Cyber Essentials

IT Tenders RFP

Cyber Essentials

Cyber Essentials Certification – Services for UK Businesses

controlling what traffic can enter and leave your network

Context

What Is Cyber Essentials?

Cyber Essentials is a UK government-backed cybersecurity certification scheme designed to protect organisations against the most common internet-based threats. It covers five key technical controls:

Firewalls and Internet Gateways

controlling what traffic can enter and leave your network

Secure Configuration

ensuring devices and software are set up securely from the start

User Access Control

making sure only the right people have access to the right data

Malware Protection

defending against viruses, ransomware, and other malicious software

Patch Management

keeping software and operating systems up to date

There are two levels:

Cyber Essentials

a self-assessment questionnaire verified by an accredited assessor

Cyber Essentials Plus

the same controls, verified by an independent, hands-on technical audit

Problem

Why Businesses Are Getting Certified Now

An increasing number of public sector contracts and enterprise procurement processes require Cyber Essentials certification. Without it, you're excluded before the conversation even starts.

Contracts require it

An increasing number of public sector contracts and enterprise procurement processes require Cyber Essentials certification. Without it, you're excluded before the conversation even starts.

Insurers ask for it

Cyber insurance providers are asking tougher questions. Holding Cyber Essentials demonstrates a minimum standard of security hygiene – and can reduce your premiums.

Clients expect it

Your clients trust you with their data. Certification gives them – and you – confidence that the basics are covered.

It's not optional for much longer

The UK government's National Cyber Security Centre (NCSC) strongly recommends Cyber Essentials for all organisations. For any business that handles personal data, works with the public sector, or operates in a regulated industry, certification is rapidly becoming a baseline expectation.

Solution

How We Help You Get Certified

1. Free Gap Analysis

We assess your current security posture against the five Cyber Essentials controls. You receive a clear, scored report showing exactly where you meet the requirements and where you fall short.

What we check:

2. Remediation

For every gap we find, we provide a clear remediation plan – and we can implement the fixes for you. This typically includes:

3. Assessment Support

We guide you through the Cyber Essentials self-assessment questionnaire – helping you answer each question accurately and submit with confidence.

For Cyber Essentials Plus , we prepare your environment for the independent technical audit, ensuring you pass first time.

4. Ongoing Cyber Essentials Compliance

Cyber Essentials certification is valid for 12 months. We help you maintain the controls year-round so re-certification is straightforward – not a scramble. For businesses on our Standard or Premium managed IT support plans, ongoing Cyber Essentials compliance is included.

How Much Does Cyber Essentials Cost

Cyber Essentials Certification Costs Explained

The cost of Cyber Essentials certification depends on two factors: the IASME assessment fee and the consultancy/remediation work needed to get your business ready.

Cost Component

Typical Cost

Notes

IASME assessment fee (Cyber Essentials)

£300 + VAT

Set fee for most small businesses

IASME assessment fee (Cyber Essentials Plus)

£1,000–£3,000 + VAT

Varies by organisation size

Consultancy and remediation

Quoted per project

Based on your current security posture

Often £0 additional

Often £0 additional

Already compliant as part of service

Cost Component

IASME assessment fee (Cyber Essentials)

IASME assessment fee (Cyber Essentials Plus)

Consultancy and remediation

Often £0 additional

Typical Cost

£300 + VAT

£1,000–£3,000 + VAT

Quoted per project

Often £0 additional

Notes

Set fee for most small businesses

Varies by organisation size

Based on your current security posture

Already compliant as part of service

The cost of NOT having Cyber Essentials:

Lost contracts: Many public sector and enterprise procurement processes now require Cyber Essentials as a minimum

Higher insurance premiums: Holding Cyber Essentials can reduce cyber insurance costs

Breach costs: The average cost of a cyber attack for a UK business is £8,460 (DCMS 2024)

Cyber Essentials Checklist

The Five Cyber Essentials Controls – A Practical Checklist

Use this checklist to understand where your business currently stands against the five Cyber Essentials technical controls:

1. Firewalls and Internet Gateways

If you cannot tick every item, you have gaps that will prevent Cyber Essentials certification.  Book your free gap analysis → and we’ll identify exactly what needs to be addressed.

Cyber Essentials Certification Timeline

How Long Does Cyber Essentials Take?

Stage

Cyber Essentials

Cyber Essentials Plus

Gap analysis

1–2 days

1–2 days

Assessment

Self-assessment questionnaire

Independent hands-on audit

Certification

1–2 weeks after submission

1–2 weeks after audit

Total

2–6 weeks

4–8 weeks

Stage

Gap analysis

Assessment

Certification

Total

Cyber Essentials

1–2 days

Self-assessment questionnaire

1–2 weeks after submission

2–6 weeks

Cyber Essentials Plus

1–2 days

Independent hands-on audit

1–2 weeks after audit

4–8 weeks

For businesses already on our managed IT support plans, most of the technical controls are already in place – significantly reducing the remediation timeline.

Comparison

Cyber Essentials vs Cyber Essentials Plus

Cyber Essentials

Other

Cyber Essentials Plus

Assessment type

Self-assessment questionnaire

Independent technical audit

Verified by

Accredited assessor (remote)

Qualified auditor (hands-on testing)

What it proves

You've declared compliance with the five controls

An independent expert has verified it

Cost

Lower

Higher (due to hands-on testing)

Timeframe

Typically 2–4 weeks

Typically 4–6 weeks

Best for

Most small businesses; baseline compliance

Businesses handling sensitive data or public sector contracts requiring Plus

We support both

Cyber Essentials

Assessment type

Verified by

What it proves

Cost

Timeframe

Best for

We support both

Other

Self-assessment questionnaire

Accredited assessor (remote)

You've declared compliance with the five controls

Lower

Typically 2–4 weeks

Most small businesses; baseline compliance

Cyber Essentials Plus

Independent technical audit

Qualified auditor (hands-on testing)

An independent expert has verified it

Higher (due to hands-on testing)

Typically 4–6 weeks

Businesses handling sensitive data or public sector contracts requiring Plus

How It Works

Getting Certified in Four Steps

Cyber Essentials is a UK government-backed cybersecurity certification scheme designed to protect organisations against the most common internet-based threats. It covers five key technical controls:

Step 1: Book Your Free Gap Analysis

We assess your environment against the five Cyber Essentials controls and tell you exactly where you stand. No cost. No obligation.

Step 2: Agree the Remediation Plan

We show you the gaps and recommend the fastest, most cost-effective path to compliance. You approve the plan.

Step 3: We Implement the Fixes

Our team implements the required technical controls – from firewall configuration to user access policies. We handle everything.

Step 4: Assessment and Certification

We guide you through the assessment process. You submit with confidence and receive your certificate.

Who Needs Cyber Essentials?

Is Cyber Essentials Right for Your Business?

You’re bidding for public sector contracts

that require certification as a minimumthat require certification as a minimum

Your insurer has asked about your cybersecurity posture

and you need a credible answer

You handle personal data

(clients, employees, patients) and want to demonstrate duty of care

You work with larger organisations

that require their supply chain to meet a baseline standard

You want to protect your business

against the most common internet-based cyber attacks

Social Proof

Trusted to Secure Growing Businesses

FAQ

Common Questions About Cyber Essentials

How much does Cyber Essentials certification cost?

The IASME assessment fee for Cyber Essentials is currently £300 + VAT for most small businesses. Our consultancy and remediation work is quoted separately based on the size and complexity of your environment. Many businesses on our managed IT support plans are already compliant – and we help them certify at no additional cost.

For a business that already has most controls in place, certification can take as little as 2 weeks. If remediation is needed, a more realistic timeline is 4 to 6 weeks. We provide a clear timeline during the gap analysis.

Cyber Essentials is a verified self-assessment. Cyber Essentials Plus adds an independent technical audit – an external expert tests your systems to verify the controls are working. Plus is more rigorous but provides stronger assurance. We support both.

Having IT support doesn't mean you're Cyber Essentials compliant. Many IT providers don't configure systems to the standard required by the scheme. Our gap analysis will tell you where you stand – even if another provider manages your IT.

It's not legally mandatory for most businesses – yet. But it's required for many public sector contracts, increasingly expected by insurers, and recommended by the NCSC for all organisations. It's rapidly becoming the cost of doing business.

If remediation is needed, you simply fix the gaps and resubmit. With our support, first-time pass rates are very high because we identify and resolve issues before you submit.

Cyber Essentials covers the basics – and the basics prevent the majority of common attacks. But it doesn't include threat detection, incident response, or advanced monitoring. For full protection, our managed cybersecurity service builds on top of Cyber Essentials with 24/7 SOC monitoring and MDR.

READY TO START?

Find Out Where You Stand – In 48 Hours

Book your complimentary managed cybersecurity assessment. We’ll evaluate your defences, show you where the gaps are, and provide a prioritised plan to address them – no obligation, no pressure.

Call us: 0800 208 8456  |  Email: hello@cyberkaizen.co.uk

✓ Free gap analysis · ✓ CISSP-certified team · ✓ Results within 48 hours · ✓ First-time pass support

If your security is already strong enough to pass, we’ll tell you – and save you the consultancy fee. We’d rather earn your trust than invoice you for work you don’t need.