UK Government-backed baseline

Get ready for Cyber Essentials certification.

Practical support to define the assessment scope, fix technical gaps, prepare the questionnaire and approach the independent assessment with confidence.

39Security provides preparation and remediation support. Certification is awarded by an authorised Cyber Essentials Certification Body. Independent assessment fees are not included in our package prices.

Choose your support

Cyber Essentials packages

Start with a focused review, choose hands-on preparation, prepare for Cyber Essentials Plus, or keep the controls under review for annual renewal.

Cyber Essentials Readiness Review

A focused gap review against the current Cyber Essentials requirements.

£395 one-off · ex. VAT

  • Scope and asset review
  • Gap review against the five technical controls
  • Prioritised remediation plan
  • 60-minute findings workshop
  • Independent certification fee not included

Cyber Essentials Plus Preparation

Technical preparation for the independently verified Cyber Essentials Plus assessment.

£2,495 one-off · ex. VAT

  • Cyber Essentials baseline validation
  • Device and software sampling preparation
  • Vulnerability and patch readiness checks
  • Remote-access and malware-protection validation
  • Mock technical evidence review
  • Independent audit and certification fee quoted separately

Cyber Essentials Renewal Care

Keep the five controls under review throughout the year and prepare early for annual renewal.

£149/monthex. VAT

£295 one-off · ex. VAT

  • Quarterly control review
  • Asset and software register updates
  • Security update and unsupported-software checks
  • Annual renewal planning workshop
  • Questionnaire change support
  • Independent certification fee not included

Prices are shown excluding VAT. UK VAT at 20% is added at checkout. The independent basic certification price is set by the scheme and varies by organisation size; Cyber Essentials Plus is separately scoped and quoted by the Certification Body.

Current requirements

The five technical controls

The current Cyber Essentials Requirements for IT Infrastructure v3.3, effective for assessment accounts created from 27 April 2026, organise the assessment around five practical controls intended to reduce exposure to common internet-based attacks.

Firewalls

Control traffic between the internet, business networks and devices, including home and remote-working connections.

Secure configuration

Remove unnecessary services and accounts, change insecure defaults and configure systems to reduce opportunities for attack.

Security update management

Keep operating systems, applications, firmware and cloud services supported and apply vulnerability fixes within the required timescale.

User access control

Give people the access they need, protect administrator privileges and use strong authentication controls.

Malware protection

Use appropriate anti-malware, application controls and platform protections to prevent or contain malicious software.

How it works

From scope to certificate

  1. Define the scope. Confirm legal entity, networks, cloud services, devices, users and any exclusions.
  2. Review the controls. Compare the current environment with the latest Cyber Essentials requirements.
  3. Remediate gaps. Fix unsupported software, access, patching, firewall, configuration and malware-protection issues.
  4. Prepare the evidence. Build accurate asset, software and control records and complete the questionnaire.
  5. Independent assessment. Submit through an authorised Certification Body. Cyber Essentials Plus adds independent technical verification.

Independent scheme fees

The Cyber Essentials assessment fee is separate from 39Security consulting and remediation. IASME publishes tiered pricing based on employee count, starting from £320 plus VAT for a micro-organisation. Cyber Essentials Plus is priced by the Certification Body after scope review.

View IASME pricing guidance ↗

View the NCSC Cyber Essentials overview and current requirements ↗

Questions

Cyber Essentials FAQ

Does 39Security issue the Cyber Essentials certificate?

No. 39Security provides readiness, remediation and evidence support. Certification is assessed and issued by an authorised Cyber Essentials Certification Body.

Is the certification-body fee included?

No. The independent Cyber Essentials or Cyber Essentials Plus assessment fee is separate and is shown clearly before work begins.

What are the five Cyber Essentials controls?

The five controls are firewalls, secure configuration, security update management, user access control and malware protection.

How often is Cyber Essentials renewed?

Cyber Essentials certification is renewed annually. The Renewal Care package helps keep scope, devices, software and evidence under review during the year.

Not sure which package fits?

Start with the readiness review or speak to 39Security about your users, devices, cloud services and certification deadline.

Discuss certification