Choosing an IT support provider has always required trust. But when that provider holds privileged access to your systems, manages the tools protecting your data and sits inside your supply chain, trust alone is not enough.
Sereno IT has been working towards Assurix verification with a simple view. If an MSP says it operates securely, follows mature processes and manages important controls properly, customers should be able to see something behind those claims.
We have now completed that process, and Sereno IT is officially an Assurix Trusted MSP.
You no longer have to rely only on us saying that we operate at the standard we promise. There is evidence behind it.
Why we did this
An MSP is one of the most trusted suppliers in a business. It may manage identities and devices, control security platforms, and hold privileged access to critical systems.
Most of that work is invisible to the customer. They do not normally see whether a failed security update was followed up, whether administrator access is tightly controlled, or whether an important technical change was properly documented.
Yet those are exactly the things that determine whether an IT service is secure, resilient and dependable.
Most often, businesses have had limited ways to verify that those standards are still being maintained between audits or reviews. That is the gap Assurix is designed to address.
What the trustmark actually means
The Assurix Trusted MSP framework covers 64 controls across two areas: cybersecurity assurance and operational maturity.
What the framework covers
-
Cybersecurity assurance
The cybersecurity controls cover areas such as enforced MFA, privileged access management, patching, backup integrity, recovery testing and incident detection and response.
-
Operational maturity
Operational maturity looks at areas including SLA performance, change control, incident handling, documentation discipline and clear ownership.
Assurix states that its cybersecurity controls are mapped to the NCSC Cyber Assessment Framework version 4.
What makes the model particularly relevant to an MSP is the way evidence is gathered. This is not simply a self-declared badge or a questionnaire completed once. Evidence is collected continuously from the live systems used to operate the MSP, alongside independent assessor review of governance.
That matters because IT changes constantly. Under the Assurix model, controls maintain an ongoing status. If a control fails, it must be remediated. The messaging framework states that if the problem is not resolved within the required period, the trustmark can be suspended publicly until the control is restored.
That is an important distinction because the trustmark is not a guarantee that nothing can ever go wrong. It is a mechanism that makes standards measurable, visible and accountable when something does.
How our clients use it
The most practical difference for a Sereno client is that the assurance is not confined to a certificate. Sereno’s status is available through a public registry.
That means a client can verify the current status without first asking Sereno to produce a document or confirm that the trustmark is still valid.
This becomes useful when somebody else starts asking questions about your IT supply chain.
Who starts asking questions
-
A customer
may ask how your IT provider is assessed.
-
An auditor
may want evidence around third-party technology risk.
-
A procurement team
may ask how privileged access and security controls are governed.
-
An insurer
may ask detailed questions about backup, recovery or cybersecurity practices.
Instead of the answer relying solely on what the MSP says about itself, there is an independent source that can be checked.
If you are choosing an IT provider
Most MSPs sound similar in a sales process. They talk about proactive support, cybersecurity, fast response times, strategic advice and best practice. Those claims may all be valid, but they are difficult for a buyer to evaluate because almost every provider says some version of the same thing.
The Assurix Trusted MSP profile changes what buyers can ask of an IT provider.
Instead of relying only on what an MSP says about its security and service standards, you can look for evidence of whether those controls are passing right now. That gives businesses a more useful way to compare providers.
Not just by price, response times or promises, but by whether the standards behind the service can be independently verified.
Frequently asked questions
How is Assurix different from ISO 27001 or Cyber Essentials Plus?
They provide different types of assurance. Cyber Essentials Plus independently verifies a defined set of technical cybersecurity controls. ISO 27001 focuses on an organisation’s information security management system and the way security risk is governed.
Assurix is specifically designed for MSPs and combines cybersecurity assurance with operational maturity.
Its distinguishing feature is continuous evidence. The question is not only whether the right controls existed during an assessment, but whether those controls continue to operate afterwards. That makes Assurix complementary to other forms of assurance rather than a direct replacement for them.
How do I check our live status?
Sereno’s Assurix Trusted MSP status can be checked on the Assurix public registry.
The significance is that the record sits outside Sereno’s own website and marketing material. Clients, auditors and other interested parties can check the current status independently.
If the required standard is not being maintained, the trustmark is designed to reflect that rather than remaining permanently valid because an assessment was passed in the past.
Two ways to take the next step
-
Existing Sereno clients
can use our Assurix Trusted MSP profile as supporting evidence during audits, supplier reviews, customer security questionnaires or procurement exercises.
-
Businesses reviewing their current IT provider
can also use the framework as a benchmark. Ask how security and operational controls are managed, how failures are handled, and what independent evidence exists behind the answers.
For clients, the next step is simple: check Sereno’s live Assurix status when you need it.
For businesses considering a change of IT provider, speak to Sereno about how we manage the controls that sit behind security, resilience and day to day service delivery.
About Sereno IT
Businesses no longer need to rely only on promises, proposals and polished messaging. They can ask for evidence, look more closely at how providers operate and choose partners that are willing to be independently assessed.
Sereno sees that as a positive change.
Founded in 2022 by IT leaders with more than 20 years of industry experience, Sereno IT is a London-based managed IT and cybersecurity provider built around clear ownership, proactive management and long term technology guidance.
Every client works with a dedicated Technology Advisor and receives structured quarterly Technology Reviews covering infrastructure health, cybersecurity posture, operational risk and future requirements. Sereno also takes ownership of day to day IT support, Microsoft 365, cybersecurity, cloud, devices, infrastructure and ongoing IT planning under one accountable team.
That operating model is designed to give clients more than responsive support. It is intended to create consistency, visibility and accountability across the technology environment.
Becoming an Assurix Trusted MSP is another layer of evidence behind that approach. It shows that the security and operational standards Sereno talks about are not simply stated, but independently assessed and expected to be maintained.



