- Scheme owner
- IASME, NCSC's delivery partner
- Assessment
- Self-assessment, independently marked
- Typical timeline
- 2–6 weeks
- Our status
- Certified assessor
What Cyber Essentials covers
Five technical control areas that between them stop the overwhelming majority of commodity attacks: firewalls, secure configuration, security update management, user access control, and malware protection. It is deliberately a baseline rather than a comprehensive standard — the point is that it addresses the attacks that actually happen to ordinary organisations.
Why organisations get certified
- Contracts. Central government contracts involving personal data or technical services require it. Increasingly, so do local authorities, NHS trusts, universities and large private-sector buyers pushing requirements down their supply chain.
- Insurance. Many cyber insurance policies price on it, and some UK insurers include automatic cover for small organisations that hold it.
- Client assurance. A certificate answers a security questionnaire far more efficiently than forty pages of prose.
- It genuinely helps. Even setting the certificate aside, the five controls are the right five things for a small organisation to get right first.
How we work
Plenty of providers will sell you the assessment and leave you to complete it. That works if you already meet the controls. If you do not, you fail, and you find out after you have paid.
Gap review first
We go through the question set with you and identify honestly where you currently stand. Most organisations have three or four genuine gaps — commonly unsupported software still in use, multi-factor authentication missing on cloud services, local administrator rights on user accounts, and mobile devices outside any management.
Remediation you can actually do
Specific, practical guidance for your environment rather than a restatement of the requirement. If you run Microsoft 365 and Intune, we will tell you which settings to change. If your IT is outsourced, we will write the instructions in a form your provider can action without a further round of translation.
Submission and certification
We help you complete the assessment accurately, review your answers before submission, and support any clarifications. Because we are a certified assessor, we know what marking actually looks for — which is not always what the question appears to ask.
Scoping honestly
Scope is where most difficulty arises. Certification can cover the whole organisation or a defined subset, and the temptation is to draw a boundary that excludes the awkward parts. Be careful: a scope that excludes most of your estate produces a certificate that a sophisticated buyer will read and discount, and it may not satisfy the contract you are certifying for in the first place. We will tell you if we think a proposed scope will not stand up.
What comes after
Certification lasts twelve months and the question set is revised periodically, so what passed last year may not pass this year. Cyber Essentials Plus adds hands-on technical verification by a licensed Plus certification body — we do not carry out the Plus audit ourselves, but we prepare you for it. IASME Cyber Assurance is the natural next step for organisations needing something broader.
Common questions
How long does Cyber Essentials take?
If you already meet the controls, you could complete the assessment in a few days. Realistically most organisations need two to six weeks including remediation. The common delay is replacing unsupported software or rolling out multi-factor authentication, neither of which can be rushed safely.
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is a self-assessment that is independently marked. Cyber Essentials Plus covers the same five controls but adds hands-on technical verification by an assessor — vulnerability scanning of a sample of devices, plus tests of malware protection and patching. You must hold valid Cyber Essentials before Plus.
Can we fail?
Yes, and a fail costs you the fee. This is exactly why we do the gap review first. Common causes are unsupported operating systems still in use, missing multi-factor authentication on cloud administrator accounts, and users with local administrator rights on their day-to-day account.
Do we need it if we do not sell to government?
Not necessarily, but requirements are spreading through supply chains faster than most people expect. If you supply anyone who supplies the public sector, or you hold client data and answer security questionnaires, it is usually worth having before somebody demands it at short notice.
Does Cyber Essentials cover our cloud services?
Yes. Cloud services in use are in scope, including infrastructure, platform and software as a service. The requirements around administrative access and multi-factor authentication on cloud services are where organisations most often discover a gap.
Related
Solusec
Typically replies within one business day
Hi 👋 Need a hand with pen testing, Cyber Essentials, or something urgent? Pick whichever suits you:
💬 WhatsApp usQuick questions, quick answers 📞 Call us
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day