Cyber Essentials Readiness

Cyber Essentials is a questionnaire
you have to answer truthfully.

Which is the whole difficulty. The five controls are not complicated and the certification is not expensive — the work is getting your business into a state where the honest answers are the passing ones. That is what we do.

What it is, plainly

A government-backed baseline, not a security strategy

Three things about the scheme that are worth understanding before you spend anything on it.

We prepare you. We do not certify you

Certification is issued by bodies accredited by IASME, the scheme's delivery partner. We are not one of them and will not pretend to be. What we do is get the controls genuinely in place and the self-assessment answerable honestly, then point you at a certifying body to issue it.

It is a floor, not a ceiling

Cyber Essentials covers five basic technical controls. Meeting them makes you meaningfully harder to attack opportunistically, which is how most small businesses are actually attacked. It does not make you secure, and anybody selling it as though it does is overselling.

Increasingly, it is a condition of bidding

This is usually the real reason a small business looks at it. Public sector contracts and a growing number of private supply chains require it, so it stops being a security decision and becomes a commercial one — you cannot bid without it.

The five controls

What you are actually being asked about

01

Firewalls

Boundary firewalls and internet gateways configured deliberately rather than left as the router arrived from the provider.

02

Secure configuration

Devices and software set up to reduce what is exposed — default passwords gone, unnecessary accounts and services removed, nothing left switched on because nobody looked.

03

User access control

Accounts that match who actually works for you now, administrative rights held only by people who need them, and a way to know that is still true in six months.

04

Malware protection

Protection against malicious software on the devices your people actually use, including the ones they own and work on.

05

Security update management

Everything patched and in support. This is the control that fails most often, and it fails quietly — it takes one unattended plugin or one operating system past its end of life.

06

And the part that catches people

Scope. The certificate covers what you declare it covers, and a self-assessment that quietly excludes the awkward half of the business is worth very little. Deciding scope honestly is most of the work.

How it runs

Four stages

  1. One

    What is actually here

    An inventory of the devices, accounts, software and services your business really runs on — including the ones nobody has thought about since they were set up. Most small businesses have never had one.

  2. Two

    Answer it honestly, first

    We go through the self-assessment with you and write down the true answers, including the failing ones. That document is the actual work plan, and it is uncomfortable reading the first time.

  3. Three

    Fix the gaps

    Closing the gaps, in the order that reduces real risk fastest rather than the order the form lists them in.

  4. Four

    Certify, then keep it true

    You submit to a certifying body. Then the harder part: it lapses annually, and a business drifts out of compliance quietly. We can keep watching it if you want that.

What we do and what we do not

We do

  • Inventory what your business actually runs on
  • Work through the self-assessment with you, truthfully
  • Close the technical gaps we find
  • Advise on scope, which is where most of the difficulty is
  • Secure and patch what we host for you
  • Keep watching it after certification, if you want that

We do not

  • Issue the certificate — an accredited body does that
  • Run a helpdesk or provide day-to-day IT support
  • Help you answer the questionnaire in a way that is not true
  • Claim this makes you secure, because it does not

Common questions

Can you certify us?

No, and be wary of anyone who says they can while also doing your remediation. Certification is issued by bodies accredited by IASME. We get you into a state where you can answer the assessment honestly and pass it, and then you certify with a body that does that for a living.

How long does it take?

It depends almost entirely on what state things are in when we start. A business with modern equipment, everything in support and a clear idea of who has access can be ready in a couple of weeks. One with unsupported systems and accounts belonging to people who left in 2021 takes longer, and finding that out is itself worth having.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

The basic scheme is a self-assessment that you complete and an accredited body reviews. Plus adds hands-on technical verification by an assessor — they check rather than take your word for it. Some contracts specify which one they require, so check the requirement before choosing.

We only need it to bid for a contract. Is that a bad reason?

It is the commonest reason and it is a perfectly good one. The useful thing is that the work still has to be real: you cannot bid on a certificate you obtained by answering untruthfully, because the declaration is signed by a company officer and it is that officer's problem if it is wrong.

Do you do IT support as well?

No, and we say so early. We are not a helpdesk and do not want to be one — we secure and maintain what we build and host. If you need somebody to fix a laptop on a Tuesday morning you need a different kind of firm, and we would rather tell you that than take the work.

Answer the questionnaire honestly
and see what happens.

It is free to look at, and the first honest run through it tells you more about your business than most paid assessments will. We will do it with you and tell you what the gaps would cost to close.