Cyber Essentials
Cyber Essentials certification, prepared properly
Cyber Essentials is a UK government-backed certification covering five basic technical controls. It is increasingly a condition of public sector contracts and larger private tenders, and for a small business it is genuinely achievable rather than a paper exercise. We do the gap analysis, the remediation and the evidence.
- Gap analysis first
- Cost known up front
- Evidence gathered as we go
What Cyber Essentials actually asks of you
It covers five control areas: firewalls and internet gateways, secure configuration, user access control, malware protection, and security update management. That is the whole scope, and the deliberate narrowness is the point. It is not an information security management system and it is not ISO 27001. It is the set of basics that closes most opportunistic attacks.
The assessment itself is a self-assessment questionnaire, verified by a certification body. Cyber Essentials Plus adds a technical audit where an assessor tests a sample of your machines rather than taking your word for it.
The certification fee for a small business is a few hundred pounds. The real cost is whatever remediation is needed beforehand, and that varies enormously depending on what state things are in. Which is why the gap analysis comes first.
Preparation is included on the Complete plan within our business IT support.
How we run it
Typically weeks rather than months, and you know the cost before the remediation starts.
-
Step 1
Scope it honestly
What is in and what is out. Scope is where most applications go wrong: too wide and the remediation balloons, too narrow and the certificate does not cover what a customer is asking about.
-
Step 2
Gap analysis
Every one of the five controls checked against what you actually have. You get a written list of what passes, what fails and what each fix will cost, before committing to anything.
-
Step 3
Remediation
The actual work. Usually multi-factor authentication, patching discipline, removing local admin rights, closing accounts belonging to people who left, and firewall configuration.
-
Step 4
Evidence and submission
The questionnaire completed with evidence behind each answer rather than assertions, so a query from the assessor is answered rather than investigated.
-
Step 5
Keep it true
Certification lasts twelve months. Keeping the controls in place through the year is ordinary support work, which is what makes the next renewal straightforward.
The controls that catch most small businesses
The two that fail most often are user access control and update management, and both fail for the same reason: nobody owns them.
Access control catches people because of accumulated accounts. The member of staff who left eighteen months ago whose login still works. The shared account everybody uses for one system. The local administrator rights granted to somebody once for a specific reason that were never removed. None of it was a decision, it is just what happens over years.
Update management catches people because patching operating systems is usually happening and patching everything else is usually not. Browsers, plugins, line-of-business applications and the software on the machine in the corner that nobody wants to touch all count, and all have to be within the supported window.
The third common failure is unsupported software still in use. A machine running an operating system past end of life will fail, and the answer is either replacing it or genuinely segregating it from the network, which has to be done properly rather than claimed.
The wider set of controls behind those five is covered under cyber security for small businesses.
What you get from us
- A scoping conversation that establishes what the certificate actually needs to cover, and why
- A written gap analysis against all five controls, with a cost against each fix
- The remediation work itself, done rather than recommended
- Evidence assembled as the work happens rather than reconstructed at submission
- The questionnaire completed with you, in language that matches what was actually implemented
- Liaison with the certification body when they query something
- The controls maintained through the year, so renewal is a review rather than a repeat
- A straight answer on whether Cyber Essentials Plus is worth it in your case
Asked for it by a customer or a tender?
That is the usual trigger, and it usually comes with a deadline. Send us the requirement and roughly how many staff and machines you have, and we will tell you whether the timescale is realistic and what the likely total is.
If it is not realistic we will say so, because a rushed application that fails costs more than a planned one.
Get in touch
Talk to us about cyber essentials
A few lines is enough. We will tell you straight whether we can help, what it would cost and how quickly we can be there. No hard sell, and no follow-up sequence if you decide against it.
- We reply within one working day
- A straight answer, including when it is no
- Free process review available, before any money changes hands
Would rather just ring? 01623 354250, Mon–Fri, 9am–5:30pm.
Frequently asked questions
If the answer is not here, ask us. You will get a straight one, from someone who does the work.
Mon–Fri, 9am–5:30pm
What is Cyber Essentials?
A UK government-backed certification covering five technical control areas: firewalls, secure configuration, user access control, malware protection and security update management. It is a self-assessment verified by a certification body, and it is increasingly a condition of public sector and larger private contracts.
How much does Cyber Essentials cost?
The certification fee itself is a few hundred pounds for a small business. The variable is the remediation beforehand, which depends entirely on what state things are in. We do a gap analysis first so that number is known rather than discovered halfway through.
How long does it take?
Weeks rather than months for most small businesses. The gap analysis takes days, the remediation is whatever it is, and the submission itself is quick once the evidence exists. The thing that extends it is discovering unsupported software late.
What is the difference between Cyber Essentials and Plus?
Cyber Essentials is a verified self-assessment. Plus adds a technical audit where an assessor tests a sample of your devices directly. Plus is more work and more cost, and it is worth it where a customer specifically requires it or where you want the assurance rather than the assertion.
Do we need it?
If you bid for public sector work or supply larger organisations, increasingly yes, and it is appearing as a tender condition more often each year. Beyond that it is a useful forcing function, because the five controls it checks are the ones worth having anyway.
Will we pass first time?
If the gap analysis was done honestly and the remediation was completed, yes. Applications fail when a business submits on the assumption that things are in place rather than on evidence that they are, which is precisely what the gap analysis prevents.