the end client who can commit them, not by you on their behalf. That is the single most common thing that delays a partner-placed test, because it depends on a person who is not in the conversation yet.
Banked days, for partners placing work regularly
Quoting each test separately is fine for one or two a year. Past that it is administrative friction on both sides and it makes short-notice work harder than it needs to be.
The alternative is a block of testing days bought up front and drawn down across multiple clients and projects. It prices better than per-test quoting, it mobilises faster because the commercial conversation has already happened, and it lets you say yes to a client with a three-week deadline without a procurement cycle in the middle. We already run this with SaaS clients where we sit close to the release cycle, and it translates directly to a partner placing work across a book of clients.
The remediation is where you make your money
A penetration test produces findings. Somebody has to fix them, and on a client whose estate you run, that somebody is you.
This is the part partners sometimes miss when they treat testing as a pass-through at a small margin. The test is the smaller half of the engagement. The remediation work it generates, and the retest that evidences closure, is scoped, justified by an independent document, and obviously yours to deliver. Partners who position it that way sell more testing, not less, because the conversation stops being about the cost of a report and starts being about a programme of work with a beginning and an end.
What we need from you
- A description of the target, or an introduction to somebody at the client who can give one. Named applications, URLs or IP ranges rather than "their systems".
- What is actually driving it. An insurer, a tender, a customer questionnaire or a board. That decides what the test needs to cover and often makes it smaller than expected.
- Credentials on day one if it is an authenticated test, working and tested by somebody on your side before the window opens.
- A named signatory at the client for the authorisation and rules of engagement.
- Your branding pack, if the report is going out under your name. Template, logo, the wording you use for severity ratings if you have house conventions.
None of that is difficult. It is sequential, and every item that surfaces late costs days on an engagement that usually has a deadline attached.
What else you can place with us
Cyber Essentials and IASME Cyber Assurance Levels 1 and 2, issued directly because we are an appointed IASME Certification Body. Cyber Essentials Plus from late October 2026. Defence Cyber Certification Level 0 for clients holding Ministry of Defence contracts, where the deadline for industry partners is 31 December 2026 and Cyber Essentials is a prerequisite at every level under Def Stan 05-138 Issue 4.
Plenty of partners start with one test and end up placing certification as well, because it turns out the same client asking for a penetration test has a tender clause about Cyber Essentials three paragraphs further down.
Can you white-label this cleanly?
Tick what is already true. These are the five things that decide whether a resold test runs smoothly or becomes your problem.
Further reading on this site
Four guides going deeper than this page does. All free, no sign-up.
- What a white-labelled engagement looks like, week by weekThe commercial arrangement is the easy part. What partners want to know is who says what to whom, and at which point it stops being your problem or becomes it again.
- Scoping a test for a client without being the testerYou are not expected to know how the test will be run. You are the only person who knows what is actually in the estate, and that is the half that decides the quote.
- The report has findings, and the estate is yoursThis is the reason some MSPs never place a test. It is also, handled properly, the single best piece of evidence you will ever get for work you have been asking to do for years.
- Testing as a catalogue line, not a favour you do twice a yearMost MSPs sell testing reactively, at no margin, when a client forwards an email. The same work sold as a product has a cadence, a price and a renewal date.