IT & NETWORK · CYBER ESSENTIALS CERTIFICATION

Cyber Essentials certification for SMEs, without the guesswork.

Cyber Essentials is the UK Government-backed certification scheme, overseen by the National Cyber Security Centre (NCSC) and delivered by the IASME Consortium, that proves your organisation has the five core technical controls in place to stop the most common cyber attacks. We guide small and medium-sized enterprises (SMEs) through it in three steps: a short gap analysis questionnaire, a call with our team to talk through what it found, and an accreditation plan we then work through with you until you’re certified.

How it works

Three steps from “where do we stand?” to certified

No lengthy audit up front, and no accreditation plan built before we understand your setup. We start small, talk it through with you, then build the plan around what’s actually needed — not a generic checklist.

01

Gap analysis questionnaire

A short, plain-English questionnaire covering the five Cyber Essentials control areas — firewalls, secure configuration, user access control, malware protection and patch management. That questionnaire is step one of Cyber Essentials Certification with us, before any technical work begins. Takes most SMEs around 10 minutes, no technical jargon required.

02

A call with our team

We talk through what the questionnaire found — in plain terms, not a jargon-heavy report. Explaining it plainly at that stage is what makes the rest of the Cyber Essentials Certification process straightforward rather than intimidating. You’ll know exactly where you already meet the standard, where the gaps are, and roughly what closing them involves before you commit to anything.

03

An accreditation plan, worked through together

A prioritised, practical plan for closing each gap, which we work through with you rather than handing over and leaving you to it — through to submitting your self-assessment (or, for Cyber Essentials Plus, your technical audit) with confidence.

Step 1 · Start here

Your gap analysis questionnaire

Around 10 minutes, mostly quick clicks. “Not sure” is a fine answer — it just tells us where to focus on the call.

About you and your business

About your certification

Quick gap check

Answer as best you can — “not sure” is a perfectly good answer and tells us where to focus on the call.

Which level do you need?

Cyber Essentials, or Cyber Essentials Plus

Both certify against the same five core controls. The difference is how that’s verified — and increasingly, which one a client or contract will actually accept.

Cyber Essentials

A self-assessment questionnaire, verified and certified by an accredited assessor. The right starting point for most SMEs, and often the minimum a client or public sector contract will ask for.

Cyber Essentials Plus

Everything in Cyber Essentials, plus a hands-on technical audit of your systems by a certified assessor — independent verification that the controls aren’t just documented, they’re actually in place.

Which one, in practice

We’ll flag this during your gap analysis call. If a specific client, tender or framework is driving the certification, tell us up front and we’ll build the plan around the level they actually require.

Who this is for

SMEs certifying for the first time, or renewing under stricter rules

Built for small and medium-sized enterprises (SMEs) that need Cyber Essentials to win or keep a contract, satisfy a client’s supply chain requirements, or simply want proper baseline security without an in-house security team to build it. Also for organisations recertifying this year, since the requirements themselves are changing.

Worth knowing before you apply

The Cyber Essentials requirements are getting stricter in April 2026

The National Cyber Security Centre (NCSC) and IASME Consortium update the scheme annually, and the next update tightens several requirements that trip up SMEs applying without help.

New automatic fail conditions

Applications will automatically fail if multi-factor authentication isn’t in place for cloud services, or if critical security updates aren’t installed within 14 days — both easy to miss without a proper review first.

Stricter scope documentation

Expanded scope descriptions, clearer documentation of anything you’re excluding, and legal entity identification — all things a rushed application tends to get wrong.

Tighter Cyber Essentials Plus retesting

Stricter retesting procedures around update management, and self-assessments can no longer be edited after the technical audit — making it more important to get the self-assessment right the first time.

Questions we’re asked most

Answered plainly

How long does Cyber Essentials certification take?

Once your gap analysis and accreditation plan are done, most SMEs with no major gaps are ready to submit their self-assessment within a few weeks. Cyber Essentials Plus adds time for the technical audit itself, usually booked once the self-assessment is approved.

Do you carry out the certification, or just help us prepare for it?

We guide you through the gap analysis, close the gaps and prepare your submission with you. Certification itself is issued by an accredited certification body under the IASME Consortium, as required by the scheme — we make sure you go into that process ready, rather than finding out what’s missing on the day.

What’s actually in the gap analysis questionnaire?

It covers the five Cyber Essentials control areas — firewalls and internet gateways, secure configuration, user access control, malware protection, and security update (patch) management — in plain-English questions, not technical audit language.

Do we need Cyber Essentials Plus, or is Cyber Essentials enough?

It depends on what’s driving the certification. Some clients, tenders and frameworks specifically require Cyber Essentials Plus; others accept the standard self-assessed certificate. We’ll help you check what’s actually required before you commit to either.

We’re recertifying this year — does the April 2026 update affect us?

Likely yes. The new automatic-fail conditions around multi-factor authentication and 14-day patching catch out several organisations that passed comfortably under the previous year’s rules. Worth running the gap analysis again even if you’ve certified before.

Not sure where you stand on Cyber Essentials?

Start with the gap analysis questionnaire — around 10 minutes, plain English, no commitment.

📞 0845 095 3600  ·  ✉ info@efficient-is.co.uk

Start your free gap analysis

Find our work useful? Add us as a preferred source on Google.