Cyber Essentials · Cyber Essentials Plus · Readiness
The certificate yourcustomers ask for,without the drama.
A readiness check first, so you know what needs fixing before anyone is watching. Then the assessment, the Plus audit if you need it, and a certificate in weeks rather than months.
Readiness checkPlus auditsTwo to four weeks typical
The five controls
What the scheme actually checks
Cyber Essentials is the NCSC-backed baseline. It is deliberately practical: five controls that stop the commodity attacks behind most incidents.
Firewalls
Boundary and software firewalls configured so only necessary services are reachable, with default passwords changed.
Secure configuration
Devices and software set up to reduce their attack surface: unused accounts and services removed, auto-run disabled, locking enforced.
User access control
Least privilege, separate admin accounts, multi-factor authentication on cloud services.
Malware protection
Supported anti-malware, application allow-listing or sandboxing on every in-scope device.
Security update management
Supported software only, with critical and high-risk updates applied within fourteen days.
Plus
The same controls, independently verified by an assessor through vulnerability scans and device checks.
The process
Ready, assess, certify
Stage 01
Readiness check
We review your estate against the five controls and tell you exactly what would fail.
Stage 02
Fix
Clear remediation guidance; our engineers can do the work if you would rather they did.
Stage 03
Assess
The Cyber Essentials self-assessment, checked before submission.
Stage 04
Plus audit
Internal and external vulnerability scans and device checks for the Plus certificate.
Pricing
What it costs
- _01Readiness and audit supportQuoted on the size and shape of your estate after a short call — number of devices, sites and cloud services — as a fixed fee.Fixed fee
- _02Certification feeThe certification body's fee is set by organisation size and passed through at cost.At cost
- _03RemediationOptional. If you want our engineers to make the fixes, that is quoted separately once the readiness check has shown what is needed.Optional
Questions
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is a verified self-assessment against the five controls. Plus adds an independent technical audit — vulnerability scans and checks on a sample of devices — so the certificate carries more weight with customers, insurers and public-sector buyers.
How long is the certificate valid?
Twelve months. Most organisations renew annually; we can run the readiness check again each year so renewal is routine.
We already have a SOC or ISO 27001. Is this still worth it?
Usually, yes. Cyber Essentials is increasingly a contractual requirement, and the readiness check is a cheap way to confirm the basics still hold.
Start a conversation