Countdown until the UK analogue phone switch-off on 31 January 2027.Is your business affected?
Certification Service

Cyber Essentials Certification for UK Businesses

Certified in 30–45 days, then kept certified: £250 + VAT per month, all-in - gap analysis, remediation done for you, submission with official fees included, and annual re-certification. Delivered in partnership with an IASME-accredited certification body, by a team that holds Cyber Essentials Plus itself.

£250+ VAT / month, all-in - standard scope
30–45days to initial certification, typically
5technical controls, implemented for you

AMVIA's Cyber Essentials certification service costs £250 + VAT per month, all-in for standard scope (up to 49 employees): gap analysis, hands-on remediation of the five technical controls, questionnaire submission with official IASME assessment fees included, and annual re-certification. Initial certification typically takes 30–45 days, delivered in partnership with an IASME-accredited certification body. Larger organisations are tiered from the same floor; Cyber Essentials Plus - the independently audited tier - is £400 + VAT per month.

What is Cyber Essentials?

Cyber Essentials is the UK government-backed certification, designed by the National Cyber Security Centre and operated through IASME, that proves your organisation has five fundamental technical controls in place: firewalls, secure configuration, user access control, malware protection and security update management. None of it is exotic - the scheme certifies disciplined execution of the basics, and the basics stop most of the commodity attacks UK SMEs actually face. With 43% of UK businesses reporting a breach or attack in the past 12 months (DSIT, Cyber Security Breaches Survey 2025), the baseline matters.

Who needs it

Three groups, in practice. Suppliers to government: certain UK central government and MoD contracts require Cyber Essentials outright, and prime contractors increasingly flow the requirement down their supply chains - for many SMEs the certificate is the difference between bidding and not bidding. The insured: UK cyber insurers increasingly ask CE-aligned questions at proposal and renewal, and basic certification through IASME includes cyber liability insurance for eligible organisations under £20 million turnover. Anyone being vetted: supplier security questionnaires now routinely ask for the certificate - you can check any company's status on the official register with our certificate checker, which is exactly what your customers do to you.

The Cyber Essentials requirements: the five controls in practice

Certification assesses five technical control areas, defined by the NCSC and assessed by IASME. The requirement is not owning tools - it is being able to answer, honestly and specifically, how each control is applied across everything in scope:

  • Firewalls and internet gateways - every in-scope device sits behind a correctly configured firewall; default passwords changed; no unapproved inbound services.
  • Secure configuration - unused accounts and software removed, default credentials gone, auto-run disabled, device locking enforced.
  • Access control - accounts are per-person and least-privilege; admin rights separated from daily-driver accounts; MFA where the standard requires it.
  • Malware protection - anti-malware (or app allow-listing/sandboxing) active and updating on every in-scope device.
  • Security update management - supported software only, with high and critical patches applied within 14 days of release.

The self-assessment questionnaire walks the whole estate through those five areas - including home workers’ devices and cloud services, which is where most first attempts stumble. Our checklist work is exactly this: finding the answers that would fail before the assessor does.

Cyber Essentials for government contracts

If you bid for central government or MOD work, Cyber Essentials stops being optional: UK government procurement policy requires suppliers on contracts involving personal information or certain ICT services to hold certification, and many framework and defence tenders will not shortlist without it. Two practical points from running these deadlines: standard-scope certification typically runs 30–45 days end to end, so start before the tender clock forces you to - and check whether the contract specifies Cyber Essentials Plus, which adds an independent technical audit and a longer runway.

Supply chains ask for it too

The fastest-growing driver we see is not government - it is customers. Larger organisations increasingly push security requirements down their supply chain, and only 15% of UK businesses formally review the cyber risks posed by their immediate suppliers (DSIT Cyber Security Breaches Survey 2025/26) - so the ones that do tend to use certification as the filter. A current certificate on the IASME register answers the security section of most vendor questionnaires in one line, which is often worth more in won business than the certificate costs.

What we do vs what you do

TaskAMVIAYou
Gap analysis against the current question set✔ We run itGive us access and an hour of walkthrough
Remediation - MFA, access control, patching, firewalls, software audit✔ Our engineers do the workApprove changes; nominate a contact
Questionnaire completion and submission✔ Completed with you, submitted by usSign off the declarations (they're yours to make)
Official assessment fees✔ Included in the monthly priceNothing extra
Keeping controls in shape between renewals✔ Monthly checks, drift fixedTell us when things change - new starters, new software, new sites
Annual re-certification✔ Included and scheduledAn hour, once a year

DIY vs consultant vs AMVIA

DIY self-assessmentGeneric consultantAMVIA managed service
Upfront costOfficial fee only (£320–£600+VAT by size)Typically £1,000–£5,000+ project fee plus official fees£250+VAT/month, everything included
Who fixes the gapsYouUsually you, from their gap reportWe do
Failure riskHigh if the estate has drift - most first-time DIY attempts find gaps mid-questionnaireLower, but remediation quality variesLow - we don't submit until the controls genuinely pass
Year twoStart againAnother project feeIncluded - the controls never lapsed

The honest caveat on DIY: if you run a small, modern, well-disciplined Microsoft 365 estate with no legacy kit, self-assessment is genuinely achievable - our free readiness assessment will tell you in ten minutes whether you're close. Most businesses discover the gaps are real, and the gap between knowing and fixing is where the service earns its fee.

Pricing, in full

£250 + VAT per month covers standard scope - up to 49 employees - with the official IASME assessment fees (£320–£600+VAT by organisation size, verified August 2026) included rather than billed on top. Larger or multi-site organisations are tiered from the same floor and quoted before you commit; the full cost guide breaks down every component, including what DIY really costs once remediation is counted. Need the audited tier? Cyber Essentials Plus is £400 + VAT per month - enterprise customers, insurers and government buyers increasingly ask for it by name.

Why a monthly service and not a project

Because the certificate expires every 12 months and the controls drift the day after the assessor leaves. A one-off certification project leaves you owning that drift - new starters without MFA, patches slipping past the 14-day window, a firewall rule added in a hurry - and turns every renewal into a fresh scramble. The monthly service keeps the five controls continuously in the state the assessment expects, which is also exactly the posture your insurer and your supply chain think the certificate means. If certification matters enough to buy once, it matters enough to keep.

Why UK businesses get certified

43%of UK businesses reported a cyber breach or attack in the last 12 months (DSIT, 2025)
£320–£600+VAT - the official IASME assessment fees, included in our service (verified Aug 2026)
£25kcyber liability insurance included with certification for eligible orgs under £20m turnover
12 mocertificate validity - which is why certification is a service, not a project

What £250/month actually includes

All-in for standard scope (up to 49 employees). Larger organisations are tiered from the same floor.

Gap analysis

Your estate assessed against the current question set - every device, account and cloud service in scope, honestly scored.

Remediation - done for you

We fix what falls short: MFA enforcement, access control, patching discipline, firewall baselines, unsupported software retired. Not a gap list and good luck - the work itself.

Submission handled

Questionnaire completed with you and submitted; official IASME assessment fees are included in the monthly price.

Annual re-certification

Certificates expire every 12 months. We keep the controls in shape between renewals, so next year's certification is a formality, not a project.

Accredited delivery

Delivered in partnership with an IASME-accredited certification body - the certificate you receive is the real, register-verifiable article.

A provider that passes it too

AMVIA holds Cyber Essentials Plus ourselves. Your controls are implemented by people audited against the same standard.

From signup to certified

Typically 30–45 days to initial certification, then a monthly rhythm that keeps you there.

01

Gap analysis (week 1)

We map your devices, accounts, cloud services and network boundary against the five controls and agree the remediation plan.

02

Remediation (weeks 2–5)

MFA rolled out, admin rights tightened, patching brought inside the 14-day window, firewalls baselined, end-of-life software replaced - done by our engineers, not left as homework.

03

Submission & certification

Questionnaire completed and submitted through our IASME-accredited certification body partner. Fees included; certificate issued and verifiable on the official register.

04

Stay certified

Monthly control checks, drift fixed as it appears, and the annual re-certification handled - the part a one-off project never covers.

Why certify with AMVIA

The difference is who does the remediation - and what happens in month thirteen.

We do the work

Most providers sell you the assessment and leave the remediation with your team. Ours includes it - because the remediation is the certification.

Published pricing

£250 + VAT/month, on the page, before you talk to anyone. Larger estates tiered from the same floor, quoted before you commit.

Built for year two

Annual renewal is in the price and in the operating rhythm. Certification that lapses eleven months from now wasn't a service - it was a transaction.

A path, not a ceiling

The same team runs managed detection and response, Microsoft 365 security and vulnerability management - when you're ready for more than the baseline, nothing gets rebuilt.

Client testimonial coming soon. AMVIA protects over 1,200 UK businesses.

AMVIA Client

Cyber Essentials Certification Service Pricing

PlanFrom / monthResponse TargetIncludes
Cyber Essentialsfrom £250.00Initial certification typically 30–45 daysGap analysis, remediation, submission, annual re-certification
Cyber Essentials PlusAudited tierfrom £400.00Initial certification typically 45–60 daysEverything in CE + independent technical audit with evidence collection

Your certification price, instantly

Two inputs, no email address required. Standard scope is priced flat; larger estates are tiered and confirmed on a 15-minute call.

Ready when you are

Standard scope starts at £250 + VAT/month with nothing else to buy. Tell us about your business and the team will confirm scope and start the gap analysis this week.

Cyber Essentials certification - your questions

Free tool

Not sure where you stand?

Take the free 20-question readiness assessment - instant per-control results in your browser, and a printable gap report to bring to the call.

Talk it through first?

Fifteen minutes with the certification team: your scope, your timeline, your exact price. No pressure - the pricing is already public.

Trusted by 1,200+ UK Businesses
Cyber Essentials Plus
IASME-Accredited Delivery Partner
Microsoft MSSP - Managed Security Service Provider