Cyber Essentials

The baseline your business needs. We get you there.

Cyber Essentials is the UK government's cybersecurity certification for businesses. It proves you have five fundamental security controls in place — the controls that prevent the vast majority of common cyber attacks.

For small businesses, it's increasingly a requirement rather than a nice-to-have. Government contracts require it. Larger clients and partners expect it. Insurance providers look for it. And the process of getting certified often reveals security gaps you didn't know existed.

We handle the technical work: auditing your current setup against the five controls, fixing what's missing, configuring your devices and accounts to meet the standard, and guiding you through the self-assessment questionnaire. Most small businesses are assessment-ready within 1–2 weeks.

The Five Controls

Cyber Essentials assesses five technical security controls. Together, they protect against approximately 80% of common cyber attacks.

01

Firewalls

Every device that connects to the internet must be protected by a properly configured firewall. This includes routers, laptops, and any cloud services. Default firewall rules must block unauthorised inbound connections.

02

Secure Configuration

Devices and software must be configured securely — default passwords changed, unnecessary services disabled, and only required software installed. No device should run with default factory settings.

03

User Access Control

User accounts must follow the principle of least privilege — people only get access to what they need. Admin accounts must be separate from day-to-day accounts, and MFA is required for all cloud services.

04

Malware Protection

Anti-malware software must be installed, active, and kept up to date on all devices. This includes real-time scanning, automatic updates, and prevention of connections to known malicious websites.

05

Security Update Management

Operating systems, applications, and firmware must be kept up to date. Critical and high-risk security patches must be applied within 14 days of release. Unsupported software must be removed.

How We Get You Certified

1

Gap audit

We review your current IT setup against all five Cyber Essentials controls. You get a clear report showing what passes, what fails, and what needs fixing.

2

Remediation

We fix the gaps — configuring firewalls, enforcing MFA, enrolling devices in Intune, patching software, tightening user access, and enabling anti-malware protection.

3

Self-assessment guidance

We walk you through the IASME self-assessment questionnaire, making sure every answer is accurate and your evidence is solid. No guesswork.

4

Ongoing compliance

Certification lasts 12 months. We maintain your security posture year-round so renewal is a formality, not a project.

Need Cyber Essentials Plus?

Cyber Essentials Plus adds an independent technical audit on top of the self-assessment. An external assessor tests your systems hands-on to verify the controls are actually working.

We prepare businesses for both levels. If your clients or contracts require Plus, we'll make sure you pass the technical audit first time.

Learn about Cyber Essentials Plus →

Frequently Asked Questions

Cyber Essentials is a UK government-backed cybersecurity certification scheme managed by the NCSC (National Cyber Security Centre). It verifies that an organisation has five basic security controls in place: firewalls, secure configuration, user access control, malware protection, and security update management.

If you handle personal data, work with larger organisations, or bid for government contracts, Cyber Essentials is increasingly expected or required. Since 2014, it has been mandatory for government contracts involving the handling of sensitive or personal data. Many private-sector procurement processes now also require it.

For most small businesses, we can get you assessment-ready within 1–2 weeks. The self-assessment itself takes a few hours to complete. If significant gaps are found during our audit, remediation might add a few days depending on the work needed.

The IASME assessment fee for micro and small businesses (under 250 employees) starts at around £300 + VAT. Our preparation, audit, and remediation service is separate and priced based on your setup's complexity — contact us for a quote.

Cyber Essentials is a self-assessment questionnaire verified by a certification body. Cyber Essentials Plus includes everything in Cyber Essentials but adds an independent technical audit — a hands-on test of your systems by an external assessor to verify the controls are actually working, not just claimed.

Cyber Essentials certification is valid for 12 months. You need to re-certify annually. We help clients maintain compliance year-round so renewal is straightforward rather than a last-minute scramble.

Other Services

Ready to get Cyber Essentials certified?

We'll audit your setup, fix the gaps, and guide you through the assessment.

Get Started