Cyber Essentials

Cyber Essentials certification in Norwich

We’re an IASME-accredited Cyber Essentials Certification Body, so we mark your submission and issue the certificate ourselves. Our Cyber Advisors check your setup first if you need it.

  • Listed on the IASME register of Cyber Essentials certification bodies
  • An NCSC Assured Service Provider for Cyber Advisor
  • Certificates last 12 months, and we keep your evidence on file for renewal
  • Based in Norwich, certifying organisations across Norfolk and the rest of the UK
IASME Cyber Essentials Certification Body

Accredited by IASME to assess and certify Cyber Essentials. Check the IASME register (opens in a new tab)

Certifications and partnerships
  • IASME Cyber Essentials Certification Body
  • IASME Cyber Assurance Level 2, audited
  • NCSC Assured Service Provider for Cyber Advisor (Cyber Essentials)
  • Microsoft Solutions Partner

Why it’s worth having.

Choose how much help you want.

Every route ends with your Cyber Essentials certificate from us. The difference is how much of the preparation we do with you.

  • Certification

    You’re ready to submit

    Your IT is in good shape and you know what the certificate needs to cover.

    • We agree the scope with you before you open the assessment account
    • We mark your answers against the current question set
    • Ask us about scope or evidence at any point
    • We issue the certificate as your certification body
  • Readiness review, then certification

    You want a check first

    You have a deadline and want to know what fails before you submit.

    • One of our Cyber Advisors checks your setup against the five controls
    • You get a written list of the gaps, worst first
    • We close the gaps with your team, or your own IT people do
    • Then we certify you, as on the first route
  • Cyber Essentials Plus

    You need Cyber Essentials Plus

    Your customer or insurer has asked for the audited level.

    • Cyber Essentials first, which Plus requires
    • We prepare your devices and accounts for the technical audit, building on the same control work

    The Plus audit itself is carried out independently, not by us.

  • Your certificate lasts 12 months. Renewal is a fresh assessment, not an automatic roll-over.
  • We scope and quote any remediation before work starts.

What Cyber Essentials checks.

There are five technical controls, the same for every organisation. Our Cyber Essentials guide covers each one in detail.

  • Firewalls

    Every device and network in scope sits behind a firewall, including devices used away from the office.

  • Secure configuration

    Default passwords and settings are changed. Software and accounts you don’t need are removed or switched off.

  • Security update management

    Only supported software is in use. High and critical updates go on within 14 days of release.

  • User access control

    People only get the access they need, and admin accounts are kept separate. MFA is on for every cloud service that offers it.

  • Malware protection

    Every device in scope is protected against malware, either with anti-malware software or by only letting approved apps run.

A quick check before you choose.

Is every device and app still supported, with high and critical updates installed within 14 days?
Is MFA on for every cloud service that offers it?
Do you know exactly which sites, devices and cloud services are in scope?

Answer all three and we’ll suggest a route.

We don’t keep your answers.

How certification runs.

  1. 01

    Scope

    We agree which sites, devices, cloud services and people the certificate covers, before you open the assessment account.

  2. 02

    Prepare

    One of our Cyber Advisors checks your setup and helps close the gaps, or your own team handles it.

  3. 03

    Submit

    You answer the questions in the IASME portal, and we mark each answer and tell you if anything falls short.

  4. 04

    Certify and renew

    Jayden Blair signs off the certificate once you pass, and we keep your evidence on file for next year’s renewal.

Defence Cyber Certification Certification Body, Level 0

If you supply the MOD, Cyber Essentials is the first Level 0 control.

We certify Cyber Essentials and assess Defence Cyber Certification at Level 0. The two scopes must match, and a mismatch is the most common reason a Level 0 submission stalls.

The MOD has asked its suppliers to hold Level 0 by 31 December 2026, though it isn’t a legal requirement. If we’ve put your controls in place or manage them for you, a different certification body must assess your DCC submission.

Cyber Essentials questions.

We’re based at White Lodge Business Park in Norwich, and most of the organisations we certify are in Norfolk, Suffolk and East Cambridgeshire. There’s more in our guide to Cyber Essentials for Norwich organisations.

Are you a Cyber Essentials certification body?

Yes. IASME accredits us as a Cyber Essentials Certification Body, so we mark your submission and issue the certificate ourselves, and you’ll find us on the IASME register.

How long does it take?

Most of the time goes on getting ready, not the assessment. You have six months from opening the assessment account to finish.

What does it cost?

It depends on the size of your organisation and how much help you want. We agree the scope, then send a quote, and any remediation is quoted separately before it starts.

What automatically fails an assessment?

Missing multi-factor authentication (MFA) on a cloud service that offers it fails the assessment on its own. So does a high or critical security update that isn’t installed within 14 days of release, and any unsupported software in scope.

Do you certify Cyber Essentials Plus as well?

No. Plus needs an independent technical audit, which we don’t carry out. We get you ready for it, so the work behind your self-assessment carries straight into Plus.

Is Cyber Essentials a legal requirement?

No law requires it, but UK central government contracts that involve personal information or certain IT services do, or ask for evidence of equivalent controls. Many other customers and insurers ask for it too.

How often do we renew?

Every 12 months, against the current question set. We keep last year’s scope notes and evidence, so you’re not starting from scratch.

Do you work with organisations outside Norwich?

Yes, we certify organisations across Norfolk, Suffolk, East Cambridgeshire and the rest of the UK. The assessment runs through the IASME portal, so location doesn’t matter.