Cyber Essentials & Cyber Essentials Plus Certification Support
Readiness, remediation and someone alongside you for the assessor's questions, so the certificate arrives on the date you promised it.
Get certified on the date you promised, not the one after
In short: Help getting certified: a pre-assessment against the five control themes, the remediation work to close what fails, and support through the questionnaire and the assessor's follow-up questions. For businesses with a contract, tender or insurer that has set a date. We work alongside certified assessors, we do not issue the certificate ourselves.
Cyber Essentials looks like a form. That is why so many first attempts fail: the questions are short, the answers are not, and the assessor is checking your actual estate rather than your intentions.
The problem
The expensive version of this is discovering the gaps during the assessment rather than before it. Certification runs to a clock, remediation takes as long as it takes, and a failed or withdrawn application usually means paying again and explaining a slipped date to whoever asked for the certificate.
What we would do
Do the pre-assessment before you apply, not after. Almost all first-time failures come from the same small set of issues, and every one of them is cheaper and faster to fix while nobody is waiting on you. If you have a deadline, that order is the difference between certifying on time and reapplying.
- If you already hold current certification, your estate has not materially changed and you are simply renewing, go straight to renewal. You do not need help with this.
- If you need Cyber Essentials Plus, scope the audit first. Plus is a hands-on technical audit of a sample of your devices rather than a longer questionnaire, and the work that makes it pass is done well before the auditor connects.
- If unsupported software is in scope, resolve that question before anything else. It is the single most common reason an application cannot proceed, and sometimes the answer is segregation rather than replacement.
When we are not the answer: If you want somebody to fill in the questionnaire for you and leave the estate as it is, that is not what this is, and it would not survive Plus or an incident anyway. We are also not a Certification Body: we prepare you, fix what fails and stand alongside you through the assessor's questions, but the certificate is issued by a certified assessor, not by us.
Cyber Essentials is a UK Government-backed scheme covering five technical control themes, and for a growing number of businesses it is no longer optional: it is written into contracts, tenders and insurance renewals, often with a date attached. We take clients through it end to end, from finding out what would fail today to standing alongside them when the assessor comes back with questions.
More on how we deliver Cyber Essentials certification
We work with certified assessors rather than issuing certificates ourselves, which is the honest description of the arrangement and also the useful one: our job is to make sure that when your submission reaches an assessor, the answers are true and the evidence is already there. We hold Cyber Essentials ourselves, so the estate we ask you to build is the one we run.
Systech is founder-led by Ryan Mangan, a Microsoft MVP for Azure Virtual Desktop and Windows 365, a Chartered Fellow of the BCS (FBCS) and author of Packt's two-edition Mastering Azure Virtual Desktop.
Everything you need, managed for you
What is Cyber Essentials, and who actually issues the certificate?
Cyber Essentials is a UK Government-backed certification covering five technical control themes: firewalls, secure configuration, security update management, user access control and malware protection. It is deliberately narrow. It does not attempt to be an information security management system, which is what ISO 27001 is for, and that narrowness is the point: it targets the commodity attacks that make up the bulk of what actually happens to businesses of this size.
The scheme is run through IASME as the accreditation body, which licenses the Certification Bodies that assess and issue certificates. That matters when you are choosing who to work with, because there are two different roles and plenty of suppliers blur them.
We are in the first role, not the second. We prepare you, remediate what fails and support you through the process, and the certificate is issued by a certified assessor. A supplier who both fixes your estate and marks its own homework is a conflict worth noticing, and it is the reason we are straightforward about which side of the line we sit on.
Certification lasts twelve months, so it is a recurring commitment rather than a one-off. That is worth planning for, because estates drift and the second year is where organisations get caught out by changes nobody registered as security changes.
Why do first attempts fail?
Almost always on the same handful of things, and rarely on anything exotic. The questions read as simple, which encourages an optimistic answer, and the assessor is asking about the estate as it is rather than as it is meant to be.
What we find, in rough order of frequency:
- Software or operating systems no longer receiving security updates, still in scope
- Administrators using their day-to-day account to administer, rather than a separate one
- Multi-factor authentication missing on cloud services, or enabled for some people and not others
- Devices that nobody can confirm are patched within the required window, because nothing reports on them
- Personal devices used for work that nobody had counted as in scope
- Default credentials or unnecessary services still enabled on something installed years ago
None of these are hard problems. They are cheap to fix in advance and expensive to discover mid-assessment, because a submission that stalls does not pause your deadline. The other reason to find them early is that the honest answer to a questionnaire question is sometimes no, and knowing that a fortnight before you apply is a completely different situation from discovering it during.
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is a self-assessment: you answer the questionnaire, a senior person signs it off, and a Certification Body reviews the answers. Cyber Essentials Plus covers exactly the same five control themes, but an assessor verifies them hands-on, testing a sample of your actual devices rather than taking the answers on trust.
You need Cyber Essentials before you can hold Plus, and Plus has to follow within a defined window after the base certification, so the two are planned together rather than as separate projects. If Plus is what your contract requires, that timing is worth confirming at the start, because it constrains when you should start the first one.
The practical difference is that Plus is much less forgiving of a gap between what was declared and what is true. An estate that scraped through the questionnaire on optimistic answers does not scrape through a technical audit, and the work that makes Plus pass happens well before the auditor connects to anything.
Which one you need is a contractual question rather than a security one, and it is worth reading the actual requirement. Plenty of organisations pay for Plus because a tender said the words and nobody checked whether the base certification would have satisfied it.
What counts as in scope, and can anything be excluded?
Scope is the single most consequential decision in the whole process, and it is made before any technical work is worth doing. The default is the whole organisation, and that default is what most contracts and insurers expect to see, because a certificate covering one department answers a much smaller question than the buyer thinks it does.
In scope means all the devices that access organisational data or services, including laptops, desktops, mobiles, tablets, servers and the cloud services you use, and it includes personal devices where people use them for work. It also includes home working, which surprises organisations that still think of their office as the boundary.
A sub-scope is possible where a part of the organisation is genuinely separated from the rest by network segregation, but the separation has to be real rather than organisational. This is the area where an honest conversation early saves the most money, and where we will sometimes tell you that the segregation you believe exists does not.
The place scope decisions most often go wrong is unsupported software. Something out of support inside the boundary is usually fatal to an application, so the choice becomes replacing it, upgrading it, or genuinely segregating it away from organisational data. All three are real options with different costs, and picking between them is work that has to happen before you apply rather than during.
What do you actually do, and what do we have to do ourselves?
We do the finding and the fixing, and you keep the parts only you can honestly own. The questionnaire is signed off by a senior person in your organisation, and that is not a formality: it is an assertion about your estate that has to be true.
So the split works out like this:
- We run the pre-assessment and give you a written gap list against all five control themes
- We tell you what scope should be, including anything you may be hoping to exclude that will not hold
- We do the remediation, or hand your own team a specific list if you would rather do it yourselves
- We help you complete the questionnaire in language that is accurate rather than optimistic
- We stay with you when the assessor comes back with follow-up questions, which they usually do
- You provide the sign-off, because the assertion is yours to make
The follow-up questions are the stage people underestimate. An assessor querying an answer is normal rather than a sign of failure, but it is also where applications stall, because the person who wrote the answer often cannot evidence it without going back to whoever configured the thing. Having the people who did the remediation available at that moment is most of why applications supported this way close on time.
Is certification worth it if nobody has asked for it yet?
Often, but be clear about which of two reasons you are buying, because they justify different amounts of effort.
The commercial reason is access. Cyber Essentials is a requirement for some public sector contracts and increasingly appears in private sector supply chains and insurance renewals, so holding it removes a barrier before you meet it. If you sell to organisations that ask their suppliers security questions, certifying ahead of the first tender that demands it is straightforwardly cheaper than certifying during one.
The security reason is that the five controls are the ones that matter most against the attacks businesses of this size actually experience. Working through them honestly usually surfaces things worth knowing regardless of the certificate, which is why we recommend the readiness check even to organisations that decide not to apply.
What it is not is proof that you are secure, and it is worth being clear-eyed about that. It is a floor rather than a ceiling, verified once a year, and treating the certificate as the end of the security conversation is a mistake we would rather you did not make on our watch.
| Cyber Essentials | Cyber Essentials Plus | |
|---|---|---|
| How it is verified | Self-assessment questionnaire, reviewed by a Certification Body | Hands-on technical audit of a sample of your devices by an assessor |
| What is assessed | The five control themes, as you declare them | The same five control themes, as they actually are |
| Order | First. Can be held on its own | Requires Cyber Essentials, within a defined window after it |
| Where the effort goes | Scoping, remediation and answering accurately | The same, done to a standard that survives testing |
| Who signs it off | A senior person in your organisation | The assessor, based on what they observe |
| When it is the right choice | The requirement says Cyber Essentials, or you are certifying ahead of demand | A contract specifically requires Plus, or you want the assurance verified rather than asserted |
Questions we hear a lot
Do you issue the Cyber Essentials certificate?
No, and it is worth being precise about this. IASME is the accreditation body for the scheme and licenses the Certification Bodies that assess submissions and issue certificates. We work alongside certified assessors: we run the pre-assessment, do the remediation, help you complete the questionnaire accurately and stay with you through the assessor's follow-up questions. Separating those roles is also healthier, because a supplier who both fixes your estate and marks its own homework is not giving you an independent result.
How long does Cyber Essentials take?
The assessment itself is fast. What takes time is remediation, and that depends entirely on what the pre-assessment finds. An estate that is already well managed can move quickly. An estate with unsupported software in scope, no multi-factor authentication on cloud services or no reliable patch reporting has real work to do first, and no amount of scheduling makes that shorter. That is why the first thing we do is find out which one you are, so you know whether your deadline is achievable before you commit to it.
What does Cyber Essentials cost?
There are two separate costs and they are worth keeping separate in your head. The certification fee is set by the scheme and banded by organisation size, and it is paid to the Certification Body rather than to us. Then there is the preparation and remediation, which is the variable part, because it depends on what needs fixing. We scope that after the readiness check rather than before, since quoting remediation before anyone has looked at the estate would be a guess dressed up as a price.
We failed last time. Can you help us reapply?
Yes, and it is a common starting point rather than an awkward one. A failed or withdrawn application is useful information: it usually means a specific control could not be evidenced, and the feedback narrows the search considerably. We would still run the full readiness check rather than only fixing the thing that failed, because an application that stalled on one control has frequently been optimistic on others that were not examined closely.
Does Cyber Essentials cover home working and personal devices?
Yes, and this catches people out. Devices used to access organisational data or services are in scope wherever they are, so home working is included, and personal devices used for work are included too. Home routers supplied by an internet provider are treated differently from corporate firewalls, and the controls that matter are then on the device itself. If your position is that people use their own phones for email but you had not counted those as in scope, that is worth resolving early rather than in the questionnaire.
Do we need Cyber Essentials or ISO 27001?
They answer different questions and are not really alternatives. Cyber Essentials certifies five specific technical controls, is achievable in weeks and is what most contracts and insurers actually ask for. ISO 27001 certifies a management system: how you decide what to protect, how you govern it and how you improve it. It is a much larger undertaking. If someone has asked you for Cyber Essentials, do that. If a customer is asking how you manage information security as an organisation, that is the ISO conversation, and doing Cyber Essentials first is a reasonable step toward it rather than wasted work.
Does certification come with cyber insurance?
Sometimes, and the conditions matter more than the headline. The scheme has included an insurance element for UK organisations under a turnover threshold that certify the whole organisation and opt in, but the terms, the threshold and the cover are set by the scheme and its insurance partner rather than by us, and they have changed over time. Treat it as a possible benefit to confirm with the Certification Body at the point of application, not as a reason to certify, and read what it actually covers before you count on it.
Cyber Essentials certification is delivered UK-wide from our office in Brough, East Yorkshire, with on-site support across the county where it helps. We work with businesses in York, Sheffield, Barnsley, Halifax, Doncaster and Wakefield and 6 more Yorkshire towns and cities, and remotely with clients right across the UK.
Would you pass today?
Forty-five minutes against the five control themes, and a written list of what would fail. Almost every first-time failure is on the same handful of things, and all of them are cheaper to fix before you apply.
