Cyber Essentials,
certified without the guesswork.

The UK government-backed baseline covering the five controls that stop the most common attacks. I take you from first assessment to certificate, and on to Plus if you need the audited version, doing the hands-on work alongside your team.

A recognised baseline, not a box-tick.

Cyber Essentials is the UK government-backed scheme, run by IASME on behalf of the NCSC. It assesses five technical controls designed to reduce exposure to common internet attacks. For a growing business it is a clear way to show clients, insurers and public-sector buyers that core safeguards are in place.

It is also frequently a requirement, not a nice-to-have. Many UK government contracts mandate it, and more private tenders and cyber insurers ask for it every year. My job is to make sure you hold it before someone asks, and that you understand what it says about you.

Five controls. Every one covered.

01

Firewalls

Boundary and device firewalls configured to keep untrusted networks out.

02

Secure configuration

Systems and devices set up to reduce weaknesses and strip out what you don’t need.

03

Security update management

Operating systems and software kept patched and supported, so known holes stay closed.

04

User access control

Accounts and admin rights granted as needed, and removed the moment they’re not.

05

Malware protection

Anti-malware or approved application controls in place across every device.

All five, verified and evidenced, in one place you keep.
Talk it through

Cyber Essentials, or Cyber Essentials Plus?

Level one

Cyber Essentials

Self-assessed and independently verified. The right starting point for most businesses and the level most tenders ask for.

  • Assessor-verified self-assessment questionnaire
  • Certificate on a passing submission
  • Meets many tender and insurer requirements; confirm the specific requirement
  • The fastest route to a recognised badge
Level two · higher assurance

Cyber Essentials Plus

Everything in Cyber Essentials, then independently tested. The version buyers increasingly specify by name.

  • Everything in Cyber Essentials
  • Hands-on technical audit by an assessor
  • Vulnerability scan of a sample of your systems
  • Proof your controls work, not just that they exist

Thinking about Cyber Essentials? Let’s map a realistic path in a free 20-minute call.

Discuss the standard

Done with you, not handed off.

01 · Assess

Know where you stand

We scope your systems and run the self-assessment together, so you see where you conform and where you don’t.

02 · Remediate

Close the gaps together

I guide your team through each fix in plain English, gathering the evidence as we go. No jargon, no homework you can’t follow.

03 · Certify

Submit, and stay current

You submit a well-prepared application for the independent assessor’s decision. I hand you the evidence pack and set a renewal reminder so you can stay current.

More than a certificate.

  • Your Cyber Essentials or Plus certificate
  • A plain-English record of every control
  • An evidence pack you own and keep
  • The confidence to speak to your own security
  • Eligibility for included cyber insurance*
  • A renewal reminder to help you stay current

The things buyers usually ask.

How long does it take?

Most organisations certify within two to four weeks. It depends on how much remediation is needed and how quickly your team can make the changes. Cyber Essentials Plus adds a short audit on top of that.

Do we need Plus, or is the standard enough?

Not always. Many tenders and insurers ask for Cyber Essentials on its own, but requirements vary. Choose Plus when a buyer specifically asks for the audited version, or when you want the higher assurance. I will help you interpret the requirement before you decide.

Does it really come with cyber insurance?

Eligible UK-based organisations with an annual turnover under £20 million get included cyber liability insurance with certification. I will confirm whether you qualify before we start.

How long is the certificate valid?

Twelve months. I set a renewal reminder and keep your evidence current, so recertifying next year is straightforward rather than a scramble.

We are not based in the UK. Can we still certify?

Yes, international organisations can hold Cyber Essentials. If a UK badge is not what your market recognises, I will point you to the equivalent baseline for your region instead.

Ready to hold the badge before someone asks for it?

Tell me a little about your business and I’ll map a realistic path to certification. A free 20-minute call, no obligation.

Start your certification