How to spot a genuine Cyber Essentials assessor

A short guide to choosing a Cyber Essentials partner whose certificate actually stands up, and spotting the ones selling a badge rather than security.

Insights · 11 September 2026

Not all Cyber Essentials providers are the same. Some get you genuinely secure and certified; others sell a badge. Here is how to tell them apart before you commit.

Green flags

  • They are a certified IASME assessor, so a qualified person actually verifies your submission.
  • They will tell you honestly if you are not ready, and help you fix it, rather than pass you regardless.
  • They explain each control in plain English so you understand what you are certifying.
  • They check rather than assume, and ask sensible questions about your setup.
  • They have a verifiable track record and are realistic about timing.

Red flags

  • A guaranteed pass regardless of the state of your controls, or a 100% pass rate used as the main headline.
  • No real questions and a suspiciously instant certificate.
  • No named assessor, and no clear answer on what happens if you are not ready.

Three questions to ask

Ask any provider: Are you a certified IASME assessor? What happens if I am not ready to pass? Will you actually check my answers, or just submit them? The answers tell you very quickly whether you are buying assurance or just a badge.

Common questions

What is the single best question to ask a Cyber Essentials provider?

“What happens if I am not ready to pass?” A genuine assessor will say they will tell you and help you fix it. A badge-seller will imply it never happens.

Does a low price mean a poor assessor?

Not necessarily. Cyber Essentials should be affordable. Judge on whether a real assessment and remediation help are included, not on price alone.

Related

Cyber Essentials that actually means something.

A genuine assessment, honest advice, and a certificate that stands up. Fixed price, no obligation.