Consultant reviewing Cyber Essentials scoping documents with a client
Cyber Essentials Certification

Cyber Essentials certification, without the guesswork.

We prepare the technical controls and the self-assessment questionnaire together, so your submission reflects what's actually running on your network rather than what the box on the form assumes.

Controls in scope
5
Typical timeline
2-4
Assessment format
1
Illustrative figures
The challenge

The questionnaire is short. Getting the answers right is not.

Cyber Essentials looks straightforward on the surface — a self-assessment questionnaire covering five technical control areas, marked by an IASME-accredited certification body. In practice, most of the effort and most of the risk sits in the scoping decision that happens before a single question is answered. Organisations that declare too narrow a scope end up with a certificate that doesn't cover the devices an attacker would actually target; organisations that declare too broad a scope without checking every device first often fail on details they didn't know existed.

The five technical control areas — firewalls and internet gateways, secure configuration, user access control, malware protection, and security update management — sound simple individually, but each has specific, testable requirements. Unsupported software, local administrator accounts left active on laptops, cloud services without multi-factor authentication, and patches applied outside the fourteen-day window for critical and high-severity updates are the recurring reasons submissions stall.

There's also a governance dimension that gets underestimated. Someone within the organisation has to sign the questionnaire, and that person is putting their name to statements about every in-scope device, whether they've personally checked it or not. Boards and finance directors are increasingly asked to sign these forms as part of insurance renewal or client due diligence, often without the technical background to verify what they're confirming.

For growing organisations taking on regulated clients — particularly in legal, healthcare and financial services — Cyber Essentials has moved from a nice-to-have to a contractual requirement. Losing a supplier assessment or a tender because certification lapsed, or because the scope didn't match what the client expected, is a commercial problem as much as a technical one.

  • Scope disputes between what's declared and what's actually in use
  • Unsupported operating systems discovered late in the process
  • Missing MFA on cloud services not originally considered 'IT'
  • Patch windows missed on devices outside routine management
Our approach

We scope it properly, fix what's outstanding, then submit.

We start with an inventory exercise rather than the questionnaire itself. Every device, server, cloud service and user account that could reasonably be considered in scope gets listed, and we agree with you which boundary makes sense for your business — including home workers, bring-your-own-device arrangements and any legacy kit that's quietly still in use.

Once scope is agreed, we run a technical review against each of the five control areas. This isn't a document exercise; we check firewall configurations, review local admin rights, confirm MFA is enforced on cloud accounts, verify anti-malware coverage and pull patch compliance reports. Where gaps exist, we give you a short, prioritised list rather than a lengthy report nobody reads.

Remediation is usually the fastest part, because the fixes are well understood — enabling MFA, removing unnecessary local admin rights, tightening firewall rules, and catching up on patching. We work alongside your existing IT provider or internal team rather than replacing them, which keeps costs down and avoids duplicated effort.

Only once the technical position is solid do we complete the self-assessment questionnaire itself, drafting answers that are accurate, evidenced and consistent with what a Cyber Essentials Plus auditor would later find if you go on to pursue that. We also brief whoever is signing the declaration so they understand exactly what they're confirming.

  • Scope agreed and documented before any technical work starts
  • Gap list prioritised by effort and by risk, not by control number
  • Questionnaire drafted with evidence held on file, not invented on the day
  • Sign-off briefing for whoever is accountable for the declaration
What's included

Everything in the engagement, set out up front.

A fixed-scope engagement covering scoping, technical review, remediation guidance and submission support.

Scoping workshop

A structured session to agree exactly which devices, services and users fall inside the certification boundary.

Technical control review

Direct checks against firewall configuration, secure build standards, access control, malware protection and patching.

Gap remediation plan

A prioritised list of fixes with realistic timescales, ready to hand to your IT provider or internal team.

Questionnaire drafting support

Plain-language help completing each answer accurately, backed by the evidence we've reviewed together.

Evidence pack

Screenshots, configuration exports and patch reports organised so they can be produced quickly if challenged.

Renewal planning

A twelve-month reminder and lightweight check so certification doesn't lapse or drift out of scope unnoticed.

Deliverables

What you receive.

  • Documented scope statement with rationale
  • Technical control gap report
  • Prioritised remediation action list
  • Completed self-assessment questionnaire draft
  • Supporting evidence file for each control area
  • MFA and patch compliance summary
  • Sign-off briefing notes for the declarant
  • Twelve-month renewal reminder plan
Who it suits

Built for organisations that need the work done properly.

Businesses new to certification

First-time applicants who need the scope and the five controls explained in plain terms before they commit resource.

Organisations under supplier pressure

Firms told by a client or a tender that certification is now a contractual requirement, often against a tight deadline.

Growing SMEs adding cloud services

Businesses whose IT estate has outgrown ad-hoc management and now needs a proper baseline before certifying.

Firms preparing for Cyber Essentials Plus

Organisations that want the base certificate solid and evidenced before moving to independent audit.

Outcomes & benefits

What changes once the work is done.

What changes once the certificate is issued and the controls are embedded.

Certificate issued first time

A submission that reflects the real environment, reducing the chance of a rejected or resubmitted questionnaire.

Clear scope you can defend

A documented boundary you can explain to a client, an insurer or an auditor without hesitation.

Fewer avoidable incidents

MFA, patching and access control fixes address the entry points most commonly exploited in low-sophistication attacks.

Supplier and tender requirements met

A live certificate that satisfies procurement checklists without a last-minute scramble.

Insurance renewal made simpler

Cyber insurance questionnaires increasingly ask for Cyber Essentials directly; having it removes a recurring point of friction.

A foundation for Plus

Controls that are already evidenced, making a future Cyber Essentials Plus audit considerably less disruptive.

Why the technical work matters more than the paperwork.

It's tempting to treat Cyber Essentials as a form-filling exercise, and some providers sell it that way — a quick call, a set of answers, a certificate. The problem is that a certificate obtained without genuine control coverage doesn't protect the organisation from anything; it just creates a false sense of assurance that tends to surface at the worst possible moment, usually during an insurance claim or a client audit that asks for evidence rather than a certificate number.

The controls Cyber Essentials asks about are, deliberately, the ones that stop the most common attacks: phishing leading to account compromise, exploitation of unpatched internet-facing services, and malware spreading through devices with unnecessary administrative rights. None of this is exotic. It's basic hygiene, applied consistently, which is exactly why it's harder than it sounds across a real device estate with remote workers, legacy applications and shadow IT that nobody quite owns.

We work with organisations across Chesterfield, Sheffield, Derby, Nottingham, Leeds, Manchester, Birmingham and London, and the pattern is consistent regardless of sector: the technical fixes are rarely expensive, but they require someone to actually go through the estate device by device rather than relying on assumptions. That's the work we do before the questionnaire is touched.

Where we differ from a pure box-ticking service is that we treat the certification process as an opportunity to close real gaps, not just to answer questions in a way that passes. If a control genuinely isn't in place, we say so and help you fix it, rather than drafting an answer that technically satisfies the wording. That approach costs a little more time up front and saves considerably more if you're later challenged, audited, or you go on to pursue Cyber Essentials Plus.

Frequently asked questions

Questions we are asked most often.

How long does Cyber Essentials certification take?

Most organisations complete the self-assessment questionnaire and receive certification within two to four weeks, provided the technical controls are already in reasonable shape. Where firewalls, patching or device configuration need remedial work first, we typically plan for four to eight weeks so fixes can be verified before submission rather than rushed at the deadline.

Who assesses the questionnaire?

IASME is the scheme's delivery body on behalf of the National Cyber Security Centre, and certification bodies accredited under IASME mark the submission. We are not the assessor — our role is to prepare your answers, evidence and technical configuration so the submission is accurate and passes first time.

What are the five technical controls?

Firewalls and internet gateways, secure configuration, user access control, malware protection, and security update (patch) management. Certification requires evidence that all five are applied consistently across every in-scope device, server, cloud service and user account, not just a sample of the estate.

Do we need this before Cyber Essentials Plus?

Yes. Cyber Essentials Plus builds directly on the base certificate and cannot be issued without a valid Cyber Essentials self-assessment already in place. Most organisations treat certification support as the first phase and move to Plus once the self-assessed controls are stable and evidenced.

What causes most submissions to fail or need resubmission?

Incomplete scoping is the most common issue — home workers, personal devices used for email, and forgotten cloud services are frequently missed. After that, unsupported operating systems, missing multi-factor authentication on cloud accounts and inconsistent patching windows across the device estate account for the majority of rework.

Can we do this ourselves without a consultant?

You can, and many smaller organisations do. Where we add value is in scoping the assessment correctly, translating the questionnaire's technical language into concrete configuration changes, and catching the answers that look fine on paper but would not survive a Plus audit or a genuine incident.

Does certification cover our whole IT estate?

Only the scope you declare. Cloud services, remote workers and bring-your-own-device arrangements can be included or carefully excluded, and that decision has real consequences for both your risk exposure and your insurer's expectations. We help you set a scope that is defensible rather than simply convenient.

How often do we need to recertify?

Cyber Essentials certification is valid for twelve months. Most organisations treat the annual renewal as a checkpoint to confirm controls haven't drifted — new starters without MFA, unpatched devices reintroduced after a rebuild, or firewall rules loosened during a project are the usual culprits we find at renewal.

Ready to scope your Cyber Essentials submission properly?

Book a free gap assessment and we'll tell you honestly how close your current setup is to certification, and what it will take to get there.

Book a free gap assessment