Cyber Essentials Certification & Accreditation
or call 01869 352002 for a no-obligation chat
Why Cyber Essentials Matters for Your Business
Cyber Essentials is a certification that protects businesses against common, everyday cyber threats. As mentioned, it’s a government-backed scheme and is often a mandatory requirement for large organisations or those seeking government contracts to prove they have a minimum security standard. The scheme is an accessible one - in 2025, over 55,000 certificates were awarded.
It can have a range of benefits for businesses, including:
Trust
Can build a good reputation with customers by showing that their data is being handled responsibly.
Business growth
It can help businesses to win work, meet supplier requirements, and stand out ahead of competitors.
Cyber Liability
This is one of the most overlooked benefits of the scheme. When UK companies with an annual turnover under £20 million achieve Cyber Essentials certification for the whole organisation (not just a single department), they receive cyber liability insurance at no additional cost. Given that organisations with Cyber Essentials in place make 92% fewer cyber insurance claims, the financial case for certification is difficult to ignore.
What Cyber Essentials Covers
The Cyber Essentials assessment covers five areas of security measures, or “controls,” which all need to be satisfied to pass.
1. Firewalls
A firewall acts as a gatekeeper between your network and the internet, deciding what traffic is allowed in and out. Most devices and routers have one built in, but it needs to be switched on and properly configured.
If any of your team work from home or use laptops away from the office, those devices need to have their own firewall active too, not just the one sitting in your office.
2. Secure Configuration
This is about making sure your devices and software aren't left in the state they arrived in. Assessors want to see that unnecessary features and accounts have been disabled, and that every admin account has a strong, unique password. This includes your router, any networked printers, and other connected equipment.
3. User Access Control
Not everyone in your business needs the same level of access to your systems. This is about making sure staff can only access the files, software, and settings relevant to their role, and no more.
You’ll need to demonstrate a clear admin access process and a process for removing access promptly when someone leaves the company.
4. Malware Protection
All company devices need up-to-date protection against malicious software, which includes viruses, ransomware, and other threats that can encrypt your files or steal your data. This applies to all devices, including any laptops your team uses at home or on the road.
5. Patch Management (Keeping Software Up to Date)
Outdated software is one of the most common ways attackers get in. This control requires that all your software, operating systems, and firmware are kept current.
Our Cyber Essentials Services
At ComputerPro, we handle everything from start to finish. Whether you're going through the process for the first time or working towards Cyber Essentials Plus, we guide you through every step so you know exactly what is happening and why.
Preparation Services
Before anything else, we assess where your business currently stands against the five core Cyber Essentials controls.
This initial review gives us a clear picture of what is already in place and what needs attention. You will receive a straightforward action plan, with no jargon, so you understand what needs to change and how quickly it can be done.
Cyber Essentials Audit and Assessment
Our Cyber Essentials audit and assessment covers your full IT environment, including devices, user accounts, software, network settings, and cloud services. We check everything against the certification requirements and identify any gaps before you submit.
We carry out a proper technical review so that by the time you submit your assessment, you can be confident it reflects your actual security posture rather than an educated guess.
Certification Support
We support you through the full certification submission process, helping you complete the self-assessment questionnaire accurately. Our job is to make sure nothing gets missed and that you pass first time.
Cyber Essentials Plus Support and Audits
For businesses that need a higher level of assurance, or that are working with clients or government bodies requiring it, we also support Cyber Essentials Plus.
Cyber Essentials Plus involves a hands-on technical audit carried out by an external assessor, including vulnerability scanning and direct testing of your systems. We prepare your environment thoroughly beforehand so that the audit reflects the security controls you have put in place. We can also carry out a pre-assessment check to make sure you are ready before the formal audit takes place.
Up to Date with the April 2026 Scheme Requirements
The Cyber Essentials scheme was updated in April 2026, bringing in revised requirements around areas including cloud services and multi-factor authentication. If your business was previously certified or is starting the process now, we make sure your approach is aligned with the current scheme from the outset.
Cyber Essentials Certification Process
It shouldn’t be complicated to get Cyber Essentials certification. We break down the process into simple areas and support you every step of the way, so you know what’s happening and what’s coming next.
1. Initial Review
We assess your current IT environment to get a clear picture of where you stand. This includes looking at your devices, network, user accounts, software, and any cloud services your business uses. We map out what is in scope for certification and assess against the five core controls.
2. Identifying Gaps
After the review, we tell you what needs to change before you can certify - some businesses may be close while others may need a bit more work. Either way, you will receive a clear list of what needs fixing, with no ambiguity about what is required or why.
3. Fixing Issues
Where changes are needed, perhaps updating software or configuring devices correctly, we carry out the work alongside you and until everything is in order.
4. Completing Your Certification
Once the issues have been resolved, we support you through the self-assessment questionnaire and certification submission. We review your answers, make sure everything is accurate, and support any queries from the certifying body. Our aim is to get you to pass the first time.
5. Cyber Essentials Plus (Optional)
If your business needs or wants a higher level of certification, we can take you through Cyber Essentials Plus. This involves a hands-on technical audit by an external assessor, and we prepare your systems fully beforehand so the audit reflects the controls you have put in place.
Cyber Essentials Plus Certification & Audits
As mentioned above, Cyber Essentials Plus is a higher tier of certification, which goes further than the standard Cyber Essentials Scheme. In Cyber Essentials Plus, an independent assessor tests your systems directly, verifying that the security controls you have declared are genuinely in place and working as they should be.
Why Businesses May Need Cyber Essentials Plus
For some organisations, Cyber Essentials Plus is a requirement rather than a choice. Government contracts, Ministry of Defence supply chains, NHS procurement frameworks, and a growing number of private sector clients now specify it as a condition of doing business.
But beyond contractual requirements, there are good reasons to get this certification independently. Cyber Essentials Plus gives your stakeholders a higher level of confidence that your security controls have been independently verified. This distinction matters for businesses operating in the regulated sector or that handle sensitive data.
What the Audit Involves
The Cyber Essentials Plus audit is carried out by an external, accredited assessor. It includes vulnerability scanning of your external-facing systems, internal configuration checks across your devices and network, and testing of your malware protection and patch management controls. The assessor is checking that what you have put in place in practice matches what the certification requires.
How We Support You Through The Process
Before the audit, our role is to work with you well before it takes place to make sure your environment is genuinely ready.
That starts with a thorough internal review of your systems against the Cyber Essentials Plus requirements - where we find issues, we fix them.
And then, before the external audit, we carry out one of our own, which allows us to catch and resolve anything that causes a problem on the day.
Who Needs Cyber Essentials?
You Work With Larger Organisations
Many larger businesses and public sector organisations now ask their suppliers and partners to hold Cyber Essentials certification before they will work with them.
You Can Handle Sensitive or Personal Data
If your business handles sensitive data, Cyber Essentials gives you a recognised framework for protecting it.
You Are Bidding for Government Contracts
Since 2014, certification has been a requirement for UK government contracts involving the handling of personal data or sensitive information.
You Are Growing and Want To Improve Security
Certification is a way for SMEs to get their security in order and demonstrate their credibility to clients.
Why Choose ComputerPro
We are local
Based in Bicester, we support businesses across Oxfordshire and the surrounding areas. Whatever support is needed, we come to you.
20+ Years of experience
We understand the pressures that smaller businesses face, because we have been working with them for a long time.
Clear, practical guidance
Everything is explained in plain English. You will always know what’s happening and why.
Whole Process Handling
We manage the process from start to finish, from your initial review through to certification.
We work with the updated April 2026 requirements
The Cyber Essentials scheme is updated regularly, and our approach reflects the current requirements throughout.
Support after certification
We continue to support you after certification, helping you stay compliant and respond to any updates.
Ongoing Support & Maintaining Compliance
Cyber threats evolve, scheme requirements are updated, and your own IT environment will change as your business grows. Staying protected in the long-term means staying on top of these.
Cyber Essentials certification is valid for twelve months and needs to be renewed annually. The requirements are reviewed and updated by the scheme, which means recertification is not simply a repeat of what you did the year before. Controls that were in place last year may need to be revisited in light of new guidance or changes to your situation.
Businesses benefit from continued long-term support, and we support our clients through that ongoing process. We are here to support with whatever you need, such as preparing for annual recertification, or to provide reassurance that you are in line with current requirements.
For businesses that want a more comprehensive approach, our Cyber Essentials support sits naturally alongside our broader managed IT and cybersecurity services. That means your security controls, software patching, user access management, and monitoring can all be handled consistently, by a team that already knows your setup and keeps everything aligned.
The businesses that stay protected are the ones that treat security as an ongoing commitment. We help make that straightforward.
Cyber Essentials Support Across Oxfordshire
At ComputerPro, we make the Cyber Essentials process straightforward from initial audit through to certification and beyond.
Working across Oxfordshire, including areas such as Witney, Didcot, Abingdon and the city of Oxford, we work with you step by step, transparently, and make sure you are fully prepared at every stage.
Whatever stage of the process you’re at - starting from scratch or preparing for annual renewal - we are a team that knows how it works.