New episode of The Scale Up Podcast out now. Lessons from Scaling a High Growth Tech Business, Now Building in AI – Listen now on Spotify

Let's break the ice

* required fields
We aim to respond within 48 hours

Cyber Essentialscertification

Our expert in-house team work alongside SMEs every single day. We’re uniquely positioned in being fully qualified to conduct the audit, but grounded in the real-world challenges businesses face, making the process straightforward and focused on getting you certified.

Fully Accredited

In this video Luke Nix, one of our technical consultants, talks through our Cyber Essentials offerings, and how impactful it can be for your business.

Luke Nix

technical account manager

proudly supporting our clients

Cyber Essentials vs Cyber Essentials Pluswhat's the difference?

Cyber Essentials

Cyber Essentials is a UK government-backed cyber security certification that helps organisations protect themselves against the most common online threats.

The scheme focuses on five key technical controls including firewalls, secure system configuration, access control, malware protection and regular security updates.

As an authorised Cyber Essentials certification body, bzb IT carries out the assessment and certification process, reviewing your organisation’s security controls to confirm they meet the required standard.

Cyber Essentials Plus

Cyber Essentials Plus verifies the same five security controls as Cyber Essentials, but with an independent technical audit to demonstrate they are correctly implemented.

While Cyber Essentials is based on a self-assessment questionnaire, Cyber Essentials Plus involves hands-on testing by a qualified assessor to confirm systems are protected against common cyber threats.

As an authorised certification body, bzb IT carries out the Cyber Essentials Plus audit directly, testing systems and verifying compliance before certification is awarded.

Need help making changes before or after the audit?

This page focuses on Cyber Essentials audit and certification.

If you would like hands on support implementing changes identified during assessment, we also offer dedicated Cyber Essentials consultancy delivered by our cyber advisors. This service is optional and separate from the certification process.

You can learn more on our Cyber Essentials Consultancy page.

Choose your certification route

Cyber Essentials

Support Package One

Independent questionnaire assessment

Cyber Essentials is a formal self-assessment reviewed by an accredited Certification Body.

You complete the Government defined questionnaire and provide supporting evidence. One of our qualified assessors reviews your submission against the scheme requirements and issues a pass or fail outcome.

If improvements are required, we explain the findings clearly so you can remediate and resubmit when ready.

 

starting from

£1100

Cyber Essentials Plus

Support Package Two

Audited technical verification

Cyber Essentials Plus includes the same requirements as Cyber Essentials, with the addition of a technical audit carried out by a qualified assessor.

We validate that required controls are operating effectively across your environment. Where issues are identified, we provide clear audit feedback so you understand exactly what needs to be addressed before certification can be achieved.

 

starting from

£1650

Cyber Essentials Plus Guided

Support Package Three

Cyber Essentials Plus guided includes all the requirements of Cyber Essentials, with the addition of a hands on technical audit carried out by a qualified assessor.

With our guided approach, we don’t just assess your environment, we support you throughout the audit process. We work alongside you to validate that required controls are operating effectively, helping you understand any issues as they arise. Making sure you aren’t left on your own.

 

starting from

£2200

Successful Cyber EssentialsJourney

People Group Services

“As a payroll services provider, the security of our IT is a top priority. I often see articles about security breaches, but day-to-day it can seem quite intangible. We wanted a way to prove — both to ourselves and to our customers — that the necessary security controls are in place to ensure our data is protected at all times.

That’s where bzb IT came in. They are our outsourced IT support provider and are also qualified to carry out Cyber Essentials Plus assessments. This was a win-win for us: they already manage our infrastructure and have a great relationship with the whole team.

They handled the entire process from start to finish and ensured nothing slipped through the net. The assessment highlighted an issue we needed to resolve, which they quickly took care of for us.

Now that we’ve successfully passed the Cyber Essentials Plus certification, we can confidently demonstrate to our customers that we take the security of their data seriously and have the right protections in place.

Thanks, bzb IT team!”

 

 

Michael Hillier

Operations Director

Why your business needsCyber Essentials

  • GDPR compliance

    Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

  • Public Sector Contracts

    Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

  • Free Cyber Insurance

    Give you up to £25k free cyber insurance. Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

  • Evidencing Shareholders

    Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

  • Prevent 80% of attacks

    Prevent 80% of cyber attack. Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

The team behindbzb IT

A Certification Bodyyou can trust

All Cyber Essentials and Cyber Essentials Plus assessments are carried out by our own in-house team, who understand the realities of SME IT because we work with businesses like yours day in, day out.

This means you benefit from an independent, evidence-based assessment, clear explanations of audit outcomes, and practical guidance on what needs to change to meet the standard.

There is no outsourcing or hand-offs throughout the process, and certification decisions are always aligned with IASME guidance and the official scheme requirements.

FAQs

Explore answers to frequently asked questions to help you find out more.

View all FAQs

Yes. Your systems should already meet the Cyber Essentials requirements before the assessment begins. Our team can help review your environment beforehand and provide guidance on any changes needed to ensure you are ready for the certification process.

The timeline depends on the size and complexity of your organisation, but most assessments can be completed within a few days once your environment is ready. We work with you to schedule testing in a way that minimises disruption to your business.

Most of the testing involved in a Cyber Essentials Plus assessment is designed to be non disruptive. We work with you to schedule testing at suitable times and explain exactly what will be tested in advance so there are no surprises for your team.

If any issues are identified, we will clearly explain what the findings mean and what needs to change to meet the Cyber Essentials requirements. As an assessor, we cannot remediate or fix the issues ourselves, but we will point you in the right direction and provide practical guidance so you can address them and move forward with certification.

If you are not ready yet, or you have previously failed and need remediation, we can help you understand what needs to change. We offer a discovery call to review your current setup and discuss the gaps against the Cyber Essentials requirements. From there we can recommend the next steps, whether that is a one off remediation project or support as part of an ongoing managed IT service.

Start or Renew your Cyber Essentials with Luke