Cyber Essentials Readiness

Cyber Essentials is a questionnaire
you have to answer truthfully.

Which is the whole difficulty. The five controls are not complicated and the certification is not expensive — the work is getting your business into a state where the honest answers are the passing ones. That is what we do.

What is Cyber Essentials?

A UK government-backed scheme that checks a business has five basic security controls in place. It is increasingly required to bid for public sector and supply-chain contracts. We get those controls genuinely in place so you can answer the assessment honestly — certification itself is issued by an accredited body, not by us.

At a glance

What it is
A government-backed security baseline
Why get it
Contracts, insurers and customers ask
The work
Five controls, genuinely in place
Two levels
Basic and Plus with a hands-on check
Certificate from
An IASME-accredited body
Our role
Getting you ready to pass honestly

What it is, plainly

A government-backed baseline, not a security strategy

Three things about the scheme that are worth understanding before you spend anything on it.

We prepare you. We do not certify you

Certification is issued by bodies accredited by IASME, the scheme's delivery partner. We are not one of them and will not pretend to be. What we do is get the controls genuinely in place and the self-assessment answerable honestly, then point you at a certifying body to issue it.

It is a floor, not a ceiling

Cyber Essentials covers five basic technical controls. Meeting them makes you meaningfully harder to attack opportunistically, which is how most small businesses are actually attacked. It does not make you secure and anybody selling it as though it does is overselling.

Increasingly, it is a condition of bidding

This is usually the real reason a small business looks at it. Public sector contracts and a growing number of private supply chains require it, so it stops being a security decision and becomes a commercial one — you cannot bid without it.

Outcomes

What changes for your business

  • The five controls genuinely in place
  • Honest answers that are also passing answers
  • Fewer easy ways in for automated attacks
  • Able to bid for contracts that require it
  • A record of what was done, for next year's renewal
  • Staff who understand the few rules that matter

The five controls

What you are actually being asked about

01

Firewalls

Boundary firewalls and internet gateways configured deliberately rather than left as the router arrived from the provider.

02

Secure configuration

Devices and software set up to reduce what is exposed — default passwords gone, unnecessary accounts and services removed, nothing left switched on because nobody looked.

03

User access control

Accounts that match who actually works for you now, administrative rights held only by people who need them and a way to know that is still true in six months.

04

Malware protection

Protection against malicious software on the devices your people actually use, including the ones they own and work on.

05

Security update management

Everything patched and in support. This is the control that fails most often and it fails quietly — it takes one unattended plugin or one operating system past its end of life.

06

And the part that catches people

Scope. The certificate covers what you declare it covers and a self-assessment that quietly excludes the awkward half of the business is worth very little. Deciding scope honestly is most of the work.

How it runs

Four stages

  1. One

    What is actually here

    An inventory of the devices, accounts, software and services your business really runs on — including the ones nobody has thought about since they were set up. Most small businesses have never had one.

  2. Two

    Answer it honestly, first

    We go through the self-assessment with you and write down the true answers, including the failing ones. That document is the actual work plan and it is uncomfortable reading the first time.

  3. Three

    Fix the gaps

    Closing the gaps, in the order that reduces real risk fastest rather than the order the form lists them in.

  4. Four

    Certify, then keep it true

    You submit to a certifying body. Then the harder part: it lapses annually and a business drifts out of compliance quietly. We can keep watching it if you want that.

What we do and what we do not

We do

  • Inventory what your business actually runs on
  • Work through the self-assessment with you, truthfully
  • Close the technical gaps we find
  • Advise on scope, which is where most of the difficulty is
  • Secure and patch what we host for you
  • Keep watching it after certification, if you want that

We do not

  • Issue the certificate — an accredited body does that
  • Run a helpdesk or provide day-to-day IT support
  • Help you answer the questionnaire in a way that is not true
  • Claim this makes you secure, because it does not

Common questions

Can you certify us?

No — and be wary of anyone who says they can while also doing your remediation. Certification is issued by bodies accredited by IASME. We get you into a state where you can answer the assessment honestly and pass it and then you certify with a body that does that for a living.

How long does it take?

It depends almost entirely on what state things are in when we start. A business with modern equipment, everything in support and a clear idea of who has access can be ready in a couple of weeks. One with unsupported systems and accounts belonging to people who left in 2021 takes longer and finding that out is itself worth having.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

The basic scheme is a self-assessment that you complete and an accredited body reviews. Plus adds hands-on technical verification by an assessor — they check rather than take your word for it. Some contracts specify which one they require, so check the requirement before choosing.

We only need it to bid for a contract. Is that a bad reason?

It is the commonest reason and it is a perfectly good one. The useful thing is that the work still has to be real: you cannot bid on a certificate you obtained by answering untruthfully, because the declaration is signed by a company officer and it is that officer's problem if it is wrong.

Do you do IT support as well?

No — and we say so early. We are not a helpdesk and do not want to be one — we secure and maintain what we build and host. If you need somebody to fix a laptop on a Tuesday morning you need a different kind of firm and we would rather tell you that than take the work.

Free website audit

Not sure where your website stands?

Get a free website health check: a written audit of your site and email domain — renewals, security, email spoofing, speed and AI visibility — read by a person before it is sent.

Get a free website audit

Answer the questionnaire honestly
and see what happens.

It is free to look at and the first honest run through it tells you more about your business than most paid assessments will. We will do it with you and tell you what the gaps would cost to close.

Support