Cyber Essentials is the UK Government-backed certification scheme, overseen by the National Cyber Security Centre (NCSC) and delivered by the IASME Consortium, that proves your organisation has the five core technical controls in place to stop the most common cyber attacks. We guide small and medium-sized enterprises (SMEs) through it in three steps: a short gap analysis questionnaire, a call with our team to talk through what it found, and an accreditation plan we then work through with you until you’re certified.
No lengthy audit up front, and no accreditation plan built before we understand your setup. We start small, talk it through with you, then build the plan around what’s actually needed — not a generic checklist.
A short, plain-English questionnaire covering the five Cyber Essentials control areas — firewalls, secure configuration, user access control, malware protection and patch management. That questionnaire is step one of Cyber Essentials Certification with us, before any technical work begins. Takes most SMEs around 10 minutes, no technical jargon required.
We talk through what the questionnaire found — in plain terms, not a jargon-heavy report. Explaining it plainly at that stage is what makes the rest of the Cyber Essentials Certification process straightforward rather than intimidating. You’ll know exactly where you already meet the standard, where the gaps are, and roughly what closing them involves before you commit to anything.
A prioritised, practical plan for closing each gap, which we work through with you rather than handing over and leaving you to it — through to submitting your self-assessment (or, for Cyber Essentials Plus, your technical audit) with confidence.
Around 10 minutes, mostly quick clicks. “Not sure” is a fine answer — it just tells us where to focus on the call.
Both certify against the same five core controls. The difference is how that’s verified — and increasingly, which one a client or contract will actually accept.
A self-assessment questionnaire, verified and certified by an accredited assessor. The right starting point for most SMEs, and often the minimum a client or public sector contract will ask for.
Everything in Cyber Essentials, plus a hands-on technical audit of your systems by a certified assessor — independent verification that the controls aren’t just documented, they’re actually in place.
We’ll flag this during your gap analysis call. If a specific client, tender or framework is driving the certification, tell us up front and we’ll build the plan around the level they actually require.
Built for small and medium-sized enterprises (SMEs) that need Cyber Essentials to win or keep a contract, satisfy a client’s supply chain requirements, or simply want proper baseline security without an in-house security team to build it. Also for organisations recertifying this year, since the requirements themselves are changing.
The National Cyber Security Centre (NCSC) and IASME Consortium update the scheme annually, and the next update tightens several requirements that trip up SMEs applying without help.
Applications will automatically fail if multi-factor authentication isn’t in place for cloud services, or if critical security updates aren’t installed within 14 days — both easy to miss without a proper review first.
Expanded scope descriptions, clearer documentation of anything you’re excluding, and legal entity identification — all things a rushed application tends to get wrong.
Stricter retesting procedures around update management, and self-assessments can no longer be edited after the technical audit — making it more important to get the self-assessment right the first time.
Once your gap analysis and accreditation plan are done, most SMEs with no major gaps are ready to submit their self-assessment within a few weeks. Cyber Essentials Plus adds time for the technical audit itself, usually booked once the self-assessment is approved.
We guide you through the gap analysis, close the gaps and prepare your submission with you. Certification itself is issued by an accredited certification body under the IASME Consortium, as required by the scheme — we make sure you go into that process ready, rather than finding out what’s missing on the day.
It covers the five Cyber Essentials control areas — firewalls and internet gateways, secure configuration, user access control, malware protection, and security update (patch) management — in plain-English questions, not technical audit language.
It depends on what’s driving the certification. Some clients, tenders and frameworks specifically require Cyber Essentials Plus; others accept the standard self-assessed certificate. We’ll help you check what’s actually required before you commit to either.
Likely yes. The new automatic-fail conditions around multi-factor authentication and 14-day patching catch out several organisations that passed comfortably under the previous year’s rules. Worth running the gap analysis again even if you’ve certified before.
Start with the gap analysis questionnaire — around 10 minutes, plain English, no commitment.
Find our work useful? Add us as a preferred source on Google.