Free download: The Cybersecurity Checklist for Growing Businesses.

CYBER ESSENTIALS READINESS

Know exactly where you stand before you apply.

A one-week gap assessment against the NCSC's five Cyber Essentials controls. We audit your setup, tell you honestly whether you'd pass today, and hand you a prioritised roadmap to close whatever's missing.

Why it matters

Cyber Essentials has quietly become the price of entry.

It wins you contracts

Cyber Essentials is a hard requirement on most UK public-sector tenders and an increasing number of enterprise ones. Without it, you're filtered out before anyone reads your proposal.

It affects your insurance

Cyber insurers now ask detailed questions about the same controls. Certification helps with eligibility, and often with the premium and the excess too.

It genuinely reduces risk

The five controls exist because they block the overwhelming majority of common, untargeted internet attacks. This isn't a paperwork exercise, it's the baseline that actually works.

It answers due diligence in one line

Client security questionnaires and supplier reviews get significantly shorter when you can point to a current certificate instead of writing prose about your firewall.

Cyber Essentials is a UK government-backed scheme run by the NCSC. You can read the official overview at ncsc.gov.uk.

What we assess

The five controls, in detail.

Cyber Essentials comes down to five technical controls. We check every one of them properly, and tell you where your evidence would fall over.

Firewalls

Boundary firewalls at every internet connection, software firewalls on every device, default credentials changed, and no unapproved inbound services reachable from the internet.

Secure configuration

Default passwords replaced across devices and services, unnecessary software and accounts removed, auto-run disabled, and macros restricted to trusted, signed ones.

User access control

Least privilege enforced, separate admin accounts, MFA on every internet-facing service, a real joiners and leavers process, and a password policy that matches current guidance.

Malware protection

Active, current anti-malware or EDR on every device, filtering that blocks known malicious sites for remote workers too, and controls on code executing from email and browsers.

Security update management

Everything on a supported version, critical and high-severity patches applied within 14 days, automatic updates enabled, and end-of-life software removed or isolated.

This is a readiness assessment. We tell you what needs fixing and how to fix it, we don't do the remediation or run the certification itself.

How it works

One week, start to finish.

For most small businesses the whole engagement runs inside a week. The initial audit can be done remotely or in person, whichever works better for your team.

  1. 01

    Free 15-minute call

    We confirm scope, headcount, and what you're certifying for, whether that's a specific tender, an insurance renewal, or a client asking questions.

  2. 02

    The audit

    Remote or in person, whichever suits you. We walk through your estate: devices, Microsoft 365 or Google Workspace, network, accounts, and the tools your team actually uses.

  3. 03

    Evidence review

    We check your configuration, policies, and processes against each of the five controls, the same way an assessor would, and note exactly where the evidence falls short.

  4. 04

    Your readiness report

    A pass or gap verdict for every control, with a prioritised remediation roadmap written in plain English, not vendor jargon.

  5. 05

    Walkthrough

    We talk your team through the findings, what to tackle first, and what each fix realistically involves, so you can plan the work with confidence.

What you get

What lands on your desk.

Pricing

From £499

Final scope depends on your headcount and the size of your estate. We confirm the price on the intro call, before any work starts.

  • A readiness scorecard, control by control
  • A clear list of every evidence gap we found
  • A prioritised remediation roadmap with effort and impact against each item
  • A straight go/no-go answer on whether you'd pass today
  • A walkthrough session with your team
  • Notes on anything outside Cyber Essentials that we think needs your attention

This is for you if…

  • A tender or client contract has made Cyber Essentials a requirement
  • Your cyber insurance renewal is coming up and the questions are getting harder
  • You're applying for the first time and don't want to fail the self-assessment
  • You started an application, hit a question you couldn't answer honestly, and stalled
  • You want an independent view of your security baseline before you commit to anything

Free first step

Want a rough idea before you spend anything?

Our free Cyber Essentials Benchmark walks you through the same five controls as a self-assessment and shows you your score by category in about five minutes. It's a good sense-check, the full readiness assessment is what you need before you actually apply.

Find out whether you'd pass today.

Book a free 15-minute call. Tell us about your setup and what's driving the certification, and we'll tell you straight what the assessment would involve.