// Cyber Essentials & Compliance
Pass the security questions that win you work.
Securitise helps UK businesses achieve and keep Cyber Essentials and Cyber Essentials Plus, and answer security requirements from clients, lenders, insurers and regulators with confidence.
// Cyber Essentials explained
What is Cyber Essentials?
Cyber Essentials is the UK government-backed certification scheme, overseen by the National Cyber Security Centre (NCSC), that shows an organisation has basic technical controls in place against the most common cyber attacks. Cyber Essentials Plus adds hands-on technical verification by an independent assessor.
It covers five control areas, and the requirements are reviewed regularly, so controls must keep pace:
- Firewalls
- Secure configuration
- Security update management
- User access control
- Malware protection

// The result
Compliance that opens doors.
Certified, and staying that way
Cyber Essentials or Cyber Essentials Plus achieved, with controls kept in place so renewal is routine rather than a scramble.
Questionnaires answered
Security due-diligence questionnaires from banks, lenders, panels and corporate clients completed accurately, backed by controls that are really in place.
Ready for the next standard, and new regulation
Controls aligned with ISO 27001, CIS Controls and the NCSC Cyber Assessment Framework, the expectations of bodies like the FCA and RICS, and the supply-chain assurance that new UK cyber regulation will bring.
We hold Cyber Essentials certification ourselves, so we meet the same standard we help our clients achieve.
// Cyber Essentials questions
Questions we are often asked.
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is a verified self-assessment of five technical control areas. Cyber Essentials Plus covers the same controls but adds an independent, hands-on technical audit of your systems, including vulnerability scans and checks on a sample of devices.
How long does Cyber Essentials certification last?
Certification is valid for twelve months and must be renewed each year.
How much does Cyber Essentials cost?
The assessment fee is set by the certification body and depends mainly on the size of your organisation, with Cyber Essentials Plus costing more because it includes a technical audit. The bigger cost for most businesses is getting and keeping their systems compliant, which is where a managed provider helps.
What is the Cyber Security and Resilience Bill?
The Cyber Security and Resilience Bill is UK legislation that updates the NIS Regulations. It brings more organisations into scope, including managed service providers and data centres, strengthens incident reporting duties and gives regulators more powers. Even businesses outside its scope can expect clients and suppliers in regulated supply chains to ask for stronger security assurance.
Do we need a policy for staff using AI?
Yes. Clients, insurers and professional bodies increasingly ask how firms control the use of AI tools with confidential data. An AI acceptable-use policy, backed by technical controls, is quickly becoming a standard part of compliance. See AI and Copilot.
Who needs Cyber Essentials?
It is required for many UK government contracts and increasingly requested by corporate clients, lenders and cyber insurers. Any business that holds client data benefits from the discipline it brings.
// Find out more
See the approach behind the results.
Tell us a little about your business. We will show you what we would change, how we would do it, and what it would mean for you.