Cyber Essentials, without the headache
We take you through Cyber Essentials and Cyber Essentials Plus end to end: gap assessment, fixes, the assessment itself and every annual renewal after it.
What is Cyber Essentials?
Cyber Essentials is the UK government-backed certification that proves your business has five core security controls in place: firewalls, secure configuration, access control, malware protection and security update management. It is increasingly required to win contracts, especially in the public sector, and certification includes cyber liability insurance for eligible smaller organisations.
- Government-backed and recognised by clients, insurers and regulators
- Five practical controls that stop the most common attacks
- Often a hard requirement in tenders and supply chains
- Certification is annual, so it needs managing, not just passing
- 5Core controls, implemented and evidenced properly
- £25kCyber insurance included for eligible UK organisations
- 1 yearCertificate validity, we manage every renewal
From gap assessment to certificate on the wall
Gap assessment
We measure your environment against the current Cyber Essentials requirements and show you exactly what needs to change.
Remediation
Our engineers make the fixes: configurations, access controls, update policies and the awkward legacy corners.
Application management
We prepare and manage the assessment submission, answering the questionnaire accurately the first time.
Cyber Essentials Plus
For the audited tier, we get you through the hands-on technical verification, including the vulnerability scans.
Annual renewal
Requirements evolve and certificates expire. We track both, so renewal is routine rather than a scramble.
Staying compliant
New starters, new devices and new software all affect compliance. Under our management, the controls stay in place between assessments.
The route to certification
Assess
A gap assessment against the current scheme requirements, with a clear list of what passes and what will not.
Remediate
We fix the gaps, from update policies to admin-account separation, with minimal disruption to your team.
Certify
We manage the assessment and evidence, for Cyber Essentials and the audited Plus tier if you need it.
Maintain
The controls become part of how your IT is run, so next year’s renewal starts from compliant, not from scratch.
One partner, fully accountable
We run IT to this standard anyway
The five controls are how we configure client environments by default, so certification formalises what is already true.
ISO 27001 certified ourselves
We hold ISO 27001 and Cyber Essentials, so we have sat on your side of the assessment table.
Beyond the badge
We treat Cyber Essentials as a floor, not a ceiling, and will show you honestly where the scheme stops and real-world risk continues.
The platforms behind this service
We are accredited on the technology we deploy, not just reselling it.
- CyberSmart Continuous compliance monitoring for Cyber Essentials
- Cyber Essentials The certification we hold and help clients achieve
Cyber Essentials, your questions answered
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is a verified self-assessment: you answer a detailed questionnaire that a qualified assessor reviews. Cyber Essentials Plus covers the same five controls but adds an independent hands-on technical audit, including vulnerability scans of your systems. Plus carries more weight in tenders and due diligence.
How long does Cyber Essentials certification take?
With our help, most businesses go from gap assessment to certificate in two to six weeks, depending on how much remediation is needed. Environments we already manage tend to be at the fast end, because the controls are largely in place from day one.
How much does Cyber Essentials cost?
There is a fixed assessment fee set by the scheme based on your organisation’s size, plus the cost of any remediation work your environment needs. The gap assessment tells you the full picture before you commit, so there are no surprises.
Do we need Cyber Essentials to win contracts?
Increasingly, yes. It is mandatory for many public sector contracts involving personal or sensitive data, and larger private-sector clients now routinely require it of suppliers. Certification is often the difference between making a shortlist and not.
Does Cyber Essentials include insurance?
Yes. Organisations certifying through the self-assessment route with a turnover under £20m are eligible for included cyber liability insurance, currently up to £25,000 of cover. It is a useful baseline, though most businesses should still hold a full cyber policy.
What happens after we certify?
The certificate lasts twelve months, and the scheme’s requirements are updated over time. We keep the controls in place as your business changes, track the renewal date and manage the reassessment, so certification becomes routine rather than an annual project.
Start with a free gap assessment
We will assess you against the current Cyber Essentials requirements and give you a clear, costed route to certification.