Security & compliance

Cyber Essentials and Cyber Essentials Plus

Managed in-house, from first gap analysis to certificate.

Checklist and laptop on a desk representing a certification assessment

5

Control areas assessed

In-house

Gap analysis, remediation and submission

Annual

Renewal kept current, not rebuilt

Overview

Cyber Essentials is the UK government-backed baseline that tells customers, insurers and public sector buyers that your business has its fundamentals in order. Cyber Essentials Plus goes further, with a hands-on technical audit rather than a self-assessment.

We manage the whole process in-house. That means one team doing the gap analysis, fixing what needs fixing, preparing the evidence and getting you through — rather than a certificate body handing you a list of problems and leaving you to find someone to solve them.

What's included

How we deliver cyber essentials and cyber essentials plus

Gap analysis

An honest assessment of where you currently stand against each of the five control areas.

Remediation work

Firewall configuration, patching, access control, malware protection and secure settings brought up to standard.

Evidence and documentation

The policies, asset lists and records the assessment requires, prepared properly the first time.

Cyber Essentials submission

The self-assessment completed accurately and submitted, with us answering the technical questions.

Cyber Essentials Plus audit prep

Sample devices checked in advance against the technical audit so there are no surprises on the day.

Annual renewal

Kept current year on year, with the underlying controls maintained rather than rebuilt each time.

How it works

What happens when you get in touch

    1

    Gap analysis

    An honest assessment against the five control areas, with a clear list of what needs to change.

    2

    Remediation

    Firewalls, patching, access control, malware protection and secure settings brought up to standard.

    3

    Evidence and submission

    Policies, asset records and answers prepared properly, with us handling the technical questions.

    4

    Plus audit and renewal

    Sample devices pre-checked against the hands-on audit, then kept compliant year on year.

Who it suits

This is usually the right fit for

  • Businesses bidding for public sector or enterprise contracts
  • Organisations asked for certification by clients or insurers
  • Companies who want a clear, recognised security baseline

Common questions

Questions we are asked about this

What is the difference between Cyber Essentials and Plus?

Cyber Essentials is a verified self-assessment. Plus adds a hands-on technical audit of a sample of your devices.

How long does it take?

Typically a few weeks, depending on how much remediation is needed after the gap analysis.

Why does it matter?

Public sector and larger clients increasingly require it, and insurers look favourably on it.

Interested in cyber essentials and cyber essentials plus?

Tell us what's frustrating you and we'll tell you honestly what we'd do about it. No jargon, no pressure, no lengthy sales process.