Menu
PricingHow We Work
Resources

020 7100 5284

Book a Consultation

HOW WE WORK

A structured, transparent process from first conversation to certificate — and beyond.

01

Discovery

We begin with a working conversation to understand your organisation, technology environment, and certification objectives. This typically takes 30–60 minutes and covers the systems you use, the data you handle, and any contractual or compliance drivers behind your certification requirement.

We assess your current security posture at a high level and identify the certification pathway that fits your needs — whether that is Cyber Essentials, Cyber Essentials Plus, IASME Cyber Assurance, or a combination.

By the end of the discovery call, you will have a clear recommendation, an honest assessment of your readiness, and a transparent cost estimate.

What you experience

  • No-pressure working conversation
  • Honest assessment of your current readiness
  • Clear recommendation on certification pathway
  • Transparent cost estimate before any commitment
Typical duration

30–60 minutes

02

Gap Assessment

We evaluate your existing controls against the specific requirements of your target certification. For Cyber Essentials, this means assessing your implementation of the five technical controls: firewalls, secure configuration, access control, malware protection, and security updates.

For IASME Cyber Assurance, we assess across all 14 security themes including governance, risk management, incident response, and supplier management.

The output is a gap assessment report that documents what is already in place, what is missing or misconfigured, and what needs to change before you can pass assessment.

What you experience

  • Clear picture of your current posture
  • No surprises during formal assessment
  • Prioritised list of gaps to address
  • Realistic timeline for remediation
Typical duration

1–5 days depending on environment complexity

03

Remediation

Based on the gap assessment, we work with you to close identified gaps. This may involve guided self-service — where your team implements changes with our direction — or hands-on technical remediation where our practitioners configure systems directly.

We implement controls across your actual technology stack: Microsoft 365, Google Workspace, AWS, Azure, on-premise infrastructure, or hybrid environments. Our approach adapts to what you have, not what we prefer.

Throughout remediation, we document evidence that will be required for assessment. You enter the formal certification process with controls in place and evidence ready.

What you experience

  • Controls implemented correctly the first time
  • Evidence documented as we work
  • Your team understands what has changed
  • Ready for assessment with confidence
Typical duration

Varies — 1 day to several weeks depending on gap depth

04

Assessment & Submission

For Cyber Essentials and IASME Cyber Assurance, we guide you through questionnaire completion, review your responses and evidence before submission, and manage the formal assessment process.

For Cyber Essentials Plus, we coordinate external vulnerability scanning of your in-scope systems and conduct hands-on technical testing of devices, configurations, and controls. This includes independent assessor testing and detailed audit reporting.

We handle communication with IASME and manage the certification timeline. If any issues arise during assessment, we support you through remediation and resubmission.

What you experience

  • Managed process from start to finish
  • No unexpected findings during audit
  • Clear communication throughout
  • Single point of contact for all certification matters
Typical duration

CE: 1–2 days | CE Plus: 1 week including testing window

05

Certification & Beyond

On successful assessment, your certificate is issued and you receive your official certification badge for use in tender documents, marketing materials, and client communications.

For eligible organisations, your Cyber Essentials certification activates £25,000 cyber liability insurance coverage. We explain the terms and help you understand what is covered.

Certification is valid for 12 months. We provide renewal planning guidance and can support you through annual recertification. For organisations that want ongoing assurance, we offer vulnerability scanning and posture maintenance services.

What you experience

  • Certificate and badge issued promptly
  • Insurance activation for eligible organisations
  • Clear understanding of renewal requirements
  • Ongoing support available if needed
Typical duration

Certificate issued within 24 hours of successful assessment

FREQUENTLY ASKED QUESTIONS

Common questions about the certification process.

Standard certification with readiness support typically takes 2–4 weeks from initial discovery to certificate issuance. This includes gap assessment, remediation, and formal assessment. Fast Track is available for organisations with urgent requirements — contact us to discuss your timeline.

Yes. Cyber Essentials is a prerequisite for Cyber Essentials Plus and IASME Cyber Assurance. The CE certificate must be current (within 12 months) at the time of your CE Plus audit. We can support you through both certifications in sequence.

Our readiness review is designed to identify gaps before submission, significantly reducing failure risk. If issues arise during assessment, we support you through remediation and resubmission at no additional assessment fee. Most failures we see come from organisations who attempted certification without prior readiness support.

Yes. We collaborate with internal IT teams and existing managed service providers. Our role is to assess, advise, and implement where needed — not to replace your existing relationships. We adapt to your organisational structure and work with whoever manages your technology environment.

We work across Microsoft 365, Google Workspace, AWS, Azure, hybrid environments, and on-premise infrastructure including Windows and Linux servers. Our approach is technology-agnostic — we adapt to your actual environment rather than requiring you to fit a particular vendor stack.

It is included with every Cyber Essentials certification for eligible organisations. Eligibility requires UK domicile, annual turnover under £20 million, and whole-organisation certification (not a subset of your business). The insurance is provided by IASME Consortium and activates automatically on certificate issuance.

Get Started

Start with a conversation.

Our initial consultation is a working call — typically 30 minutes — in which we understand your organisation, your certification objectives, and your current security posture.

30-minute call
Honest assessment
Clear pricing