You cannot certify your own work
Where you built and maintain the environment, an independent certification body marking the assessment is a cleaner position for you and a more credible one for your client.
Malwise does not sell managed IT support, helpdesk or infrastructure projects. We have no reason to approach your clients for anything beyond the certification or testing you introduce us for, and we say so in writing before we speak to them.
Talk to us about a clientMost IT providers meet Cyber Essentials the same way: a client forwards a customer questionnaire and asks whether you can sort it. You can do the technical work. What you often do not want is to become the assessor as well.
Where you built and maintain the environment, an independent certification body marking the assessment is a cleaner position for you and a more credible one for your client.
The technical audit must be carried out by an assessor working for a licensed certification body. There is no route around that, whatever the state of the estate.
Penetration testing delivered by Cyber Scheme certified testers, with findings written so your engineers can act on them rather than decode them.
Referral. You introduce the client, we contract with them directly, you stay in the loop on findings and remediation. Simplest arrangement, no commercial complexity for you.
Through you. You contract with us and present the work as part of your service. Certification itself must be issued by us to the client as the certificate holder, but the commercial relationship can sit with you.
Either way, remediation stays yours unless you ask us to help. We would rather your engineers fix what we find; they know the estate and they are already being paid to look after it.
Service needed, rough size of the client, any deadline. No client details required at this stage.
Against published prices for certification, scoped days for testing.
You see the findings. We do not contact your client about anything else.
No. We do not provide managed IT support, helpdesk, infrastructure or procurement, so there is nothing for us to approach them about. Where you want it in writing, we will sign a client non-solicitation agreement before any introduction.
Not the certificate itself. Cyber Essentials and Cyber Essentials Plus certificates are issued by the licensed certification body to the client, and the assessor is named. The commercial relationship can sit with you; the certification cannot be presented as yours.
They are told exactly what fell short and have two working days to fix it and resubmit at no extra cost. In most cases that is a configuration change your team can make the same day. Nothing is published and nobody outside the process is told.
Our prices are published, so you can see them before you introduce anyone and build your own margin openly if you contract through us. Cyber Essentials fees are set by IASME and identical at every certification body in any case.
For a prepared client, Cyber Essentials can be completed inside a working week. Cyber Essentials Plus needs a testing window agreed, and must be completed within three months of the base certificate. Testing is scoped before it is booked.
Yes. Assessment is remote as standard and we work UK wide. Being in Salisbury matters for on site testing and for providers who want to meet before they refer a client.