Firewalls & boundaries
Perimeter, host firewalls, Conditional Access, remote access. Configured, documented, evidenced.
Cyber Essentials and Cyber Essentials Plus certification for UK SMBs
End-to-end Cyber Essentials and CE+ prep. We handle the gap analysis, remediation, evidence, paperwork and assessor liaison. You get the badge, the insurance and the unlocked procurement pipeline.
Both levels cover the same five technical controls — the difference is whether an assessor tests your environment in person (CE+) or trusts your answers (CE).
Perimeter, host firewalls, Conditional Access, remote access. Configured, documented, evidenced.
Device baselines via Intune/Addigy. Unused accounts disabled, default credentials removed, admin surface reduced.
Least privilege, MFA, separate admin accounts, joiner-mover-leaver process. The boring stuff that always fails audits.
EDR, policy enforcement, application control. Auditor-friendly configuration with evidence trail.
14-day critical SLA. OS + third-party. Aligned to our Patch Management service; pre-built for CE+.
We fill the questionnaire, gather the evidence, brief your signatories, and liaise with the assessor. You sign, we submit.
1-day audit against the current IASME scheme. We tell you exactly where you sit, what it'll take to pass, and realistic timelines. Written report, fixed fee.
We fix the gaps. Conditional Access, baselines, patch policy, MFA, admin accounts, documentation. Done by our engineers, not delegated back to you.
Screenshots, config exports, audit logs, policy docs all assembled in one pack. Written to the questionnaire you'll sign. No surprises at assessor review.
We liaise with the assessor, book the technical audit (CE+), answer clarifications, and walk you through the final sign-off. Certificate issued, badge delivered, insurance activated.
CE/CE+ isn't just a logo for your footer. It unlocks public-sector tenders, reduces insurance premiums, hardens your estate in real ways, and gives clients and prospects a credible, externally-validated answer to "what are you doing about security?". And it genuinely reduces risk — the controls are the five that stop most SMB breaches.
CE is a self-assessment questionnaire. CE+ adds a hands-on technical audit by an external assessor — authenticated vulnerability scans, sample device tests, phishing and malware tests. CE+ is what most public-sector contracts and larger clients want.
CE: typically 3–5 weeks including remediation. CE+: 6–10 weeks. Depends on how far the baseline is from compliant. We run a short gap analysis up front so you know what's involved.
Often yes, and it unlocks free cyber insurance up to £25k for small businesses via the IASME scheme (UK HQ, under £20m turnover). Most clients pay for the certification and save it back in year one.
For many central government and NHS contracts, yes. Increasingly also for large private-sector suppliers. If in doubt, ask — we'll tell you which level fits your pipeline.
12 months. Re-certification annually. Once the first run is in place, renewals are typically much faster — baselines stay, just evidence refreshes.
Yes. Common path: CE in month 1, operate for a quarter, CE+ when ready. We keep the same environment in scope so remediation carries forward.
14-day critical patching is a CE requirement. Our service is pre-built to comply.
Read more 02Satisfies the malware protection control with evidence assessors love.
Read more 03Intune baselines, Conditional Access, MFA, admin hygiene — the bulk of CE evidence.
Read moreTell us your estate, your timeline and your target (CE or CE+). We'll give you a realistic cost, a realistic timeline, and a go/no-go. Honest one either way.