Cyber Essentials

Cyber Essentials
Certification Made Simple

Cyber Essentials is the UK government's cyber security certification scheme and it's increasingly required by public sector contracts, insurers and enterprise clients. We guide you from pre-assessment readiness through to certified status.

What Is Cyber Essentials?

Cyber Essentials is a UK government-backed certification scheme, managed by the NCSC (National Cyber Security Centre). It defines five core technical controls that, when properly implemented, protect organisations against the most common cyber attacks including phishing, ransomware and opportunistic hacking.

There are two levels: Cyber Essentials (self-assessment verified by an external certifying body) and Cyber Essentials Plus (the same five controls but independently verified by a technical assessor conducting hands-on testing). We support both.

The Five Controls

1
Boundary Firewalls
Properly configured firewalls to block unauthorised access at the network perimeter.
2
Secure Configuration
Devices and software configured securely default passwords changed, unnecessary services disabled.
3
Access Control
User accounts with minimum necessary privileges; MFA for remote access and admin accounts.
4
Malware Protection
Antivirus, application allow-listing or sandboxing to prevent malicious code from running.
5
Patch Management
Operating systems and software kept up to date critical patches applied within 14 days.

Which Level Do You Need?

Feature CE CE+
NCSC-recognised certification Yes Yes
Assessment method Self-assessed Independently tested
Technical verification No Yes (on-site/remote)
Government contract mandatory Sometimes Often required
Cyber insurance (under 25 emp.) £25K free £25K free
Demonstrates technical rigour Basic High
Ideal for SMBs starting out Supply chain, public sector

Who needs Cyber Essentials? It is mandatory for any business bidding for central government contracts involving sensitive information. It is increasingly required by NHS contracts, local authorities, and many enterprise supply chain requirements. All businesses benefit from the baseline security it establishes.

Our Cyber Essentials Support Services

From readiness gap assessment to post-certification remediation we take you through the whole process.

Readiness Assessment

Before you apply, we assess your current posture against all five CE controls and produce a gap report with prioritised remediation actions.

  • Five-control gap analysis
  • Prioritised action list
  • Risk-rated findings
  • Timeline to certification

Remediation Support

We fix what needs fixing firewall configuration, patching, MFA deployment, access control reviews so you pass first time.

  • Firewall rule review & config
  • MFA deployment
  • Patch gap remediation
  • Access control tightening

CE Self-Assessment Guidance

We guide you through the IASME self-assessment questionnaire explaining each question in plain English so you can answer accurately and confidently.

  • Question-by-question guidance
  • Scope definition advice
  • Evidence documentation
  • Submission support

CE Plus Technical Assessment

For CE+, an independent technical assessor verifies your controls through hands-on testing of your devices, firewalls and configurations.

  • External vulnerability scan
  • Internal configuration checks
  • Device compliance testing
  • Formal assessment report

Annual Renewal Support

Cyber Essentials must be renewed annually. We track your renewal date, conduct a readiness check and handle the process end-to-end.

  • Renewal reminder & planning
  • Annual readiness check
  • Change-impact assessment
  • Submission & documentation

Supply Chain Compliance

If your clients or contracts require you to hold CE, we make the process fast and straightforward so compliance doesn't slow down your business.

  • Contract requirement review
  • Fast-track assessment path
  • Certificate & documentation
  • Client-facing evidence pack

Our Certification Process

Most businesses achieve Cyber Essentials within 4–6 weeks from initial assessment.

1

Gap Assessment

We test your current state against all five CE controls and identify what needs fixing.

2

Remediation

We implement the required changes firewall rules, MFA, patching, access controls.

3

Self-Assessment

We guide you through the IASME questionnaire submission for CE, or prepare for CE+ testing.

4

Certified

You receive your Cyber Essentials certificate valid for 12 months.

Why Choose Use-It for Cyber Essentials

End-to-end support from assessment through to certification no switching between suppliers.

4–6 Wks
Typical time to certification
CE+
Technical assessors available
NCSC
Aligned assessment methodology
Annual
Renewal management included
Assessment + Remediation
We don't just identify gaps we fix them. One partner from start to certificate.
CE and CE+ Covered
We support both levels of certification including the technical hands-on assessment required for CE+.
First-Time Pass Focus
We prepare you thoroughly before submission reducing the risk of failed assessments.
Broader Security Context
CE is a foundation, not a ceiling. We help you build on it with penetration testing, GDPR and ISO 27001 alignment.
Renewal Management
We track your annual renewal and manage the process proactively no lapse in certification.
Lancashire-Based Support
Our engineers know your environment and can implement remediation changes quickly and accurately.

Frequently Asked Questions

Ready to Achieve Cyber Essentials Certification?

Get started with a free readiness call we'll tell you exactly where you stand and what it takes to get certified.