Cyber Essentials Readiness and Certification Support
Prove the cyber basics are under control and make it easier to answer customer, tender and insurance security questions. We help SMEs scope, fix gaps and certify - then keep evidence current year on year.

What Cyber Essentials actually requires
Cyber Essentials is a UK Government-backed certification covering five core control areas designed to reduce the most common internet-based threats. It is increasingly expected by customers, public sector buyers, enterprise procurement teams and cyber insurers - and it gives your team a clear, defensible baseline that the basics are in place.
Customers ask for it because it answers a simple question on supplier security questionnaires, tenders and insurance forms: 'do you take cyber security seriously?' For most UK SMEs it is now easier to list the customers who don't ask for it than the ones who do.
The five controls in plain English: Firewalls control what can connect to the business. Secure configuration removes unsafe settings and defaults. User access control gives people only the access they actually need. Malware protection keeps malicious software off devices. Security update management keeps software patched and supported. We help you evidence each control - often pulling data directly from your Microsoft 365 tenant rather than asking you to write things from scratch.
We start with a short readiness review - typically a 30-minute call followed by a structured questionnaire. Most businesses have gaps, and most gaps are minor configuration issues we can close in days. We tell you upfront if a gap will take real effort, and we will scope the assessment carefully so you certify what you can defend.
Cyber Essentials Plus adds an independent technical audit by a qualified assessor. We handle the pre-audit remediation, attend the audit with you and fix any findings on the spot where possible. Certification lasts 12 months - we diary the renewal, refresh evidence and re-submit so the certification never lapses, which can break compliance with many contracts.
How we take you from scope to certificate
A four-step journey from prepare to maintain.
Prepare
Scope the assessment and find the gaps before money is spent.
Scope definition
We agree what is in and out of scope so you certify what you can defend.
Readiness review
30-minute call plus structured questionnaire to surface gaps quickly.
Gap report
A plain-English summary of what is in place and what needs attention.
Secure
Close the five core control areas with evidence you can stand behind.
Remediation plan
Prioritised actions: MFA enforcement, patching, configuration tightening, asset replacement.
Firewalls - plain English
Control what can connect to the business - office, home workers and cloud.
Secure configuration
Remove unsafe defaults: unused accounts, default passwords, unnecessary services.
User access control
People get only the access they need; admin accounts kept separate; MFA enforced.
Malware protection
Anti-malware or application allow-listing across every in-scope device.
Security update management
Supported software only, auto-update on, high-risk patches inside 14 days.
Certify
Submit evidence, manage the assessor and pass the audit.
Certification support
We submit, manage assessor questions and attend the CE Plus audit with you.
Evidence collection
Pulled from your Microsoft 365 tenant where possible to reduce admin.
Maintain
Stay compliant all year so renewal is a formality, not a fire drill.
Monthly assurance option
Optional ongoing control monitoring so renewal is straightforward, not a scramble.
What we do, and what stays with you
We do
- Agree the scope so you certify something you can defend
- Run the readiness review and produce a plain-English gap report
- Close configuration gaps: MFA enforcement, patching, unsafe defaults, account tidy-up
- Collect the evidence, pulling from your Microsoft 365 tenant where we can
- Submit, manage assessor questions and attend the CE Plus audit with you
Stays with you
- Replacing hardware or software that is out of support, which is the one gap we cannot configure away
- Signing the declaration, which is a board-level statement about your business
- Paying the certification body fee, which goes to the assessor not to us
- Keeping us told about new devices, sites and starters during the assessment window
How long it takes, honestly
- 01
Week 1: scope and readiness review
A 30-minute call and a structured questionnaire. You get the gap report at the end of it, whether you carry on with us or not.
- 02
Weeks 2 to 4: remediation
Most gaps are minor configuration issues closed in days. We tell you upfront where a gap means replacing an end-of-life device, because that has a cost and a lead time.
- 03
Weeks 4 to 6: submission
Evidence collected, self-assessment submitted, assessor questions handled.
- 04
Plus 2 to 4 weeks: the CE Plus audit
An independent technical audit by a qualified assessor. We run the pre-audit first and fix findings on the day where possible.
Certification lasts 12 months. We diary the renewal and refresh the evidence, because a lapsed certificate breaks compliance with many contracts.
What you have at the end
- The certificate itself
- Cyber Essentials or Cyber Essentials Plus, awarded by the certification body, valid for 12 months and listed publicly.
- A gap report and remediation record
- What was wrong, what was fixed and when, which is the document procurement teams and insurers actually want to see.
- Evidence you can reuse
- The same evidence answers most supplier security questionnaires and maps onto ISO 27001 Annex A if you certify later.
- A diary date, not a scramble
- Renewal is booked, and with the monthly assurance option the controls are checked through the year rather than the week before.
Why businesses come to us for this
Common scenarios where this service delivers measurable value.
Public-sector and NHS bidding
Required for many central government, NHS and council contracts.
Enterprise supplier reviews
Customers now require CE or CE Plus from their supply chain.
Cyber insurance qualification
Insurers price - and sometimes refuse cover - based on certification status.
Baseline for ISO 27001
CE controls map directly to ISO 27001 Annex A controls, accelerating later certification.
Common questions
Talk to us about cyber essentials readiness and certification support
A short call, no obligation.
Related guides

End-of-life devices and the risk to your Cyber Essentials certification
Unsupported operating systems, firmware and network kit are the most common reason UK businesses fail assessment. Here is how to stay ahead of it.

The top cyber attacks facing UK businesses
Ransomware, business email compromise, credential stuffing, supply chain and AI-assisted fraud - what each looks like and the control that stops it.

Managed security operations centre (SOC): what it is and when you need one
In-house SOC, managed SOC or MDR - coverage, detection versus response, and the questions to ask a provider.