Cyber Essentials (CE) is the UK government-backed scheme that proves your business has the five basic technical controls in place that stop the most common cyber attacks. Required for many public sector and supply chain contracts, and the first step to CE+ (Cyber Essentials Plus).

Every client we have taken through an accreditation has achieved it - and kept it at every renewal.
We submit ourselves to independent third-party testing. Certification is always issued by an independent body, never by us.
We prove each control works on your real devices and services. Questionnaire answers can be inaccurate or optimistic; tests cannot.
We will look at your current position for free and tell you exactly which controls you need - with no obligation.
Cyber Essentials, often shortened to CE or CE Basic, was created by the UK government and the National Cyber Security Centre (NCSC) and is delivered by IASME. It certifies that your organisation has five technical controls in place across its devices, cloud services and networks.
You complete an online self-assessment question set, which is marked by an independent assessor. Certificates last 12 months, so the scheme is renewed every year - and the requirements are refreshed by the NCSC each year too.
Eligible UK organisations with a turnover under £20m that certify their whole organisation also receive cyber liability insurance with their certificate (see the IASME terms).
Every internet-connected device and your office network sit behind a correctly configured firewall, with default passwords changed and unneeded services closed.
Devices and cloud services are set up securely: unused software and accounts removed, auto-run disabled, device locking in place.
All software is licensed and supported, and high and critical security updates are applied within 14 days of release.
Only the people who need access have it, admin accounts are separate and restricted, and multi-factor authentication protects your cloud services.
Anti-malware or application allow-listing is active on every in-scope device.
We review your devices, cloud services and processes against Cyber Essentials and show you where you stand.
We fix or guide you through every control that would fail, in priority order.
We prove each control works - scans, patch checks, malware tests, restores and MFA checks - before anyone else looks.
An independent assessor, auditor or certification body confirms it. We never certify our own work.
We monitor your controls in real time and fix drift as it happens, so renewal is a normal day, not a cliff edge.
Our own intellectual property is how we run compliance: we monitor the major Cyber Essentials controls in real time using the leading enterprise SaaS tools. That lets us map gaps and bridge controls quickly and accurately while you work towards accreditation - and then keep standards up, and risk down, every day after it.
We watch the major controls continuously using leading enterprise SaaS security and compliance tools - not once a year with a questionnaire.
Live data shows exactly which controls are missing or drifting, so we can map the gaps and bridge them quickly and accurately.
Every change to your systems follows a compliant change process, so an upgrade or a new starter never quietly breaks a control.
Issues are picked up and fixed as they happen. Your risk goes down over the year instead of creeping up until the next audit.
Annual review is not viable in the current threat landscape. Attackers do not wait twelve months - so neither do we.
Prices exclude VAT. Payment is taken securely by instant bank payment through GoCardless and we contact you within one working day to start.
The official IASME assessment at the IASME fee. You complete the question set; we register it, give you portal access and help if you get stuck.
Cyber Essentials (v26) Supported Submission: we prepare, evidence and submit your first or lapsed CE certification with you - gap remediation guidance included.
Certification is a snapshot. Our compliance plans keep the controls tested, the evidence current and renewals handled - Level 1 demonstrates, Level 2 practises and Level 3 proves compliance continuously.
CE and Digital GDPR Controls - Our consultants will complete the CE submission with input from your staff.
CE, CE+ and Digital GDPR Controls -Monitoring & Submission as a Service (Submission following Quarter)
CE, CE+, GDPR Governance, Supply Chain Audits, Pen Testing, Vulnerability Scanning, (Real-time Maintained) Compliance As A Service
CE (Cyber Essentials) is a verified self-assessment of five technical controls. CE+ (Cyber Essentials Plus, also written CE Plus) covers the same controls but adds a hands-on technical audit by an independent assessor, so it carries more weight with customers, public sector buyers and insurers. You must hold CE before taking CE+, and the CE+ audit must be completed within three months of your CE certificate.
With our supported service most organisations are ready to submit within two to four weeks, depending on how many gaps our free assessment finds. Once submitted, IASME assessors usually mark it within a few working days.
Assessment only is the official IASME assessment at the IASME fee - you answer the questions yourself and we are on hand if you get stuck. Supported means our consultants assess your systems, fix or guide you through the gaps, evidence each control and complete the submission with you.
With the supported service we do not submit until our own tests show you will pass - which is why every client we have taken through has achieved certification. On the assessment-only route, IASME allows a short window to correct answers.
Yes. Certificates are valid for 12 months and the requirements are updated each year, so renewal is also your annual security check-up. Our Level 1-3 plans take care of renewal for you.
IASME includes cyber liability insurance for eligible UK organisations with a turnover under £20m that certify their whole organisation. We will confirm eligibility during your free assessment.
We do not rely on a questionnaire. We physically test each control on your devices and services before you submit, and our own work is independently tested by a third party - we never mark our own homework.
We monitor the major controls in real time using leading enterprise SaaS tools, with compliant change management behind every change. Gaps are found and bridged quickly, standards are maintained every day, and accreditation stops being a fraught cliff edge - you can say you were compliant yesterday, not a year ago.
Controls drift: devices miss patches, accounts change, new services appear. With an annual review that drift goes unnoticed for months while risk rises. Real-time monitoring catches it as it happens, so issues are fixed quickly and your compliance improves rather than decays.
Book a free, no-obligation Cyber Essentials assessment. We will show you which controls you already meet, which you need, and the quickest route to getting certified.