Firewalls & internet connections
A properly configured boundary between your network and the internet — default passwords changed, inbound access locked down, and admin interfaces kept off the open web.
Cyber Essentials is the UK government-backed security baseline — and for a growing number of contracts, tenders and insurers, it’s the price of entry. We take Sheffield and Yorkshire businesses from wherever they are today to a certifiable baseline, with the remediation built into onboarding rather than billed as a surprise project.
Cyber Essentials is a government-backed scheme, run by IASME, that certifies you have five fundamental security controls in place. It’s deliberately about the basics — the controls that stop the overwhelming majority of common, opportunistic attacks — rather than a deep technical audit. That focus is its strength: it’s achievable for a small business, and it’s widely recognised.
It increasingly turns up where it counts. It’s mandatory for many central-government and MOD-linked contracts, frequently requested in tenders and supplier due-diligence, and it smooths the path with cyber-insurers. Even when no one is asking for it, the certificate is a clean, defensible way to show clients and partners that you take security seriously.
Cyber Essentials checks five practical control areas. Get these right and you’ve closed the doors most attackers walk through.
A properly configured boundary between your network and the internet — default passwords changed, inbound access locked down, and admin interfaces kept off the open web.
Devices and software set up to reduce their attack surface: no unnecessary accounts, services or default settings left exposed, and auto-run risks turned off.
Supported software and timely patching, so known vulnerabilities are closed before they’re exploited — with critical fixes applied within 14 days and automatic updates on wherever possible.
The right people with the right access, multi-factor authentication on accounts, and administrator rights rationed to those who genuinely need them.
Anti-malware or approved-application controls on devices and servers, so malicious software is blocked or simply prevented from running in the first place.
Run our free, plain-English readiness check — it mirrors these five areas and gives you an honest read before you apply.
Try the readiness check ->Both cover the same five controls. The difference is how they’re verified — and Plus carries more weight where assurance really matters.
A verified self-assessment. You complete a questionnaire about your security and a certification body checks it before the certificate is issued. The right starting point for most businesses — and a prerequisite for Plus.
Everything in Cyber Essentials, plus a hands-on technical audit. An assessor independently tests a sample of your devices and systems to confirm the controls really are in place — the version insurers and larger supply chains often ask for.
There are two parts to it. The certification fee itself is set by IASME and banded by the size of your organisation, so a micro business pays less than a larger one. The bigger variable is usually the remediation — the work to bring your systems up to the standard before you apply. That’s where most of the real cost, and most of the surprises, live.
We handle that differently. For managed clients, the remediation needed to reach a certifiable baseline is built into onboarding with no upfront project fee, and the secure baseline every client is brought up to is set out in the NorthMSP Standard. You get a clear, specific figure for your environment before anything starts — not an open-ended bill once we’re halfway in.
There are two parts. The certification fee itself is set by IASME, the body that runs the scheme, and is banded by the size of your organisation — so a micro business pays less than a larger one. The bigger variable is usually the remediation: the work to bring your systems up to the standard before you apply. For NorthMSP clients that remediation is built into onboarding with no upfront project fee, so the cost is predictable rather than a surprise bill. We’ll give you a clear figure for your specific environment before anything starts.
Cyber Essentials is a self-assessment: you complete a questionnaire about your security and it’s verified by a certification body. Cyber Essentials Plus covers the same five controls but adds a hands-on technical audit — an assessor independently tests a sample of your devices and systems to confirm the controls really are in place. Plus carries more weight with insurers and in supply chains, and you need the base certification first. We can take you through either.
For a reasonably well-run environment the assessment itself is quick, often a matter of days once everything is in order. The honest answer is that the timeline depends on how much remediation is needed first; legacy kit, unmanaged devices or third-party systems can add time. We scope that up front so there are no surprises, and we won’t promise a date that depends on things outside our control.
It’s not legally mandatory for most businesses, but it’s increasingly expected. It’s required for many government and MOD-linked contracts, often asked for in tenders and supply chains, and frequently reduces cyber-insurance friction. Even where no one’s demanding it, it’s a recognised, defensible baseline — a straightforward way to show you take security seriously.
Yes. We’re Sheffield-based and work across South Yorkshire and the wider North, but Cyber Essentials is delivered largely remotely, so location isn’t a barrier. If you’re nearby we’re happy to come on-site; if you’re further afield we can run the whole thing remotely.
Tell us where you are today and we’ll map the route to a clean Cyber Essentials pass — what’s already in place, what needs tidying, and what it’ll cost. No jargon, no pressure.