It is a requirement in a tender
You are part way through a bid and Cyber Essentials is listed as a mandatory requirement. The submission date is fixed and you need to know whether you can realistically get there.
Cyber Essentials for small business
A free 30-minute readiness review with the accredited assessor who would actually mark it. Not a salesperson. Not a generalist.
If a tender, a main contractor or an insurer has asked whether you hold Cyber Essentials certification, half an hour with one of our qualified assessors will tell you exactly where you stand before you commit to anything.
No obligation, no sales pitch, and the written summary is yours whatever you decide to do next.
Almost nobody goes looking for Cyber Essentials certification. It arrives as a requirement in someone else's paperwork, usually with a deadline attached. If any of these sound like your week, you are in the right place.
You are part way through a bid and Cyber Essentials is listed as a mandatory requirement. The submission date is fixed and you need to know whether you can realistically get there.
Your subcontract terms have been updated and certification is now expected across the supply chain. The work is already yours. You just need to keep it.
A council or NHS framework application asks for certification before you can be listed, and the prequalification questionnaire will not let you past the question.
A renewal form or a board paper wants evidence that basic controls are in place, and nobody internally can say for certain whether they are.
Whichever one brought you here, the first question is the same. Would you pass today? Half an hour with a qualified assessor will tell you.
Book your free readiness reviewFree readiness review
Thirty minutes, online, with a qualified Cyber Essentials assessor. Choose a slot from the calendar and we will send a confirmation straight away.
We will ask one short question when you book, so the assessor knows what is driving this and can spend the time where it matters most.
Your readiness review is with one of our qualified Cyber Essentials assessors. Not an account manager, not a generalist engineer, and not someone reading from a checklist. The people below assess against the scheme for a living, which is why they can tell you in thirty minutes what would fail and why it matters.
Fern Ritchie and Narayan Dosanjh, our qualified Cyber Essentials assessors.
Fern Ritchie
Team Leader, Senior Security & Compliance Engineer
Fern leads our security and compliance team. She joined as an apprentice in 2019, completed her Level 3 Infrastructure Technician Apprenticeship in 2022, then specialised in cyber security, earning CompTIA Security+ and going on to complete an Applied Cyber Security degree with a first.
She holds the Cyber Essentials Assessors Certificate, has been featured on Notts Today on Notts TV, and has presented at Channel Futures in London.
Narayan Dosanjh
Cyber Essentials Assessor
Narayan brings nearly eight years of hands-on experience across the full IT support spectrum. Starting as a service desk apprentice, he progressed through Tier 2 technical support before specialising in cyber security.
Today he leads Cyber Essentials and Cyber Essentials Plus assessments for our clients, supporting organisations through audits, gap analysis, remediation planning and certification. His background across IT operations gives him a clear understanding of the real-world challenges businesses face when implementing security controls.
About the scheme. Cyber Essentials is the National Cyber Security Centre's scheme, operated by IASME. Your IT Department provides assessor led support, guidance and certification services under that scheme. We are not the certification body, and no readiness review can guarantee a pass. What it gives you is a clear, honest picture of where you stand before you commit.
No preparation needed, and nothing to install or fill in beforehand. The assessor leads, you answer what you can, and where you do not know the answer that is useful information too. Here is how the time is spent.
What is driving this, what the deadline looks like, and a quick picture of your setup: how many people, where they work, and what you run.
A walk-through of what the scheme actually asks for, in plain English, with the assessor asking targeted questions as you go rather than reading out a checklist.
A straight answer on what would fail today and what is already fine. No softening it, and no inventing problems that are not there.
A prioritised fix list split into what can be sorted this week and what needs planning, so you leave the call knowing where to start.
You receive a written one-page summary setting out what would fail and why it matters. It is yours to keep and act on however you choose, whether that is with us, with your existing IT provider, or on your own.
To be clear about what this is. A readiness review is a diagnostic, not the certification itself and not a guarantee of passing. It tells you where you stand today. If you want us to take you through certification afterwards we will quote for it, and if you would rather handle it yourself or stay with your current provider, that is genuinely fine.
Free readiness review
Thirty minutes, online, with a qualified Cyber Essentials assessor. Choose a slot from the calendar and we will send a confirmation straight away.
We will ask one short question when you book, so the assessor knows what is driving this and can spend the time where it matters most.
Published prices, because you should not have to fill in a form to find out whether this is affordable. Three levels of assessor led support, and the readiness review itself is free whichever route you end up taking.
For capable in house teams
From £250
A straightforward certification route for teams who will complete the assessment and any remediation themselves.
Guided assessment support
From £995
Guided support completing the assessment accurately, while you keep technical remediation in house.
The complete journey
From £2,995
The complete journey to independently assessed Cyber Essentials Plus, with assessor coordination throughout.
Starting prices for organisations of up to 100 employees, exclusive of VAT. Pricing is fixed and scaled by the size of your organisation. Certification and assessor fees are charged at cost as a pass through, with nothing marked up. Multi site, operational technology and multiple tenant environments are quoted separately.
Find out which level you actually need before you spend anything. Thirty minutes with a qualified assessor, a written summary to keep, and no obligation to go any further.
We would rather tell you now than waste half an hour of your time.
| You employ roughly more than 10 people and certification has come up as a requirement. | |
| You sell into, or want to sell into, central government, the NHS, local authorities or the main contractors who serve them. | |
| You are a subcontractor and a main contractor has added certification to your terms. | |
| A tender or prequalification questionnaire is asking the question and you need a straight answer before you respond. | |
| You have no in-house security specialist and want someone qualified to tell you where you stand. |
| You have an in-house security team who already know exactly where the gaps are. | |
| What you actually need is penetration testing rather than certification. | |
| You are a public sector body rather than a supplier to one. | |
| You want ongoing monitoring and vulnerability management rather than a point-in-time certificate. |
Still worth a conversation. If it is ongoing assurance you are after, our cyber assurance and vulnerability management programme covers monthly scanning, dark web monitoring and quarterly reviews. Call us and we will point you the right way.
Certification requirements cascade down supply chains, so some sectors feel it sooner than others. These are the businesses most often on the other end of the call.
Plenty of readiness reviews end with a straightforward certification and nothing more, which is a perfectly good outcome. Sometimes the call surfaces something bigger: gaps that will reappear next year, or an IT setup that is not really being looked after. If that is where you land, here is what comes next.
A certificate proves a point in time. If the review shows gaps that need watching rather than a one-off fix, this is the programme that keeps you on top of them and gives you evidence that things are improving.
Some of what fails a Cyber Essentials assessment fails because nobody owns it. Patching that slipped, devices nobody tracked, accounts that were never closed. If that sounds familiar, the certificate is treating the symptom.
None of this is a condition of the review. The readiness review is free and the written summary is yours regardless. If certification on its own is all you need, that is exactly what we will quote for, and we will not chase you about anything else.
Let's answer the questions we get asked most on the readiness review call.
You do not get a public black mark, and nobody is told. You are given the reasons the submission did not meet the requirements, and in most cases you can correct them and resubmit. The real cost is time and the certification fee, which is exactly why a readiness review beforehand is worth half an hour. We would rather tell you what would fail while you can still do something about it than after you have paid to find out.
Detail, almost never effort. The five we see most often are scope drawn in the wrong place, multi-factor authentication missing from an account or a service somebody forgot, software or devices that have quietly fallen out of support, patching that happens but cannot be evidenced, and firewall or device settings left on defaults. None are difficult to fix once you know about them.
The honest answer is that it depends entirely on the remediation gap. If your controls are largely in place, a few weeks is realistic. If the readiness review turns up unsupported software or devices that need replacing, that is the part that sets the timeline, not the paperwork. Cyber Essentials Plus needs more planning, because it has to be achieved within a limited window after you pass Cyber Essentials. If you have a tender deadline, tell us the date on the call and we will tell you honestly whether it is achievable.
Check the wording, because the two are different certifications and buyers are usually specific. Cyber Essentials is a verified self-assessment. Cyber Essentials Plus adds an
independent technical assessment of your devices and systems, and is more often specified for higher-value contracts, NHS work and some main contractor frameworks. If the documentation is ambiguous, bring it to the call and an assessor will read it with you.
It is genuinely free, and the written summary is yours to keep and act on however you like, including with your existing IT provider or on your own. We offer it because a proportion of businesses go on to certify with us, and because it is a straightforward way to show you what working with us is like. There is no obligation and we will not chase you.
No. Nothing to install, nothing to fill in and no documents to dig out. The assessor leads the conversation and you answer what you can. Where you do not know the answer, that is useful information in itself, because it usually points at the area worth looking into first. It helps if someone who knows how your IT is set up can join, but it is not essential.
Not at all, and it happens often. Cyber Essentials is a specialist assessment and plenty of capable IT providers do not have a qualified assessor in the team. The summary is written so you can hand it straight to them and they can get on with the fixes. If you would rather we handled certification separately from your day to day IT support, that is a normal arrangement.
Increasingly, yes, though we will not pretend it is urgent if it is not. Certification is appearing in more tenders, more subcontract terms and more insurance questionnaires every year, and it is far less stressful to hold it before somebody asks than to scramble for it against a deadline. The controls themselves are also the basics that stop the most common attacks, so the work is worth doing regardless of the certificate.
Free readiness review
Thirty minutes, online, with a qualified Cyber Essentials assessor. Choose a slot from the calendar and we will send a confirmation straight away.
We will ask one short question when you book, so the assessor knows what is driving this and can spend the time where it matters most.
Contact Us today on
or send us an email direct at:
Contact Us today on
or send us an email direct at: