Cyber Security

Cyber Essentials

The certificate is often the difference between qualifying for a tender and being filtered out before anyone reads your bid. We close the gaps against the five control areas, then help you produce the evidence, because the assessment is the easy part.

5technical control areas the scheme tests
4-12weeks is the typical path from gap analysis to certificate
Annualrecertification, which we diarise for you
A walkthrough of the five control areas, the evidence you need, and where most businesses lose points.

What this protects

Your place on tender and supplier lists

Cyber Essentials is often a gate rather than a grade. Miss it and a bid can be closed before your price is ever read.

The gate on public sector work

It is increasingly a mandatory question in tenders and supply chain checks. A certificate answers it quickly, and its absence can end the conversation.

Insurance and contractual cover

Insurers and larger customers ask about the same five controls. Meeting them keeps your cover valid and your answers honest.

Evidence, not guesswork

A documented baseline you can stand behind. If something does go wrong, you can show what you had in place rather than describe what you meant to.

What Cyber Essentials actually is

Cyber Essentials is a UK government-backed scheme run by IASME. It sets out five technical control areas and asks you to demonstrate you meet them. It is not a measure of how mature your security is. It is a baseline, and a reasonably sensible one.

It matters commercially because it is increasingly requested in public sector tenders and supply chain questionnaires. A certificate is a quick, verifiable answer to "are you taking this seriously?" that does not require you to write a novel.

Where businesses get stuck is rarely the technology. It is that nobody has documented what they actually have, so the self-assessment becomes guesswork.

The five control areas

Firewalls

Boundary and host-based firewalls, correctly configured, with rules you can justify rather than rules nobody dares remove.

Secure configuration

Default accounts removed or renamed, unnecessary services switched off, and software kept current.

User access control

Accounts created only with approval, admin rights restricted, and leavers removed promptly and provably.

Malware protection

Endpoint protection that is present, updating and actually reporting, rather than installed in 2021 and forgotten.

Patch management

A defensible patching process with evidence of timings, including the exceptions and why they exist.

What we do for you

  • A gap analysis against the current scheme requirements, in plain English
  • Remediation work to close anything that fails, quoted before it starts
  • Asset inventory, network diagrams and configuration records you did not previously have
  • A documented patching and access control process that stands up to scrutiny
  • Support through the self-assessment questionnaire, then the assessment itself
  • A diary reminder before your certificate expires, because nobody remembers annually

Cyber Essentials or Plus?

Cyber Essentials is a self-assessed questionnaire, verified by a certification body. It is a reasonable starting point and satisfies most supply chain requests.

Cyber Essentials Plus adds an independent technical assessment where an assessor tests your controls directly. It is harder, more expensive and occasionally uncomfortable, which is rather the point. Larger public sector contracts often insist on it.

We will tell you honestly which one you need rather than selling you the bigger one by default.

Common reasons businesses fail

  • Unsupported operating systems still running somewhere and unaccounted for
  • Local administrator rights on every laptop because nobody ever removed them
  • Endpoint protection installed but the console has not been checked in months
  • A firewall rule allowing inbound access that nobody can explain
  • No formal process for removing access when someone leaves

Questions we get asked about Cyber Essentials

If you bid for public sector contracts, increasingly yes. It is often a mandatory question. In the private sector it depends on your customers. If you supply a large organisation, they will probably ask about it within a year or two.

Usually between four and twelve weeks. Most of that is remediation rather than assessment. If your environment is already tidy, it can be far quicker.

No, and anyone who tells you otherwise is selling you something. It is a baseline covering five areas. It will not protect you from a determined attacker or a convincing phishing email. It is a sensible floor, not a ceiling.

Certification must come from an accredited certification body, so we prepare you and manage the process rather than issuing the certificate ourselves. That separation is deliberate and a good thing.

You get the findings and a period to remedy them. We work through the list with you. The goal is that the findings are small and the fix is quick, which is what the gap analysis is for.

Not sure whether you need cyber essentials?

Book a free 60-minute health check. We will tell you what you actually need, including when the answer is nothing.