We hold Cyber Essentials and ISO 27001 ourselves — we know exactly where businesses get stuck. We'll walk your team through the self-assessment, fix the gaps our scanner already found, and get you through to certification by an accredited body.
Back to scannerMost businesses fail their first Cyber Essentials attempt on things that are quick to fix once someone points them out.
We run a full Solvbeat scan against your domain and infrastructure to see where you stand today.
A real conversation walking through the five Cyber Essentials control themes and what applies to your setup.
We help you fix what's flagged — firewall config, patch management, access control, malware protection.
We help you complete and submit the self-assessment (or coordinate the audit for Cyber Essentials Plus).
Same five Cyber Essentials control themes, applied to the fraud and outage patterns that actually happen in your sector.
Cyber Essentials is the UK government-backed certification scheme, run by IASME on behalf of the National Cyber Security Centre (NCSC). It checks that an organisation has five basic technical controls in place — the controls that, according to the NCSC, would stop the large majority of common, opportunistic cyber attacks. It is deliberately not an exhaustive standard like ISO 27001; it is a focused baseline that any organisation can reach, and it has become the certificate that UK customers, funders and insurers recognise and ask for by name.
There are two levels. Cyber Essentials (the base level) is a verified self-assessment: you answer a structured questionnaire about your systems and an accredited certification body reviews and marks it. It is honesty-based, which is why getting the answers genuinely right — rather than guessing — matters. Cyber Essentials Plus covers the same five controls but adds a hands-on technical audit by an assessor, who tests a sample of your devices and your internet-facing systems to confirm the controls are actually working. Plus is often what a larger customer or a public-sector contract specifically requires; the usual route is to pass the self-assessment first and then book the Plus audit, which must follow within three months.
Cyber Essentials suits any UK organisation, but it is most urgent when someone is asking you for it: a larger customer flowing the requirement down their supply chain, a grant funder doing due diligence, an insurer pricing cyber cover, or a public-sector tender that mandates it. The controls are universal, but what they protect against is not — the fraud that hits a small charity is not the ransomware that stops a factory line. That is why we treat the certificate the same everywhere and the risk differently by sector: see our tailored pages for manufacturing, e-commerce, charities, law firms, accountants and more.
Most organisations fail their first attempt on a handful of predictable things: no multi-factor authentication on Microsoft 365 or Google Workspace, an unsupported operating system still in use, default passwords on a router or firewall, everyday accounts running with admin rights, and old leavers' accounts never disabled. None of these is hard to fix once someone points it out — the value of preparation is that you find them before you submit rather than getting marked down and having to resubmit.
Cyber Essentials is often the first rung on a longer ladder. ISO 27001 is a full information-security management system — far broader, involving risk assessment, policies, ongoing governance and an external audit — and is usually pursued by larger organisations or those whose customers demand it. Cyber Essentials, by contrast, can be reached in weeks and gives you the concrete technical baseline that ISO 27001 also expects. Many organisations start with Cyber Essentials to answer immediate customer and funder requirements, then build towards ISO 27001 later if their contracts call for it. The two are complementary, not competing, and the work you do to pass Cyber Essentials is never wasted.
Certification is issued through an accredited certification body and the fee is banded by organisation size. Cyber Essentials self-assessment starts from around £300 plus VAT for the smallest organisations and rises in bands with headcount; Cyber Essentials Plus adds the technical audit and costs more on top. Preparation and certification typically take one to three weeks — the limiting factor is how fast you can close gaps such as enabling MFA or replacing unsupported software, not the paperwork. The certificate is valid for twelve months, after which you recertify.
The fastest way to find out where you stand is a free baseline scan — it gives you an honest read on how far you are from certification before you commit to anything.
Run a free scan first, or just ask us — we'll give you an honest read on how far off certification you are.
We'll get back to you within one business day.