Cyber Essentials Certification

Compare Cyber Essentials Certification Providers UK (2026)

Compare Assessment, Preparation, Plus Audits, Support, Renewal And Cost

Compare Cyber Essentials certification providers by IASME licensing, self-assessment support, scope guidance, Cyber Essentials Plus audit capability, technical remediation, assessor access, pricing, turnaround, retesting, renewal and service ownership. Evaluate providers against the same legal entities, devices, cloud services, controls and certification deadline before purchasing an assessment or supported package.

Reviewed 16 July 2026Current v3.3 RequirementsCertification-Only Comparison
Step 1 of 2 · Free quote
Free
Request tailored quotes
Cyber Security
Request tailored quotes

Tell us what you need and we will match your business with suitable providers.

8certification-provider profiles reviewed
5mandatory technical control themes assessed
15scope, readiness and certification checks included
12 moannual certification and renewal cycle
Cyber Essentials certification preparation for a UK business
Compare Cyber Essentials providers by scope guidance, assessment support, technical preparation, Plus audit capability, retesting, renewal and complete service cost.

Certification Starts With An Accurate Scope

The certificate should represent the infrastructure, legal entities and cloud services that genuinely support the organisation’s business activity.

  • Identify every legal entity and business unit included in the certificate
  • Reconcile devices, networks, cloud services and internet-facing systems
  • Justify exclusions and prove separation from the certified environment
  • Keep every in-scope system supported and compliant on the issue date

Cyber Essentials is the UK Government-recommended minimum cyber security standard for organisations of every size. The scheme assesses five technical control themes: firewalls, secure configuration, security update management, user access control and malware protection. The standard level uses a verified self-assessment reviewed by a qualified assessor working for an IASME-licensed Certification Body.

Cyber Essentials Plus uses the same requirements but adds an independent technical audit. The auditor tests a representative sample of in-scope devices, every internet gateway and relevant internet-facing servers to verify that the declared controls operate in practice. The organisation must first achieve Cyber Essentials and normally progress to Plus within the permitted three-month window.

This page compares Cyber Essentials and Cyber Essentials Plus certification services only. It does not compare broader management-system or industry certifications. Providers may sell several assurance services, but the quote, assessor, readiness work, audit and certificate discussed here must remain specific to the Cyber Essentials scheme.

Certification Routes

Choose The Right Assessment And Support Package

The official assessment price is standardised by organisation size, but provider support, technical remediation and Plus auditing vary significantly.

Certification RouteWhat It Usually ProvidesBest-Fit Question
Cyber Essentials assessment onlyProvides the official assessment account and qualified review of the verified self-assessmentIs the organisation already compliant and able to interpret every question without consultancy?
Guided Cyber Essentials packageAdds assessor explanations, scope support, document review or limited advisory time to the official assessmentHow much direct support is included, and does the assessor remain independent when marking the submission?
Turnkey readiness and certificationAdds discovery, gap analysis, remediation planning and hands-on preparation before assessmentWhich technical changes are included, which remain the customer’s responsibility and what happens if the business is not ready?
Cyber Essentials Plus auditAdds technical verification after successful Cyber Essentials certification using the same control requirementsCan the provider complete the audit within the three-month window and support the required device sample and retest?
Cyber Essentials and Plus combined packageCoordinates the verified self-assessment, readiness work and Plus audit under one engagementAre both certificates, preparation, audit, retest and travel clearly separated in the proposal?
Renewal and continuous-readiness supportTracks annual renewal, question changes, asset changes and control maintenance between certificatesDoes the service improve ongoing compliance or merely remind the organisation to complete another questionnaire?
Sector or education-focused certificationProvides certification and preparation tailored to sector technology, procurement routes or shared servicesDoes sector experience improve the assessment without creating unsupported assumptions about the organisation’s own scope?
Certification with Cyber Advisor supportCombines an IASME Certification Body with NCSC-assured advisory help for SMEs needing practical control implementationWhich company provides the advice, which provides certification and how are conflicts and charges managed?
Requirements To Compare

Eight Areas That Determine Certification Readiness

Use the same scope and control evidence for every provider so fast-certification claims do not hide unsupported software, cloud accounts or incomplete device inventories.

01

Comparison Criterion

Firewalls And Internet Gateways

Confirm every boundary between in-scope devices and the internet, including routers, host firewalls and cloud controls. Review default credentials, inbound services, administrative access, approved rules and removal of unnecessary exposure. The Plus audit may test gateways and internet-facing services.

02

Comparison Criterion

Secure Configuration

Compare how the provider helps identify default accounts, unnecessary software, insecure services, weak settings, browser configuration and avoidable administrative access. Require a process that can be maintained across new devices and cloud services rather than one-off screenshots.

03

Comparison Criterion

Security Update Management

All in-scope software must remain supported. Under the current v3.3 requirements, high-risk or critical security updates and vulnerability fixes for operating systems, router or firewall firmware and applications must be installed within 14 days. The provider should verify inventory, ownership and exceptions before submission.

04

Comparison Criterion

User Access Control And MFA

Review account approval, unique identities, least privilege, administrator separation, leaver processes and authentication. MFA is mandatory for cloud services where it is available under the current requirements, including where a paid option must be enabled. Shared or unmanaged cloud accounts commonly create failure risk.

05

Comparison Criterion

Malware Protection

Assess anti-malware, application allow-listing, application sandboxing or other accepted protection methods across supported devices. Confirm central management, update health, mobile and non-Windows coverage, exclusions and how the organisation demonstrates that protections are active.

06

Comparison Criterion

Scope, Legal Entities And Cloud Services

Define every legal entity, business unit, location, device population, internet service and cloud service included. Cloud services processing or storing organisational data cannot simply be ignored. Exclusions require justification and effective separation from the certified scope.

07

Comparison Criterion

Verified Self-Assessment And Declaration

Compare portal usability, question guidance, assessor feedback, response time and evidence expectations. A board member or director signs the declaration, confirming that answers are accurate and acknowledging responsibility to maintain the controls during the certification period.

08

Comparison Criterion

Cyber Essentials Plus Technical Audit

Review discovery, external and internal testing, random device sampling, gateway testing, server checks, update verification, malware-protection tests, retest rules and operational preparation. The verified self-assessment must be final before Plus testing begins.

Certification Evidence

Measures To Define Before Buying A Certification Package

Translate fast, supported and audit-ready into measurable scope, control, timetable and ongoing-compliance outcomes.

MeasureWhat It Should DefineEvidence To RequestCommon Weakness
Scope reconciliationWhether every declared legal entity, device, network, cloud service and internet gateway is represented accuratelyAsset, identity, cloud and network inventories; exclusions; separation; owner; last reviewThe assessment uses an old device list that excludes remote workers and newly adopted SaaS services
Supported-software complianceWhether every in-scope operating system, application, browser, firmware and security product is supported on the certificate dateProduct, version, support status, end date, owner, upgrade and approved exceptionA legacy application is kept in scope even though the operating system is no longer supported
Critical-update complianceWhether high-risk and critical fixes are applied within the required 14-day periodRelease date, risk rating, applicable assets, installation date, failure, owner and completion evidenceThe organisation patches sampled devices but cannot prove consistent deployment across the scope
Cloud MFA coverageWhether MFA is enabled for every user of every in-scope cloud service where it is availableCloud-service register, users, MFA method, exceptions, paid feature, enforcement and monitoringMicrosoft 365 is protected while smaller SaaS accounts continue using passwords only
Administrative-access controlWhether privileged accounts are separate, limited, approved and reviewedAdministrator list, business need, unique account, authentication, review, leaver and dormant accountDaily email and web browsing are performed through unrestricted administrator accounts
Assessment return qualityWhether answers are complete, consistent and supported by the actual infrastructureAssessor queries, returned questions, corrections, evidence, declaration and final approvalConsultancy text is copied into the portal without the organisation verifying that it is true
Plus audit readinessWhether the declared scope can be sampled and technically verified without last-minute selective remediationDevice population, sample, gateways, servers, scans, test accounts, support contacts and readiness reviewOnly the expected sample devices are updated before the Plus audit
Certification timetableWhether readiness, assessment, remediation and Plus audit complete before a tender or renewal deadlineMilestones, account expiry, assessor response, audit date, retest date, dependencies and ownerThe business purchases certification shortly before a bid closes and discovers unsupported software
Annual control maintenanceWhether the five controls remain in place after the certificate is issuedMonthly asset, update, access and malware checks; change process; control owner; renewal readinessCertification becomes a once-a-year project rather than an operational baseline
Total certification costThe complete official assessment, support, remediation, Plus audit, retest and internal-effort costOrganisation size, official fee, package, consultancy hours, audit, travel, retest, tools and renewalA low assessment price is compared with a package that includes extensive technical remediation
Provider Comparison

Cyber Essentials Certification Providers UK Businesses Can Consider

Shortlist IASME-licensed Certification Bodies whose support, Plus audit capability and timetable fit the organisation. Confirm current licensing, package details and pricing directly before purchase.

01

Provider Profile

CyberSmart

IASME Certification Body offering Cyber Essentials and Cyber Essentials Plus through a digital platform, with package options that can combine assessment, guided support, device monitoring and renewal assistance. Include CyberSmart where an SME values an online certification journey and a wider compliance platform. Confirm the exact official assessment fee within the package, support level, organisation-size limits, device software, Plus audit method, remediation boundaries, response times, renewal pricing and whether monitoring remains optional after certification.

Review official CyberSmart certification
02

Provider Profile

GRC Solutions

GRC Solutions, formerly IT Governance Ltd, is a long-established Cyber Essentials Certification Body offering assessment-only, supported and combined Cyber Essentials Plus packages through its certification portal. Include it where a business wants fixed package options, assessor guidance and access to broader governance expertise. Confirm the exact current brand and contracting entity, official fee, included one-to-one support, Plus audit, retest, portal access, standard renewal price, technical remediation and any optional toolkit or consultancy.

Review official GRC Solutions certification
03

Provider Profile

Cyber Tec Security

UK Certification Body focused strongly on Cyber Essentials, Cyber Essentials Plus and practical readiness support, with packages for certification, renewal and related cyber improvement. Include Cyber Tec Security where a business wants specialist attention and support through the current question set and Plus audit. Confirm assessment and consultancy separation, scope workshop, technical remediation, audit location, retest allowance, response times, supported organisation complexity, renewal process and whether product or managed-security services are optional.

Review official Cyber Tec certification
04

Provider Profile

Citation Cyber

Citation Cyber provides Cyber Essentials and Cyber Essentials Plus certification with online purchasing and optional support, alongside wider security testing and consultancy. Include it where an SME wants a direct certification route and the option to add technical assistance. Confirm the official organisation-size fee, current package price, included assessor help, Plus audit, retesting, remediation, portal ownership, turnaround claims, renewal, contracting entity and the boundary from broader Citation services.

Review official Citation Cyber certification
05

Provider Profile

Assure Technical

IASME Certification Body offering Cyber Essentials, supported turnkey options and Cyber Essentials Plus audits, with pragmatic technical advice and package-specific support. Include it where a business wants hands-on scope and readiness help before submission. Confirm official fees, consultant hours, assessor independence, whether the provider completes questionnaire content or guides the applicant, Plus audit price, free-retest terms, onsite requirements, remediation responsibilities and annual renewal support.

Review official Assure Technical certification
06

Provider Profile

URM Consulting

Certification Body offering several Cyber Essentials support levels aligned to the current Danzell question set, plus Cyber Essentials Plus technical audits and pre-assessment assistance. Include URM where an organisation values structured scope verification, assessor access and a clear route from assessment to Plus. Confirm the selected package, support hours, scope workshop, official fee, audit scheduling, sample preparation, retest terms, remediation advice, data handling, renewal and the separation from other URM assurance services.

Review official URM certification
07

Provider Profile

WorkNest Secure

Current Cyber Essentials Certification Body formed from established UK security and compliance businesses, offering Cyber Essentials and Plus packages with consultancy support, policy documentation and retest allowances. Include WorkNest Secure where a business wants a packaged route with hands-on preparation. Confirm the current legal entity, package inclusions, assessor team, support hours, official fee, GuardNest portal use, Plus audit, retests, technical remediation, terms for audit evidence, renewal and continuity from legacy provider brands.

Review official WorkNest Secure certification
08

Provider Profile

Jisc Cyber Essentials

Jisc provides Cyber Essentials certification, renewal and preparation services focused particularly on education, research and public-sector technology environments. Include Jisc where an eligible member or sector organisation values familiarity with shared education infrastructure and sector support. Confirm customer eligibility, assessment and Plus availability, official fees, preparation services, assessor response, training charges, audit scheduling, cloud and network scope, renewal and whether broader Jisc services are required or independently optional.

Review official Jisc certification
Provider-profile rule: these profiles describe relevant comparison positions, not a universal ranking. Verify every provider through the current IASME network directory, review the provider evaluation approach, then score the service against your own scope, readiness, audit and deadline requirements.
Pricing Factors

What Changes Cyber Essentials Certification Cost

The official standard assessment fee is transparent, but support, remediation and Cyber Essentials Plus auditing can materially change the complete budget.

Cost DriverWhy It Changes SpendWhat A Comparable Proposal Should Show
Official Cyber Essentials assessmentThe standard verified self-assessment fee is tiered by organisation size rather than chosen freely by the providerMicro 0–9 employees: £320 + VAT; small 10–49: £440 + VAT; medium 50–249: £500 + VAT; large 250+: £600 + VAT
Guidance and assessor supportProviders add different levels of portal help, calls, question review, evidence guidance and resubmission supportIncluded hours, response target, named contact, channels, excluded technical advice and additional hourly rate
Scope discovery and readiness reviewComplex legal entities, cloud services, remote work, BYOD and segregated environments require additional analysisWorkshops, asset reconciliation, scope description, exclusions, legal entities, deliverables and customer tasks
Technical remediationUnsupported software, missing MFA, patching, firewall, account and malware-protection gaps may require engineering before assessmentExact changes, tools, licences, hours, supplier dependencies, testing, evidence and work excluded from the package
Cyber Essentials Plus auditPlus pricing is quoted individually because device numbers, gateways, servers, locations and complexity influence audit effortCertified scope, sample population, remote or onsite method, audit days, travel, testing, report, retest and deadline
Retesting and failed assessmentThe verified self-assessment provides a limited correction period, while Plus audit retest rules and provider packages varyCorrection window, assessor remark, included retest, new sample, failed retest, rescheduling and reapplication charges
Multiple legal entities and certificatesThe 2026 scheme supports clearer legal-entity identification and additional entity certificates within a wider certified scopeEntities, scope relationship, certificate count, additional certificate charge, ownership and procurement need
Tools, monitoring and policy templatesSome providers bundle device agents, compliance dashboards, policies, awareness or monitoring that are not part of the official assessment feeOptional or mandatory status, users, devices, term, renewal, ownership, cancellation and value after certification
Travel and onsite auditCyber Essentials Plus can be delivered remotely or onsite, but premises, equipment and specialist environments may add costLocations, travel, expenses, onsite days, access, sampling constraints and cancellation terms
Annual renewal and price changeCertificates expire after 12 months and the organisation must complete a new assessment using the current question setRenewal reminder, preparation, official fee, support price, uplift, Plus renewal, data reuse and cancellation
Budgeting rule: separate the official IASME assessment fee from provider support and technical work. Compare the full cost to reach a valid certificate, including remediation, Plus auditing, retesting and annual renewal.
Business Fit

How Readiness And Assurance Change The Shortlist

The right provider depends on current compliance, infrastructure complexity, certification deadline and whether independent technical verification is required.

Micro Business Already Meeting The Controls

Prioritise an assessment-only or light-support route, transparent official pricing, fast assessor communication and no compulsory software subscription.

SME Needing Practical Readiness Help

Prioritise scope workshops, asset and cloud-service reconciliation, direct technical guidance, clear remediation boundaries and a package that does not promise a pass without evidence.

Business Requiring Cyber Essentials Plus

Prioritise Certification Body capability for both levels, audit availability within three months, device-sample preparation, gateway and server testing, retest terms and operationally safe scheduling.

Education Or Complex Multi-Entity Organisation

Prioritise sector experience, legal-entity handling, detailed scope descriptions, cloud and shared-service understanding, multiple locations, structured evidence and predictable annual renewal.

How To Compare Certification Proposals

Give every provider the same employee count, legal entities, business units, locations, devices, networks, gateways, servers, cloud services, BYOD, remote-working model, current controls, Plus requirement and deadline. Require each quote to separate official fees, support, remediation and audit work.

  • Current IASME Certification Body status is independently verified
  • The proposed scope includes every relevant legal entity and cloud service
  • Official fees and provider-added services are itemised separately
  • Unsupported software, MFA and update gaps are identified early
  • Plus audit sampling, timing and retesting are explicit
  • Renewal, data export and cancellation terms are covered

Make Every Provider Review The Same Scope

Give each finalist the same device inventory, cloud-service register, legal entities, remote-working design, network boundaries and unsupported-software list.

Compare the questions they identify, the remediation they separate and the certificate scope they recommend before comparing package price.

Quote Questions

Six Questions To Put To Every Certification Provider

The answers expose unlicensed intermediaries, incomplete scope, hidden consultancy charges and unrealistic certification deadlines before purchase.

01

Are You Currently Licensed By IASME?

Verify the organisation in the current IASME network directory and confirm whether it can deliver Cyber Essentials, Cyber Essentials Plus or both.

02

What Exactly Is Included In The Quoted Price?

Separate the official assessment, assessor support, scope review, consultancy, technical remediation, Plus audit, travel, retesting, tools and renewal.

03

How Will You Validate Our Certification Scope?

Ask how the provider reconciles legal entities, devices, BYOD, remote workers, cloud services, gateways, servers, exclusions and segregated networks.

04

Who Is Responsible For Making Technical Changes?

Confirm whether the provider only advises, performs remediation, coordinates an IT supplier or requires the customer to implement and evidence every change.

05

Can You Meet Our Plus Or Tender Deadline?

Request milestones for readiness, assessment submission, assessor feedback, certificate issue, Plus audit, remediation, retest and contingency.

06

What Happens At Renewal Or Exit?

Confirm annual preparation, current-question changes, records reuse, portal access, device software, subscription cancellation, data export and provider transfer.

Selection Process

A Seven-Stage Cyber Essentials Certification Process

Move from a verified business scope to maintained annual compliance rather than purchasing an assessment account before identifying control gaps.

  1. Confirm the commercial, contractual or risk reason for certification, the required level, the deadline and the accountable board or director sponsor.
  2. Inventory legal entities, business units, devices, networks, gateways, servers, cloud services, remote workers, BYOD and software support status.
  3. Assess the five technical controls against the current v3.3 requirements, including cloud MFA and 14-day high-risk or critical update requirements.
  4. Issue one written brief and obtain comparable official-fee, support, remediation, Plus audit, retest and annual-renewal proposals.
  5. Complete readiness work, approve the final scope, preserve evidence and ensure the declaration accurately reflects the organisation's real controls.
  6. Submit the verified self-assessment, respond to assessor questions and, where required, complete Cyber Essentials Plus within the permitted period.
  7. Maintain the five controls, review changes and prepare for recertification before the 12-month certificate expires.
Risk Control

Cyber Essentials Certification Comparison Checklist

Use this table before purchasing an assessment, supported package or Cyber Essentials Plus audit.

No.RequirementEvidence To Obtain Before AwardConfirmed
01Certification objective, level and deadline agreedTender, supply chain, customer, insurer or baseline requirement; Cyber Essentials or Plus; owner and date
02Current IASME Certification Body verifiedNetwork-directory record, certification levels, contracting entity, assessor access and service contact
03Legal entities and business scope confirmedEntity names, company numbers, addresses, business units, locations and certificate requirements
04Device and network inventory reconciledLaptops, desktops, servers, mobile, BYOD, routers, firewalls, virtual devices, owners and support status
05Cloud-service register completedSaaS, PaaS, IaaS, users, administrators, data, MFA, ownership and services that cannot be excluded
06Firewalls and gateways reviewedInternet boundaries, rules, inbound services, administration, defaults, remote access and change ownership
07Secure configuration evidencedAccounts, services, software, settings, browsers, device builds, administrator use and repeatable baseline
08Update management meets v3.3Supported software, risk classification, high-risk and critical fixes within 14 days, failures and evidence
09User access and cloud MFA compliantUnique accounts, approval, least privilege, administrator separation, leavers, MFA availability and enforcement
10Malware protection verifiedProtection method, supported devices, central management, health, updates, exclusions and evidence
11Assessment support and remediation separatedOfficial fee, assessor help, consultancy hours, technical changes, tools, customer tasks and extra rates
12Board or director declaration preparedNamed signatory, answer verification, control ownership and acknowledgement of continuing compliance
13Cyber Essentials Plus plan acceptedPrerequisite certificate, three-month timing, device sample, gateways, servers, audit, retest and operations
14Complete certification cost comparedOfficial assessment, support, remediation, Plus, travel, retest, tools, internal effort and renewal
15Annual maintenance and renewal assignedAsset, update, access and malware reviews, scheme changes, renewal date, records and accountable owner
Buying Mistakes

Common Cyber Essentials Certification Mistakes

Most avoidable failures begin with an inaccurate scope, unsupported software, missing cloud MFA or a package comparison that mixes official fees with consultancy.

MistakeWhy It Creates RiskBetter Control
Buying from an unverified intermediaryA reseller may offer support but cannot independently issue the certificateVerify the licensed Certification Body
Comparing package price without separating the official feeAssessment, consultancy, software and Plus audit become impossible to compareRequire itemised pricing
Using an incomplete device or cloud inventoryThe declared scope does not reflect the organisation’s actual infrastructureReconcile assets, identities and cloud services
Excluding cloud services for convenienceCurrent requirements place organisational cloud services in scopeMap shared responsibility and apply controls
Keeping unsupported software in scopeUnsupported operating systems or applications cause assessment failureUpgrade, replace or redesign the scope legitimately
Treating MFA as optional for smaller SaaS servicesCloud services where MFA is available can create an automatic failureEnforce MFA across the complete cloud register
Patching only shortly before assessmentThe organisation cannot demonstrate a maintained 14-day processOperate measured update management throughout the year
Copying consultant answers without verificationThe signed declaration may not match the real environmentValidate every answer with accountable owners
Booking Plus without readiness or timeSampling and retesting can miss the three-month progression windowComplete a readiness review and contingency plan
Treating the certificate as permanentCertification expires after 12 months and requirements can change annuallyMaintain controls and plan recertification
FAQs

Frequently Asked Questions

Answers to common questions from UK businesses comparing Cyber Essentials and Cyber Essentials Plus certification providers.

What Is Cyber Essentials Certification?

Cyber Essentials is the UK Government-recommended minimum cyber security standard. It assesses five technical control themes: firewalls, secure configuration, security update management, user access control and malware protection. The standard certificate is issued after a qualified assessor verifies the organisation's self-assessment.

What Is The Difference Between Cyber Essentials And Cyber Essentials Plus?

Both levels use the same technical requirements. Cyber Essentials is a verified self-assessment, while Cyber Essentials Plus adds an independent technical audit of a representative sample of devices, internet gateways and relevant internet-facing servers. Plus provides a higher level of assurance.

Who Can Issue A Cyber Essentials Certificate?

A qualified Cyber Essentials assessor working for an IASME-licensed Certification Body can assess the submission and issue the certificate. Businesses should verify the proposed provider through the current IASME network directory rather than relying only on a reseller or consultancy claim.

How Much Does Cyber Essentials Cost In 2026?

The official Cyber Essentials assessment costs £320 plus VAT for 0–9 employees, £440 for 10–49, £500 for 50–249 and £600 for 250 or more. Provider guidance, technical remediation and Cyber Essentials Plus audits cost extra and should be itemised separately.

How Long Does Cyber Essentials Certification Take?

A prepared organisation may complete the questionnaire quickly, and assessors generally aim to return an initial result within a few working days. The complete timetable depends on scope, unsupported software, cloud MFA, patching, assessor questions and remediation. The assessment account normally remains available for six months.

How Long Is Cyber Essentials Certification Valid?

Cyber Essentials and Cyber Essentials Plus certificates are valid for 12 months. Organisations must recertify annually using the current requirements and question set. The signed declaration also confirms responsibility for maintaining the controls throughout the certification period.

What Changed In Cyber Essentials In April 2026?

Version 3.3 strengthened scope transparency, legal-entity information, cloud-service definitions, MFA and security-update requirements. MFA is mandatory for cloud services where available, and high-risk or critical fixes for operating systems, firmware and applications must be installed within 14 days.

Can Cloud Services Be Excluded From Cyber Essentials?

Cloud services that store or process organisational data or services are within the assessment responsibility and cannot simply be ignored. The cloud provider may implement some controls, but the applicant must understand shared responsibility, manage accounts and ensure the relevant Cyber Essentials requirements are met.

Does Cyber Essentials Plus Include A Penetration Test?

No. The Plus audit uses technical tests to verify the Cyber Essentials controls, including scans and sampling, but it is not a broad penetration test of business logic, attack paths or every application. A separate penetration test has a different scope and purpose.

How Should A UK Business Compare Cyber Essentials Providers?

Give every provider the same organisation size, legal entities, devices, cloud services, scope, control gaps, Plus requirement and deadline. Compare IASME licensing, official and added fees, support, remediation boundaries, audit availability, retesting, renewal and provider transfer.

Official Scheme And Certification-Provider Resources

Reviewed by Bhav Giva, Founder & Lead Analyst at CompareServices.co.uk, on 16 July 2026.

Use NCSC, IASME and official provider documentation to confirm the current requirements, question set, Certification Body status, Plus audit capability, support and pricing. The scheme is reviewed annually and provider packages can change.

  1. NCSC — Cyber Essentials Overview
  2. NCSC — Cyber Essentials Requirements And Resources
  3. IASME — Cyber Essentials Frequently Asked Questions
  4. IASME — Find A Certification Body
  5. IASME — Preview The Self-Assessment Questions
  6. CyberSmart — Cyber Essentials
  7. GRC Solutions — Cyber Essentials
  8. Cyber Tec Security — Cyber Essentials
  9. Citation Cyber — Cyber Essentials
  10. Assure Technical — Cyber Essentials
  11. URM Consulting — Cyber Essentials
  12. WorkNest Secure — Cyber Essentials
  13. Jisc — Cyber Essentials