Compliance · Service 03

Cyber Essentials Certification

We are a licensed Certification Body. We assess and certify directly. No broker, no middleman, no platform that hands your application to someone else.

Cyber Essentials certified
Cyber Essentials Plus certified
Licensed by IASME

We assess and certify both levels directly.

Click either badge to verify the licence on the registry.

Cyber Essentials
Cyber Essentials Plus
Pricing

Published, by organisation size.

The Cyber Essentials fee is set by IASME and is the same at every certification body. Cyber Essentials Plus pricing is set by each certification body. Ours is below.

Organisation sizeEmployeesCyber EssentialsCyber Essentials Plus
Micro0 to 9£320 + VAT£1,095 + VAT fixed
Small10 to 49£440 + VAT£1,395 + VAT fixed
Medium50 to 249£500 + VATfrom £1,750 + VAT
Large250 or more£600 + VATfrom £2,500 + VAT

Cyber Essentials Plus requires a passing Cyber Essentials certificate, so both fees apply. Fixed means fixed. The "from" prices depend on the size and spread of the estate, which we scope before quoting. Whole organisation certification also includes £25,000 of cyber liability insurance for UK organisations under £20 million turnover.

Full cost breakdown, including optional support

What changed in April 2026

v3.3 Danzell is now in force

Any Cyber Essentials assessment started on or after 27 April 2026 uses the new standard. The five controls haven't changed. The enforcement has. Most significantly: multi-factor authentication failures are now automatic failures. If any in-scope cloud service supports multi-factor authentication and you haven't enabled it, the assessment fails with no exceptions.

Other changes that catch renewals off guard: scope is broader (personal devices accessing work systems are in scope), application development has new requirements for custom software, and home working is handled differently: a home router is only in scope where your organisation supplied it, otherwise the firewall requirement must be met on the device itself. If your last assessment was before 2026, your renewal will look different.

Which level?

Cyber Essentials or Cyber Essentials Plus

Two levels. Different scopes. We'll tell you which one your contract or supply chain actually requires.

Cyber Essentials

Verified self-assessment

You answer a detailed questionnaire covering the five control areas. We review, verify, and certify. Required for certain government and defence supply chain contracts, and increasingly requested by commercial customers and insurers.

  • Certain government and defence contracts
  • Some cyber insurance requirements
  • Supply chain compliance
  • Customer trust signal
Higher assurance
Cyber Essentials Plus

Technical verification included

Everything in Cyber Essentials, plus independent technical testing. An assessor verifies your controls actually work: vulnerability scans, device configuration sampling, boundary protection testing.

  • MOD supply chains
  • NHS and public sector contracts
  • Higher-tier government frameworks
  • Where Cyber Essentials Plus is explicitly required
The framework

The five technical controls

Every device, user account, and cloud service in scope must meet the requirements across all five.

01

Firewalls

Boundary devices and host-based firewalls must be configured to block by default. Inbound rules must be documented and justified. Routers and firewalls with factory default credentials are an automatic failure.

Boundary firewall configured Host-based firewall on all devices Inbound rules documented
02

Secure configuration

Default accounts removed, unnecessary services disabled, password quality managed by one of the permitted approaches: multi-factor authentication, a minimum length of 12 characters, or a minimum of eight characters with automatic blocking of common passwords. Multi-factor authentication must be enabled on all admin accounts. Under v3.3, missing multi-factor authentication on any cloud service that supports it is an automatic failure.

Default credentials removed Multi-factor authentication on all admin accounts Unnecessary services disabled
03

User access control

Least privilege enforced throughout. Joiner-mover-leaver process documented. Admin accounts kept separate from day-to-day accounts and only used for administration. Special access privileges must be removed or disabled when they are no longer required.

Least privilege enforced Admin accounts separate JML process documented
04

Malware protection

Active endpoint protection on every in-scope device. Signatures current. Mobile apps from official stores only. On-access scanning enabled. One approved mechanism must be in place on every device in scope.

Active on every in-scope device Signatures kept current Mobile apps: official stores only
05

Security update management

High and critical patches applied within 14 days of release. Only software still receiving vendor security updates may remain in scope. Unsupported software must be replaced, removed from scope through a valid scope definition, or covered by a recognised vendor extended support programme. Mainstream Windows 10 support ended on 14 October 2025.

Critical patches within 14 days Vendor-supported software only EOL systems removed
Where assessments fail

The five things that break a first attempt

The questions look simple. These are the failure modes we see again and again as a Certification Body.

01

Scope underestimated

Cloud services used for work (Slack, Notion, GitHub, Figma, your Microsoft 365 tenant) are in scope. Personal devices accessing work systems are in scope. Most first attempts exclude things that should be included.

02

Multi-factor authentication gaps on cloud services

Under v3.3, an automatic failure. If any in-scope service supports multi-factor authentication and it isn't enabled, the assessment fails. Check every cloud service, not just email.

03

Admin account misuse

Using the same account for admin tasks and day-to-day work is a failure. Admin accounts must be dedicated, protected by multi-factor authentication, and used only for administration.

04

Unsupported software in use

Any software no longer receiving vendor security updates is a failure. Mainstream Windows 10 support ended on 14 October 2025, so devices without updates cannot meet the requirement. Eligible devices covered by a valid Extended Security Updates programme remain supported while that coverage continues.

05

Default credentials on devices

If the admin password on any boundary firewall or router is still the factory default, that is an automatic failure. Check every boundary device in scope.

How we work

From scoping call to certificate.

i

Scoping call

Free 15 minutes. Understand your environment, confirm Cyber Essentials or Cyber Essentials Plus, flag any obvious issues.

ii

Fixed-price quote

Clear price based on your organisation size. No per-question fees, no scope-creep billing.

iii

Assessment

Structured questionnaire for Cyber Essentials, or questionnaire plus technical audit for Cyber Essentials Plus.

iv

Certification

Certificate issued typically within 2 working days of a passed assessment.

v

Annual renewal

We remind you well in advance and recertify efficiently each year.

What comes next

After certification

Cyber Essentials gets you certified. It doesn't tell you what to fix next or how to build a security programme around the controls. If you want strategic advice on what comes after the certificate, our Security Consulting service covers risk prioritisation, remediation planning, and building on Cyber Essentials towards a stronger overall posture.

Security Consulting →
Ready to start?

Book your free scoping call

15 minutes. We'll confirm the right level, flag anything that needs fixing first, and give you a fixed price.

Get in touch