Skip to main content

Cyber Security

Cyber Essentials support

Cyber Essentials support: we prepare your systems and evidence against the five controls, explain CE versus CE Plus and work with your IASME assessor.

In short

Cyber Essentials is the UK government-backed scheme, run by the NCSC with IASME as the certification body, that checks five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. Dig IT Solutions gets your systems and evidence ready, helps you complete the self-assessment and works with the assessor if you go for Cyber Essentials Plus.

When you need this

Signs this is the right conversation

  • A client or tender requires Cyber Essentials and we don't know where to start.
  • We tried the self-assessment and failed on questions we didn't understand.
  • We're not sure whether we need Cyber Essentials or Cyber Essentials Plus.
  • Our current provider says we're compliant but has never shown evidence.
  • We have old devices and software that we suspect will fail us.

Scope

What we deliver

  • 01

    Gap analysis

    Your current setup reviewed against the five controls and the current requirements, with a list of what passes, what needs work and what needs replacing.

  • 02

    Remediation

    Fixing the gaps: MFA enforcement, removing unsupported software, firewall and device configuration, patch compliance, admin account separation, endpoint protection.

  • 03

    Scope definition

    Deciding which devices, networks and cloud services are in scope, and documenting them, which is where many self-assessments go wrong.

  • 04

    Self-assessment completion

    Help answering the questionnaire accurately, with evidence for each answer so it stands up if challenged.

  • 05

    Cyber Essentials Plus preparation

    Getting devices ready for the assessor's vulnerability scans and tests, and coordinating the assessment day with your IASME-licensed certification body.

  • 06

    Ongoing compliance

    Monthly patching, monitoring and access reviews so you stay compliant between annual renewals rather than scrambling each year.

Outcomes

What you get out of it

  • A realistic view of how far you are from certification before you pay for it.
  • Systems that meet the controls in practice, not just on paper.
  • Evidence organised for assessment and renewal.
  • Tender and supply-chain requirements satisfied.

FAQ

Questions we are asked

Straight answers. If yours is not here, call 020 8482 4020 or 01992 939 365 and ask an engineer.
What are the five Cyber Essentials controls?
Firewalls (boundary and device firewalls configured properly), secure configuration (removing defaults and unnecessary features), security update management (applying critical patches promptly on supported software), user access control (unique accounts, MFA, minimal admin rights, prompt removal of leavers) and malware protection (antivirus or EDR, application controls). Full detail is at https://www.ncsc.gov.uk/cyberessentials/overview.
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is a self-assessment questionnaire reviewed by a certification body. Cyber Essentials Plus covers the same five controls but adds an independent technical audit: an assessor scans your devices, tests malware protection and checks configurations. Plus is more rigorous and costs more, and is increasingly required by larger clients and public-sector contracts. Most firms start with the basic level.
How hard is it to get Cyber Essentials certification?
For a well-maintained Microsoft 365 environment with managed, patched devices and MFA, it is achievable with modest effort. Difficulty rises where there are unsupported operating systems, devices staff own, shared accounts, no patching process or unclear scope. Most failures come from unclear answers rather than bad security. A gap analysis first tells you which camp you're in.
How much does Cyber Essentials cost?
The certification fee is set by IASME and depends on organisation size, with Plus priced separately by the certification body based on the assessment work. Our preparation and remediation work is quoted fixed-price after the gap analysis. The bigger cost is usually fixing gaps such as replacing unsupported devices. Current fees are at https://iasme.co.uk/cyber-essentials/ and we'll give a full breakdown.
Is Dig IT Solutions a Cyber Essentials certification body?
No. Certification is issued through IASME and its licensed certification bodies. Our role is to prepare your systems and evidence, help you complete the self-assessment accurately, and work alongside the assessor for Cyber Essentials Plus. We'll help you choose a certification body if you don't already have one. Keeping preparation and assessment separate is how the scheme is designed.
Is Cyber Essentials worth it?
For most small businesses, yes. The controls are the same ones that stop the majority of common attacks, so the work improves security regardless of the badge. The certificate opens tenders that require it and satisfies many supplier questionnaires. IASME also offers cyber insurance to eligible UK organisations that certify, so check the current terms at iasme.co.uk when you apply.

Next step

Talk to an engineer, not a sales script

Tell us what is not working, or what you are planning, and we will give you a straight view on what it would take to fix.

WhatsApp us