Cyber Essentials Certification for UK Businesses
发布时间:2026-08-10 | 浏览:1
Certified in 30–45 days, then kept certified: £250 + VAT per month, all-in — gap analysis, remediation done for you, submission with official fees included, and annual re-certification. Delivered in partnership with an IASME-accredited certification body, by a team that holds Cyber Essentials Plus itself.
AMVIA's Cyber Essentials certification service costs £250 + VAT per month, all-in for standard scope (up to 49 employees): gap analysis, hands-on remediation of the five technical controls, questionnaire submission with official IASME assessment fees included, and annual re-certification. Initial certification typically takes 30–45 days, delivered in partnership with an IASME-accredited certification body. Larger organisations are tiered from the same floor; Cyber Essentials Plus — the independently audited tier — is £400 + VAT per month.
What is Cyber Essentials?
Cyber Essentials is the UK government-backed certification, designed by the National Cyber Security Centre and operated through IASME, that proves your organisation has five fundamental technical controls in place: firewalls , secure configuration , user access control , malware protection and security update management . None of it is exotic — the scheme certifies disciplined execution of the basics, and the basics stop most of the commodity attacks UK SMEs actually face. With 43% of UK businesses reporting a breach or attack in the past 12 months (DSIT, Cyber Security Breaches Survey 2025), the baseline matters.
Three groups, in practice. Suppliers to government: certain UK central government and MoD contracts require Cyber Essentials outright, and prime contractors increasingly flow the requirement down their supply chains — for many SMEs the certificate is the difference between bidding and not bidding. The insured: UK cyber insurers increasingly ask CE-aligned questions at proposal and renewal, and basic certification through IASME includes cyber liability insurance for eligible organisations under £20 million turnover. Anyone being vetted: supplier security questionnaires now routinely ask for the certificate — you can check any company's status on the official register with our certificate checker , which is exactly what your customers do to you.
What we do vs what you do
DIY vs consultant vs AMVIA
The honest caveat on DIY: if you run a small, modern, well-disciplined Microsoft 365 estate with no legacy kit, self-assessment is genuinely achievable — our free readiness assessment will tell you in ten minutes whether you're close. Most businesses discover the gaps are real, and the gap between knowing and fixing is where the service earns its fee.
Pricing, in full
£250 + VAT per month covers standard scope — up to 49 employees — with the official IASME assessment fees (£320–£600+VAT by organisation size, verified August 2026) included rather than billed on top. Larger or multi-site organisations are tiered from the same floor and quoted before you commit; the full cost guide breaks down every component, including what DIY really costs once remediation is counted. Need the audited tier? Cyber Essentials Plus is £400 + VAT per month — enterprise customers, insurers and government buyers increasingly ask for it by name.
Why a monthly service and not a project
Because the certificate expires every 12 months and the controls drift the day after the assessor leaves. A one-off certification project leaves you owning that drift — new starters without MFA, patches slipping past the 14-day window, a firewall rule added in a hurry — and turns every renewal into a fresh scramble. The monthly service keeps the five controls continuously in the state the assessment expects, which is also exactly the posture your insurer and your supply chain think the certificate means. If certification matters enough to buy once, it matters enough to keep.
Why UK businesses get certified
What £250/month actually includes
All-in for standard scope (up to 49 employees). Larger organisations are tiered from the same floor.
Your estate assessed against the current question set — every device, account and cloud service in scope, honestly scored.
Remediation — done for you
We fix what falls short: MFA enforcement, access control, patching discipline, firewall baselines, unsupported software retired. Not a gap list and good luck — the work itself.
Submission handled
Questionnaire completed with you and submitted; official IASME assessment fees are included in the monthly price.
Annual re-certification
Certificates expire every 12 months. We keep the controls in shape between renewals, so next year's certification is a formality, not a project.
Accredited delivery
Delivered in partnership with an IASME-accredited certification body — the certificate you receive is the real, register-verifiable article.
A provider that passes it too
AMVIA holds Cyber Essentials Plus ourselves. Your controls are implemented by people audited against the same standard.
From signup to certified
Typically 30–45 days to initial certification, then a monthly rhythm that keeps you there.
Gap analysis (week 1)
We map your devices, accounts, cloud services and network boundary against the five controls and agree the remediation plan.
Remediation (weeks 2–5)
MFA rolled out, admin rights tightened, patching brought inside the 14-day window, firewalls baselined, end-of-life software replaced — done by our engineers, not left as homework.
Submission & certification
Questionnaire completed and submitted through our IASME-accredited certification body partner. Fees included; certificate issued and verifiable on the official register.
Monthly control checks, drift fixed as it appears, and the annual re-certification handled — the part a one-off project never covers.
Why certify with AMVIA
The difference is who does the remediation — and what happens in month thirteen.
Most providers sell you the assessment and leave the remediation with your team. Ours includes it — because the remediation is the certification.
Published pricing
£250 + VAT/month, on the page, before you talk to anyone. Larger estates tiered from the same floor, quoted before you commit.
Built for year two
Annual renewal is in the price and in the operating rhythm. Certification that lapses eleven months from now wasn't a service — it was a transaction.
A path, not a ceiling
The same team runs managed detection and response, Microsoft 365 security and vulnerability management — when you're ready for more than the baseline, nothing gets rebuilt.
Client testimonial coming soon. AMVIA protects over 1,200 UK businesses.
Cyber Essentials Certification Service Pricing
Your certification price, instantly
Two inputs, no email address required. Standard scope is priced flat; larger estates are tiered and confirmed on a 15-minute call.
Ready when you are
Standard scope starts at £250 + VAT/month with nothing else to buy. Tell us about your business and the team will confirm scope and start the gap analysis this week.
Cyber Essentials certification — your questions
How much does Cyber Essentials certification cost with AMVIA? expand_more
£250 + VAT per month, all-in for standard scope (up to 49 employees): gap analysis, remediation done by our engineers, questionnaire submission with the official IASME assessment fees included, and annual re-certification. Larger organisations are tiered from the same floor and quoted before commitment.
How long does Cyber Essentials certification take? expand_more
Typically 30–45 days from signup to certificate for standard scope: about a week of gap analysis, two to four weeks of remediation depending on what we find, then submission. A clean, modern estate can be faster; heavy legacy software is the usual thing that extends it — and we tell you at gap-analysis stage, not at week six.
What are the five Cyber Essentials controls? expand_more
Firewalls (every device behind a correctly configured boundary or software firewall), secure configuration (default passwords changed, unused software and accounts removed), user access control (least privilege, restricted admin rights, MFA on cloud services), malware protection (anti-malware or allow-listing on every in-scope device), and security update management (supported software only, high and critical patches within 14 days).
Is Cyber Essentials a legal requirement? expand_more
No — it's voluntary certification. But it's contractually required for certain UK government and MoD work, increasingly demanded down supply chains by prime contractors, and asked about by cyber insurers at proposal and renewal. For many businesses the commercial pressure makes it effectively mandatory even though no law does.
What's the difference between Cyber Essentials and Cyber Essentials Plus? expand_more
Both certify the same five controls. CE is a verified self-assessment — you answer the questionnaire, a qualified assessor reviews it. CE Plus adds an independent technical audit with tests run against your actual systems, which carries more weight with enterprise buyers, insurers and government. With AMVIA, CE is £250+VAT/month and Plus is £400+VAT/month.
Who actually certifies us — AMVIA or IASME? expand_more
Certification is issued through the official IASME scheme. AMVIA delivers the service — gap analysis, remediation, submission, renewals — in partnership with an IASME-accredited certification body, so the certificate you receive is the standard, register-verifiable Cyber Essentials certificate. You can confirm any certificate, including ours, with our free certificate checker.
What if we fail the assessment? expand_more
Our model makes that unlikely by design: we don't submit until the gap analysis says the controls genuinely pass, because we did the remediation ourselves. If an assessment does surface something, fixing it and resubmitting is part of the service — not a new invoice.
Do the official IASME fees cost extra? expand_more
No — the official assessment fees (£320+VAT for micro organisations, £440+VAT for small, rising to £600+VAT for large enterprises; verified August 2026) are included in the monthly price. There is nothing to pay on top for standard scope.
What does 'standard scope' mean? expand_more
Up to 49 employees with a typical single-organisation estate — the shape most UK SMEs are. More employees, multiple legal entities or unusually complex estates are tiered from the same £250/£400 floors, with the exact price confirmed on a 15-minute call before you commit to anything.
Does Cyber Essentials include insurance? expand_more
Basic Cyber Essentials certification through IASME includes cyber liability insurance (£25,000 indemnity) for eligible UK organisations with under £20 million turnover, at no extra cost. It's a useful baseline — not a substitute for a standalone cyber policy sized to your actual risk.
We use Microsoft 365 — does that make certification easier? expand_more
Considerably, if it's configured properly: MFA enforcement, access control and patching are all natively manageable. Misconfigured tenants are also one of the most common gap sources — our free Microsoft 365 security baseline check shows where yours stands, and tenant hardening is part of our remediation work.
Do home workers count in the scope? expand_more
Yes — devices used for business, wherever they are, are in scope, including home-worker laptops and BYOD phones accessing company data. This is one of the most commonly misunderstood scope areas and a routine gap-analysis finding; our remediation covers bringing remote devices under control.
What happens after we're certified? expand_more
The service keeps running: monthly control checks, drift fixed as it appears (new starters, new software, expiring configurations), and the annual re-certification handled on schedule. That continuity is the point of the monthly model — the certificate never lapses and renewal never becomes a project.
Can you certify us if another IT company runs our systems? expand_more
Yes — co-managed certification is common. We coordinate the remediation with your incumbent IT provider, or handle just the certification layer while they run day-to-day support. The responsibility split is agreed at gap-analysis stage so nobody's stepping on anyone.
Do you offer Cyber Essentials without the remediation? expand_more
We don't sell certification-only, because submitting an estate we haven't verified would put our name on something we can't stand behind. If you genuinely just need the assessment, the DIY route through IASME costs £320–£600+VAT — and our free readiness assessment will tell you honestly whether you're ready for it.
How do I check if a company has Cyber Essentials? expand_more
Search the official register operated by IASME on behalf of the NCSC — free, no account needed. Our certificate checker takes you straight there with the company name ready to search. Certificates expire after 12 months, so a supplier who 'has Cyber Essentials' from two years ago is not currently certified.
Will Cyber Essentials stop us being hacked? expand_more
It materially reduces the risk from commodity attacks — the automated, untargeted kind that make up most of what UK SMEs face — because the five controls close the doors those attacks use. It is not a complete security programme: it doesn't cover detection, response or user training, which is where managed detection and response picks up.
When should we go straight to Cyber Essentials Plus? expand_more
When a contract, insurer or customer names it specifically; when you handle data sensitive enough that self-assessment won't satisfy your stakeholders; or when you want the independent audit as genuine assurance rather than paperwork. The controls are identical — Plus proves them harder. If in doubt, start the conversation at CE and upgrade; the work transfers.
Not sure where you stand ?
Take the free 20-question readiness assessment — instant per-control results in your browser, and a printable gap report to bring to the call.
Talk it through first?
Fifteen minutes with the certification team: your scope, your timeline, your exact price. No pressure — the pricing is already public.
Certification resources
Cyber Essentials Plus — £400/month
The independently audited tier: technical audit, evidence collection, and the certificate enterprise buyers ask for by name.
Cyber Essentials cost, in full
Official fees, what drives Plus audit costs, and what DIY really costs once remediation is counted.
Readiness assessment
Twenty questions against the five controls — find your gaps before you spend a pound.
Certificate checker
Verify any company's certification against the official register in under a minute.
Protect your business → Get Cybersecurity Assessment