Mitigate cyber risk
Blocks roughly 80% of the most common cyber attacks.
UK government-backed certification, run by NCSC and delivered by IASME. Blocks up to 80% of common cyber attacks. We deliver both levels, including Cyber Essentials Plus, the hands-on audited version.
Cyber Essentials is the UK Government's flagship cyber security scheme, owned by the National Cyber Security Centre (NCSC) and delivered by the IASME consortium through a network of accredited certification bodies. It assesses your organisation against five technical controls that block the majority of common internet-facing attacks.
Firewalls · perimeter and software firewalls properly configured. Secure configuration · hardened devices, no default passwords. User access control · least privilege, MFA on admin accounts. Malware protection · enforced AV/EDR on every device. Security update management · OS and apps patched within defined windows.
Required for some UK Government contracts (MoD, central government supply chain). Pre-requisite for many enterprise procurement processes. Useful for any business that wants a credible baseline. Many cyber insurance underwriters offer reduced premiums for certified organisations.
The Plus level tests the same five controls, but a qualified assessor verifies them hands-on with internal and external vulnerability scans on a sample of your devices. It's the level enterprise supply chains and regulated buyers ask for when self-assessment isn't enough. We run a mock-test first, so you pass first time.
Blocks roughly 80% of the most common cyber attacks.
Visible certification mark to display on your website and proposals.
UK Government contracts, NHS DSPT alignment, supply-chain requirements.
Lower premiums and faster underwriting with the certificate in hand.
Week 1. Assess current state against the five technical controls.
Week 2. Fix the easier controls first. Firewalls, AV, patching cadence.
Weeks 3-4. Secure configuration baselines, MFA rollout, access control review.
Week 5-6. We complete the questionnaire with you and submit to an IASME-accredited body.
2-6 weeks depending on your starting maturity. Organisations already running MFA, EDR and patching cadence can move in 2-3 weeks. Those starting from scratch take 4-6.
The certification itself is £300-£500 paid to IASME. Our fixed-scope implementation support adds £2,000-£6,000 depending on org size. Many clients recover this in the first cyber-insurance renewal.
Cyber Essentials is a 5-control technical baseline. ISO 27001 is a full Information Security Management System covering 93 controls and ongoing governance. Cyber Essentials is a great stepping stone. Many clients do CE first, then graduate to ISO 27001.
Yes. The certificate is valid for 12 months. Re-certification is required annually to maintain the badge and the cyber-insurance discount.
Same five controls, but independently verified. A qualified assessor runs hands-on internal and external vulnerability scans on a sample of your devices, rather than relying on self-assessment. It's required by many enterprise supply chains and regulated buyers. We deliver both levels and prepare you with a mock-test so you pass first time.
Of course. The scheme is designed for self-assessment. We just dramatically increase your first-time success rate. The IASME failure-rate for un-supported applicants on first submission is around 40-50%.