Cyber Essentials Certification for UK Businesses
Certified in 30–45 days, then kept certified: £250 + VAT per month, all-in - gap analysis, remediation done for you, submission with official fees included, and annual re-certification. Delivered in partnership with an IASME-accredited certification body, by a team that holds Cyber Essentials Plus itself.
AMVIA's Cyber Essentials certification service costs £250 + VAT per month, all-in for standard scope (up to 49 employees): gap analysis, hands-on remediation of the five technical controls, questionnaire submission with official IASME assessment fees included, and annual re-certification. Initial certification typically takes 30–45 days, delivered in partnership with an IASME-accredited certification body. Larger organisations are tiered from the same floor; Cyber Essentials Plus - the independently audited tier - is £400 + VAT per month.
What is Cyber Essentials?
Cyber Essentials is the UK government-backed certification, designed by the National Cyber Security Centre and operated through IASME, that proves your organisation has five fundamental technical controls in place: firewalls, secure configuration, user access control, malware protection and security update management. None of it is exotic - the scheme certifies disciplined execution of the basics, and the basics stop most of the commodity attacks UK SMEs actually face. With 43% of UK businesses reporting a breach or attack in the past 12 months (DSIT, Cyber Security Breaches Survey 2025), the baseline matters.
Who needs it
Three groups, in practice. Suppliers to government: certain UK central government and MoD contracts require Cyber Essentials outright, and prime contractors increasingly flow the requirement down their supply chains - for many SMEs the certificate is the difference between bidding and not bidding. The insured: UK cyber insurers increasingly ask CE-aligned questions at proposal and renewal, and basic certification through IASME includes cyber liability insurance for eligible organisations under £20 million turnover. Anyone being vetted: supplier security questionnaires now routinely ask for the certificate - you can check any company's status on the official register with our certificate checker, which is exactly what your customers do to you.
The Cyber Essentials requirements: the five controls in practice
Certification assesses five technical control areas, defined by the NCSC and assessed by IASME. The requirement is not owning tools - it is being able to answer, honestly and specifically, how each control is applied across everything in scope:
- Firewalls and internet gateways - every in-scope device sits behind a correctly configured firewall; default passwords changed; no unapproved inbound services.
- Secure configuration - unused accounts and software removed, default credentials gone, auto-run disabled, device locking enforced.
- Access control - accounts are per-person and least-privilege; admin rights separated from daily-driver accounts; MFA where the standard requires it.
- Malware protection - anti-malware (or app allow-listing/sandboxing) active and updating on every in-scope device.
- Security update management - supported software only, with high and critical patches applied within 14 days of release.
The self-assessment questionnaire walks the whole estate through those five areas - including home workers’ devices and cloud services, which is where most first attempts stumble. Our checklist work is exactly this: finding the answers that would fail before the assessor does.
Cyber Essentials for government contracts
If you bid for central government or MOD work, Cyber Essentials stops being optional: UK government procurement policy requires suppliers on contracts involving personal information or certain ICT services to hold certification, and many framework and defence tenders will not shortlist without it. Two practical points from running these deadlines: standard-scope certification typically runs 30–45 days end to end, so start before the tender clock forces you to - and check whether the contract specifies Cyber Essentials Plus, which adds an independent technical audit and a longer runway.
Supply chains ask for it too
The fastest-growing driver we see is not government - it is customers. Larger organisations increasingly push security requirements down their supply chain, and only 15% of UK businesses formally review the cyber risks posed by their immediate suppliers (DSIT Cyber Security Breaches Survey 2025/26) - so the ones that do tend to use certification as the filter. A current certificate on the IASME register answers the security section of most vendor questionnaires in one line, which is often worth more in won business than the certificate costs.
What we do vs what you do
| Task | AMVIA | You |
|---|---|---|
| Gap analysis against the current question set | ✔ We run it | Give us access and an hour of walkthrough |
| Remediation - MFA, access control, patching, firewalls, software audit | ✔ Our engineers do the work | Approve changes; nominate a contact |
| Questionnaire completion and submission | ✔ Completed with you, submitted by us | Sign off the declarations (they're yours to make) |
| Official assessment fees | ✔ Included in the monthly price | Nothing extra |
| Keeping controls in shape between renewals | ✔ Monthly checks, drift fixed | Tell us when things change - new starters, new software, new sites |
| Annual re-certification | ✔ Included and scheduled | An hour, once a year |
DIY vs consultant vs AMVIA
| DIY self-assessment | Generic consultant | AMVIA managed service | |
|---|---|---|---|
| Upfront cost | Official fee only (£320–£600+VAT by size) | Typically £1,000–£5,000+ project fee plus official fees | £250+VAT/month, everything included |
| Who fixes the gaps | You | Usually you, from their gap report | We do |
| Failure risk | High if the estate has drift - most first-time DIY attempts find gaps mid-questionnaire | Lower, but remediation quality varies | Low - we don't submit until the controls genuinely pass |
| Year two | Start again | Another project fee | Included - the controls never lapsed |
The honest caveat on DIY: if you run a small, modern, well-disciplined Microsoft 365 estate with no legacy kit, self-assessment is genuinely achievable - our free readiness assessment will tell you in ten minutes whether you're close. Most businesses discover the gaps are real, and the gap between knowing and fixing is where the service earns its fee.
Pricing, in full
£250 + VAT per month covers standard scope - up to 49 employees - with the official IASME assessment fees (£320–£600+VAT by organisation size, verified August 2026) included rather than billed on top. Larger or multi-site organisations are tiered from the same floor and quoted before you commit; the full cost guide breaks down every component, including what DIY really costs once remediation is counted. Need the audited tier? Cyber Essentials Plus is £400 + VAT per month - enterprise customers, insurers and government buyers increasingly ask for it by name.
Why a monthly service and not a project
Because the certificate expires every 12 months and the controls drift the day after the assessor leaves. A one-off certification project leaves you owning that drift - new starters without MFA, patches slipping past the 14-day window, a firewall rule added in a hurry - and turns every renewal into a fresh scramble. The monthly service keeps the five controls continuously in the state the assessment expects, which is also exactly the posture your insurer and your supply chain think the certificate means. If certification matters enough to buy once, it matters enough to keep.
Why UK businesses get certified
What £250/month actually includes
All-in for standard scope (up to 49 employees). Larger organisations are tiered from the same floor.
Gap analysis
Your estate assessed against the current question set - every device, account and cloud service in scope, honestly scored.
Remediation - done for you
We fix what falls short: MFA enforcement, access control, patching discipline, firewall baselines, unsupported software retired. Not a gap list and good luck - the work itself.
Submission handled
Questionnaire completed with you and submitted; official IASME assessment fees are included in the monthly price.
Annual re-certification
Certificates expire every 12 months. We keep the controls in shape between renewals, so next year's certification is a formality, not a project.
Accredited delivery
Delivered in partnership with an IASME-accredited certification body - the certificate you receive is the real, register-verifiable article.
A provider that passes it too
AMVIA holds Cyber Essentials Plus ourselves. Your controls are implemented by people audited against the same standard.
From signup to certified
Typically 30–45 days to initial certification, then a monthly rhythm that keeps you there.
Gap analysis (week 1)
We map your devices, accounts, cloud services and network boundary against the five controls and agree the remediation plan.
Remediation (weeks 2–5)
MFA rolled out, admin rights tightened, patching brought inside the 14-day window, firewalls baselined, end-of-life software replaced - done by our engineers, not left as homework.
Submission & certification
Questionnaire completed and submitted through our IASME-accredited certification body partner. Fees included; certificate issued and verifiable on the official register.
Stay certified
Monthly control checks, drift fixed as it appears, and the annual re-certification handled - the part a one-off project never covers.
Why certify with AMVIA
The difference is who does the remediation - and what happens in month thirteen.
We do the work
Most providers sell you the assessment and leave the remediation with your team. Ours includes it - because the remediation is the certification.
Published pricing
£250 + VAT/month, on the page, before you talk to anyone. Larger estates tiered from the same floor, quoted before you commit.
Built for year two
Annual renewal is in the price and in the operating rhythm. Certification that lapses eleven months from now wasn't a service - it was a transaction.
A path, not a ceiling
The same team runs managed detection and response, Microsoft 365 security and vulnerability management - when you're ready for more than the baseline, nothing gets rebuilt.
Client testimonial coming soon. AMVIA protects over 1,200 UK businesses.
AMVIA Client
Cyber Essentials Certification Service Pricing
| Plan | From / month | Response Target | Includes |
|---|---|---|---|
| Cyber Essentials | from £250.00 | Initial certification typically 30–45 days | Gap analysis, remediation, submission, annual re-certification |
| Cyber Essentials PlusAudited tier | from £400.00 | Initial certification typically 45–60 days | Everything in CE + independent technical audit with evidence collection |
Your certification price, instantly
Two inputs, no email address required. Standard scope is priced flat; larger estates are tiered and confirmed on a 15-minute call.
Ready when you are
Standard scope starts at £250 + VAT/month with nothing else to buy. Tell us about your business and the team will confirm scope and start the gap analysis this week.
Cyber Essentials certification - your questions
£250 + VAT per month, all-in for standard scope (up to 49 employees): gap analysis, remediation done by our engineers, questionnaire submission with the official IASME assessment fees included, and annual re-certification. Larger organisations are tiered from the same floor and quoted before commitment.
Typically 30–45 days from signup to certificate for standard scope: about a week of gap analysis, two to four weeks of remediation depending on what we find, then submission. A clean, modern estate can be faster; heavy legacy software is the usual thing that extends it - and we tell you at gap-analysis stage, not at week six.
Firewalls (every device behind a correctly configured boundary or software firewall), secure configuration (default passwords changed, unused software and accounts removed), user access control (least privilege, restricted admin rights, MFA on cloud services), malware protection (anti-malware or allow-listing on every in-scope device), and security update management (supported software only, high and critical patches within 14 days).
No - it's voluntary certification. But it's contractually required for certain UK government and MoD work, increasingly demanded down supply chains by prime contractors, and asked about by cyber insurers at proposal and renewal. For many businesses the commercial pressure makes it effectively mandatory even though no law does.
Both certify the same five controls. CE is a verified self-assessment - you answer the questionnaire, a qualified assessor reviews it. CE Plus adds an independent technical audit with tests run against your actual systems, which carries more weight with enterprise buyers, insurers and government. With AMVIA, CE is £250+VAT/month and Plus is £400+VAT/month.
Certification is issued through the official IASME scheme. AMVIA delivers the service - gap analysis, remediation, submission, renewals - in partnership with an IASME-accredited certification body, so the certificate you receive is the standard, register-verifiable Cyber Essentials certificate. You can confirm any certificate, including ours, with our free certificate checker.
Our model makes that unlikely by design: we don't submit until the gap analysis says the controls genuinely pass, because we did the remediation ourselves. If an assessment does surface something, fixing it and resubmitting is part of the service - not a new invoice.
No - the official assessment fees (£320+VAT for micro organisations, £440+VAT for small, rising to £600+VAT for large enterprises; verified August 2026) are included in the monthly price. There is nothing to pay on top for standard scope.
Up to 49 employees with a typical single-organisation estate - the shape most UK SMEs are. More employees, multiple legal entities or unusually complex estates are tiered from the same £250/£400 floors, with the exact price confirmed on a 15-minute call before you commit to anything.
Basic Cyber Essentials certification through IASME includes cyber liability insurance (£25,000 indemnity) for eligible UK organisations with under £20 million turnover, at no extra cost. It's a useful baseline - not a substitute for a standalone cyber policy sized to your actual risk.
Considerably, if it's configured properly: MFA enforcement, access control and patching are all natively manageable. Misconfigured tenants are also one of the most common gap sources - our free Microsoft 365 security baseline check shows where yours stands, and tenant hardening is part of our remediation work.
Yes - devices used for business, wherever they are, are in scope, including home-worker laptops and BYOD phones accessing company data. This is one of the most commonly misunderstood scope areas and a routine gap-analysis finding; our remediation covers bringing remote devices under control.
The service keeps running: monthly control checks, drift fixed as it appears (new starters, new software, expiring configurations), and the annual re-certification handled on schedule. That continuity is the point of the monthly model - the certificate never lapses and renewal never becomes a project.
Yes - co-managed certification is common. We coordinate the remediation with your incumbent IT provider, or handle just the certification layer while they run day-to-day support. The responsibility split is agreed at gap-analysis stage so nobody's stepping on anyone.
We don't sell certification-only, because submitting an estate we haven't verified would put our name on something we can't stand behind. If you genuinely just need the assessment, the DIY route through IASME costs £320–£600+VAT - and our free readiness assessment will tell you honestly whether you're ready for it.
Search the official register operated by IASME on behalf of the NCSC - free, no account needed. Our certificate checker takes you straight there with the company name ready to search. Certificates expire after 12 months, so a supplier who 'has Cyber Essentials' from two years ago is not currently certified.
It materially reduces the risk from commodity attacks - the automated, untargeted kind that make up most of what UK SMEs face - because the five controls close the doors those attacks use. It is not a complete security programme: it doesn't cover detection, response or user training, which is where managed detection and response picks up.
When a contract, insurer or customer names it specifically; when you handle data sensitive enough that self-assessment won't satisfy your stakeholders; or when you want the independent audit as genuine assurance rather than paperwork. The controls are identical - Plus proves them harder. If in doubt, start the conversation at CE and upgrade; the work transfers.
For many, yes - UK government procurement policy requires suppliers to hold Cyber Essentials for central government contracts involving personal information or certain ICT services, and MOD contracts routinely require it (often Plus). Check the tender documents for which level, and start early: standard-scope certification typically runs 30–45 days end to end.
The five control areas: firewalls and internet gateways, secure configuration, access control, malware protection, and security update management (supported software patched within 14 days for high/critical updates) - applied across every in-scope device, including home workers and cloud services. The assessment is a self-assessment questionnaire verified by an IASME assessor; Plus adds an independent technical audit of the same controls.
Not sure where you stand?
Take the free 20-question readiness assessment - instant per-control results in your browser, and a printable gap report to bring to the call.
Talk it through first?
Fifteen minutes with the certification team: your scope, your timeline, your exact price. No pressure - the pricing is already public.
Certification resources
Cyber Essentials Plus - £400/month
The independently audited tier: technical audit, evidence collection, and the certificate enterprise buyers ask for by name.
Cyber Essentials cost, in full
Official fees, what drives Plus audit costs, and what DIY really costs once remediation is counted.
Readiness assessment
Twenty questions against the five controls - find your gaps before you spend a pound.
Certificate checker
Verify any company's certification against the official register in under a minute.
Protect your business → Get Cybersecurity Assessment