Blog / Insights

Cyber Essentials and Your RMM: Evidencing the Five Controls with Tooling You Already Run

Insights By the Helios team · 16 August 2026 · 7 min read

Your RMM can evidence most of Cyber Essentials: endpoint firewall state, installed software and local accounts, local administrators, anti-malware status and definition age, and patch compliance against the 14-day rule. What an RMM cannot evidence is the boundary firewall, unmanaged BYOD, most cloud configuration and the written policies the scheme assumes. Yet most small MSPs fill in the assessment from memory the week before renewal. The gap between "we believe we patch within 14 days" and the report proving it is the gap between an anxious submission and a boring one.

What counts as cyber essentials RMM evidence

Cyber Essentials basic is self-assessment, so strictly you attest rather than prove. But two things make evidence worth generating anyway. First, Cyber Essentials Plus involves an assessor actually testing devices, and the same reports tell you in advance whether you will pass. Second, client security questionnaires increasingly ask you to demonstrate, not declare. A dated export from your RMM answers both, and it answers your own doubt, which is usually the loudest voice in the room.

Rule of thumb: for every question on the assessment, decide whether the answer comes from a report, a policy document or a screenshot of a portal setting. If it comes from memory, you do not have an answer yet.

Control 1: firewalls, mostly not your RMM's job

Start with the uncomfortable one. Most RMM platforms do not manage network hardware, so the boundary firewall questions, changed default passwords, no unauthenticated inbound services, admin interfaces not exposed to the internet, are evidenced from the firewall vendor's own portal or config export. Do not pretend otherwise on the form.

What your RMM can evidence is the software firewall on every endpoint. That matters more than it used to, because the scheme cares about devices used on untrusted networks, which is now most laptops most weeks.

Control 2: secure configuration, where inventory earns its keep

Secure configuration asks whether you have removed what you do not need and locked down what remains. This is inventory work, and inventory is the one thing an RMM does better than anything else you own.

What tooling cannot cover: the password and PIN policy itself is a written policy plus your identity platform's settings. For Microsoft 365 estates, most of it lives in Entra and Intune, and our Microsoft 365 security checklist covers the settings the assessment leans on.

Control 3: user access control, half tooling, half discipline

The scheme wants unique accounts, least privilege, controlled admin access and prompt removal of leavers. Your RMM evidences the endpoint half.

The other half is process. Joiner and leaver workflows, MFA on cloud accounts, separate admin accounts for admin tasks: these are evidenced by your identity platform and your written procedure, not by monitoring. Tooling shows the state; only a documented process shows intent.

Control 4: malware protection, the easiest report you will run

This is the control RMMs were practically built for. You need to show that every in-scope device runs supported anti-malware, that it updates, and that it scans or blocks in real time.

Control 5: security update management, the control that fails people

The scheme's requirement is blunt: high and critical updates applied within 14 days of release, on operating systems and applications, with unsupported software removed. This is where self-assessed confidence and measured reality diverge most.

A patch policy without a patch report is a promise. A patch report without a policy is an accident. The assessment wants both.

The gaps tooling will not cover

Be honest on the form about what your RMM cannot see: the boundary firewall and router estate, unmanaged BYOD devices that touch organisational data, cloud service configuration beyond what your Microsoft 365 integration surfaces, and every written policy the scheme assumes exists. The failure mode on each side is instructive. Teams that lean entirely on tooling submit accurate data about an estate with no documented rules, and fail on process questions. Teams that lean entirely on policy submit beautiful documents describing an estate that does not match them, and fail at Plus when a real laptop is tested. You need the report and the paragraph.

Reports to schedule before assessment

Set these up as scheduled exports at least a month before you submit, so you have time to fix what they show you.

ReportControlFrequency
Endpoint firewall stateFirewallsWeekly
Installed software and local accountsSecure configurationMonthly
Local administrators per deviceAccess controlMonthly
AV status and definition ageMalware protectionWeekly
Patch compliance by update ageUpdate managementWeekly
End-of-life software inventoryUpdate managementMonthly

The 14-day test: pick any critical update released a month ago and ask your tooling which devices still lack it. If you cannot answer in five minutes, fix the reporting before you fix the estate.

Where this fits with Helios

Helios is an RMM and PSA in one platform, so the evidence above, patch compliance including third-party applications via winget, security posture, Defender status and Microsoft 365 configuration, comes from one place rather than four exports stitched together. The service desk keeps the failed-patch follow-up tickets next to the data that raised them. We are open about the gaps: Helios does not monitor network hardware, so your boundary firewall evidence still comes from the firewall itself, and the written policies are yours to write. Most of this article is discipline. The tooling just makes the discipline visible.

Helios is flat-priced RMM and PSA for small MSPs and internal IT, from £99 a month with every feature on every plan. 14-day trial, no card, no feature gating. Start free.

Related: Business email compromise: anatomy of an attack that almost worked

Why MSPs choose Helios

One platform that does the work, at a price that stays put

Helio fixes, not just flags

When an alert fires, Helio, the AI technician built into Helios, investigates it, writes the fix and runs it once you approve. It keeps what works, so the next one is quicker.

Everything in one product

RMM, a service desk with SLAs, patching including third-party apps, remote access, Microsoft 365 and Defender checks, backup monitoring, a client portal and billing into Xero or QuickBooks.

Priced by fleet, not by people

£4 a device on Launch up to 25 devices, from £20 a month, then £99, £199 or £399 a month by fleet size, with any number of technicians and every feature on every plan.

A price that stays put

Your price is locked for as long as you stay subscribed, and that is written into our terms. Monthly billing, cancel any time.

Bring your clients across

Import your clients and machines from another RMM's CSV export, then roll the Helios agent out at your own pace, with a count of how many have arrived.

14 days free, no card

The full platform from the first minute, on your own machines. No sales call, no feature held back for the trial.

See it on your own fleet

Helios is the AI-native platform for MSPs: monitoring, patching, security, Microsoft 365, backup monitoring, remote access, client billing and an AI service desk in one product, at one flat price per MSP. Contracts and logged time become invoices in Xero or QuickBooks without leaving the platform. Every feature is on every plan. 14-day free trial, card-free, set up in minutes, cancel any time.

Start free

Researched and written with Helio SEO, our AI writer for business blogs.