Firewalls
Everything between your business and the internet is configured deliberately rather than left as it came out of the box.
Cyber Essentials
Somebody has asked whether you’re certified, and now it’s holding up a contract. We take businesses through Cyber Essentials and Cyber Essentials Plus, with the whole cost laid out at the start. We hold it ourselves too.
Five controlsthat’s the whole scheme
12 monthsthen you renew
Both levelsEssentials and Plus
Why you’re here
In our experience one of four things has happened, and all of them come with a deadline attached.
Central government contracts handling certain data require it, and plenty of private buyers have copied that requirement into their own procurement. No certificate, no bid.
Usually a larger client tidying up their supply chain. Cyber Essentials answers most of it in one line, which is quicker than answering forty questions individually.
Cyber insurance schedules list the things you’ve told them you’re doing. The controls Cyber Essentials asks for and the things a schedule warrants are close to the same list.
A new director, a board member, an incident at a business down the road. This is the best reason of the four, because it isn’t a deadline, it’s a decision.
What it actually is
There’s no mystery to Cyber Essentials. It asks whether you’re doing five things properly. Most businesses are doing three of them and assuming they’re doing all five.
Everything between your business and the internet is configured deliberately rather than left as it came out of the box.
Default passwords gone, accounts and software you don’t use removed, and devices set up to a known standard rather than however the last person did it.
Everything supported and patched, and nothing left running on a version the vendor stopped fixing.
People have the access their job needs and no more. Admin rights are given deliberately and taken back when they’re no longer needed.
Protection on every device that’s actually running, actually up to date, and ideally with somebody reading what it finds.
The two levels
People often ask for Plus when they need Essentials, or the other way round. Which one you need is usually decided by whoever is asking you for it.
A verified self-assessment.
You answer the question set, one of your board members signs a declaration confirming the answers are true, and an assessor marks it. There’s no technical testing at this level. The certificate lasts twelve months.
The same controls, independently tested.
Everything above, plus a technical audit. Internal and external vulnerability scans, and hands on testing of a sample of your user devices, internet gateways and accessible servers. It’s a different piece of work and it’s priced separately.
Worth knowing
You have to pass Cyber Essentials before you can attempt Plus. If a tender is asking for Plus and you have neither, that’s two pieces of work rather than one, and it needs starting sooner than people expect.
What changed
Assessment accounts created on or after 27 April 2026 are marked against Requirements for IT Infrastructure v3.3. Accounts opened before that date carry on against the previous version, which catches people out at renewal.
Multi-factor authentication is now mandatory on every cloud service that offers it. Miss it and you automatically fail.
That single change fails more assessments than anything else, because MFA on email is the bit everybody has done and MFA on the other nine cloud services is the bit nobody has looked at. The update also leans harder on passwordless sign in and passkeys, tidies up how cloud services are defined, and simplifies the scoping rules.
If you certified before April 2026, your renewal is against a stricter question set than the one you passed.
Source: IASME, changes to the Cyber Essentials scheme, April 2026. IASME is the NCSC’s delivery partner for the scheme.
Our honest view
Cyber Essentials is a point in time, tick box exercise. We say that as a company that helps clients get certified and genuinely believes it makes businesses more secure.
The certificate tells you that on the day you were assessed, you met the controls. It doesn’t tell you what’s happened since. It doesn’t tell you whether somebody set up a forwarding rule on your finance mailbox this morning, or whether a scheduled task has been calling out from your domain controller every ten minutes since 2019.
And yet the thinking behind it is good. The controls it asks for are the basic hygiene every small business should be doing anyway.
If every UK business met those five things consistently, the national picture would look dramatically different. So our position is simple. If you need the badge for a contract, a tender or a regulator, get it. If you don’t need the badge, you still need the controls, so do them anyway. And whatever you do, don’t treat the certificate as the finish line, because you have to stay compliant for the next twelve months and one of your board members has signed to say you will.
Half the job is convincing people the badge isn’t the goal. The goal is the posture the badge was meant to prove.
A recent one
Talk to us
Tell us what you're running and when the deadline is. We'll tell you which level you need, what would fail right now, and what the whole thing costs including the assessment fee.
How we do it
The worst version of this is paying an assessment fee, failing, and finding out what it will cost to fix afterwards. We do it the other way round.
We go through the current question set against what you actually have, and tell you what would fail today. You get that before anybody pays an assessment fee.
The remediation work, our time, and the certification body’s fee. All of it, before you commit. Nothing turns up on the invoice at the end that wasn’t agreed at the start.
Usually MFA on the services nobody thought about, kit that’s out of support, and admin rights on accounts that shouldn’t have them. Then we submit.
Your board member has signed to say you’ll stay compliant for twelve months. If we support you, that’s our job as much as yours, and renewal isn’t a scramble.
Questions
Cyber Essentials is a verified self-assessment with no technical testing. Cyber Essentials Plus is the same controls plus an independent technical audit: internal and external vulnerability scans, and hands on testing of a sample of your devices, gateways and accessible servers. You have to pass Cyber Essentials before you can attempt Plus.
Twelve months, then you recertify. Organisations that don’t recertify come off the list of certified companies, which matters if a client is checking.
A board member. They sign a declaration confirming the answers you’ve given are true, which is why it’s worth somebody senior understanding what’s been submitted rather than nodding it through.
Probably not. Assessment accounts created from 27 April 2026 are marked against a stricter question set, and the biggest change is that multi-factor authentication is now mandatory on every cloud service that offers it, with an automatic fail if it’s missing. Plenty of businesses that passed comfortably last year would not pass today without some work.
Two things: the certification body’s assessment fee, which depends on the size of your organisation, and our time to get you through it. Both are laid out in full before you commit to anything. If you’re a support client the remediation work is usually already covered, which makes the whole thing cheaper.
No. We take businesses through certification whether or not we look after their IT. If we do support you, most of the controls are already in place because we put them there.
Yes. You can check our certificate rather than take our word for it. It would be a strange thing to sell and not have.
Next step
Tell us who's asking and by when. We'll tell you which level you need, what would fail today, and what the whole thing costs including the assessment fee.
Based in Cardiff, working across Wales and the West.