Cyber Essentials, done properly, in weeks not months.
Cyber Essentials is the UK government-backed standard that insurers, public-sector buyers and larger customers increasingly ask for. The questionnaire is not hard; being able to answer it honestly is. We fix the settings, answer the questions and get you the certificate.
Who this is for
Businesses that have been asked for Cyber Essentials by a customer, a tender, an insurer or a regulator, and businesses that simply want a recognised baseline. Charities, healthcare providers, professional services firms and anyone in a public-sector or defence supply chain are the usual candidates.
What is included
Gap assessment
We check your devices, accounts, firewall and Microsoft 365 against the five Cyber Essentials controls and tell you exactly what would fail today.
The fixes
Multi-factor authentication, patching, device encryption, admin account separation, firewall rules, unsupported software removed. For managed IT clients most of this is already in place; for others it is the bulk of the work.
The questionnaire, answered
We complete the self-assessment with you, in language the assessor accepts, and submit it through an IASME-licensed certification body.
Cyber Essentials Plus
Where you need Plus, we arrange the independent audit, prepare the devices it will test, and sit in on the assessment.
Evidence for insurers and tenders
The certificate, the scope statement and a short summary you can attach to insurance renewals and bids.
Renewal
Certification lasts twelve months. We diarise it, re-check the controls and resubmit, so it never lapses in the middle of a tender.
What is not included, and why
- The certification body's fee. Charged at cost by the body, based on the size of the organisation, and shown on the quotation.
- Replacing unsupported equipment. If a device or piece of software has to go because it is out of support, we tell you before starting and quote replacements separately.
What it costs
A fixed price for the assessment, fixes and submission, plus the certification body's fee at cost. Cyber Essentials Plus is quoted on top, based on the number of devices to be tested. Managed IT clients usually need only the submission, at a lower fixed price. Prices are available on request: get in touch or book a call.
How it starts
- 1Free IT Health CheckA short online check that benchmarks your security and business risk and tells you where you stand.
- 2Discovery callAn engineer, not a salesperson. What you have, what is broken, what it would cost to fix, in writing.
- 3OnboardingEverything moves across on a plan, with no gap in cover and nothing lost.
Questions people ask before signing
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is a self-assessment verified by a certification body. Plus adds an independent technical audit where an assessor tests a sample of your devices and your email and browser protections. Tenders and some insurers specify Plus; most only require the basic level.
How long does it take?
Two to six weeks, depending on how much needs fixing first. Managed IT clients are usually at the short end because the controls are already in place.
Does it cover working from home?
Yes, and that is where most businesses fail. Any device that accesses company data is in scope, including personal laptops and phones. We either bring them under management or design the scope so they are excluded properly.
Will it satisfy our cyber insurer?
Most UK cyber insurers now either require Cyber Essentials or discount for it. Certifying the whole organisation also includes free cyber liability insurance for eligible smaller organisations, subject to the scheme's current terms.
We failed last time. Can you help?
Yes. The usual causes are unsupported software, admin accounts used for everyday work, missing MFA and devices that were never updated. All are fixable within the fortnight; we look at the failure report and tell you exactly what happened.
Is it the same as being secure?
No. It is a baseline that stops the common, untargeted attacks, which is most of them. The 24/7 monitoring on our cyber security page is the next layer, for businesses whose data is worth a targeted attempt.