Cyber Essentials
Cyber Essentials certification in Norwich
We’re an IASME-accredited Cyber Essentials Certification Body, so we mark your submission and issue the certificate ourselves. Our Cyber Advisors check your setup first if you need it.
- Listed on the IASME register of Cyber Essentials certification bodies
- An NCSC Assured Service Provider for Cyber Advisor
- Certificates last 12 months, and we keep your evidence on file for renewal
- Based in Norwich, certifying organisations across Norfolk and the rest of the UK

Accredited by IASME to assess and certify Cyber Essentials. Check the IASME register (opens in a new tab)
Why it’s worth having.
- 43%of UK businesses had a cyber breach or attack in the last 12 months.Cyber Security Breaches Survey 2025/26, DSIT (opens in a new tab)
- 92%fewer cyber insurance claims come from organisations with the Cyber Essentials controls in place.Cyber Essentials scheme overview, GOV.UK (opens in a new tab)
- 26%of large UK businesses now require suppliers to hold Cyber Essentials, up from 10% the year before.Cyber Security Breaches Survey 2025/26, DSIT (opens in a new tab)
- 61,430Cyber Essentials and Plus certificates were issued in the UK in the year to June 2026.Cyber Essentials management information, DSIT (opens in a new tab)
Choose how much help you want.
Every route ends with your Cyber Essentials certificate from us. The difference is how much of the preparation we do with you.
- Certification
You’re ready to submit
Your IT is in good shape and you know what the certificate needs to cover.
- We agree the scope with you before you open the assessment account
- We mark your answers against the current question set
- Ask us about scope or evidence at any point
- We issue the certificate as your certification body
- Readiness review, then certification
You want a check first
You have a deadline and want to know what fails before you submit.
- One of our Cyber Advisors checks your setup against the five controls
- You get a written list of the gaps, worst first
- We close the gaps with your team, or your own IT people do
- Then we certify you, as on the first route
- Cyber Essentials Plus
You need Cyber Essentials Plus
Your customer or insurer has asked for the audited level.
- Cyber Essentials first, which Plus requires
- We prepare your devices and accounts for the technical audit, building on the same control work
The Plus audit itself is carried out independently, not by us.
- Your certificate lasts 12 months. Renewal is a fresh assessment, not an automatic roll-over.
- We scope and quote any remediation before work starts.
What Cyber Essentials checks.
There are five technical controls, the same for every organisation. Our Cyber Essentials guide covers each one in detail.
Firewalls
Every device and network in scope sits behind a firewall, including devices used away from the office.
Secure configuration
Default passwords and settings are changed. Software and accounts you don’t need are removed or switched off.
Security update management
Only supported software is in use. High and critical updates go on within 14 days of release.
User access control
People only get the access they need, and admin accounts are kept separate. MFA is on for every cloud service that offers it.
Malware protection
Every device in scope is protected against malware, either with anti-malware software or by only letting approved apps run.
A quick check before you choose.
Answer all three and we’ll suggest a route.
We don’t keep your answers.
How certification runs.
- 01
Scope
We agree which sites, devices, cloud services and people the certificate covers, before you open the assessment account.
- 02
Prepare
One of our Cyber Advisors checks your setup and helps close the gaps, or your own team handles it.
- 03
Submit
You answer the questions in the IASME portal, and we mark each answer and tell you if anything falls short.
- 04
Certify and renew
Jayden Blair signs off the certificate once you pass, and we keep your evidence on file for next year’s renewal.

If you supply the MOD, Cyber Essentials is the first Level 0 control.
We certify Cyber Essentials and assess Defence Cyber Certification at Level 0. The two scopes must match, and a mismatch is the most common reason a Level 0 submission stalls.
The MOD has asked its suppliers to hold Level 0 by 31 December 2026, though it isn’t a legal requirement. If we’ve put your controls in place or manage them for you, a different certification body must assess your DCC submission.
Cyber Essentials questions.
We’re based at White Lodge Business Park in Norwich, and most of the organisations we certify are in Norfolk, Suffolk and East Cambridgeshire. There’s more in our guide to Cyber Essentials for Norwich organisations.
Are you a Cyber Essentials certification body?
Yes. IASME accredits us as a Cyber Essentials Certification Body, so we mark your submission and issue the certificate ourselves, and you’ll find us on the IASME register.
How long does it take?
Most of the time goes on getting ready, not the assessment. You have six months from opening the assessment account to finish.
What does it cost?
It depends on the size of your organisation and how much help you want. We agree the scope, then send a quote, and any remediation is quoted separately before it starts.
What automatically fails an assessment?
Missing multi-factor authentication (MFA) on a cloud service that offers it fails the assessment on its own. So does a high or critical security update that isn’t installed within 14 days of release, and any unsupported software in scope.
Do you certify Cyber Essentials Plus as well?
No. Plus needs an independent technical audit, which we don’t carry out. We get you ready for it, so the work behind your self-assessment carries straight into Plus.
Is Cyber Essentials a legal requirement?
No law requires it, but UK central government contracts that involve personal information or certain IT services do, or ask for evidence of equivalent controls. Many other customers and insurers ask for it too.
How often do we renew?
Every 12 months, against the current question set. We keep last year’s scope notes and evidence, so you’re not starting from scratch.
Do you work with organisations outside Norwich?
Yes, we certify organisations across Norfolk, Suffolk, East Cambridgeshire and the rest of the UK. The assessment runs through the IASME portal, so location doesn’t matter.



