Cyber Essentials and Cyber Essentials Plus support
Gap analysis against the five controls, technical remediation of what is failing, and support through the certification process itself.
Cyber Essentials is the UK government-backed baseline scheme, run by IASME on behalf of the National Cyber Security Centre. It covers five technical control areas: firewalls, secure configuration, user access control, malware protection, and security update management. Increasingly it is not optional — it is a condition of tendering, a requirement in supply chain contracts, and a standing question on cyber insurance forms.
The scheme is a self-assessment questionnaire, which creates a temptation to answer it optimistically and move on. That is a bad idea for two reasons. Insurers have declined claims where the answers did not match reality. And Cyber Essentials Plus, the audited tier, involves an assessor testing your actual systems — at which point optimistic answers surface anyway.
Our approach is to treat the questionnaire as the last step, not the first. We assess what you have against the five controls, tell you plainly what would fail today, fix it, and then take you through certification with answers that are true.
What's included
What cyber essentials covers
Gap analysis against the five controls
A clear statement of what currently passes, what fails, and what is unclear.
Firewall and boundary configuration
Rule review and hardening, with the default-deny posture the scheme expects.
Secure configuration
Default accounts and unnecessary services removed; device baselines set and applied.
User access control
Administrative privilege separated from day-to-day accounts, with MFA enforced.
Malware protection
Endpoint protection configured and verified as actually deployed everywhere.
Security update management
Patching brought inside the required timescales and evidenced.
Asset inventory and scoping
The scope question derails more applications than any other. Answered properly first.
Support through submission
We complete the questionnaire alongside you and stay involved through to the result.
This is probably for you if
- A tender or customer contract has asked whether you hold Cyber Essentials
- Your insurer has started asking questions you cannot confidently answer
- You certified once and let it lapse
- You are not sure whether your setup would pass if anyone actually checked
Not sure? The free security assessment scores all four pillars in 10–15 minutes and tells you which of these actually apply.
Cyber Essentials for North West businesses
Cyber Essentials comes up most often in the North West through supply chains. A manufacturer or engineering firm in St Helens, Warrington or Knowsley wins work with a larger customer, and certification appears in the contract terms. Public sector and MoD-linked work makes it a hard requirement rather than a preference.
For most businesses of 10 to 25 users the technical remediation is the real work, and how long it takes depends entirely on what state things are in. We would rather tell you that honestly at gap analysis than discover it a week before a tender deadline.
Common questions
Cyber Essentials is a self-assessment questionnaire, independently reviewed and then certified. Cyber Essentials Plus covers the same five controls but adds hands-on technical testing by an assessor, including vulnerability scanning and checks on a sample of your devices. CE Plus requires you to hold current Cyber Essentials first.
There are two separate costs. Certification fees are paid to your certification body and are banded by organisation size, with Cyber Essentials Plus priced separately based on the size of the device sample to be tested — check the current IASME bands, as they are reviewed periodically. Then there is the cost of fixing whatever is failing, which varies entirely with your starting position. We quote remediation as a fixed price after gap analysis, so you know both numbers before committing.
If your environment is already in reasonable shape, a matter of weeks. If MFA is not deployed, patching is unmanaged, or nobody can produce an asset list, expect longer — the remediation is the variable, not the paperwork.
Yes. The scheme covers cloud services including Microsoft 365, and the user access control requirements apply to them. Cloud is frequently where applications fail, because MFA has been enabled for some accounts but not enforced for all.
We are working towards our own certification. We would rather say that plainly than imply otherwise — and it does not affect our ability to prepare you for yours, which is a technical exercise against a published, public standard.
Related services
Free · No obligation · UK
Find out where you stand first.
Before committing to anything, take the free security assessment. 24 questions across four pillars, your score and priority action list the moment you finish — no call required.