Cyber Essentials

Cyber Essentials, without the headache

We take you through Cyber Essentials and Cyber Essentials Plus end to end: gap assessment, fixes, the assessment itself and every annual renewal after it.

The short answer

What is Cyber Essentials?

Cyber Essentials is the UK government-backed certification that proves your business has five core security controls in place: firewalls, secure configuration, access control, malware protection and security update management. It is increasingly required to win contracts, especially in the public sector, and certification includes cyber liability insurance for eligible smaller organisations.

  • Government-backed and recognised by clients, insurers and regulators
  • Five practical controls that stop the most common attacks
  • Often a hard requirement in tenders and supply chains
  • Certification is annual, so it needs managing, not just passing
  • 5Core controls, implemented and evidenced properly
  • £25kCyber insurance included for eligible UK organisations
  • 1 yearCertificate validity, we manage every renewal
What's included

From gap assessment to certificate on the wall

Gap assessment

We measure your environment against the current Cyber Essentials requirements and show you exactly what needs to change.

Remediation

Our engineers make the fixes: configurations, access controls, update policies and the awkward legacy corners.

Application management

We prepare and manage the assessment submission, answering the questionnaire accurately the first time.

Cyber Essentials Plus

For the audited tier, we get you through the hands-on technical verification, including the vulnerability scans.

Annual renewal

Requirements evolve and certificates expire. We track both, so renewal is routine rather than a scramble.

Staying compliant

New starters, new devices and new software all affect compliance. Under our management, the controls stay in place between assessments.

How it works

The route to certification

01

Assess

A gap assessment against the current scheme requirements, with a clear list of what passes and what will not.

02

Remediate

We fix the gaps, from update policies to admin-account separation, with minimal disruption to your team.

03

Certify

We manage the assessment and evidence, for Cyber Essentials and the audited Plus tier if you need it.

04

Maintain

The controls become part of how your IT is run, so next year’s renewal starts from compliant, not from scratch.

Why Alternative

One partner, fully accountable

We run IT to this standard anyway

The five controls are how we configure client environments by default, so certification formalises what is already true.

ISO 27001 certified ourselves

We hold ISO 27001 and Cyber Essentials, so we have sat on your side of the assessment table.

Beyond the badge

We treat Cyber Essentials as a floor, not a ceiling, and will show you honestly where the scheme stops and real-world risk continues.

Delivered with

The platforms behind this service

We are accredited on the technology we deploy, not just reselling it.

  • CyberSmart Continuous compliance monitoring for Cyber Essentials
  • Cyber Essentials The certification we hold and help clients achieve

Accredited & partnered with the names you trust

FAQs

Cyber Essentials, your questions answered

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a verified self-assessment: you answer a detailed questionnaire that a qualified assessor reviews. Cyber Essentials Plus covers the same five controls but adds an independent hands-on technical audit, including vulnerability scans of your systems. Plus carries more weight in tenders and due diligence.

How long does Cyber Essentials certification take?

With our help, most businesses go from gap assessment to certificate in two to six weeks, depending on how much remediation is needed. Environments we already manage tend to be at the fast end, because the controls are largely in place from day one.

How much does Cyber Essentials cost?

There is a fixed assessment fee set by the scheme based on your organisation’s size, plus the cost of any remediation work your environment needs. The gap assessment tells you the full picture before you commit, so there are no surprises.

Do we need Cyber Essentials to win contracts?

Increasingly, yes. It is mandatory for many public sector contracts involving personal or sensitive data, and larger private-sector clients now routinely require it of suppliers. Certification is often the difference between making a shortlist and not.

Does Cyber Essentials include insurance?

Yes. Organisations certifying through the self-assessment route with a turnover under £20m are eligible for included cyber liability insurance, currently up to £25,000 of cover. It is a useful baseline, though most businesses should still hold a full cyber policy.

What happens after we certify?

The certificate lasts twelve months, and the scheme’s requirements are updated over time. We keep the controls in place as your business changes, track the renewal date and manage the reassessment, so certification becomes routine rather than an annual project.

Start with a free gap assessment

We will assess you against the current Cyber Essentials requirements and give you a clear, costed route to certification.