Skip to main content
cyber essentials logo

Cyber Essentials Certification & Accreditation

Achieving cyber essentials certification can feel like a very technical process and can leave some businesses unsure where to start. At ComputerPro, we provide tailored solutions to support businesses throughout their journey, from preparation and remediation to certification and Cyber Essentials Plus.

or call 01869 352002 for a no-obligation chat

Why Cyber Essentials Matters for Your Business

Cyber Essentials is a certification that protects businesses against common, everyday cyber threats. As mentioned, it’s a government-backed scheme and is often a mandatory requirement for large organisations or those seeking government contracts to prove they have a minimum security standard. The scheme is an accessible one - in 2025, over 55,000 certificates were awarded.

It can have a range of benefits for businesses, including:

Check icon

Can build a good reputation with customers by showing that their data is being handled responsibly.

Check Icon

It can help businesses to win work, meet supplier requirements, and stand out ahead of competitors.

Check Icon

This is one of the most overlooked benefits of the scheme. When UK companies with an annual turnover under £20 million achieve Cyber Essentials certification for the whole organisation (not just a single department), they receive cyber liability insurance at no additional cost. Given that organisations with Cyber Essentials in place make 92% fewer cyber insurance claims, the financial case for certification is difficult to ignore.

shield Icon

What Cyber Essentials Covers

The Cyber Essentials assessment covers five areas of security measures, or “controls,” which all need to be satisfied to pass.

A firewall acts as a gatekeeper between your network and the internet, deciding what traffic is allowed in and out. Most devices and routers have one built in, but it needs to be switched on and properly configured.

If any of your team work from home or use laptops away from the office, those devices need to have their own firewall active too, not just the one sitting in your office.

This is about making sure your devices and software aren't left in the state they arrived in. Assessors want to see that unnecessary features and accounts have been disabled, and that every admin account has a strong, unique password. This includes your router, any networked printers, and other connected equipment.

Not everyone in your business needs the same level of access to your systems. This is about making sure staff can only access the files, software, and settings relevant to their role, and no more.

You’ll need to demonstrate a clear admin access process and a process for removing access promptly when someone leaves the company.

All company devices need up-to-date protection against malicious software, which includes viruses, ransomware, and other threats that can encrypt your files or steal your data. This applies to all devices, including any laptops your team uses at home or on the road.

Outdated software is one of the most common ways attackers get in. This control requires that all your software, operating systems, and firmware are kept current.

Our Cyber Essentials Services

At ComputerPro, we handle everything from start to finish. Whether you're going through the process for the first time or working towards Cyber Essentials Plus, we guide you through every step so you know exactly what is happening and why.

Check icon

Before anything else, we assess where your business currently stands against the five core Cyber Essentials controls.

This initial review gives us a clear picture of what is already in place and what needs attention. You will receive a straightforward action plan, with no jargon, so you understand what needs to change and how quickly it can be done.

Check Icon

Our Cyber Essentials audit and assessment covers your full IT environment, including devices, user accounts, software, network settings, and cloud services. We check everything against the certification requirements and identify any gaps before you submit.

We carry out a proper technical review so that by the time you submit your assessment, you can be confident it reflects your actual security posture rather than an educated guess.

Check Icon

We support you through the full certification submission process, helping you complete the self-assessment questionnaire accurately. Our job is to make sure nothing gets missed and that you pass first time.

Check icon

For businesses that need a higher level of assurance, or that are working with clients or government bodies requiring it, we also support Cyber Essentials Plus.

Cyber Essentials Plus involves a hands-on technical audit carried out by an external assessor, including vulnerability scanning and direct testing of your systems. We prepare your environment thoroughly beforehand so that the audit reflects the security controls you have put in place. We can also carry out a pre-assessment check to make sure you are ready before the formal audit takes place.

Check icon

The Cyber Essentials scheme was updated in April 2026, bringing in revised requirements around areas including cloud services and multi-factor authentication. If your business was previously certified or is starting the process now, we make sure your approach is aligned with the current scheme from the outset.

Cyber Essentials Certification Process

It shouldn’t be complicated to get Cyber Essentials certification. We break down the process into simple areas and support you every step of the way, so you know what’s happening and what’s coming next.

1. Initial Review

We assess your current IT environment to get a clear picture of where you stand. This includes looking at your devices, network, user accounts, software, and any cloud services your business uses. We map out what is in scope for certification and assess against the five core controls.

2. Identifying Gaps

After the review, we tell you what needs to change before you can certify - some businesses may be close while others may need a bit more work. Either way, you will receive a clear list of what needs fixing, with no ambiguity about what is required or why.

3. Fixing Issues

Where changes are needed, perhaps updating software or configuring devices correctly, we carry out the work alongside you and until everything is in order.

4. Completing Your Certification

Once the issues have been resolved, we support you through the self-assessment questionnaire and certification submission. We review your answers, make sure everything is accurate, and support any queries from the certifying body. Our aim is to get you to pass the first time.

5. Cyber Essentials Plus (Optional)

If your business needs or wants a higher level of certification, we can take you through Cyber Essentials Plus. This involves a hands-on technical audit by an external assessor, and we prepare your systems fully beforehand so the audit reflects the controls you have put in place.

Cyber Essentials Plus Certification & Audits

As mentioned above, Cyber Essentials Plus is a higher tier of certification, which goes further than the standard Cyber Essentials Scheme. In Cyber Essentials Plus, an independent assessor tests your systems directly, verifying that the security controls you have declared are genuinely in place and working as they should be.

Why Businesses May Need Cyber Essentials Plus

For some organisations, Cyber Essentials Plus is a requirement rather than a choice. Government contracts, Ministry of Defence supply chains, NHS procurement frameworks, and a growing number of private sector clients now specify it as a condition of doing business.

But beyond contractual requirements, there are good reasons to get this certification independently. Cyber Essentials Plus gives your stakeholders a higher level of confidence that your security controls have been independently verified. This distinction matters for businesses operating in the regulated sector or that handle sensitive data.

What the Audit Involves

The Cyber Essentials Plus audit is carried out by an external, accredited assessor. It includes vulnerability scanning of your external-facing systems, internal configuration checks across your devices and network, and testing of your malware protection and patch management controls. The assessor is checking that what you have put in place in practice matches what the certification requires.

How We Support You Through The Process

Before the audit, our role is to work with you well before it takes place to make sure your environment is genuinely ready.

That starts with a thorough internal review of your systems against the Cyber Essentials Plus requirements - where we find issues, we fix them.

And then, before the external audit, we carry out one of our own, which allows us to catch and resolve anything that causes a problem on the day.

Who Needs Cyber Essentials?

Many larger businesses and public sector organisations now ask their suppliers and partners to hold Cyber Essentials certification before they will work with them.

If your business handles sensitive data, Cyber Essentials gives you a recognised framework for protecting it.

Since 2014, certification has been a requirement for UK government contracts involving the handling of personal data or sensitive information.

Certification is a way for SMEs to get their security in order and demonstrate their credibility to clients.

Shield Icon

Why Choose ComputerPro

Check icon

Based in Bicester, we support businesses across Oxfordshire and the surrounding areas. Whatever support is needed, we come to you.

Check Icon

We understand the pressures that smaller businesses face, because we have been working with them for a long time.

Check Icon

Everything is explained in plain English. You will always know what’s happening and why.

Check Icon

We manage the process from start to finish, from your initial review through to certification.

Check Icon

The Cyber Essentials scheme is updated regularly, and our approach reflects the current requirements throughout.

Check Icon

We continue to support you after certification, helping you stay compliant and respond to any updates.

Ongoing Support & Maintaining Compliance

Cyber threats evolve, scheme requirements are updated, and your own IT environment will change as your business grows. Staying protected in the long-term means staying on top of these.

Cyber Essentials certification is valid for twelve months and needs to be renewed annually. The requirements are reviewed and updated by the scheme, which means recertification is not simply a repeat of what you did the year before. Controls that were in place last year may need to be revisited in light of new guidance or changes to your situation.

Businesses benefit from continued long-term support, and we support our clients through that ongoing process. We are here to support with whatever you need, such as preparing for annual recertification, or to provide reassurance that you are in line with current requirements.

For businesses that want a more comprehensive approach, our Cyber Essentials support sits naturally alongside our broader managed IT and cybersecurity services. That means your security controls, software patching, user access management, and monitoring can all be handled consistently, by a team that already knows your setup and keeps everything aligned.

The businesses that stay protected are the ones that treat security as an ongoing commitment. We help make that straightforward.

Cyber Essentials Support Across Oxfordshire

At ComputerPro, we make the Cyber Essentials process straightforward from initial audit through to certification and beyond.

Working across Oxfordshire, including areas such as Witney, Didcot, Abingdon and the city of Oxford, we work with you step by step, transparently, and make sure you are fully prepared at every stage.

Whatever stage of the process you’re at - starting from scratch or preparing for annual renewal - we are a team that knows how it works.

Book Your Cyber Essentials Support or call 01869 352002

Cyber Essentials FAQs


What is Cyber Essentials, and why does my business need it?

Cyber Essentials is a UK government-backed certification scheme that helps businesses protect themselves against common cyber threats. Achieving certification demonstrates that your basic security controls are in place, which builds client confidence, satisfies procurement requirements, and is a mandatory requirement for many government contracts. It is also increasingly expected by larger organisations when appointing suppliers. For SMEs looking to grow, win contracts, and demonstrate credibility, it is a practical and valuable step forward.

How long does it take to get Cyber Essentials certified?

Quicker than most businesses expect. With our structured approach, most certifications are completed within one to two months from start to finish. The actual timeline depends on your current security posture and how much preparation work is needed beforehand. Businesses that are already well set up may move through the process faster. We assess where you stand at the outset and give you a realistic timeframe based on your specific situation, not a generic estimate.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a self-assessment certification. You complete a questionnaire covering the five core security controls, which is then verified by a certification body. Cyber Essentials Plus goes further. An independent, accredited assessor carries out hands-on technical testing to verify that the controls you have declared are genuinely in place and working correctly. Cyber Essentials Plus carries greater weight with clients and is required for certain higher-level government and public sector contracts.

What does a Cyber Essentials audit involve?

The Cyber Essentials Plus audit is carried out by an accredited external assessor. It typically involves a call with the assessor, submission of evidence across the five core controls, and technical testing of your systems to verify compliance. This includes vulnerability scanning and configuration checks. We prepare you thoroughly before the audit takes place, running our own internal pre-assessment so that your systems are in the right shape and there are no surprises on the day.

What are the five controls covered by Cyber Essentials?

Cyber Essentials covers five core technical controls: firewalls and internet gateways, secure configuration, user access control, malware protection, and patch management. These controls address the most common vulnerabilities that cyber attackers exploit. Meeting all five is required for certification at both the standard and Plus levels. We assess your current position against each control as part of our initial review and help you address any areas that need attention before you apply.

How much does Cyber Essentials certification cost?

Our Cyber Essentials service includes all consultancy support, from your initial gap analysis through to certification submission, so our fees reflect the full end-to-end process rather than the certification fee alone. This means the overall cost is higher than applying direct, but you benefit from having experienced support at every stage. Because every business is different, we prefer to discuss your specific situation before quoting. Get in touch and we will give you a clear picture of what is involved.

Will Cyber Essentials certification affect my cyber insurance premium?

Many insurers look favourably on businesses that hold Cyber Essentials certification, and some are beginning to require it as a condition of cover. Holding certification may contribute positively to your insurance position, though outcomes vary depending on your insurer and policy. We would always recommend speaking directly with your insurance provider about how certification may affect your specific cover. What we can say is that having your security controls properly in place is increasingly important to insurers.

Can you help if we fail the Cyber Essentials assessment?

Yes, absolutely. If your assessment is unsuccessful, we review exactly what fell short, address the specific gaps, and support you through resubmission. A failed attempt does not mean the process starts from scratch. In most cases, the issues are specific and fixable. Our preference is always to prepare businesses thoroughly before submission to avoid this situation, but if you come to us having already received an unsuccessful result, we will get you back on track.

Do you provide Cyber Essentials Plus audits?

Yes. Through our trusted accredited partner, we are able to arrange and support the full Cyber Essentials Plus audit process. We handle the preparation work ourselves, ensuring your systems and controls are in the right shape before the external assessor carries out their technical review. This means you have continuity of support throughout, with one team managing the process end-to-end rather than having to coordinate separately with an auditor yourself.

How often do we need to renew Cyber Essentials certification?

Cyber Essentials certification is valid for twelve months and must be renewed annually. Recertification is not simply a repeat of the original process. The scheme requirements are reviewed and updated regularly, and your own IT environment will change over time, so each renewal requires a fresh assessment of your controls. We support our clients through annual renewals as part of our ongoing service, making sure your certification stays current and your security controls remain aligned with the latest requirements.