Policy Pros
Written by Joanne Hughes, Policy & Compliance SpecialistLast reviewed

Policies for IT Companies and MSPs

This page is for software companies, IT support businesses and managed service providers that need their documentation in order. Policy Pros writes bespoke information security, data protection and HR policies for UK technology businesses, from a single patch management policy to the full set behind Cyber Essentials or ISO 27001.

Bespoke, audit-ready policies from £65 + VAT per document. Get a quote or call 020 3951 2875 for a free scoping conversation.

Policies IT Companies and MSPs Need

Legally Required

  • Health and Safety Policy Statement - required in writing once you have 5 or more employees (Health and Safety at Work etc. Act 1974)
  • Data Protection Policy - UK GDPR and the Data Protection Act 2018 require you to demonstrate compliance with the data protection principles
  • Data Processing Agreement terms - Article 28 UK GDPR requires a written contract whenever you process personal data on a client's behalf
  • Personal Data Breach Procedure - under UK GDPR Article 33, processors must alert their client without undue delay and controllers have 72 hours to report to the ICO
  • Written employment particulars and core HR policies - required from day one of employment (Employment Rights Act 1996)

Expected by Regulators and Clients

  • Information Security Policy - the top-level document ISO 27001 requires (clause 5.2) and the first thing client due diligence asks for
  • Patch Management Policy - Cyber Essentials requires critical and high updates within 14 days, an automatic fail since April 2026
  • Access Control Policy with a joiners, movers and leavers process - evidences the Cyber Essentials user access control requirement and ISO 27001 Annex A
  • Password and Authentication Policy - missing multi-factor authentication on cloud services is now an automatic Cyber Essentials failure point
  • Incident Response Plan - client contracts demand one, and the Cyber Security and Resilience Bill plans 24-hour incident reporting for MSPs
  • Business Continuity and Disaster Recovery Plan - written into most MSP service agreements and tested at ISO 27001 audit
  • Acceptable Use and BYOD Policy - Cyber Essentials scopes in home workers and personal devices that access organisational data
  • Supplier and Sub-processor Policy - Article 28 controls sub-processor appointments, and enterprise clients audit your supply chain

Cyber Essentials Marking Got Stricter in 2026

Cyber Essentials moved to the Danzell question set on 27 April 2026, with automatic failure marking for missing multi-factor authentication and late security updates. The scheme is run by IASME on behalf of the NCSC, and our Cyber Essentials 2026 changes guide covers exactly what changed.

The assessment is a questionnaire, but you cannot answer it honestly without the underlying documents. Our guide to the documents Cyber Essentials requires lists what assessors expect to sit behind each answer, and our Cyber Essentials policies service writes them.

Enterprise Clients Ask for ISO 27001

Once you sell into mid-market and enterprise clients, security questionnaires start asking for ISO 27001 certification, or at least the documentation behind it. The mandatory set is smaller than most toolkits suggest, and our ISO 27001 mandatory documents list sets out what the standard actually names.

Our IT security policies service covers the full framework, from the information security policy through the Annex A topic policies to the operating records auditors check.

The Cyber Security and Resilience Bill Targets MSPs

The Cyber Security and Resilience Bill would bring medium and large managed service providers under direct regulation for the first time, with registration at the ICO and 24-hour incident reporting. The Bill is still before Parliament, reaching its House of Lords second reading in July 2026, so these duties are not yet law, but the government's factsheet confirms MSPs are squarely in scope.

Our managed service provider guide to the Bill explains who counts as a relevant MSP and the reporting clocks, and our small business guide covers the wider regime. The documentation it expects, from incident response to supplier controls, is worth building now rather than after Royal Assent.

Processor Duties Under UK GDPR

Most IT companies and MSPs are processors of their clients' personal data, which brings legal duties of your own on top of whatever the contract says. Article 28 requires written terms covering security, sub-processors and breach notification, and the ICO's controllers and processors guidance sets out what those terms must say.

If a breach happens on your watch, you must tell your client without undue delay so they can meet their own 72-hour deadline to the ICO. A breach procedure that names who calls whom, and when, is what makes that possible at 2am.

What Policy Pros Delivers

  • Bespoke documents written around your actual stack, clients and team, not a generic template
  • A fixed-price quote before any work starts
  • Review rounds included, so the final documents say what you need them to say
  • Documents delivered on professionally branded templates, ready to show a client or an assessor

Extremely professional and thorough. The policies were tailored perfectly to our sector and delivered ahead of schedule.

You can read more Policy Pros reviews on Trustpilot.

How to Get Started

Tell us whether you are aiming at Cyber Essentials, ISO 27001, a client security questionnaire or the full set, and we will scope exactly what you need. You get a fixed-price quote before we start, with no obligation. Get a quote or call 020 3951 2875.

Frequently Asked Questions

What policies does an IT company or MSP legally need?

The legal core is a written health and safety policy statement once you have 5 or more employees, data protection documentation under UK GDPR and the Data Protection Act 2018, and written employment particulars from day one of employment. If you process personal data on a client's behalf, Article 28 UK GDPR also requires written contract terms and you need a breach procedure to meet the notification duties.

Most of the rest, such as patch management, access control and incident response, is driven by Cyber Essentials, ISO 27001 and client contracts rather than statute. Those are the documents that win and keep contracts.

What documents do we need to pass Cyber Essentials in 2026?

Cyber Essentials is a self-assessment questionnaire rather than a document upload, but assessors expect a patch management policy, an access control policy, a password and MFA policy, an acceptable use policy and an asset list to sit behind your answers.

Since the Danzell question set took effect in April 2026, missing multi-factor authentication on cloud services and security updates applied later than 14 days are automatic failures, so those two policies need to reflect what is genuinely happening on your estate.

Does the Cyber Security and Resilience Bill apply to my MSP?

The Bill targets medium and large managed service providers, broadly those with 50 or more staff or turnover above 10 million euros, who would need to register with the ICO, maintain proportionate security measures and report significant incidents within 24 hours. As of mid-2026 the Bill is still before the House of Lords, so none of this is law yet.

Smaller providers are expected to fall outside direct regulation, but regulated customers will push the same expectations down their supply chain. Preparing your incident response and supplier documentation now is the low-cost option.

Do we need ISO 27001 certification or just the policies?

It depends what your clients ask for. Many due diligence questionnaires accept a documented information security management system and the key policies, while some enterprise and public sector contracts require certification by a UKAS-accredited body.

We write the documentation either way, so you can start with the policy set clients ask to see and move to full certification when a contract demands it.

Trustpilot Reviews - 5 Stars