Conosco is now an Assurix Trusted MSP. Here is what changes for our clients.
by Aaron Flack on Aug 4, 2026

Recently, Conosco earned the Assurix Trusted MSP Trustmark. For our clients, that means something specific: you no longer have to take our word that we are operating at the standard we said we would. You can check, live, on a public registry, without asking us. The evidence is not a document we send you. It is a public record that exists whether or not we choose to share it, and it reflects our controls as they stand today, not as they stood at our last audit.
Your IT provider is unregulated by default
Accountants, solicitors, and independent financial advisers all operate within external regulatory frameworks. Managed service providers do not. The IT industry has no equivalent body, no mandatory standard, and no external watchdog.
We hold more access to your business than most of your own staff. Your email. Your devices. Your files. Your accounts. Your security tools. The basis on which you trust us with that access is typically our word, a contract, and whatever certifications we happen to mention.
What you see from us is tickets, helpdesk responses, account management, and service level agreement (SLA) reports. What you do not see is whether our backups are completing, whether patching is current, whether access controls are correctly configured, or whether incident detection is running properly. Those are the invisible controls that determine how a serious incident plays out.
Annual certifications tell you where a provider stood on the day an assessor visited. Between audits, the honest answer to “are they still doing what they said?” is “presumably.” That is not a satisfying answer when you are explaining your IT supply chain to a client, an insurer, or an auditor. Assurix was built to close that gap.
64 controls, continuously verified
Assurix is a UK live trustmark platform, founded in 2025 by Mit Patel, a former MSP Managing Director with twenty years in the industry. It assesses providers across 64 controls and two pillars.
The first pillar covers security assurance: enforced multi-factor authentication (MFA), privileged access management, patching, backup integrity, recovery testing, incident detection and response. These are the controls that determine what actually happens inside a provider’s environment, not what is written on a policy document.
The second pillar covers operational maturity: SLA performance, change control, incident handling, documentation discipline, and clear ownership. This is the operational infrastructure that determines whether a provider consistently delivers what it said it would.
The key difference from other certification schemes is how the assessment runs. Assurix does not collect evidence once a year. The system verifies controls continuously, refreshing every six hours. Every control sits in one of three states at any given moment: passing, pending, or failing.
Assurix lists the trustmark publicly on the BlockMark public registry. Anyone can verify our status without contacting us. If a control breaks and we do not resolve it within 30 days, Assurix suspends the trustmark publicly. That suspension is visible and automatic. The credibility of the scheme comes precisely from the fact that it can be removed.
A different kind of certification
Cyber Essentials and ISO 27001 are well-established frameworks. They continue to serve their purpose. Assurix does not replace them.
What Assurix addresses is a limitation both frameworks share: they are point-in-time. An ISO 27001 audit confirms that controls existed on the day an auditor visited. A Cyber Essentials assessment confirms a snapshot of a provider’s security posture at the time of application. Both are useful. Neither tells you what is happening now.
Assurix confirms that our controls are active now. Assurix maps the 64 controls against the National Cyber Security Centre (NCSC) Cyber Assessment Framework (CAF) v4, and the scheme aligns with the forthcoming Cyber Security and Resilience Bill, which means it tracks the direction of UK regulation rather than sitting at a distance from it.
We are not suggesting the trustmark means nothing can go wrong. It means the controls designed to detect, prevent, and respond to incidents are running and verified. That is a different claim from “we passed an audit,” and it is a more honest one.
Turning verification into a practical tool
The moment our clients most need to evidence their IT supply chain is not at annual review. It arrives when a prospect runs due diligence, when an insurer asks about third-party security controls at renewal, when a procurement team sends a vendor questionnaire, or when a board or audit committee asks how IT risk is being managed.
Until now, the answer to those questions involved a document, an email, and a wait. Sometimes it involved a call to us to confirm which certifications we held and whether they were still current.
Now the answer is a URL.
One link. Live. Independent. Current. It shows the status of our Assurix Trustmark without requiring anything from us. Due diligence gets shorter because the answer is a verification page, not a 20-page supplier form.
Cyber insurance underwriters have begun asking about IT supplier verification as part of renewal questionnaires, reflecting a broader shift toward supply chain scrutiny. Having a live trustmark simplifies that conversation. The answer is not an assertion. It is a verifiable fact.
For organisations in financial services, legal, or professional services, where clients themselves face supply chain scrutiny, this is useful beyond your own audit programme. When your clients ask who you trust with your systems, you now have a live, independently verified answer rather than a brochure claim.
Frequently asked questions
How Assurix differs from ISO 27001 and Cyber Essentials Plus
ISO 27001 and Cyber Essentials Plus are point-in-time certifications. They confirm that a set of controls existed when the audit or assessment happened. Assurix verifies that our controls are active now, with evidence refreshed every six hours. The frameworks sit alongside each other rather than replacing one another.
How to verify Conosco’s live Assurix status
Our Assurix Trustmark is publicly listed on the BlockMark public registry. You can verify our current status at any time, without contacting us, at https://assurix.com/directory/conosco.
Verify it yourself
Check our live Assurix Trustmark status: https://assurix.com/directory/conosco
To discuss what this means for your supply chain reporting or due diligence process, book a 20-minute call: https://conosco.com/contact-us/expert
About Conosco
Conosco is a London-based managed IT and cybersecurity provider, supporting UK businesses in financial services, legal, and professional services since 2002. We are now an Assurix Trusted MSP, independently verified against the UK standard for MSP security and operational maturity.
You May Also Like
These Related Stories

Long Read: NCSC 2025 Review: What CIOs Must Do as Major Attacks Surge
Empty shelves at M&S were not the real warning sign. The 50 per cent rise in nationally significant attacks was.

An Investment In Knowledge Pays The Best Interest
What makes a great IT support function? What are the pillars for an effective infrastructure? What is the key to buildin …

What are the OWASP Top 10 vulnerabilities?
The OWASP Top 10 is the most widely referenced framework for web application security risk. Published by the Open Worldw …
