Cyber Essentials Certification
Cyber Essentials Certification for UK Businesses
Certified once. Compliant all year.
A customer, an insurer or a framework is asking for Cyber Essentials and you haven't got it. The deadline is real, the contract depends on it, and you need someone to get you there without the guesswork. That's the job. We take UK businesses through Cyber Essentials and Cyber Essentials Plus, then keep them in the passing state afterwards rather than only in the week before the assessment. Certification and monitoring run through CyberSmart, the accredited platform we work on, behind a UK team that already operates the five controls the scheme tests. First time or renewing under the April 2026 rules, the destination is the same: certified through an accredited body, and still compliant in month eleven.
- Microsoft Partner Cloud Solution Provider (CSP)
- Cyber Essentials we hold it ourselves
- UK team no overseas call centre
- All year continuous compliance, not one-off
Book a Cyber Essentials readiness call Download the Cyber Essentials readiness checklist
Who issues your certificate
We help you achieve and maintain certification. The certificate itself is issued by an IASME-accredited body through our partner platform, CyberSmart. We do the work that gets you there, and the work that keeps you there.
Why UK Businesses Need Cyber Essentials Now
For a lot of firms it isn't optional any more. When a contract, an insurer or a regulator sets the date, missing it costs real work.
You cannot bid without it
More tenders now list Cyber Essentials as a straight pass or fail. Under the government's procurement rules (PPN 014) it's required on many public-sector contracts, and the requirement cascades down the supply chain, so subcontracting to a certified prime pulls you in too. No certificate, no bid. Firms get quietly locked out of work they'd have won, and often only find out when the tender lands.
Regulated and public-sector supply chains are setting hard dates
If you supply the Ministry of Defence, or a prime that does, MOD has asked all industry partners to hold Defence Cyber Certification Level 0 by 31 December 2026, and Cyber Essentials is its first control. If you handle NHS data, the NHS Data Security and Protection Toolkit and a Cyber Essentials Plus expectation are now treated as separate evidence streams you have to satisfy. Both come with dates you do not control.
Your cyber-insurance renewal is getting harder
Insurers increasingly ask for it at renewal, and some price it in or decline cover without it. Renewal is an annual date you can see coming, which makes turning up to it uncertified an expensive kind of surprise.
The April 2026 rules just changed the bar
The scheme's v3.3 requirements took effect on 27 April 2026. Multi-factor authentication is now mandatory across all cloud services, cloud can't be scoped out, and scoping is tighter throughout. Certification now depends on how your systems are configured and kept configured. Plenty of firms that passed last year won't pass renewal without work, and MFA is where most of them get caught.
Certified last year, and nothing has been maintained since
A certificate is a snapshot of one day. The moment a laptop gets built wrong, a starter is added without MFA or a patch slips, your real state drifts from your certified state. One-off certifiers hand over the PDF and leave the problem to reappear twelve months later.
How HGC Helps You Achieve and Maintain Cyber Essentials
Cyber Essentials tests five technical controls. For the businesses we look after these aren't a project bolted on before an assessment, they're what we run daily. We prepare, harden and evidence your environment; the assessment and certificate are issued by an IASME-accredited body through CyberSmart. It starts with a short readiness call, so you know what's needed before committing to anything.
Firewalls and network boundaries
The first control is a properly configured boundary between your systems and the internet. We lock firewalls and internet-facing devices down to what the business actually needs, clear out default passwords, and close anything an automated scan could walk through. On managed clients that's set correctly on day one and checked continuously, not rediscovered at renewal.
Secure configuration
Devices and software ship configured for convenience rather than security. This control is about removing what you don't use and setting the rest to a safe standard. We build and maintain laptops, servers and cloud services to one pattern, so the estate stays in a known-good state instead of drifting into the gaps assessors look for.
Access control and multi-factor authentication
Only the right people should reach your systems, and a password on its own no longer counts. This is the control April 2026 tightened most, with MFA now mandatory across all cloud services. As a Microsoft Cloud Solution Provider, configuring and managing MFA and access control in Microsoft 365 is daily work for us, so the control the scheme now hinges on is one we already own.
Malware protection
Every device needs malware and ransomware protection that's actually active and actually current, everywhere. We deploy and manage it consistently, so there's no forgotten laptop running uncovered and no gap between buying antivirus and it working on the whole estate.
Security update management (patching)
Attackers live on known flaws in software nobody updated. This control requires supported software to be patched and out-of-support software to be removed. We patch continuously, which is also the single biggest reason a maintained estate walks through renewal while an unmaintained one fails.
Why Choose HGC for Cyber Essentials
Plenty of people can get you a certificate. Fewer can keep you certified. We already run the controls the scheme tests, so passing isn't an event we cram for.
We already run the controls the scheme tests
Cyber Essentials assesses firewalls, secure configuration, access control and MFA, malware protection and patching. On a managed estate those aren't extras introduced for the assessment, they're what runs every day. That's why renewal is a formality rather than a fire drill, and why April 2026 was home ground rather than a problem.
Microsoft Partner and CSP, on the controls that now matter most
As a Microsoft Partner and Cloud Solution Provider, we configure and manage the MFA, Conditional Access and secure configuration inside your Microsoft 365 tenant. Those are exactly the controls the scheme hinges on after April 2026. It's competence on the specific things you're assessed against, rather than a badge.
We hold Cyber Essentials ourselves
We have been through certification for our own business, so we know the process from the inside and we practise what we recommend. When we tell you what good looks like, it is because we hold ourselves to the same standard.
You deal with HGC, not a platform
One relationship, one accountable UK team. CyberSmart is the accredited platform we certify and monitor through, and an IASME-accredited body issues the certificate on it. Think of it the way you think about your accountant: we do the work and own the outcome, the platform is what we file through.
A named UK team, not an overseas call centre
Real people you can reach, based here. We're headquartered in Dorchester, Dorset, and support businesses across the country, so you get local accountability without a ticket disappearing into an overseas queue.
Continuous compliance, not a certificate mill
We get you certified properly, through an accredited body, then hold the estate in the passing state between certificates instead of handing over a PDF and walking off. Certified once, compliant all year, so the certificate still means something in month eleven.
Cyber Essentials: Frequently Asked Questions
Straight answers to what UK businesses ask us most about getting, and keeping, Cyber Essentials.
What is Cyber Essentials certification?
It's a UK government-backed certification showing your business has the core technical controls in place against the most common attacks. Five areas: firewalls, secure configuration, access control and multi-factor authentication, malware protection, and keeping software updated. It's widely recognised, increasingly required to win work, and a practical baseline that stops most everyday threats. We help you achieve it and, just as importantly, stay compliant with it all year.
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is a verified self-assessment: you complete a questionnaire confirming the controls are in place, and it's the faster route. Cyber Essentials Plus covers the same five controls but adds an independent hands-on technical audit, where an assessor checks your systems directly. More assurance, longer to arrange. CE Plus is often what larger contracts and defence or NHS-adjacent supply chains ask for. Not sure which you need? That's what the readiness call is for.
How much does Cyber Essentials cost?
It depends on your size and the state of your systems today, so we scope it per business rather than quote a headline figure. There's a certification assessment fee set by IASME, tiered by organisation size, and then whatever remediation is needed to get the controls passing. After a short readiness call you'll know what's required before committing to anything, so the bill doesn't arrive as a discovery.
Do I need Cyber Essentials to win contracts?
Increasingly, yes. Under the government's procurement rules (PPN 014) it's required on many public-sector contracts, and that cascades down supply chains to subcontractors. Ministry of Defence suppliers face Defence Cyber Certification expectations that include it, NHS-data suppliers face related assurance requirements, and plenty of private-sector buyers now ask too. If you bid for work, expect to be asked for the certificate, and to be ruled out early without one.
What is changing with Cyber Essentials in April 2026?
The scheme's v3.3 requirements took effect on 27 April 2026. Multi-factor authentication is now mandatory across all cloud services, cloud can no longer be left out of scope, and scoping rules are tighter overall. In practice certification depends more than ever on how systems are set up and kept set up, and a lot of businesses that passed before will need work on MFA to pass the next renewal.
Does HGC issue the Cyber Essentials certificate?
No, and we'd rather say so plainly. We're not the certification body. We prepare, harden and evidence your environment so you meet the standard, then your assessment and certificate are issued by an IASME-accredited body through our partner platform, CyberSmart. You get properly accredited certification, managed end to end by a UK team. We're the people who get you there and keep you there. The accredited body issues the certificate.
How long does Cyber Essentials certification take?
It depends on the state of your systems and which level you need, so we won't put a number on it before we've looked. As a guide, Cyber Essentials is a self-assessment and the quicker route, while Cyber Essentials Plus involves an independent technical audit and takes longer to arrange. Tell us your deadline on the readiness call and we'll tell you honestly whether it's reachable.
What happens after we are certified?
This is where we differ from a one-off certifier. A certificate is a snapshot of one day, and your real security drifts the moment a device is built wrong or a patch is missed. We hold the five controls in the passing state continuously, through the CyberSmart platform and the team running your IT, so renewal is a formality, your insurer and customers keep getting the answer they expect, and the certificate still holds up in month eleven.
Which industries do you help with Cyber Essentials?
Across UK sectors, with most of the pull coming from professional services (legal, accountancy, consultancy, architecture and engineering), finance, healthcare-adjacent organisations, and the defence and engineering supply chain where MOD requirements are a live driver. Those are the places contracts, regulators and insurers ask for it hardest. Not sure whether it applies to you? The readiness call will tell you.
Not ready to book? Get the free readiness checklist
Explore more
Cyber Essentials sits alongside the rest of your security and IT, so it works best when everything is joined up. If you supply the Ministry of Defence or its primes, Cyber Essentials is the first control of Defence Cyber Certification, which we run as a dedicated service. If you want protection that goes beyond the certificate, our managed cybersecurity covers ongoing monitoring and threat defence. The access and MFA controls Cyber Essentials now hinges on live inside your tenant, which is why our Microsoft 365 support matters to certification. Many firms also choose to have the whole estate looked after by one UK team through our managed IT support. And if you would like a local team, here is how we deliver local IT support across Dorset.
The pressure arrives differently in different places: insurer-led for the professional firms around Lansdowne, so Cyber Essentials for Bournemouth firms is usually a renewal question; contract-led for Bridport manufacturers and the supply chain around Blandford; and client-led for Cyber Essentials in Wimborne, where accountants and solicitors are being asked by the people they act for.
Get Cyber Essentials ready
Book a short, no-obligation readiness call with our UK team. We'll talk through your deadline, look at where you are today, and give you a plain-English view of what it takes to get certified and stay certified. You'll know what's needed before you commit to anything. Certified once, compliant all year.
- Free, no-obligation readiness call
- Done for you, by a UK team
- Kept compliant all year, not just at renewal
- No surprise remediation bills, you know the plan before you commit
Call 01305 310006 · Email [email protected]