Cyber Essentials & compliance

Get Cyber Essentials certified — and stay certified.

Readiness review, the five controls implemented properly, certification and annual maintenance — aligned to Cyber Essentials, CE+ and ISO 27001, and built for what SRA, FCA and PII insurers actually ask.

No obligation · 30-minute call · A clear written 90-day plan you keep, even if we never work together.

21 yearsInside regulated financial services
CE, CE+ & ISO 27001Implemented hands-on, not just advised
Insurer-readyBuilt for SRA, FCA and PII expectations
No tie-insFixed engagements, start small and scale
Why this matters now

The bar for 'good enough IT' has moved

Insurers, clients and regulators no longer take security on trust. PII and cyber insurance renewals now probe your technical controls directly, public sector work often requires certification, and clients in regulated sectors ask how their data is protected. Vague answers cost you — in premiums, in cover, or in trust.

Cyber Essentials is the simplest credible answer: a government-backed certification showing the five controls that stop the most common attacks are actually in place. Done properly, the work behind the certificate is what protects the firm — the badge is just the proof.

What's included

From first review to certificate on the wall

A complete route to certification for firms without an in-house IT team, with clear scope before any work starts.

Readiness review and gap analysis

A free 30-minute review of where your firm stands today — Cyber Essentials and insurer readiness gaps, data-handling risks and continuity weak points — with a written, prioritised 90-day plan you keep.

The five controls, implemented

Firewalls, secure configuration, user access control, malware protection and patch management — put in place properly across your devices, accounts and cloud services, not just written down.

Certification and evidence

The assessment answered accurately and backed by evidence, so the certificate reflects how your firm actually operates — and stands up when an insurer or client looks closer.

Staying certified

Certification is annual and controls drift. We keep the evidence current, catch drift before it becomes a gap, and answer insurer questionnaires from a live picture of your setup.

Which level?

Cyber Essentials or Cyber Essentials Plus

Both certify the same five technical controls. The difference is how much verification stands behind the certificate — the readiness review will tell you which level your firm actually needs.

Cyber Essentials
  • Self-assessed question set, reviewed by an assessor
  • Covers firewalls, secure configuration, access control, malware protection and patching
  • Government-backed certificate, renewed annually
  • Frequently required for public sector contracts
Cyber Essentials Plus
  • Everything in Cyber Essentials
  • Independent technical audit of your systems
  • Vulnerability testing that proves the controls work
  • The stronger signal for insurers, clients and tenders
How it works

Four steps to certified

01

Review

A free readiness review: an honest read on where your firm is exposed and a written 90-day plan — no obligation, no jargon.

02

Fix

Close the gaps the review found: the five technical controls implemented and evidenced across devices, accounts and cloud services.

03

Certify

Complete the Cyber Essentials assessment with confidence, then step up to Cyber Essentials Plus with its independent audit if your firm needs the stronger signal.

04

Maintain

Keep the certificate, the controls and the evidence current year after year — including at renewal and whenever your insurer asks questions.

Honest answers

Cyber Essentials — common questions

What is Cyber Essentials?

Cyber Essentials is a UK government-backed certification scheme that helps businesses protect against the most common cyber threats. It covers five technical controls: firewalls, secure configuration, user access control, malware protection and patch management. It is often required for public sector work, and increasingly expected by insurers and clients as basic evidence that security is taken seriously.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a self-assessed certification: your firm answers a question set about the five controls and the answers are reviewed by an assessor. Cyber Essentials Plus covers the same controls but adds an independent technical audit, including vulnerability testing of your systems. Plus carries more weight with insurers, clients and tenders because someone has verified the controls actually work.

Does my firm actually need Cyber Essentials?

If you bid for public sector contracts it is often mandatory. Beyond that, professional indemnity and cyber insurers increasingly probe your cyber controls at renewal, and clients in regulated sectors ask directly. Certification is the simplest way to answer those questions with evidence rather than assurances — and the process of getting certified fixes the gaps that matter most.

How long does it take to get certified?

That depends entirely on where you are today, which is exactly what the free readiness review tells you. Firms with well-managed IT may only need small adjustments before assessing; firms with older setups usually need a short programme of fixes first. Either way, you leave the review with a written 90-day plan showing the route.

What does it cost?

The readiness review is free and there is no obligation afterwards. The certification body sets its own assessment fee based on your organisation size, and our support is quoted as a fixed engagement once the review shows what your firm actually needs — no long tie-in contracts, so you can start small and scale.

Free readiness review

Find out how far you are from certified.

Thirty minutes with a senior IT lead, an honest read on your exposure, and a written 90-day plan you keep — whatever you decide afterwards.

Book my free review

Prefer to talk? Call 0330 223 7404