UK Certification
Cyber Essentials is the UK government-backed baseline for cyber security. For many organisations it is also the fastest, lowest-cost route to a recognised certification.
Who this is for: Organisations bidding for UK government contracts, or needing a fast, recognised baseline certification.
The problem: Confusion between Cyber Essentials and ISO 27001 leads organisations to pursue the wrong certification first.
The outcome: Cyber Essentials or Cyber Essentials Plus certification, with a clear route into ISO 27001 later if you need it.
The problem
Many UK organisations know they need some form of recognised cyber security certification, usually because a client, a public sector procurement process, or a cyber insurance renewal has asked for one, but they do not know where to start. ISO 27001 gets mentioned most often, and it is frequently the wrong first step for an organisation that has not yet put basic technical controls in place.
Cyber Essentials, and its more rigorous counterpart Cyber Essentials Plus, is the UK government-backed scheme administered through IASME on behalf of the National Cyber Security Centre. It certifies five fundamental technical controls: firewalls, secure configuration, user access control, malware protection, and security update management. It is a self-assessment (Cyber Essentials) or an externally verified assessment (Cyber Essentials Plus) against those five areas, not a full management system audit.
The confusion between Cyber Essentials and ISO 27001 costs organisations time and money. Some pursue ISO 27001 when Cyber Essentials would have satisfied the actual requirement they were responding to. Others get Cyber Essentials and assume it covers obligations that only a full ISMS under ISO 27001 actually addresses.
For organisations bidding on UK government contracts, Cyber Essentials is frequently a mandatory prerequisite, not an optional enhancement. Missing it can mean exclusion from a bid before technical evaluation even begins.
What we do
FortressPoint supports UK organisations through Cyber Essentials and Cyber Essentials Plus certification. We assess your current technical controls against the five Cyber Essentials requirement areas, close the gaps, and prepare your self-assessment questionnaire or coordinate the external technical verification required for Cyber Essentials Plus.
We help you decide which of the two certifications you actually need. Cyber Essentials is a self-assessment, verified by an accredited certification body, and suits most organisations as a starting point. Cyber Essentials Plus adds an independent technical audit of your systems and suits organisations facing higher-assurance procurement requirements or handling more sensitive data.
Where an organisation’s ambitions go beyond Cyber Essentials, we plan the route from Cyber Essentials into ISO 27001 as a coherent progression rather than two disconnected projects, since Cyber Essentials controls form a useful technical foundation for several ISO 27001 Annex A requirements.
Who this is for
What you get
Why FortressPoint
We do not default to selling the largest certification available. If Cyber Essentials genuinely satisfies what you need, that is what we recommend, and we are equally direct when your requirements point toward ISO 27001 instead.
We treat Cyber Essentials as a foundation, not an isolated exercise. Where it makes sense, we design the technical controls so they carry forward directly into a future ISO 27001 programme rather than needing to be redone.
We understand UK procurement in practice, including where Cyber Essentials is a hard prerequisite for public sector bids, so certification timing gets planned around your actual commercial deadlines.
Common questions
Cyber Essentials is a self-assessment questionnaire, checked and certified by an accredited certification body, covering five technical control areas. Cyber Essentials Plus adds an independent, externally conducted technical audit of your actual systems, providing a higher level of assurance. Plus certification typically costs more and takes longer because of the hands-on technical verification involved.
The certification fee itself is set by the certification body and is relatively low cost compared to ISO 27001, particularly for Cyber Essentials rather than Cyber Essentials Plus. The larger cost variable is the remediation work needed to close any gaps found during assessment, which depends on how mature your current technical controls already are.
You complete a self-assessment questionnaire covering the five control areas, which is then reviewed and certified by an IASME-accredited certification body. Most organisations benefit from a gap assessment and remediation support beforehand, since submitting a questionnaire that fails review costs time and, in some cases, a resubmission fee.
If you are bidding for UK government contracts, it is frequently a mandatory requirement. Beyond that, it is worth pursuing if a client, insurer, or partner has asked for evidence of baseline cyber security controls, or if you want a recognised, achievable first certification before considering something more extensive like ISO 27001.
Cyber Essentials certifies five specific technical controls and suits organisations that need a fast, lower-cost, recognised certification, particularly for public sector procurement. ISO 27001 certifies a full information security management system covering governance, risk management, and a much broader set of controls, and suits organisations facing more demanding client or regulatory requirements. Many organisations start with Cyber Essentials and use it as a foundation for ISO 27001 later.
Certification itself can be completed in days to a few weeks once your technical controls meet the requirements, since it is a self-assessment reviewed by the certification body rather than a lengthy audit process. The main variable is how much remediation work is needed before you are ready to submit, which a gap assessment identifies upfront.
If you need Cyber Essentials or Cyber Essentials Plus certification, or you are not sure which certification fits your organisation, contact us.