Cyber Essentials, without the headache.
I'm Lewis — I help small businesses across Lancashire and the North West get Cyber Essentials certified and stay certified. I review where you stand, fix what's missing, walk you through the assessment, and pick it back up again at renewal.
Usually it starts with a customer asking.
Most small businesses come to Cyber Essentials because someone else has asked for it. It's worth having for its own sake too.
Customers are asking for it
Cyber Essentials is a UK government-backed scheme created by the National Cyber Security Centre. It is commonly required for public-sector work involving sensitive or personal data — and if you cannot show a certificate, you often cannot bid.
Bigger clients push it down the chain
Larger organisations increasingly ask their suppliers to certify before they will sign. Having it already sorted turns an awkward questionnaire into a one-line answer and gets you onboarded faster.
The controls genuinely help
The five controls are the basics that stop the everyday attacks — phishing, malware, ransomware, stolen passwords. Most businesses find a gap or two they had no idea about, which is rather the point.
What certification actually asks of you.
Cyber Essentials covers five technical control themes. None of them are exotic — they're the things that quietly slip when nobody owns them.
1. Firewalls
Everything that touches the internet sits behind a properly configured firewall, with inbound connections blocked unless you actually need them.
2. Secure configuration
Default passwords changed, unnecessary software and accounts removed, and your devices and cloud services set up so there is less to attack in the first place.
3. User access control
Everyone works from a standard account, admin rights are kept separate and minimal, access goes when people go, and multi-factor authentication is on.
4. Malware protection
Devices are properly protected against malware — usually active anti-malware kept up to date, with dodgy websites blocked while people browse.
5. Security update management
Everything in use is still supported by its vendor, updates are applied promptly, and end-of-life software is removed rather than quietly tolerated.
And then, every year
Certification runs for twelve months. I keep an eye on things through the year and handle the renewal, so it never becomes a last-minute scramble.
From "where do I even start" to certified.
You deal with me from start to finish. The certificate itself is issued by an approved certifying body — I get you ready for it and stay alongside you through the process.
Gap review
I look at what you have and compare it against the five controls, then tell you plainly where you stand and what needs doing.
Scope it properly
We agree what counts — laptops, servers, the office router, cloud services, work phones and any personal devices touching company data.
Fix the gaps
I do the work: multi-factor authentication, device settings, admin accounts, malware protection, updates and anything else the review flagged.
The questionnaire
We go through the self-assessment together so your answers are accurate and you understand what you are signing up to.
Certification
You submit to an approved certifying body and I stay with you through the review and any questions that come back.
Quoted properly, once I know your setup.
- A gap review of your setup against all five controls
- Help agreeing what is in scope — devices, cloud services, phones
- Hands-on fixing of whatever the review turns up
- A walk-through of the self-assessment questionnaire with you
- Support right through submission and any follow-up questions
- Annual renewal support so you stay certified year after year
- Plain-English explanations, no jargon, one person throughout
Every business is a slightly different shape, so I quote once I've seen your setup. The certifying body's own assessment fee is separate and I'll always show it to you plainly — no mark-up hidden in the middle.
Common questions
What actually is Cyber Essentials?+
It is a UK government-backed certification created by the National Cyber Security Centre. It confirms your business has five fundamental security controls in place — firewalls, secure configuration, user access control, malware protection and keeping software updated. It is deliberately practical: the basics, done properly, rather than a huge compliance programme.
What does the assessment involve?+
You complete an online self-assessment questionnaire covering the five controls, and an assessor at a certifying body reviews your answers. I am not a certifying body — my job is to get you genuinely ready, help you answer the questionnaire accurately, and support you through submission. The certificate itself is issued by an approved body.
My business is tiny. Is it still worth it?+
Often yes. I work with businesses of up to about five people and the controls apply just the same — small does not mean out of scope, and attackers are not fussy. It is usually a shorter, simpler job than owners expect, and it settles a lot of customer questions in one go.
What if I do not pass?+
You are told exactly what fell short and you get the chance to put it right. That is the whole reason I start with a gap review rather than diving at the questionnaire — the point is to find the problems while they are still easy and private to fix. I cannot promise an outcome, but surprises are rare when the groundwork is done.
Does it come with cyber insurance?+
Certification under the scheme can include a level of cyber liability insurance for eligible UK organisations, but eligibility and terms are set by the certifying body and can change. I would not treat it as a reason to certify — I will point you at the current terms so you can check whether you qualify.
What is the difference between Cyber Essentials and Cyber Essentials Plus?+
There are two levels. Cyber Essentials is a verified self-assessment: you answer the questionnaire, a qualified assessor checks your answers, and you certify. Cyber Essentials Plus covers exactly the same five controls but adds a hands-on technical audit — an assessor tests a sample of your devices and your email and browser protections to prove the controls really are in place. You have to hold Cyber Essentials first, and the Plus audit has to be completed within three months of it. For most businesses of up to five people, plain Cyber Essentials is what customers ask for; Plus is worth doing when a contract or framework specifically names it.
How much does Cyber Essentials cost?+
Two parts. The certifying body’s assessment fee is set by IASME and tiered by organisation size — for a micro business of up to nine people it currently starts at £320 plus VAT, and I always show it to you at cost with no mark-up. Then there is my fee for the gap review, fixing what turns up and walking you through the questionnaire, which I quote once I have seen your setup, because a two-laptop business with Microsoft 365 already set up properly is a very different job from one with an old server in the corner. Cyber Essentials Plus is priced separately by the certification body.
How long does Cyber Essentials take?+
It depends on what the gap review finds. A small business already on Microsoft 365 with modern, updated laptops and multi-factor authentication switched on can go from first conversation to a submitted questionnaire in a couple of weeks, and assessors typically come back within a few working days. The questionnaire itself is an hour or two sat together. What stretches it out is old kit — a laptop still on an unsupported version of Windows, a router nobody has logged into for years — because that has to be fixed or replaced before you can honestly answer yes.
Can I do Cyber Essentials myself?+
Yes — the questionnaire is designed to be completed by the business itself, and if you are technically confident you can. Where people get stuck is knowing what a question actually means in practice (what counts as “in scope”, what a sufficiently strong password policy looks like, whether your phones count) and then doing the fixes. That is the bit I do, so you answer accurately first time rather than getting sent back.
Do I need to renew Cyber Essentials every year?+
Yes. The certificate lasts twelve months, and recertification is a fresh self-assessment against whatever the current question set is — the scheme is updated periodically, so a few questions usually change from one year to the next. Because I look after your setup through the year, renewal is normally a short check-in rather than starting from scratch, and I put the date in the diary so it does not lapse and catch you out in the middle of a tender.
How can I check whether a Cyber Essentials certificate is genuine?+
Every current certificate is listed on the public register run by IASME on behalf of the NCSC, searchable by company name. It is worth knowing about for two reasons: you can check a supplier who claims to be certified, and once you certify, your customers can check you the same way — which is often exactly what their procurement team does.
Find out how close you already are.
Most small businesses are further along than they think. Tell me a bit about your setup and I'll tell you honestly what stands between you and a Cyber Essentials certificate.
Get certifiedStart your Cyber Essentials certification.
Tell me roughly how many people and computers you have, and whether a customer has asked you for certification. I'll come back within one working day with a quote and a straightforward plan. No pressure, no jargon.