close icon
National Cyber Security Centre Assured Service Provider Cyber Advisor Cyber Essentials Logo
Cyber Essentials Cyber Advisor Logo
Cyber Essentials Certified Plus Logo 150px
IASME CYBER ASSURANCE CERT BODY
Dcc level 0 cb
Choose Your Route to Certification

Choose Your Route to Certification

The verified self-assessment and the technical audit are two different certifications with different levels of assurance. Most contracts specify one or the other. Choosing the wrong route means either paying for more than you need or submitting a certificate that does not satisfy the requirement.

If your contract specifies Cyber Essentials, CE alone is sufficient. If it specifies Cyber Essentials Plus or CE+, you need the technical audit. If you are unsure which applies, we confirm it on the scoping call, usually in the first five minutes.

The CE and CE+ Bundle delivers both in a single project, which is the most cost-effective route if there is any chance you will need CE+ within the next 12 months.

Packages & Pricing

Every package includes guided support from an assessor at an NCSC Assured Service Provider, a pre-submission review, and clear remediation advice if gaps are identified.

Pricing is based on your whole-organisation headcount. This is the total number of employees across the legal entity, not the number of staff in scope for certification. Choose the package that matches your certification requirement and current position.

Cyber Essentials (CE)

Cyber Essentials — Verified Self-Assessment

Pricing

Micro (1–9): £595 + VAT

Small (10–49): £795 + VAT

Medium (50–249): £995 + VAT

Large (250+): from £1,295 + VAT

Best for Organisations certifying for the first time, or meeting a contract or tender requirement that specifies Cyber Essentials.

CE & CE+ Bundle

Cyber Essentials and CE+ in one project

Pricing

Micro (1–9): £1,495 + VAT

Small (10–49): £2,395 + VAT

Medium (50–249): £2,895 + VAT

Large (250+): from £3,895 + VAT

Best for Organisations pursuing government supply chain contracts requiring CE+ or wanting full certification in a single project.

Cyber Essentials Plus

CE+ – Technical verification audit

Pricing

Micro (1–9): £1,195 + VAT

Small (10–49): £2,095 + VAT

Medium (50–249): £2,595 + VAT

Large (250+): from £3,595 + VAT

Best for Existing CE holders ready to upgrade, or organisations renewing CE+ in a staged approach.

What's Included in Every Package

NCSC Assured Service Provider

NCSC Assured Service Provider

A dedicated, qualified assessor from an NCSC Assured Service Provider guides you through every question, reviews your scope, and checks your submission before it goes to marking.

No surprises before submission

No surprises before submission

We identify gaps in your controls before your application is submitted. You know what needs fixing before anything is formally marked — not after.

Fixed pricing by organisation size

Fixed pricing by organisation size

Prices are set by the number of employees in scope. No hidden fees, no day-rate surprises. Full pricing including all tier sizes is listed on our certification page.

Certificate issued directly by SHONSYS

Certificate issued directly by SHONSYS

As an IASME Licensed Certification Body, we assess your application and issue your certificate directly. One partner from first call to certificate — no third-party handoffs.

Why SHONSYS?

We help organisations achieve Cyber Essentials and Cyber Essentials Plus with clear guidance, practical support, and experienced delivery. As an NCSC Assured Cyber Advisor and IASME Licensed Certification Body, we provide a straightforward route to certification from initial review through to certificate issue.

IASME Licensed Certification Body

We are an IASME Licensed Certification Body. That means no third party, no handoffs: one experienced team takes you from initial scoping through to the certificate in your inbox.

NCSC Assured Cyber Advisor (Cyber Essentials)

The NCSC assures a small number of cyber security firms to advise SMEs on Cyber Essentials. As an Assured Cyber Advisor, we follow a strict NCSC code of conduct and give advice that is sensible, proportionate, and independent.

100+ Organisations Certified

We have supported over 100 organisations through Cyber Essentials and Cyber Essentials Plus, helping them identify gaps early and move towards certification with clarity.

Our Partners.

Our relationships are built around our customers’ needs. Through strategic partnerships with leading technology providers, we maximise the value of your cyber security investment – working together to deliver world-class security solutions for your business.

What Certified Organisations Say

We’re trusted by organisations across a wide range of industries to deliver Cyber Essentials certification with clear guidance and practical support. Don’t just take our word for it — here’s what our customers have to say about us:

I would highly recommend working with SHONSYS. They expertly guided us through the Cyber Essentials Plus certification with clear and comprehensive support. We always understood the reasoning behind each step, and it was clear they cared about strengthening our cybersecurity posture - not just achieving certification.
testimonial

Co-Founder

Semiconductor Startup, UK

Working with SHONSYS has been a real breath of fresh air. The whole process was smooth, clear and never overwhelming. Pride did a brilliant job at breaking down complex information in a way that was easy to follow and actually made sense. The gap analysis provided has been so valuable in helping us identify areas for improvement in our cyber security. I can’t thank Pride enough for his time and expertise, and I would highly recommend SHONSYS to anyone looking to strengthen their cyber security.
testimonial

Operations and Engagement Officer

Registered Charity, UK

Joyous, easy, thorough, competent - I just highly recommend working with your organisation. You do demystify jargon and make the process so simple and straightforward.
testimonial

CEO

Housing Association, UK

Thanks to SHONSYS, we secured the government contract we needed. The Cyber Essentials Plus certification process was much easier than we feared, and now we feel more credible when dealing with major clients.
testimonial

Director

Media & Communications, UK

Shonsys made the Cyber Essentials process much easier than we expected. The guidance was clear and practical throughout, which made the whole experience straightforward to manage.
testimonial

CEO

myLifePA Ltd, UK

Book A Call With An Assessor

Tell us a little about your business and we’ll confirm a time for your call. We’ll review where you are with Cyber Essentials and tell you exactly what getting certified involves.








    Cyber Essentials FAQs

    Is the certification annual?

    Yes. Cyber Essentials certificates are valid for 12 months. We contact you ahead of renewal so the deadline does not catch you out, and the renewal process follows the same guided route as the original certification. If your systems have changed significantly since your last certificate, we review those changes on the scoping call.

    What is in scope for the assessment?

    Scope covers the devices, software, and cloud services your organisation uses to access or process data, typically laptops, desktops, mobile devices, servers, firewalls, and cloud services such as Microsoft 365 or Google Workspace. Getting scope right at the start is one of the most common areas where unsupported assessments go wrong. We confirm your exact scope on the initial scoping call before anything else happens.

    Can we certify if we use cloud services like Microsoft 365?

    Yes, and cloud services are explicitly in scope under the current requirements. From 27 April 2026, MFA on cloud services becomes a mandatory auto-fail control. If MFA is available and not enabled, the assessment will fail automatically. If your organisation uses Microsoft 365, Google Workspace, or any other cloud platform, we review your configuration as part of the readiness check and flag anything that needs to be in place before submission.

    What are the April 2026 scheme changes?

    The Danzell question set replaces Willow from 27 April 2026. MFA becomes a mandatory auto-fail control. Organisations that have MFA available on cloud services and have not enabled it will fail automatically. There are also updated definitions around what constitutes a cloud service and tighter marking criteria on patch management. Assessments registered before 27 April use the current question set and have six months to complete. Book a call and we will advise on the most practical route given your timing.

    cyber security

    What’s Your Cyber Essentials Certification Readiness Score?

    Almost half of cyber attacks target small and medium-sized businesses.

    Take this focused 15-question assessment to benchmark your Cyber Essentials Certification readiness.

    • Identify Security Gaps
    • Complimentary Results Consultation
    • Personalised Readiness Score
    • Tailored Recommendations
    DISCOVER YOUR SCOREarrow
    DISCOVER YOUR CYBER ESSENTIALS READINESS SCORE arrow