The verified self-assessment and the technical audit are two different certifications with different levels of assurance. Most contracts specify one or the other. Choosing the wrong route means either paying for more than you need or submitting a certificate that does not satisfy the requirement.
If your contract specifies Cyber Essentials, CE alone is sufficient. If it specifies Cyber Essentials Plus or CE+, you need the technical audit. If you are unsure which applies, we confirm it on the scoping call, usually in the first five minutes.
The CE and CE+ Bundle delivers both in a single project, which is the most cost-effective route if there is any chance you will need CE+ within the next 12 months.
Every package includes guided support from an assessor at an NCSC Assured Service Provider, a pre-submission review, and clear remediation advice if gaps are identified.
Pricing is based on your whole-organisation headcount. This is the total number of employees across the legal entity, not the number of staff in scope for certification. Choose the package that matches your certification requirement and current position.
A dedicated, qualified assessor from an NCSC Assured Service Provider guides you through every question, reviews your scope, and checks your submission before it goes to marking.
We identify gaps in your controls before your application is submitted. You know what needs fixing before anything is formally marked — not after.
Prices are set by the number of employees in scope. No hidden fees, no day-rate surprises. Full pricing including all tier sizes is listed on our certification page.
As an IASME Licensed Certification Body, we assess your application and issue your certificate directly. One partner from first call to certificate — no third-party handoffs.
We help organisations achieve Cyber Essentials and Cyber Essentials Plus with clear guidance, practical support, and experienced delivery. As an NCSC Assured Cyber Advisor and IASME Licensed Certification Body, we provide a straightforward route to certification from initial review through to certificate issue.
Our relationships are built around our customers’ needs. Through strategic partnerships with leading technology providers, we maximise the value of your cyber security investment – working together to deliver world-class security solutions for your business.
We’re trusted by organisations across a wide range of industries to deliver Cyber Essentials certification with clear guidance and practical support. Don’t just take our word for it — here’s what our customers have to say about us:
Tell us a little about your business and we’ll confirm a time for your call. We’ll review where you are with Cyber Essentials and tell you exactly what getting certified involves.
Yes. Cyber Essentials certificates are valid for 12 months. We contact you ahead of renewal so the deadline does not catch you out, and the renewal process follows the same guided route as the original certification. If your systems have changed significantly since your last certificate, we review those changes on the scoping call.
Scope covers the devices, software, and cloud services your organisation uses to access or process data, typically laptops, desktops, mobile devices, servers, firewalls, and cloud services such as Microsoft 365 or Google Workspace. Getting scope right at the start is one of the most common areas where unsupported assessments go wrong. We confirm your exact scope on the initial scoping call before anything else happens.
Yes, and cloud services are explicitly in scope under the current requirements. From 27 April 2026, MFA on cloud services becomes a mandatory auto-fail control. If MFA is available and not enabled, the assessment will fail automatically. If your organisation uses Microsoft 365, Google Workspace, or any other cloud platform, we review your configuration as part of the readiness check and flag anything that needs to be in place before submission.
The Danzell question set replaces Willow from 27 April 2026. MFA becomes a mandatory auto-fail control. Organisations that have MFA available on cloud services and have not enabled it will fail automatically. There are also updated definitions around what constitutes a cloud service and tighter marking criteria on patch management. Assessments registered before 27 April use the current question set and have six months to complete. Book a call and we will advise on the most practical route given your timing.
Almost half of cyber attacks target small and medium-sized businesses.
Take this focused 15-question assessment to benchmark your Cyber Essentials Certification readiness.