CYBER ESSENTIALS SUPPORT

Prepare for Cyber Essentials with practical technical support

Simtech helps organisations understand the Cyber Essentials requirements, define the assessment scope, identify technical gaps and implement the changes needed before submitting for certification.

Whether you are seeking certification for the first time, renewing an existing certificate or preparing for Cyber Essentials Plus, we provide clear and practical support throughout the process.

Preparation and technical support are provided by Simtech. Certification is assessed and awarded through an authorised Cyber Essentials Certification Body.

Get an IT Support Quote

Tell us a little about your organisation, your current support arrangement and what you would like to improve.

Readiness and scope review
Technical gap identification
Microsoft 365 and device support
Remediation projects available
Cyber Essentials Plus preparation
Ongoing managed IT support available
A RECOGNISED CYBERSECURITY BASELINE

What is Cyber Essentials?

Cyber Essentials is a UK Government-backed cybersecurity certification scheme designed to help organisations protect themselves against common cyber threats.

The scheme focuses on a defined set of technical controls covering the devices, software, accounts and internet-facing services within the agreed assessment scope.

Cyber Essentials can help an organisation demonstrate that it has implemented a recognised baseline of practical cybersecurity measures.

LEVEL 1

Cyber Essentials

Cyber Essentials uses a verified self-assessment questionnaire.

The organisation describes how the relevant requirements are met, and the answers are reviewed through an authorised Certification Body.

Verified self-assessment

WHY CYBER ESSENTIALS MATTERS

More than a badge for the website

Businesses pursue Cyber Essentials for different reasons.

For some, it is a customer or tender requirement. For others, it provides a structured way to review basic cybersecurity arrangements and address weaknesses that may have developed over time.

01

Reason 1

Customer and supply-chain requirements

A larger customer may require suppliers to hold Cyber Essentials before sharing information, awarding work or renewing a contract.

02

Reason 2

Public-sector opportunities

Some government and public-sector contracts require Cyber Essentials or an equivalent level of assurance.

EVIDENCE, NOT A GUARANTEE
03

Reason 3

Cyber insurance

Insurers may ask whether the organisation holds Cyber Essentials or has implemented comparable controls.

Certification does not guarantee insurance eligibility, but it can provide useful evidence of a recognised baseline.

04

Reason 4

Tender and due-diligence questionnaires

Certification can provide a clearer response when prospective customers ask how common cybersecurity risks are managed.

05

Reason 5

Internal improvement

The readiness process can expose unsupported software, inconsistent patching, unnecessary administrator access and unclear device ownership.

06

Reason 6

Management assurance

Directors gain a clearer understanding of which systems are included and whether the basic technical controls are being maintained.

07

Reason 7

Demonstrating commitment

Certification can help reassure customers, employees and partners that the organisation takes cybersecurity seriously.

SUITABLE FOR ORGANISATIONS OF DIFFERENT SIZES

Cyber Essentials can apply to almost any organisation using IT

Cyber Essentials is commonly used by small and medium-sized organisations, but the requirements can also apply to larger businesses, charities, professional firms and public-sector suppliers.

The complexity of the process usually depends less on employee count alone and more on the number of devices, locations, systems, suppliers and exceptions within the assessment scope.

Typical organisations seeking support

Professional-services firms
Legal practices
Financial-services businesses
Construction companies
Charities
Public-sector suppliers
Technology suppliers
Organisations responding to tenders
Businesses renewing an existing certificate
Companies preparing for Cyber Essentials Plus
Organisations with mixed internal and outsourced IT
Businesses that have grown without standardised IT controls

Simtech can support existing managed IT customers and organisations using another IT provider, subject to an agreed technical scope and access arrangements.

THE CYBER ESSENTIALS FOUNDATION

Five areas that work together to reduce common risks

The current Cyber Essentials requirements are organised around five technical control themes.

The precise questions and requirements should always be checked against the current scheme documentation before an assessment begins.

01

Control 1

Firewalls

The organisation must control how devices and networks connect to the internet.

This includes reviewing internet gateways, router or firewall configuration, default passwords, administrative access and unnecessary services.

Simtech may help with:

  • Firewall and router review
  • Default-password changes
  • Administrative-access review
  • Internet-facing service review
  • Remote-access configuration
  • Network-boundary documentation
  • Supplier coordination
02

Control 2

Secure configuration

Devices, applications and accounts should be configured to reduce unnecessary exposure.

This includes removing unused software, changing default credentials, limiting unnecessary features and applying appropriate security settings.

Simtech may help with:

  • Device-configuration review
  • Removal of unnecessary software
  • Default-account review
  • Account and permission cleanup
  • Microsoft 365 configuration
  • Security-policy deployment
  • Standard device-build improvement
04

Control 4

User access control

Users should receive only the access needed for their role, with appropriate separation of privileged administration.

Simtech may help with:

  • User-account review
  • Administrator-account separation
  • Privileged-access review
  • Starter and leaver processes
  • Dormant-account removal
  • Microsoft 365 role review
  • Access-permission improvement
  • Multi-factor authentication support
05

Control 5

Malware protection

The organisation must use an appropriate method to reduce malware risk on relevant devices.

Simtech may help with:

  • Antivirus deployment
  • Endpoint detection and response
  • Malware-protection review
  • Application-control options
  • Device-management standards
  • Alert monitoring
  • Removal of unmanaged devices
DEFINE WHAT IS BEING CERTIFIED

Cyber Essentials begins with a clear assessment scope

Scope determines which organisation, users, devices, networks and cloud services are included in the assessment.

An unclear or unnecessarily complicated scope can create delays and uncertainty.

The correct scope must reflect the organisation being certified and the way its technology connects to the internet.

DEFINING THE CERTIFICATION BOUNDARY

Scope questions may include

  1. 01

    Which legal entity is seeking certification?

  2. 02

    Are all offices and locations included?

  3. 03

    Which remote employees are included?

  4. 04

    Which laptops, desktops, servers and mobile devices are included?

  5. 05

    Are personally owned devices used for business?

  6. 06

    Which cloud services are in use?

  7. 07

    Is Microsoft 365 included?

  8. 08

    Are home routers relevant?

  9. 09

    Are third-party managed systems included?

  10. 10

    Are subsidiaries included?

  11. 11

    Are there segregated networks?

  12. 12

    Are any systems being excluded?

  13. 13

    Can the exclusions be justified technically?

PRACTICAL PREPARATION

SIMTECH’S ROLE

Simtech can help:

  • Identify systems and devices
  • Understand the operating environment
  • Document the proposed scope
  • Identify complicated areas
  • Coordinate with other IT suppliers
  • Explain likely technical implications
  • Prepare information for the Certification Body
FIND THE GAPS BEFORE SUBMISSION

Is your organisation ready for Cyber Essentials?

Submitting before the technical environment has been reviewed can lead to avoidable delays, failed answers or urgent remediation work.

A readiness assessment allows the organisation to compare its current arrangements with the applicable requirements before beginning or completing the formal assessment.

Readiness area 01

Devices

  • Device inventory
  • Supported operating systems
  • Personally owned devices
  • Mobile devices
  • Servers
  • Network equipment
  • Remote-working equipment

Readiness area 02

Software

  • Operating-system versions
  • Business applications
  • Browser versions
  • Unsupported applications
  • Patch-management arrangements
  • Automatic-update settings

Readiness area 03

User accounts

  • Active users
  • Dormant accounts
  • Administrator privileges
  • Shared accounts
  • Starter and leaver processes
  • Authentication controls

Readiness area 04

Internet and network

  • Firewalls
  • Routers
  • Default passwords
  • Internet-facing services
  • Remote access
  • Network segregation

Readiness area 05

Malware protection

  • Antivirus coverage
  • Endpoint security
  • Device exclusions
  • Alert management
  • Unmanaged devices
ISSUES THAT OFTEN NEED ATTENTION

Common reasons organisations are not ready

01

Obstacle 1

Unsupported operating systems

Devices using operating systems that no longer receive appropriate security support may need upgrading or replacing.

02

Obstacle 2

Unsupported applications

Older business software, server applications or browser versions may prevent the organisation from meeting update requirements.

03

Obstacle 3

Excessive administrator access

Employees may use administrator accounts for everyday work without a clear business need.

04

Obstacle 4

Unclear device inventory

The organisation may not know which computers, mobile devices or remote-working systems are accessing its services.

06

Obstacle 6

Shared or dormant accounts

Accounts may remain active after employees leave, or several people may use the same sign-in.

07

Obstacle 7

Default credentials

Routers, firewalls, devices or services may still use supplier-default passwords.

08

Obstacle 8

Unmanaged home or personal devices

Employees may access business systems from devices that fall outside normal IT management.

09

Obstacle 9

Unclear supplier responsibilities

The business may assume that its IT provider, cloud supplier or software vendor manages a control when the responsibility actually remains with the customer.

10

Obstacle 10

Complicated scope

Multiple entities, sites, networks or outsourced services can make the assessment boundary difficult to define.

FROM READINESS TO CERTIFICATION

How Simtech helps you prepare

01

Step 1

Initial requirement discussion

We establish why certification is needed, the target date and whether the organisation is seeking Cyber Essentials or Cyber Essentials Plus.

02

Step 2

Scope review

We identify the organisation, users, devices, locations, cloud services and suppliers likely to fall within scope.

03

Step 3

Information gathering

Simtech collects available technical and administrative information.

04

Step 4

Readiness assessment

The current environment is compared with the relevant Cyber Essentials requirements.

06

Step 6

Remediation proposal

Where Simtech can implement the required improvements, the work is clearly scoped and priced.

07

Step 7

Technical remediation

Agreed changes are completed, such as patching, device replacement, account cleanup, endpoint protection or configuration improvement.

08

Step 8

Questionnaire preparation

Simtech helps gather and explain the technical information required to complete the verified self-assessment.

09
CERTIFICATION DECISION

Step 9

Certification Body submission

The organisation submits through the relevant certification process.

The authorised Certification Body reviews the answers and determines the outcome.

10

Step 10

Further clarification

If the assessor requests clarification or changes, Simtech can help respond to technical questions within the agreed service scope.

11
ANNUAL MAINTENANCE

Step 11

Certification and ongoing maintenance

Once certification is achieved, the organisation must continue maintaining the controls and plan for annual renewal.

PRACTICAL TECHNICAL SUPPORT

Support before, during and after the assessment

01

Project stage 1

Preparation

  • Explain the likely process
  • Review certification objectives
  • Help establish scope
  • Identify users, devices and services
  • Review available documentation
  • Coordinate technical information
  • Preview likely assessment questions
03

Project stage 3

Remediation

  • Deploy or improve patch management
  • Replace or upgrade unsupported devices
  • Remove unnecessary administrator access
  • Improve account-management processes
  • Deploy antivirus or EDR
  • Update firewall or router settings
  • Improve Microsoft 365 configuration
  • Document devices and responsibilities
04

Project stage 4

Assessment support

  • Help prepare technical answers
  • Explain terminology
  • Gather evidence and configuration information
  • Assist with assessor clarification questions
  • Coordinate other IT suppliers where required
AFTER CERTIFICATION
05

Project stage 5

Ongoing maintenance

  • Device monitoring
  • Patch management
  • Endpoint protection
  • Microsoft 365 administration
  • Starter and leaver support
  • Annual readiness review
  • Managed IT support
  • Cybersecurity planning
CLEAR CERTIFICATION BOUNDARIES

Preparation support is not the same as awarding certification

Cyber Essentials certification must be assessed through an authorised Cyber Essentials Certification Body.

Unless Simtech is formally operating as an authorised Certification Body, Simtech does not:

IMPORTANT SERVICE BOUNDARY

Simtech cannot:

Award Cyber Essentials certification

Make the final certification decision

Guarantee that an application will pass

Override assessor decisions

Approve scope exclusions

Issue the certificate

Conduct Cyber Essentials Plus testing

Represent itself as the scheme owner

Provide legal assurance regarding tender eligibility

Guarantee cyber-insurance acceptance

CHOOSE THE REQUIRED LEVEL

What is the difference?

VERIFIED SELF-ASSESSMENT

Cyber Essentials

Cyber Essentials is based on a verified self-assessment questionnaire.

The organisation confirms how it meets the requirements, and the answers are reviewed through the certification process.

May suit organisations that:

  • Need a recognised baseline
  • Have a customer or tender requirement
  • Are seeking certification for the first time
  • Want to review common technical controls
  • Do not currently require independent technical testing
PREPARE FOR TECHNICAL TESTING

Additional readiness for Cyber Essentials Plus

Cyber Essentials Plus requires more than completing the self-assessment.

An independent assessor tests a sample of relevant systems and controls within the agreed scope.
Preparation should therefore consider whether the actual technical environment reflects the answers provided during Cyber Essentials.

Preparation may include

Confirming Cyber Essentials remains valid
Reviewing the final certification scope
Confirming device and user samples
Checking supported operating systems
Verifying update status
Reviewing malware protection
Checking administrator access
Reviewing internet-facing services
Confirming remote-working arrangements
Resolving outstanding readiness gaps
Coordinating access for testing
Preparing employees for assessment activity
Planning remediation if issues are identified

Cyber Essentials Plus testing must be conducted by an authorised Certification Body with the appropriate assessment capability.

Simtech can help prepare the environment and coordinate technical access but should not describe itself as the independent assessor unless formally authorised.

CLOUD SERVICES ARE PART OF THE SECURITY PICTURE

Microsoft 365 configuration can affect certification readiness

CLOUD AND REMOTE-WORKING CONTROLS

Microsoft 365 may form part of the assessment

Cyber Essentials is not limited to computers in the office.

Cloud services, user accounts, administrator access and remote-working arrangements may all be relevant to the assessment.

For organisations using Microsoft 365, readiness work may include reviewing:

  • User accounts
  • Administrator roles
  • Multi-factor authentication
  • Dormant accounts
  • Guest users
  • Remote access
  • Supported devices
  • Mobile-device use
  • Shared accounts
  • Browser and application updates
  • Supplier responsibilities
  • Business Premium capabilities
MAINTAIN THE CONTROLS AFTER CERTIFICATION

Certification is easier to maintain when everyday IT is managed consistently

ONGOING CYBER ESSENTIALS MAINTENANCE

Certification depends on day-to-day IT management

Many Cyber Essentials requirements depend on regular operational activities.

Devices must remain supported. Security updates must continue. Accounts must be removed when employees leave. New devices must be configured appropriately.

A one-off certification exercise can quickly become outdated if the underlying IT environment is not maintained.

INCLUDED AS STANDARD

Included within Simtech Managed IT

  • Device inventory and monitoring
  • Patch management
  • Antivirus
  • Endpoint detection and response
  • Microsoft 365 administration
  • Starter and leaver support
  • User and device support
  • Microsoft 365 SaaS backup
  • Network and Wi-Fi support
  • Annual or six-monthly reviews
CONNECTED SERVICE

PRACTICAL BENEFITS

Benefits of combining services

  • Better visibility of devices
  • More consistent patching
  • Clearer account administration
  • Easier identification of unsupported systems
  • Central security-tool management
  • Improved renewal preparation
  • Fewer responsibilities left unmanaged

MANAGED IT CONNECTION

Maintain the controls after certification

Simtech Managed IT brings routine support, endpoint management, Microsoft 365 administration and ongoing cybersecurity oversight into one managed service.

Explore Managed IT Support
CYBER ESSENTIALS IS RENEWED ANNUALLY

Maintain the controls throughout the certification period

Cyber Essentials and Cyber Essentials Plus certificates are valid for 12 months.

Renewal should not be treated as an exercise that begins shortly before expiry.

Changes to employees, devices, software, cloud services and suppliers can affect readiness during the year.

Ongoing activities

Maintain an accurate device inventory
Replace unsupported software and systems
Continue applying security updates
Review administrator access
Remove leaver accounts promptly
Manage new devices consistently
Maintain malware protection
Review firewall and router changes
Record material scope changes
Review supplier responsibilities
Prepare early for renewal
Check the latest scheme requirements

Annual-update point

Cyber Essentials requirements are reviewed and updated periodically.

The organisation should confirm which requirement version applies when beginning each new assessment or renewal.

PLAN AROUND YOUR DEADLINE

How long does Cyber Essentials take?

CERTIFICATION PLANNING

The timetable depends on your current environment

The timescale depends on the condition and complexity of the current environment.

An organised organisation with supported devices, consistent patching and clear account controls may progress quickly.

A business with unsupported systems, missing documentation or a complicated scope may require more substantial remediation.

TIMETABLE VARIABLES

Factors affecting the timetable

01

Certification deadline

02

Number of legal entities

03

Number of users

04

Number of devices

05

Number of locations

06

Remote and home working

07

Personally owned devices

08

Unsupported software

09

Patch-management consistency

10

Administrator-account use

11

Microsoft 365 configuration

12

Availability of technical information

13

Cooperation of other suppliers

14

Cyber Essentials Plus testing availability

15

Remediation and equipment lead times

CLEARLY SCOPED SUPPORT

How much does Cyber Essentials support cost?

CLEARLY SCOPED CYBER ESSENTIALS PRICING

Pricing reflects the organisation and work involved

The cost depends on the number of users, devices, locations, suppliers and technical gaps within the assessment scope.

Simtech therefore confirms pricing after a short discovery conversation.

COMMERCIAL COMPONENTS

Possible pricing components

01
Readiness review

A fixed-price review of the proposed scope and current technical controls.

02
Remediation work

Separately priced technical work needed to meet identified requirements.

03

THIRD-PARTY CHARGE

Certification fee

The Cyber Essentials assessment and certification charge payable through the authorised certification route.

04

CERTIFICATION BODY CHARGE

Cyber Essentials Plus assessment

A separate charge determined by the authorised Certification Body conducting the technical assessment.

06
Annual renewal support

A defined review and preparation service before certificate renewal.

CLEARLY ITEMISED

PROPOSAL TRANSPARENCY

The Simtech proposal should identify:

  • Included organisation
  • Assessment scope
  • Number of users
  • Number of devices
  • Locations
  • Readiness activities
  • Deliverables
  • Meetings
  • Remediation included
  • Remediation excluded
  • Third-party fees
  • Certification Body responsibility
  • Customer responsibilities
  • Timescale
  • Price and payment terms
TECHNICAL SUPPORT THAT CONTINUES AFTER THE ASSESSMENT

Cyber Essentials support grounded in everyday IT management

Cyber Essentials controls depend on practical activities such as patching devices, managing accounts, maintaining antivirus and replacing unsupported technology.

Simtech combines certification preparation with the ability to implement and maintain many of the underlying technical controls.

CONNECTED IT AND CYBERSECURITY SUPPORT

IT management and cybersecurity are connected

Our team understands how devices, Microsoft 365, users and support processes operate together.

TECHNICAL DELIVERY

Practical remediation is available

Simtech can implement many of the technical improvements identified during readiness work.

MANAGEMENT CLARITY

Clear language for management

Findings are explained as practical actions rather than unexplained technical terminology.

DIRECT SUPPORT

Support is delivered by our own team

Work is not passed to an anonymous outsourced helpdesk.

Since 2009

ESTABLISHED EXPERIENCE

Supporting organisations for more than 16 years

Simtech has supported organisations through changing IT and security requirements for more than 16 years.

ONE TEAM. CONNECTED RESPONSIBILITY.

Move from one-off preparation to ongoing IT oversight

Combine practical Cyber Essentials support with managed IT, Microsoft 365 administration and day-to-day cybersecurity management.

Why Businesses Choose Simtech
COMMON SWITCHING QUESTIONS

Cyber Essentials FAQs

START YOUR CYBER ESSENTIALS PROJECT

Find out what your organisation needs before applying

Tell us why certification is required, which level you need and when you need to achieve it.

Simtech will discuss your current environment, recommend the appropriate readiness process and provide clearly scoped pricing.