Challenges we solve
Cyber Essentials certification protects your organisation and opens doors — but navigating the process alone can be daunting.
Vulnerable to common cyber threats
Without basic security controls in place, your organisation is exposed to the most common and preventable cyber attacks that target businesses of every size.
Compliance and contract requirements
Many government contracts and supply chains now require Cyber Essentials certification. Without it, you may be locked out of opportunities and unable to demonstrate due diligence.
Uncertainty about your security posture
You know you need to improve your cyber security, but you are not sure whether your firewalls, patching and access controls meet the required standard.
Navigating the certification process
The self-assessment questionnaire covers over 70 questions across five control themes. Getting expert guidance ensures you pass first time and avoid costly delays.
What is Cyber Essentials?
Cyber Essentials is a UK Government-backed certification scheme, overseen by the National Cyber Security Centre (NCSC) and delivered nationally by IASME, the scheme's official delivery partner. It sets out a baseline of security controls - covering firewalls, secure configuration, access control, malware protection and patch management - designed to protect organisations against the most common, opportunistic cyber-attacks.
Certification is increasingly a commercial requirement, not just a security best practice: many UK government contracts, public-sector tenders and enterprise supply chains now require suppliers to hold a current Cyber Essentials certificate before they can bid or trade.
Claranet Cyber Security is a licensed IASME Certification Body, authorised to certify organisations of any size against both Cyber Essentials (verified self-assessment) and Cyber Essentials Plus (independent technical audit). Our qualified assessors guide you through every step - from completing the self-assessment questionnaire to achieving certification.
For organisations that need a deeper level of assurance, Cyber Essentials Plus adds a technical audit including external and internal vulnerability scanning, MFA validation, and physical testing of end-user devices and infrastructure against the five key control themes.
Key Benefits
- UK government-backed certification scheme
- Protects against the most common cyber threats
- Required for many government and supply chain contracts
- Expert assessor guidance through the entire process
- Two certification levels: self-assessment and Plus
- Demonstrates your commitment to cyber security
Which certification do you need?
Cyber Essentials and Cyber Essentials Plus test the same five security controls, but at different levels of assurance. Most organisations start with Cyber Essentials; some are required - by a contract, a client, or their own risk profile - to go further with Cyber Essentials Plus.
| Cyber Essentials | Cyber Essentials Plus | |
|---|---|---|
| Assurance level | Verified self-assessment | Independent technical audit |
| How it works | You complete a self-assessment questionnaire; your assessor pre-checks and formally scores it | A hands-on technical audit, including vulnerability scanning and device testing, verifies the controls are actually in place |
| Typical for | Most SMEs, first-time applicants, lower-risk contracts | Organisations handling sensitive data, government/regulated-sector suppliers, or where a client mandates the higher level |
| What's checked | Your answers against the five control themes | External and internal vulnerability scanning, MFA validation, admin account separation, anti-malware testing, MDM review (where applicable) |
| Delivery | Remote, questionnaire-based | Remote or on-site |
Not sure which one applies to you? Talk to our Cyber Essentials specialist and we'll help you work out the right level before you start. If you have 250 or more employees, a different route into certification applies - see our guide to the Cyber Essentials Pathways for larger organisations.
Why Claranet?
The five control themes
Cyber Essentials certification is built around five fundamental security controls that every organisation should implement.
Firewalls
Boundary firewalls and internet gateways configured to protect your network
Secure Configuration
Devices and software configured to reduce vulnerabilities
Access Control
User accounts managed with appropriate access privileges
Malware Protection
Anti-malware defences for browsers, email and applications
Patch Management
Software and devices kept up to date with latest patches
Service Components
Comprehensive certification services delivered by qualified IASME assessors.
Verified self-assessment (CE)
Complete a 70+ question self-assessment questionnaire covering the five control themes. Your Claranet assessor pre-checks responses, provides guidance and formally scores the submission.
Technical audit (CE Plus)
Hands-on technical audit including external and internal vulnerability scanning, MFA validation, admin account separation checks, anti-malware testing and MDM review where applicable.
Assessor-guided process
A dedicated Claranet assessor supports you throughout — from account setup and questionnaire completion through marking, remediation guidance and formal certification.
Remediation support
If non-compliance is found during pre-check or technical audit, you receive a detailed report with guidance on what needs to change. Up to 30 days remediation window is provided.
Remote or on-site delivery
Cyber Essentials Plus technical audits can be delivered remotely or on-site, including physical assessment of end-user devices, servers, mobile phones and cloud services.
Certificate management
Your Claranet assessor manages your certificates through Blockmark, the IASME digital certificate management system, ensuring your certification is properly registered and maintained.
Cyber Essentials as part of a wider security strategy
Cyber Essentials sets a strong security baseline, but it's a starting point rather than a complete security programme. Many of our Cyber Essentials clients go on to strengthen their posture further with penetration testing, continuous vulnerability scanning, managed detection and response, or a wider compliance programme such as ISO 27001 - particularly where they handle sensitive data, operate in a regulated sector, or are building towards more demanding client and government requirements.
Explore our full range of cybersecurity services to see how Cyber Essentials fits alongside the rest of your security programme.
Accreditations & partnerships
Certified expertise you can trust.


Ready to get certified?
Talk to a licensed IASME assessor about whether Cyber Essentials or Cyber Essentials Plus is right for your organisation, and what's involved in getting there.
Talk to a Cyber Essentials specialist
Or call us on 0330 390 0507
Frequently asked questions
-
Cyber Essentials is a verified self-assessment — you answer a questionnaire and your assessor checks and scores it. Cyber Essentials Plus adds an independent technical audit, including vulnerability scanning and device testing, to verify the same controls are genuinely in place.
-
It's not mandatory for every UK organisation, but it is required for many government contracts involving sensitive or personal data, and it's increasingly requested by supply chains and enterprise clients as a condition of doing business.
-
Cyber Essentials typically takes a few days to a few weeks from starting the self-assessment questionnaire to certification, depending on how quickly any required changes can be made and how promptly your team can respond to assessor feedback.
Cyber Essentials Plus takes longer, because it adds an independent technical audit on top of the verified self-assessment. From April 2026, the scheme also requires the Cyber Essentials self-assessment to be fully approved before Cyber Essentials Plus testing can begin — so build this into your timeline if you're working towards a contract deadline.
If gaps are found during the pre-check or technical audit, you'll receive a detailed remediation report, with up to 30 days to put fixes in place before re-assessment.
-
Certification is valid for 12 months, and renewal isn't a formality - you'll need to demonstrate that your controls are still in place, and the scheme's requirements are periodically updated, so processes that passed last year aren't guaranteed to pass again without review. From 27 April 2026, updated requirements apply to all new and renewing applications - including mandatory MFA on all cloud services (with automatic failure if MFA is available but not enabled) and a stricter 14-day window to apply critical and high-severity security updates. If you already hold a valid certificate, the update applies from your next renewal. Our assessors can help you prepare ahead of renewal, including a gap analysis against the current requirements and support with vulnerability scanning to evidence your patching processes.
Read our full breakdown of the April 2026 scheme changes for a detailed look at what's new and how to prepare or see our shorter guide to avoiding the most common Cyber Essentials renewal mistakes this year for a practical rundown. -
Cyber Essentials Plus includes external and internal vulnerability scanning as part of its technical audit. Standard Cyber Essentials doesn't formally require scanning, but from April 2026 the scheme's stricter 14-day patching requirement makes regular vulnerability scanning practically necessary to evidence compliance.
-
It depends on what's being asked of you contractually and how sensitive your data is. If a client, government contract or regulator specifies Cyber Essentials Plus, you'll need the technical audit; otherwise, standard Cyber Essentials is often the right starting point. Our assessors can help you confirm which applies to you.

