Cyber Essentials

Government-Backed Cyber Security Certification – Self Assessment

Mitigate common attack risks and improve your company’s credentials with the correct security. Achieving Cyber Essentials certification demonstrates that you are effectively managing cyber security and adhering to the standards established by the scheme.

amtivo feefo rating

Get Started Today

Enter your details below to get started on
your journey to certification.

What Is Cyber Essentials Certification?

The Cyber Essentials Standard, set by the UK Government, defines technical controls to help organisations improve the level of IT infrastructure security and guard their organisation against cyber attacks.

This scheme is designed to help organisations prevent highly common internet-based attacks and to implement the correct controls to protect the confidentiality, integrity, and availability of stored data on all internet-facing devices. Certification gives you peace of mind that your defences will protect against the vast majority of common cyber attacks.

The Cyber Essentials certification process involves testing the five technical controls of your IT infrastructure. You are required to complete and submit a self-assessment questionnaire for evaluation.

Cyber Essentials Certification

What Are the Benefits of Cyber Essentials?

  • Certification gives you peace of mind that your defences will protect against the vast majority of common cyber attacks
  • Stand out from competitors, retain and win more business
  • Increased credibility and reputation, customers feel more confident in sharing information with you
  • Raised awareness of threat with staff reduces risk levels
  • Improved business continuity management
  • Tender for contracts with the MOD, NHS, and central government work
  • Reduce your insurance premiums by reducing your resilience to cyber threats
  • Drive business efficiencies throughout your organisation which helps improve productivity

Why You Should Choose British Assessment Bureau

Our experts are with you at every step of your certification journey.
  • UKAS-accredited certification services – Your certification comes with the coveted Crown & Tick mark, which proves to your clients that it has the strength and security of government backing. Find out more about our UKAS accreditation

  • Expert support when you need it – Our auditors are with you every step of the way and our team is available online to offer support when you need it.

  • 5-star Feefo customer satisfaction – Our customers are so happy with our service that 97% have given us 4- or 5-star reviews. We are proud to hold an “Exceptional” Feefo rating – awarded to businesses achieving a rating of at least 4.5 for over ten years.

Why you should choose British Assessment Bureau

How to Become Cyber Essentials Certified

STEP 1
STEP 2
STEP 3
STEP 4
STEP 5
Identify requirements First, assess the status quo using the five critical security controls.
Develop cyber security policy Identify existing weaknesses in your security and determine where you are now and where you need to be. Create a set of initiatives to address the high priority risks and control gaps.
Plan and implement Using the gap analysis focus on identifying a set of actions and best practice for implementing and administering improvements and test success.
Complete and submit self-assessment questionnaire for audit Provide evidence to support your cyber security policy meets as a minimum the five critical security goals.
Certification and annual renewal If your evaluation is successful you will be notified and receive certification within five days. It is recommended that the Cyber Essentials certification is reviewed and resubmitted annually to maintain certification.

How to Become Cyber Essentials Certified

STEP 1
Identify requirements First, assess the status quo using the five critical security controls.
STEP 2
Develop cyber security policy Identify existing weaknesses in your security and determine where you are now and where you need to be. Create a set of initiatives to address the high priority risks and control gaps.
STEP 3
Plan and implement Using the gap analysis focus on identifying a set of actions and best practice for implementing and administering improvements and test success.
STEP 4
Complete and submit self-assessment questionnaire for audit Provide evidence to support your cyber security policy meets as a minimum the five critical security goals. If your evaluation is successful you will be notified and receive certification within five days.
STEP 5
Certification and annual renewal It is recommended that the Cyber Essentials certification is reviewed and resubmitted annually to maintain certification.

Implementing Cyber Essentials

Cyber Essentials and Cyber Essentials Plus certification is delivered by our sister company, Ascentor – an expert in cyber security and information risk management with over 20 years of experience. As one of the UK’s earliest providers of Cyber Essentials, Ascentor has issued more than 1,000 certificates, helping hundreds of organisations strengthen their cyber resilience and meet core security standards.

What sets Ascentor apart is a tailored, pragmatic approach built on deep expertise in technical assurance, governance, and risk management. You’ll gain structured guidance, practical insights, and the confidence that your organisation is taking measurable steps to improve its security posture.

Find Out More

 

Cyber Essentials Plus

Cyber Essentials Plus has all the trademark of the Cyber Essentials simplicity of approach but has a hands-on technical audit of your system by an assessor.

We will examine the same five basic security controls as the Cyber Essentials certification and tests they work through a technical audit.

Cyber Essentials Plus

Cyber Essentials Certification FAQs

How much does a Cyber Essentials assessment cost?

We offer a variety of packages starting from £320 + VAT.

Request a quote today for more details.

 

What is the purpose of Cyber Essentials certification?

Cyber Essentials is a UK Government standard for technical controls to help organisations improve the level of IT infrastructure security and guard your organisation against cyber attack.

This scheme is designed to help organisations prevent highly common internet-based attacks and to implement the correct controls to protect the confidentiality, integrity, and availability of stored data on all internet-facing devices.

Why should I get Cyber Essentials certified?

There are several benefits to becoming Cyber Essentials certified. It also depends on the industry sectors you work within as some government contracts require Cyber Essentials certification as a minimum.

Becoming Cyber Essentials certified confirms you are addressing cyber security effectively and mitigating the risk from internet-based threats and have met the standards set by the Cyber Essentials scheme. Certification will give assurance to stakeholders that you demonstrate compliance to the five key controls, protecting your organisation against cyber threats and this reassurance may help with winning new business.

Key benefits of Cyber Essentials certification?

  • Protecting your organisation against the majority of common cyberattacks demonstrates to stakeholders your commitment to keeping their data secure which can lead to business retention and potentially new business.
  • By having a higher level of security of your systems it will help drive business efficiencies throughout your organisation which helps improve productivity through streamlined processes and reducing operational costs.
  • Bid for UK central government contracts that involve the handling of personal and sensitive information.
  • Reduce your insurance premiums by increasing your resilience to cyber threats.
Should I choose Cyber Essentials or Cyber Essentials Plus?

This all depends on your organisational needs. If you are looking to work within the public sector and bid for central government contracts than they will ask for Cyber Essentials as a minimum. If you want to demonstrate that your organisation is compliant with cyber security and takes data protection seriously and you hold sensitive data, then you may also want to achieve Cyber Essentials Plus certification.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials certification is a simple process to protect your business against common cyber threats. You will need to complete a self-assessment questionnaire which is assessed by an experienced cyber security assessor. They will independently check your completed questionnaire to ensure that you have in place the recommended FIVE cyber key controls necessary to protect your organisation from the most common cyber attacks

Cyber Essentials Plus certification still has the same basic principles as Cyber Essentials but will have a more rigorous test of your organisation’s cyber security systems. It will require a hands-on technical verification with a qualified assessor to check your eligibility for Cyber Essentials Plus certification.

How do I get Cyber Essentials certified?

Become Cyber Essentials certified through three simple steps:

  1. Purchase Cyber Essentials certification through our website
  2. You may find it useful to review our Free online Cyber Essentials training
  3. Complete the online self-assessment question (SAQ)
  4. Your submission will be reviewed by an experienced assessor. If you are successful you will be issued with Cyber Essentials certification.

If you would like to extend your Cyber Essentials certification to Cyber Essential Plus certification, this must be completed within 3 months of achieving CE certification. Our sales advisors will advise you of the further steps required to apply for Cyber Essential Plus.

 

Where can I find details of full requirements for the Cyber Essentials scheme?

More details on cyber security and the Cyber Essentials and Cyber Essentials Plus scheme can be found at the National Cyber Security Centre website.

Can I see the self-assessment questions before I pay for an assessment?

How are the Cyber Essentials assessments verified?

An authorised member of your organisation will need to sign a declaration to confirm that the assessment answers are true. A qualified assessor will then evaluate the responses. If you meet the FIVE core requirements, you will pass and receive certification.

Do I have to complete Cyber Essentials to apply for Cyber Essential Plus?

Cyber Essentials self-assessment forms part of the application for Cyber Essentials Plus and is processed at the same time. You must meet the minimum requirements of Cyber Essentials before we process the Cyber Essentials Plus and complete the Cyber Essentials questionnaire which will verify your compliance as part of achieving Cyber Essentials Plus.

To apply for Cyber Essentials Plus you must possess a Cyber Essentials certificate, supply a copy of the Cyber Essentials questionnaire submitted, and confirm that no changes have been made to your controls since that submission.

 

How quickly can I get certified to Cyber Essentials certified?

We aim to return the result of your self-assessment as quickly as possible and certainly within your target timescales. If you have any concerns or you have a timetable you need to meet please discuss this with our adviser.

How long will I have to complete and submit my assessment?

You can take as long as you want to start your assessment. Once you have started it, you need to complete it including any corrective actions identified by your assessor within one month.

If I fail will I get feedback about why I failed?

If you fail the assessment, we will supply a report with the answers you gave along with the assessor feedback. This should help you improve your security so you can achieve certification in the future.

My organisation in not based in the UK can still obtain cyber essentials certification?

Yes, organisations overseas can get certified, contact us at [email protected] for more details on the process.

 

Do certifications have an expiry date?

Certificates expire after 12 months, therefore, we recommend you seek to renew your certification before expiry.

Will I receive a reminder to recertify?

Yes. We will contact you before your expiry date.

If I have ISO 27001 certification, do I still need to Cyber Essentials/Cyber Essentials Plus certification.

This will depend on your motivations for being certified, if you are asked to be Cyber Essentials certified, a ISO 27001 certification although more comprehensive will not show that your security levels are up to the National Cyber Security Centre (NCSC) standards.

ISO 27001 is an international standard that provides specifications for an ISMS (Information Security Management System) – a systematic approach to managing information security risk. It goes considerably further than Cyber Essentials, but they are complementary to one another.

Do I need Cyber Essentials to bid for a government contract?

Some government contracts may require you to be Cyber Essentials certified – it is important that you seek clarification for each contract.

Who is IASME?

Cyber security firm IASME was chosen by the National Cyber Security Centre (NCSC) to take over full responsibility for Cyber Essentials delivery and become the Cyber Essentials Partner with the NCSC. The IASME Governance standard allows small companies in a supply chain to demonstrate their level of cyber security and show that they are taking steps to properly protect their customers’ information.

Can I use my previous accreditation body?

From 1 April 2020 IASME Consortium took over the running of the Cyber Essentials scheme on behalf of the NCSC. You will need to use an IASME-certified organisation such as Ascentor, who are working with British Assessment Bureau, to apply for certification. Having a Cyber Essentials partner (rather than 5 certification bodies) will ensure there’s greater consistency in the way the scheme operates. It will ensure that Certification Bodies are all working to the same standard and provide a more streamlined path to certification so we can ensure Cyber Essentials remains relevant.

What support will I get during certification?

We understand that certification can appear daunting. Our experts are here to make sure that the process is as smooth as possible and that you gain maximum benefits.

If you find yourself struggling and need further support please contact one of our advisors to discuss options that are available to you.

Sign Up to Our Newsletter

Enter your details below to stay up to date with all the latest certification news and expert insights.

Related Standards

Cyber Essentials Plus

Learn about Cyber Essentials Plus – who needs it and why, and how to implement robust cyber security measures.

ISO 27001

Discover ISO 27001, the global standard for information security management, safeguarding data integrity, confidentiality, and availability.

ISO 42001

Learn about ISO 42001, the first international standard outlining the requirements for Artificial Intelligence Management Systems (AIMS).

ISO 14001

ISO 14001 is a globally recognised standard for Environmental Management Systems, helping organisations improve sustainability & reduce environmental impact.

ISO 22301

Get in touch with Amtivo now to find out how we can help your business to become ISO 22301 certified.

ISO 9001

ISO 9001 is an internationally recognised standard for quality management, helping businesses across industries improve the quality of their products and services.