All Services
Certification without the runaround

Cyber Essentials without the consultancy bill.

The government-backed certification your insurer and your bigger clients keep asking for. We get you ready, fix what actually needs fixing, and see you through the assessment.

Cyber Essentials has quietly stopped being optional. Insurers ask whether you hold it, and increasingly price your premium accordingly. Public sector contracts require it outright. Larger clients put it on tender documents as a tick-box, and a missing tick can be the end of the conversation.

The good news is that it is far less painful than it sounds, and most businesses are closer to passing than they expect.

What it actually is

Cyber Essentials is a UK government-backed scheme, run by IASME on behalf of the National Cyber Security Centre. It certifies that you have five basic technical controls in place:

  • Firewalls — controlling what can reach your network from outside
  • Secure configuration — devices and software set up sensibly rather than left on defaults
  • Security update management — updates applied, in reasonable time
  • User access control — people having the access they need and no more
  • Malware protection — something competent watching for the obvious threats

None of that is exotic. It is the list of things you should be doing anyway. Which is why most businesses we assess are already most of the way there — they need the remaining gaps closed and the evidence assembled, not a wholesale rebuild.

What changed in April 2026

The scheme moved to version 3.3 for assessments started after 27 April 2026, and one change matters more than the rest.

Multi-factor authentication is now required on every cloud service that offers it. Not recommended — required. If a cloud service you use supports MFA and you have not switched it on, that is an automatic fail, however good the rest of your setup is.

Two related changes come with it. “Cloud service” now has a formal definition and cannot be left out of scope, so the mail platform or file-sharing tool somebody forgot to mention is in whether you like it or not. And the scoping language has been tightened, which in practice widens what counts as in-scope.

The update also leans harder towards passwordless sign-in — passkeys and hardware keys — as the preferred approach rather than passwords plus a code.

If you were certified before April, none of this bites until you renew. It will bite then, and MFA coverage is the thing worth checking first.

Most businesses fail on evidence and MFA, not on security. The security is usually fine.

How we work

We are not a Certification Body. We prepare you for certification, and an IASME-licensed body assesses the result.

We think that is the right way round. Doing the technical work and then marking the same homework is an awkward position for anyone to be in, and an independent assessment is worth more to you — and to whoever is asking you for the certificate.

What we actually do:

  • An honest assessment of where you stand today, including what already passes
  • The technical work to close the gaps — MFA rollout, update policies, account tidying, configuration
  • Writing the policies you are asked for, at the length they actually need to be
  • Getting your answers straight before submission, so the assessment is not a guessing game
  • Staying with it if anything comes back needing clarification

No upselling tools you do not need. No fifty-page security policy nobody will ever read.

Cyber Essentials Plus

Cyber Essentials is a self-assessment, reviewed by the Certification Body. Cyber Essentials Plus adds an independent technical audit — someone checks your actual machines rather than taking your word for it.

Some contracts and some insurers specifically require Plus. If yours does, say so at the outset: the Plus audit has to follow on from your basic certification within a defined window, so it is much easier to plan for from the start than to bolt on afterwards. We prepare systems to pass it first time rather than discovering problems during the audit.

What it costs

The certification fee goes to IASME and depends on your headcount:

Organisation sizeCertification fee
0–9 employees£320 + VAT
10–49 employees£440 + VAT
50–249 employees£500 + VAT
250+ employees£600 + VAT

Our work is separate and depends on how much closing the gaps takes — which is exactly what the initial assessment tells us. You get that figure before we start, not afterwards.

Certification lasts 12 months and is then renewed. Renewals are usually far quicker than the first time, because the hard part is already done.

Getting started

Tell us roughly how many staff and machines you have, and whether anyone has asked you for the certificate specifically. We will tell you where you stand and what it would take.

If it turns out you are already close, we will say so.

What's included

Everything you need, nothing you don't.

Honest gap assessment

We tell you what already passes as well as what does not. Most businesses are closer than they expect.

MFA, properly rolled out

Now an automatic fail if it is missing. We switch it on across your cloud services without locking anybody out.

The technical work

We fix the gaps rather than hand you a list of them. Updates, configuration, account tidying.

Policies at sensible length

The documents the assessment asks for, written to be read rather than to look thorough.

Cyber Essentials Plus

Preparation for the independent technical audit, so it passes the first time.

Renewals

Certification lasts a year. We keep track and make the next one quicker than the last.

Other services

Explore more of what we do.

Ready to get started? Let's talk.

Get in touch for a no-obligation chat about how we can help with your IT.

Get in Touch