Cyber Essentials & Cyber Essentials Plus – Pass First Time
Pass Cyber Essentials under the 2026 rules: MFA on all cloud services, 14-day patching.
Readiness check, remediation & Plus support for UK SMEs.
Assessment
Until You Pass
Technical Testing Prep
14-Day Patching Covered
27001 Lead Implementers
Leadership
Certified Company
Why Cyber Essentials Still Matters in 2026
Cyber Essentials is the UK Government-backed certification that proves your business has the fundamental security controls in place to defend against the most common cyber attacks. Increasingly it is a hard requirement: government contracts, enterprise procurement teams and cyber insurers all ask for it. Without it, you are invisible to an entire tier of clients.
What Changed in the 2026 Cyber Essentials Rules
The certification requirements have been tightened. Businesses that passed under older rules are now failing renewal because the goalposts have moved:
- Multi-factor authentication on every cloud service – MFA is now mandatory on all cloud services in scope wherever it is available, not just email and admin accounts. A single missed SaaS account can fail the assessment.
- 14-day patching requirement – critical and high-severity security updates must be applied within 14 days of release on every in-scope device – including laptops, servers, firewalls and mobile devices.
- Full device scope – all devices that access organisational data or services count, including BYOD and remote-worker home setups.
- Stricter evidence for Plus – Cyber Essentials Plus technical testing now requires demonstrable proof that controls work, not just policy statements.
The Five Cyber Essentials Controls We Implement
1. Firewalls & Internet Gateways
Correctly configured boundary firewalls on every internet connection – default credentials changed, unnecessary services blocked, admin access restricted.
2. Secure Configuration
Devices hardened to a secure baseline – unused accounts and software removed, default passwords changed, auto-run disabled, screen locks enforced.
3. User Access Control
Least-privilege access for every account – admin rights granted only where needed, unique accounts per user, MFA enforced on all cloud services as required by the 2026 rules.
4. Malware Protection
Active anti-malware on every device – centrally managed where possible, real-time scanning enabled, and definitions updating automatically.
5. Security Update Management
Patch management that meets the 14-day rule – every OS and application kept supported, licensed and patched within the certification window. Our managed Essential Care platform tracks this continuously, so renewal is never a scramble.
How We Get You Certified
1. Cyber Essentials Readiness Check
A fixed-fee gap assessment of your environment against the current certification requirements. You receive a plain-English report showing exactly which controls pass, which fail, and precisely what needs to change – before you pay for the assessment itself.
2. Remediation Support
We fix the gaps for you – enforcing MFA across your cloud services, bringing patching inside the 14-day window, hardening device configurations and deploying compliant endpoint protection. Then we guide you through the self-assessment questionnaire so your answers are accurate and defensible.
3. Cyber Essentials Plus Support
For Plus, an accredited assessor runs hands-on technical tests on your devices. We prepare your environment in advance – internal vulnerability scans, device sampling checks and remediation – so there are no surprises on test day.
Who is this for:
UK SMEs bidding on government or enterprise contracts, businesses whose cyber insurance requires certification, and any organisation that wants an independently verified security baseline. If you already use our Essential Care, Secure Business or Cyber Shield packages, most of the technical controls are already in place – certification becomes a paperwork exercise.
Cyber Essentials Frequently Asked Questions
Cyber Essentials Support Across Hertfordshire, North London & Surrey
Our office in Borehamwood, Hertfordshire means we can assess and remediate on-site across Hertfordshire, North London and
the M25 south-west corridor into Surrey. For remote-first teams we deliver the complete readiness and remediation
programme virtually with no reduction in quality.
Hertfordshire: Borehamwood, Elstree, Radlett, Watford, St Albans, Potters Bar, Hatfield, Welwyn.
North & West London: Barnet, Edgware, Harrow, Enfield, Finchley.
Surrey / M25 South-West: Chertsey, Staines, Egham, Weybridge, Woking.
Remote support across the UK.
Ready to Pass Cyber Essentials First Time?
Book a free readiness check. We will review your environment
against the 2026 requirements and give you a clear, fixed-fee plan
to certification with no obligation.
Also see our ISO 27001 Compliance service