Cyber Essentials Certification UK
Managed Cyber Essentials certification by an active IASME assessor. We complete and verify your self-assessment of the five controls, then issue your certificate directly. Optional consultancy with pre-submission gap analysis, and 48-hour expedited certification where you need it fast.
- IASME assessor
- Pre-submission gap analysis
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
core controls, verified and issued by an IASME assessor. Certification in days, not weeks, with a fixed price agreed up front.
Cyber Essentials, the certification that wins contracts.
Cyber Essentials is a government-backed certification built around five technical controls. You self-assess against the controls, and an IASME assessor reviews your answers and issues the certificate. We manage the whole process, complete and verify the questionnaire with you, and list your certificate on the IASME registry.
For most organisations, Cyber Essentials is the baseline that unlocks tenders and supplier frameworks. It is widely accepted as the entry requirement for UK government contracts, NHS DSPT, and enterprise procurement, and it is recognised by cyber-insurance underwriters as a maturity signal. We are an active certification body licensed by IASME, verifiable on the IASME registry.
When a contract calls for independently audited assurance, Cyber Essentials Plus is the audited next step: the same five controls tested hands-on by an assessor. You can certify to Cyber Essentials now and add Plus when you need it.
THE FIVE CONTROLS
The 5 Controls You Certify Against
Cyber Essentials certifies your organisation against five technical controls. You declare how you meet each one, and we verify it before submission.
Boundary Firewalls & Gateways
You declare that every device on your boundary, firewalls and internet gateways, is configured to block unapproved connections, with administrative interfaces protected and default rules tightened.
Secure Configuration
You declare that devices and software are built securely: default passwords changed, unnecessary accounts and services removed, and only the functions you need enabled.
User Access Control
You declare that user accounts are assigned to named individuals, administrative privileges are controlled and separated, and multi-factor authentication is in place where required.
Malware Protection
You declare that all in-scope devices are protected against malware, whether by anti-malware software, application allow-listing, or sandboxing, kept up to date.
Security Update Management
You declare that operating systems, browsers and applications are licensed, supported and patched, with critical and high-risk updates applied within the required timeframe.
THREE-STEP PROCESS
Cyber Essentials: From Gap Analysis to Certificate
Optional gap analysis, a verified self-assessment, and direct certificate issuance by our IASME assessor.
Gap Analysis
On the consultancy tier we review your environment against the five controls, flag anything that would fail, and tell you exactly what to put right so you pass first time.
Self-Assessment Questionnaire
We complete the Cyber Essentials questionnaire with you and our IASME assessor verifies every answer against the five controls before submission.
Assessor Review & Certificate Issuance
Our IASME assessor reviews the verified submission and issues your Cyber Essentials certificate directly, listed on the IASME registry, with an annual renewal cycle.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a fixed Cyber Essentials quote in 24 hours
A fixed-price Cyber Essentials quote back in one business day from a named IASME assessor, with an optional pre-submission gap analysis. No sales pipeline.
- IASME assessor delivery. Cyber Essentials certification your auditors and clients already recognise.
- Pre-submission gap analysis to ensure first-time pass. Issues identified before you submit, over 95% first-time pass.
- Direct IASME certificate issuance, listed on the IASME registry.
- Fixed price, agreed after a short scoping call. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named IASME assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Pre-submission gap analysis identifies issues before you submit, and we advise you on exactly what to implement so you pass first time.
- We send the Cyber Essentials questionnaire and analyse your responses.
- Once you pass, we issue your IASME-stamped certificate and list it on the IASME registry.
Get your fixed Cyber Essentials quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named IASME assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Cyber Essentials Mapped to Every Framework
Cyber Essentials is the entry baseline recognised across UK procurement, regulatory and insurance frameworks.
UK Government Supplier
Cyber Essentials is the baseline entry requirement for many UK government contracts. CCS framework, G-Cloud framework and NHS supplier framework participation commonly start here.
NHS DSPT
Cyber Essentials is recognised evidence for the NHS Data Security and Protection Toolkit, covering boundary control, secure configuration and malware protection.
Cyber Insurance
UK cyber-insurance underwriters recognise Cyber Essentials as a baseline maturity signal, and many policies expect it as a minimum for cover or renewal.
Enterprise Procurement
Cyber Essentials is the de facto baseline for enterprise vendor onboarding, the certificate buyers ask for first when assessing new suppliers.
IASME Cyber Assurance
Once you hold Cyber Essentials, IASME Cyber Assurance is the next tier up. Aligned to ISO 27001 but a lighter-touch certification process.
ISO 27001 Foundation
The Cyber Essentials control set is a foundation for ISO 27001, mapping to a subset of Annex A controls (A.13 networking, A.12.6 vulnerabilities, A.9 access).
PRICING
Transparent Cyber Essentials Pricing
All tiers are IASME assessor delivery, fixed-price after a short scoping call. Prices exclude VAT.
+ VAT · managed certification
We manage the whole certification: submission and direct liaison with IASME. Best for organisations already confident they meet the five controls.
Get a fixed quote+ VAT · 48-hour expedited
End-to-end certification plus expert-led support: targeted gap analysis against your requirements and hands-on remediation guidance. Expedited processing, certified within 48 hours where other providers take 5 to 8 days.
Get a fixed quote+ VAT · the audited next tier
Need an independently audited certificate? Cyber Essentials Plus tests the same five controls hands-on, with boundary and internal vulnerability scans. Requires a valid Cyber Essentials first. 50 to 250 employees £1,200 to £3,500; 250+ or complex cloud £3,500+.
Explore Cyber Essentials PlusAll quotes are fixed-price after a short scoping call.
BY SECTOR
Cyber Essentials for Your Sector
Cyber Essentials is the certificate buyers ask for first across every sector, from startups winning their first contract to established suppliers. We also test schools, colleges and multi academy trusts, with education penetration testing scoped around term dates.
Fintech
Fintech startups and FCA-regulated firms winning their first enterprise and payment-partner contracts.
Fintech sector pageSaaS
SaaS suppliers proving baseline security to enterprise buyers and accelerating vendor onboarding.
SaaS sector pageLaw
Law firms meeting client and SRA expectations with a recognised baseline certification.
Law firm sector pageHealthcare
Healthcare and health-tech suppliers evidencing the NHS DSPT baseline for NHS supply-chain work.
Healthcare sector pageInsurance
Insurance and brokerage firms demonstrating baseline cyber hygiene to underwriters and partners.
Insurance sector pagePublic Sector
Smaller public-sector suppliers meeting the entry requirement for CCS and G-Cloud frameworks.
Public sector pageWHY EJN LABS
What You Actually Get
Six things that distinguish our managed Cyber Essentials service from a DIY self-assessment.
Managed Submission
We complete and submit the Cyber Essentials self-assessment with you and liaise with IASME directly, so you never wrestle with the portal alone.
48-Hour Expedited Certification
Cyber Essentials with consultancy support, certified within 48 hours where other providers take 5 to 8 days.
IASME Certification Body
We are an active certification body licensed by IASME and issue your certificate directly, listed and verifiable on the IASME registry.
Pre-Submission Gap Analysis
On the consultancy tier we identify any failing controls before you submit. First-time-pass rate above 95% for clients who complete gap analysis.
Fixed Price, No Surprises
One fixed price agreed after a short scoping call, with no hidden fees, no cancellation charges and free rescheduling.
UK CREST + IASME + ISO 27001 + ISO 9001
Multi-accredited and independently verifiable. Reports and certificates accepted by every UK auditor, regulator and procurement framework.
FAQ
Frequently Asked
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials (CE) is a self-assessment questionnaire; you confirm how you meet the five controls in writing, and an IASME assessor reviews your answers and issues the certificate. Cyber Essentials Plus (CE+) is the audited next step: an assessor independently tests the same five controls hands-on. Most organisations start with Cyber Essentials and add Plus when a contract requires it.
Is Cyber Essentials a self-assessment?
Yes. Cyber Essentials is a verified self-assessment: you declare how you meet the five technical controls, and an IASME assessor checks your answers before certifying. We manage the questionnaire with you so it is completed correctly first time.
Who verifies my Cyber Essentials answers?
An IASME assessor. We are an active IASME certification body, so your submission is reviewed and your certificate issued in-house, not passed to a third party. Your certificate is listed on the IASME registry.
Can we do Cyber Essentials without Cyber Essentials Plus?
Yes. Cyber Essentials is a standalone certification and is all most organisations need for procurement and supplier frameworks. Cyber Essentials Plus is optional and only required when a contract specifically calls for an independently audited certificate. You can always upgrade later.
How much does Cyber Essentials cost in the UK?
Cyber Essentials from £400 + VAT (managed), or £600 + VAT with consultancy support and 48-hour expedited certification. All quotes are fixed-price after a short scoping call, with no hidden fees.
What are the 5 controls?
Cyber Essentials covers five technical controls: boundary firewalls and gateways, secure configuration, user access control, malware protection, and security update management. You declare how you meet each one and we verify it before submission.
Are you an IASME Certification Body?
Yes. We are an active IASME Cyber Essentials certification body, verifiable on the IASME registry. Our IASME accreditation is independent and externally audited.
Do you offer pre-submission gap analysis?
Yes. Our consultancy tier includes a pre-submission gap analysis. We review your environment against the five controls before you submit, identify anything that would fail, and tell you exactly what to put right. First-time-pass rate above 95% for clients who complete gap analysis.
How long is a Cyber Essentials certificate valid?
A Cyber Essentials certificate is valid for 12 months. You recertify annually to keep it current. We send an annual recertification reminder so your certificate never lapses between contract renewals.
What is IASME Cyber Assurance?
IASME Cyber Assurance is a more comprehensive certification that goes beyond Cyber Essentials. It is aligned to ISO 27001 (covering similar control areas) but uses a lighter-touch process. Suitable for organisations that need more rigour than Cyber Essentials but find ISO 27001 disproportionate.
How often must we recertify?
Cyber Essentials is an annual certification. Recertification typically takes 80 to 90% of the original effort, focused on what has changed since the prior year. We send an annual reminder and can manage the renewal for you.
Do you sign NDAs?
Yes. Standard NDA before any detail is shared. We operate under a project-specific master agreement that includes data handling, deliverable IP, and breach notification clauses.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a fixed Cyber Essentials quote in 24 hours
An IASME assessor will contact you within one business day with a fixed-price Cyber Essentials quote and an optional pre-submission gap analysis. No sales pipeline.



