Cyber Essentials and Cyber Essentials Plus

Cyber Essentials is the UK government scheme, run by the NCSC and delivered by IASME, that certifies you have five technical security controls in place. We take you through both tiers and keep the controls current at each annual renewal. We are an appointed certification body, so our assessors work to the standard every day. Preparation, remediation and formal assessment are separate pieces of work.

Verified
ISO 27001 & 9001Certified by a UKAS-accredited certification body Cyber EssentialsCertification body Cyber Essentials PlusCertified NCSC AssuredCyber Advisor Cyber EssentialsAssessor, held by Daniel McClure Fisher
Cyber Essentials / 01 · What it is

Cyber Essentials preparation and certification

Get the five controls right and you close off the most common, opportunistic attacks, and clear the baseline a serious supply chain expects.

Cyber Essentials / 02 · What we do

Preparation, assessment and the Cyber Essentials Plus audit

We handle the whole path, or step in wherever you are stuck. Most well prepared organisations reach base certification in two to four weeks, Cyber Essentials Plus in four to eight.

01

Scope and review

A gap analysis against the five controls, so you know what it will take to certify before you commit.

02

Close the gaps

We put the missing controls in place and fix the configuration that would otherwise fail the assessment.

03

Assess and certify

We complete the self assessment with you and, where you need it, run the Cyber Essentials Plus audit, in which an assessor tests a sample of your devices and accounts.

04

Renew

Certification lapses after a year. We keep the controls current and handle each renewal.

Cyber Essentials / 03 · The difference

An appointed Cyber Essentials certification body

We are an appointed Cyber Essentials certification body, so we assess and certify organisations against the standard. Preparation, remediation and formal assessment are three separate pieces of work, quoted separately, and where separation of duties matters we will say so and keep the roles apart.

LiveControls that runWe secure the technology too, so the five controls stay configured and working across your systems.
RecognisedWhat buyers expectThe baseline UK government contracts, insurers and supply chains increasingly require.
Cyber Essentials / 04 · What it costs

Scheme fees and our prices

The IASME assessment fee is fixed by the scheme and tiered by organisation size. We are the certification body that collects it, so here it is, followed by what we charge on top and why. The scheme fees below were reviewed on 23 August 2026.

1–9Micro£320 + VAT, the IASME assessment fee
10–49Small£440 + VAT, the IASME assessment fee
50–249Medium£500 + VAT, the IASME assessment fee
250+Large£600 + VAT, the IASME assessment fee

That fee buys an assessment. It does not buy getting your controls into a state that passes, fixing what does not, or keeping it true for the next twelve months. So here are three.

01Assess

Assessment only

You are confident you meet the five controls. We assess and certify, and charge you the scheme fee with nothing added.

£320–£600 + VATBy size
02Guide

Guided to certified

We review you against the five controls first and tell you what will fail. You fix it or we quote to. Then we assess and certify. Includes the scheme fee.

From £950 + VATScheme fee included
03Maintain

Managed certification

Controls managed, remediation included, evidence maintained, and annual recertification handled rather than remembered. Priced monthly by organisation size on our pricing page.

Monthly, by sizeRecert included

Cyber Essentials Plus

The audited tier: the same five controls, tested by an assessor against a sample of your devices and accounts rather than self assessed.

Cyber Essentials Plus is priced from £1,299 + VAT for one to nine people, rising by organisation size, and every price includes the Cyber Essentials certification because you cannot hold Plus without it. The full ladder, what the assessor tests on the day and the blockers that fail assessments are on our Cyber Essentials Plus page.

If you supply the Ministry of Defence, note that every level of Defence Cyber Certification requires Cyber Essentials, and DCC Levels 2 and 3 require Cyber Essentials Plus. DCC Level 0 is priced two ways: one for suppliers who already hold Cyber Essentials, and one that includes the certification for those who do not. If you need both, start there rather than buying them separately.

Remediation, where it is needed, is quoted separately and you decide whether we do it or you do. You get the findings either way. If scope changes what you owe, we say so in writing before we start.

FAQ

Common questions

What is Cyber Essentials?

Cyber Essentials is a UK government scheme, run by the NCSC and delivered by IASME, that certifies you have five technical security controls in place: firewalls, secure configuration, security update management, user access control, and malware protection. It is designed to stop the most common, opportunistic attacks.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Both cover the same five controls; the difference is how they are checked. Base Cyber Essentials is a self assessment, verified by a certification body. Cyber Essentials Plus adds a technical audit, in which an assessor tests a sample of your devices and accounts. Plus is often specified for contracts involving sensitive data.

How long does Cyber Essentials take?

A well prepared organisation can reach base certification in two to four weeks. Cyber Essentials Plus commonly takes four to eight, because it includes a technical audit in which an assessor tests a sample of your devices and accounts. The timeline depends on how much needs fixing first, which a readiness review tells you up front.

Do I need Cyber Essentials to win contracts?

Often, yes. Cyber Essentials is a minimum requirement for many UK government contracts and is increasingly expected by enterprise clients, insurers and supply chains. If a contract or questionnaire names a level, send it to us and we will confirm which tier it asks for.

What does it mean that you are a certification body?

It means we are appointed to assess and certify organisations against the Cyber Essentials standard. In practice, our assessors work to the standard every day, so preparation work is informed by what an assessment looks for, and if you need your own suppliers certified, we can assess them too. Preparation, remediation and formal assessment are separate pieces of work, and where separation of duties matters we will say so and keep the roles apart.

Book a Cyber Essentials review

Book a Cyber Essentials review, or send us the clause you need to satisfy and we will tell you which tier fits.

Reading, Berkshire  /  Cyber Essentials certification body  /  reply within one working day