Cyber Essentials and CE Plus Certification, Handled For You

Get certified. Stay certified.

Most businesses come to us because a contract requires it and the deadline is closer than they would like. We handle the technical work and the evidence, so it does not take over your month.

Why you are probably here

In our experience almost nobody pursues Cyber Essentials out of curiosity. Something has triggered it: a tender requires it, a customer has asked, an insurer wants it, or you are bidding for public-sector work where it is mandatory. And the deadline is rarely generous.

The good news is that it is achievable quickly. The certification is deliberately pitched at controls every organisation should have anyway, and if your IT is in reasonable order you may be closer than you think.

What Cyber Essentials actually covers

It is a UK government-backed scheme, overseen by the NCSC and delivered through IASME. It covers five technical control areas:

ControlWhat it means in practice
Firewalls Every device protected by a properly configured firewall, with default passwords changed and no unnecessary services exposed.
Secure configuration Default accounts removed or renamed, unused software gone, and nothing shipped-as-default left as it was.
Security update management Operating systems and applications supported and patched, with high-risk updates applied within 14 days.
User access control Individual accounts, least privilege, admin rights restricted, MFA on cloud services, leavers removed promptly.
Malware protection Anti-malware present, updating and actually enabled across the estate.

Cyber Essentials or Cyber Essentials Plus?

Cyber Essentials is a verified self-assessment. You answer the question set, a certification body reviews it, and you are certified.

Cyber Essentials Plus covers the same five controls but adds independent technical testing — an assessor checks a sample of your devices rather than taking your word for it. It carries more weight, takes longer and costs more. Many tenders specify which one they want, so check before you start; you must hold basic CE before you can do Plus, and Plus must follow within three months.

How we run it

  1. Gap analysis. We work through the question set against your actual estate and tell you where you stand. Usually a handful of genuine gaps rather than a wholesale rebuild.
  2. Remediation. We fix them. MFA rollout, patch policy, admin rights, firewall configuration, removing that Windows machine nobody mentioned. This is the part that takes the time.
  3. Submission. We complete the technical answers and assemble the evidence, then take you through it before it goes in.
  4. The Plus audit, if you need it — we prepare the sample devices and are present for the assessment.
  5. Renewal. Certification lasts twelve months. We diarise it and start early, so it does not lapse the week a tender lands.

The failure we see most often. Unsupported software still in use — an old Windows version, an unsupported phone, a line-of-business application that will not run on anything current. Worth checking early, because it is the one gap that can take real time and money to close.

How long it takes

If your IT is in good order, a few weeks. If the gap analysis turns up unsupported operating systems or a scattering of local admin accounts, longer — the assessment is quick, the fixing is not. Start earlier than feels necessary, particularly if a contract depends on it.

Staying certified

Certification is a snapshot of one day. The value is in staying at that standard, which is precisely what a managed support agreement does: patching stays current, MFA stays on, leavers actually get removed, and the annual renewal is a formality rather than a fortnight of remediation.

Clients on our managed IT support tend to find their second and third renewals almost uneventful.

GDPR and the wider picture

Cyber Essentials is not a data protection certification, and holding it does not make you GDPR compliant. It does cover a good deal of the technical security that UK GDPR expects of you. We also help with the rest of the technical side — encryption, access control, retention and audit logging — and produce the evidence packs clients ask for during audits.

Not sure whether this is what you need? Book a free IT review. A real engineer looks at what you have, tells you honestly what is fine and what is not, and gives you a number. No obligation, and no sales script.

Common questions

How long does Cyber Essentials take?

If your IT is already in reasonable order, a few weeks. The assessment itself is quick; the time goes on closing whatever the gap analysis finds. Unsupported software is the usual delay, so start earlier than feels necessary if a contract depends on it.

What is the difference between Cyber Essentials and CE Plus?

Both cover the same five controls. Basic Cyber Essentials is a verified self-assessment. CE Plus adds independent technical testing of a sample of your devices. You must hold basic CE before doing Plus, and Plus has to follow within three months.

Do we need to re-certify?

Yes, annually. We diarise it and start early so it does not lapse at an inconvenient moment. For clients on managed support, renewal is usually straightforward because the controls have stayed in place all year.

Does Cyber Essentials make us GDPR compliant?

No. It is a technical security certification, not a data protection one. It does cover much of the technical security UK GDPR expects, but GDPR also involves policies, records and processes beyond its scope.

What usually causes a failure?

Unsupported software still in use — an old Windows version, an out-of-date phone, or an application that will not run on a current OS. After that, missing MFA on cloud services and users running as local administrators.