Cyber Essentials

Get Cyber Essentials certified without the hassle.

From £320 + VAT

The UK government-backed scheme covering the five technical controls that stop the large majority of common internet-based attacks. You complete the verified self-assessment, we review your responses against the standard, and we certify you ourselves.

Fixed price, no surprises Reviewed and certified by us Plain-English support
Fixed price, by organisation size

What Cyber Essentials costs

One fixed fee, based on how many employees your organisation has. No scoping call needed to get a number.

Micro

1-9 employees

£320

+ VAT, fixed price

Get a quote
Small

10-49 employees

£440

+ VAT, fixed price

Get a quote
Medium

50-249 employees

£500

+ VAT, fixed price

Get a quote
Large

250+ employees

£600

+ VAT, fixed price

Get a quote

Prices shown are for Cyber Essentials. Cyber Essentials Plus is quoted per environment once we know your scope. Ask us if you're not sure which band applies to you.

The credential customers expect

Prove the basics are covered.

Cyber Essentials is increasingly expected by customers, insurers and public-sector tenders, and the NCSC recommends it as the minimum baseline cyber security standard for organisations of all sizes, from small businesses and SMEs to large enterprises. It's a clear, recognised signal that your organisation has the fundamentals in place.

You complete the verified self-assessment questionnaire; we do the rest. Our own assessor reviews your responses for gaps against the standard, gives you the chance to remediate anything that falls short, and, because we're an IASME-appointed Cyber Essentials Certification Body, certifies you and issues your certificate in-house. One supplier, no middleman.

We hold it ourselves, too. Plainsight Security is Cyber Essentials Plus and IASME Cyber Assurance Level 2 certified.

The five controls

What's assessed

  • Firewalls and internet gateways
  • Secure configuration
  • User access control
  • Malware protection
  • Security update management
Start your certification
How it works

A frictionless route to certification

  1. You complete the self-assessment

    You work through the verified self-assessment questionnaire covering the five controls.

  2. We review your responses

    We check your answers for gaps against the standard. If anything falls short, you get the chance to remediate before we proceed.

  3. We certify you

    As a Cyber Essentials Certification Body, we certify you as compliant and issue your certificate ourselves.

Common questions

Cyber Essentials, answered.

How do I get Cyber Essentials certified?

Request a quote and we will confirm your fixed price within one working day. You then work through the verified self-assessment questionnaire at your own pace, covering the five technical controls. We review your responses against the standard and tell you plainly if anything needs fixing before you resubmit. Once you pass, we certify you ourselves, as an IASME-appointed Cyber Essentials Certification Body, and issue your certificate the same day. It is valid for twelve months.

How much does Cyber Essentials certification cost?

Cyber Essentials starts from £320 + VAT as a fixed price, with no hidden extras. Cyber Essentials Plus is quoted per environment, because the cost depends on the number of devices and users in scope. Ask for a quote and we will come back within one working day with a clear figure.

How long does Cyber Essentials certification take, and how quickly can I get certified?

You complete the self-assessment at your own pace, so there is no waiting on us until you submit. Once you do, we review your responses within two working days and, on a pass, issue your certificate the same day, so the fastest realistic route is a matter of days if your organisation already meets the standard. The certificate is valid for twelve months, after which you recertify.

How hard is it to get Cyber Essentials?

It depends on where your organisation starts from. If you already run supported software, keep devices patched and control user access sensibly, most organisations pass comfortably. The controls that trip people up most often are missing security updates, weak password or multi-factor authentication policy, and unsupported operating systems still in use. If your review flags a gap, we tell you exactly what to fix in plain English and give you the chance to remediate before we proceed, so a shaky first attempt is rarely the end of the story.

Is Cyber Essentials certification worth it?

For most UK organisations, yes. It is increasingly expected in contracts, tenders and insurance applications, and the NCSC recommends it as the minimum baseline cyber security standard because the five controls address the large majority of common internet-based attacks. It will not stop every attack on its own, but it closes off the gaps that opportunistic attackers rely on, and it gives customers a recognised, independently reviewed signal that the basics are covered.

Is Cyber Essentials the same as ISO 27001?

No, they cover different things. Cyber Essentials is a focused, five-control technical baseline, verified through a self-assessment questionnaire that we review and certify, typically completed in days. ISO 27001 certifies an entire information security management system, covering policies, risk management and governance as well as technical controls, and is assessed through an external audit that usually takes months, with ongoing surveillance audits afterwards. Many organisations use Cyber Essentials as the quick, practical baseline and work towards ISO 27001 later as their security governance matures.

What does the Cyber Essentials assessment cover?

The assessment checks five technical controls: firewalls and internet gateways, secure configuration, user access control, malware protection, and security update management. Together these stop the large majority of common internet-based attacks.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a verified self-assessment that we review and certify. Cyber Essentials Plus adds a hands-on technical audit, where a tester checks that the controls you have described actually hold up in practice. Many organisations start with Cyber Essentials and move to Plus when a customer or tender requires it.

Who assesses and certifies my Cyber Essentials application?

We do, in-house. As an IASME-appointed Cyber Essentials Certification Body, your answers are reviewed against the standard by our own assessor and certified by us, rather than passed to a third party. One supplier, no middleman.

Is Cyber Essentials suitable for small businesses and SMEs?

Yes. Cyber Essentials is designed to be achievable for small businesses and SMEs, not just large enterprises, and the NCSC recommends it as the minimum baseline cyber security standard for organisations of all sizes. It is often the credential smaller firms need to win contracts or satisfy insurers, and we keep the process plain-English and fixed-price so there are no surprises.

How do we prepare for Cyber Essentials, and how do we know if we are ready?

The quickest way to gauge readiness is our free Cyber Essentials readiness checklist, which walks through what each control expects. If anything falls short during our review, we tell you plainly and give you the chance to remediate before we proceed, so preparation and support are built into the process.

What happens if we do not pass first time?

Nothing dramatic. If your responses fall short of the standard, we explain exactly what needs to change in plain English and let you fix it, then recheck. The aim is to get you certified, not to catch you out.

Not sure where to start? Download our free Cyber Essentials readiness checklist.

Get a quote

Get your fixed price for Cyber Essentials

A couple of details is all we need. We'll reply within one working day with a clear, fixed price and the next steps.