Cyber Essentials and Cyber Essentials Plus Certification
Get certified first time. As a Cyber Essentials Certification Body based in Livingston, we take Scottish and UK businesses from gap analysis to certificate, and carry out the hands-on Cyber Essentials Plus audit ourselves.
What is Cyber Essentials?
Cyber Essentials is the UK Government's baseline standard for cyber security, run by the National Cyber Security Centre and delivered through IASME. It is built around five technical controls that stop the vast majority of common, untargeted attacks. Certification is renewed annually and is increasingly required by public sector buyers, insurers and larger customers before they will trade with you.
The two levels of certification
Cyber Essentials
A verified self-assessment. You answer the questionnaire about your firewalls, device configuration, patching, user access and malware protection, and we review and verify your answers before the certificate is issued. Certificates are normally issued within a few days of a compliant submission.
Cyber Essentials Plus
The same five controls, independently tested. An assessor scans your internet-facing systems, runs authenticated vulnerability scans on a sample of your devices, and tests that malware sent by email and downloaded in the browser is blocked. It has to be completed within three months of your Cyber Essentials certificate.

Ready to get certified?
Speak to us about a gap analysis, a first-time certification, or an annual renewal. We will tell you honestly whether you are ready.
Start your applicationOr call 01506 533100
The five controls
Every question in the assessment maps back to one of these. If you have them in place across every device and cloud service in scope, you will pass.
Firewalls
A boundary firewall on your internet connection and a software firewall on every device, with default passwords changed and no unnecessary services exposed.
Secure configuration
Devices and cloud services set up securely: unused accounts and software removed, auto-run disabled, and device unlocking protected by a PIN, password or biometric.
Security update management
All software supported by its vendor and critical or high-risk updates applied within 14 days of release.
User access control
Named accounts for every user, admin rights kept separate from day-to-day accounts, and multi-factor authentication on all cloud services.
Malware protection
Anti-malware software on every device, or application allow-listing, kept up to date and configured to scan files and block known-malicious websites.
How certification works
Most of our clients certify within two to six weeks, depending on how much remediation is needed. You always know where you stand before the formal submission.
- 1
Scoping call
We agree what is in scope: which offices, devices, cloud services and home workers. Getting scope right at the start avoids surprises at the assessment stage.
- 2
Gap analysis
We check your environment against the current requirements and give you a plain-English list of what would fail and why.
- 3
Remediation
Fix the gaps yourself, or have us do it. Typical work includes enforcing MFA, removing local admin rights, retiring unsupported kit and tightening Microsoft 365.
- 4
Self-assessment
We help you complete the questionnaire accurately, then review and verify the submission. The Cyber Essentials certificate is issued on a pass.
- 5
Plus audit (optional)
If you are going for Cyber Essentials Plus, we book the technical audit within the three-month window, carry it out remotely, and issue the Plus certificate when the tests pass.
Transparent pricing
Fixed fees based on your organisation size. No hidden extras.
Cyber Essentials
Verified self-assessment
| Size | Price |
|---|---|
| Micro (0–9) | £320 |
| Small (10–49) | £440 |
| Medium (50–249) | £500 |
| Large (250+) | £600 |
Best for Organisations certifying for the first time, or meeting a contract or tender requirement that specifies Cyber Essentials.
EnquireCyber Essentials Plus
Technical verification audit
| Size | Price |
|---|---|
| Micro (0–9) | from £1,050 |
| Small (10–49) | from £1,250 |
| Medium (50–249) | from £1,450 |
| Large (250+) | from £1,650 |
Best for Existing Cyber Essentials holders ready to upgrade, or organisations whose contract specifies Plus.
About the Plus auditAll prices exclude VAT. Large (250+) priced per quote based on scope.
Who needs certification?
Public sector suppliers
Cyber Essentials is a condition of many central government, NHS, MOD and local authority contracts, especially where personal data is handled. Higher-risk contracts often specify Cyber Essentials Plus.
Supply chains
Larger customers increasingly ask for the certificate in supplier questionnaires. Having it ready shortens procurement and removes a reason to choose someone else.
Cyber insurance
Many insurers ask about Cyber Essentials on the proposal form, and some price against it. Certified organisations can also access the free cyber liability insurance included with certification for small organisations.
Any business that wants a baseline
The five controls block most of the incidents we are called in to clean up. Certification is the cheapest way to prove the basics are covered.
Certification from Livingston, for Scotland and the UK
We are based in Livingston, West Lothian. Everything is done remotely, from the self-assessment to the Cyber Essentials Plus audit, so we certify businesses across Edinburgh, Glasgow, Fife, Dundee, Aberdeen and the rest of the UK without anyone needing to travel.
Cyber Essentials in Scotland →Read before you apply
Compliance
Cyber Essentials in 2026: The Complete What-You-Need-To-Do Guide
A walkthrough of every technical control you need in place before you apply for Cyber Essentials, plus the CE Plus audit…
Compliance
Cyber Essentials v3.3: What Changed in 2026 and What Assessors Now Expect
The NCSC has published v3.3 of the technical requirements, applying to both Cyber Essentials and CE Plus from April 2026…
Insights
Is Cyber Essentials Worth It?
The short answer is yes, but not for the reasons most people quote. Here's what the badge actually gets you, and what it…
Frequently asked questions
What is Cyber Essentials?
Cyber Essentials is a UK government-backed certification that shows an organisation has the five core technical controls in place to defend against the most common cyber attacks. Cyber Essentials Plus adds an independent technical audit of those controls.
What's the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is a verified self-assessment: you complete the questionnaire and we review it as an accredited certification body. Cyber Essentials Plus covers the same five controls but adds a hands-on technical audit, where an assessor independently tests your systems to confirm the controls are working. The Plus audit must be completed within three months of the Cyber Essentials certificate.
Does my business need Cyber Essentials?
It is increasingly expected in supply chains and is mandatory to bid for many UK public sector contracts, particularly where personal data is involved. Beyond winning work, it gives you a recognised baseline of security and can help reduce cyber insurance premiums.
How much does Cyber Essentials certification cost?
Cyber Essentials is a fixed fee set by IASME: £320 for micro organisations (0 to 9 people), £440 for small (10 to 49), £500 for medium (50 to 249) and £600 for large (250+). Cyber Essentials Plus starts from £1,050 for micro organisations. All prices exclude VAT, and large organisations are quoted based on scope.
How long does Cyber Essentials certification take?
A prepared organisation can certify within one to two weeks. If remediation is needed, two to six weeks is typical. We run a gap analysis first so you know exactly what needs fixing before anything is submitted, which is how our clients pass first time.
How long is Cyber Essentials valid for?
Twelve months. Both Cyber Essentials and Cyber Essentials Plus are renewed annually against whatever the current version of the requirements is at the time. We keep track of the changes so your renewal is not a surprise.
Do you certify businesses outside Scotland?
Yes. Both the Cyber Essentials self-assessment and the Cyber Essentials Plus audit are carried out remotely, the audit over a screen-sharing session with a member of your team at each sampled device, so we certify organisations anywhere in the UK.
What happens if we fail?
For the self-assessment, you receive feedback on the non-compliant answers and there is a short window to fix them and resubmit. For the Plus audit, you get a list of the failed tests and we re-test those items once fixed. Our pre-checks are designed so that neither happens.
