Cyber Essentials

Get certified. Know what you're fixing first.

Cyber Essentials is the UK government-backed certification scheme that demonstrates your organisation has the basic security controls in place. Xcevia helps SMEs prepare for certification by finding the gaps before the assessor does.

Two levels

Cyber Essentials vs Cyber Essentials Plus

Cyber Essentials

Self-assessed

You complete an online questionnaire covering the five controls. An assessor reviews your answers. If they meet the standard, you receive the certification.

  • Lower cost
  • Faster to complete
  • Accepted for most government contracts
  • Annual renewal required

Cyber Essentials Plus

Independently verified

Everything in Cyber Essentials, plus an independent technical audit carried out by an IASME-certified Certification Body. Higher assurance, required by some larger clients and contracts. Xcevia prepares you for this audit; we do not conduct or issue the certification ourselves.

  • Independently verified
  • Stronger signal to enterprise clients
  • Required by some MOD and NHS contracts
  • Includes vulnerability scanning and testing
What it covers

The five technical controls

Cyber Essentials is built around five controls. Most SMEs already meet some of them. The gaps are usually in configuration and patch management.

01

Firewalls

Boundary firewalls and internet gateways configured to block unauthorised access.

02

Secure configuration

Devices and software configured securely, removing unnecessary features and default credentials.

03

User access control

User accounts limited to what each person needs, with admin privileges tightly controlled.

04

Malware protection

Protection against viruses and malware through anti-malware software or application allow-listing.

05

Patch management

Software and devices kept up to date, with security patches applied within 14 days of release.

Where most SMEs fail

Unpatched software, default admin credentials, and overly permissive user accounts are the most common failure points. A gap assessment catches these before submission.

What we do

Find the gaps before the assessor does

Many businesses submit their Cyber Essentials questionnaire without a proper review first and get rejected, then have to fix issues under time pressure. Xcevia reviews your environment against the five controls beforehand, so you know exactly what needs fixing before you pay for certification.

Professional reviewing security compliance documentation
Get started

What's included

  • Review of your current environment against all five Cyber Essentials controls
  • Written gap report identifying what passes, what needs fixing, and how serious each gap is
  • Remediation checklist with specific, actionable steps, not generic advice
  • Readiness support ahead of your official assessment, whether that is the self-assessment questionnaire (CE) or the technical audit (CE+) carried out by an IASME-certified Certification Body
  • Support responding to queries from the certification body
  • Re-review once remediation is complete, before you submit

Who needs Cyber Essentials

Businesses bidding for UK public sector contracts (CE is mandatory for many)
SMEs required to demonstrate security posture to enterprise clients or insurers
Regulated organisations in finance, legal, or healthcare seeking baseline certification
Businesses that want a structured starting point for improving their security

How an engagement works

Every engagement starts with a written scope agreement covering systems in scope, timeline, and deliverables. No work begins until this is signed by both parties.

Ready to get certified?

Book a free 30-minute call. We'll review your current environment and tell you exactly where you stand before you commit to anything.

Book a free review