CYBER ESSENTIALS SUPPORT
Prepare for Cyber Essentials with practical technical support
Simtech helps organisations understand the Cyber Essentials requirements, define the assessment scope, identify technical gaps and implement the changes needed before submitting for certification.
Whether you are seeking certification for the first time, renewing an existing certificate or preparing for Cyber Essentials Plus, we provide clear and practical support throughout the process.
Preparation and technical support are provided by Simtech. Certification is assessed and awarded through an authorised Cyber Essentials Certification Body.
Get an IT Support Quote
Tell us a little about your organisation, your current support arrangement and what you would like to improve.
A RECOGNISED CYBERSECURITY BASELINE
What is Cyber Essentials?
Cyber Essentials is a UK Government-backed cybersecurity certification scheme designed to help organisations protect themselves against common cyber threats.
The scheme focuses on a defined set of technical controls covering the devices, software, accounts and internet-facing services within the agreed assessment scope.
Cyber Essentials can help an organisation demonstrate that it has implemented a recognised baseline of practical cybersecurity measures.
LEVEL 1
Cyber Essentials
Cyber Essentials uses a verified self-assessment questionnaire.
The organisation describes how the relevant requirements are met, and the answers are reviewed through an authorised Certification Body.
Verified self-assessment
LEVEL 2
Cyber Essentials Plus
Cyber Essentials Plus is based on the same technical requirements but adds independent technical testing of the organisation’s systems.
The organisation must first achieve Cyber Essentials before completing the Plus assessment.
Cyber Essentials plus technical testing
WHY CYBER ESSENTIALS MATTERS
More than a badge for the website
Businesses pursue Cyber Essentials for different reasons.
For some, it is a customer or tender requirement. For others, it provides a structured way to review basic cybersecurity arrangements and address weaknesses that may have developed over time.
Reason 1
Customer and supply-chain requirements
A larger customer may require suppliers to hold Cyber Essentials before sharing information, awarding work or renewing a contract.
Reason 2
Public-sector opportunities
Some government and public-sector contracts require Cyber Essentials or an equivalent level of assurance.
Reason 3
Cyber insurance
Insurers may ask whether the organisation holds Cyber Essentials or has implemented comparable controls.
Certification does not guarantee insurance eligibility, but it can provide useful evidence of a recognised baseline.
Reason 4
Tender and due-diligence questionnaires
Certification can provide a clearer response when prospective customers ask how common cybersecurity risks are managed.
Reason 5
Internal improvement
The readiness process can expose unsupported software, inconsistent patching, unnecessary administrator access and unclear device ownership.
Reason 6
Management assurance
Directors gain a clearer understanding of which systems are included and whether the basic technical controls are being maintained.
Reason 7
Demonstrating commitment
Certification can help reassure customers, employees and partners that the organisation takes cybersecurity seriously.
SUITABLE FOR ORGANISATIONS OF DIFFERENT SIZES
Cyber Essentials can apply to almost any organisation using IT
Cyber Essentials is commonly used by small and medium-sized organisations, but the requirements can also apply to larger businesses, charities, professional firms and public-sector suppliers.
The complexity of the process usually depends less on employee count alone and more on the number of devices, locations, systems, suppliers and exceptions within the assessment scope.
Typical organisations seeking support
Simtech can support existing managed IT customers and organisations using another IT provider, subject to an agreed technical scope and access arrangements.
THE CYBER ESSENTIALS FOUNDATION
Five areas that work together to reduce common risks
The current Cyber Essentials requirements are organised around five technical control themes.
The precise questions and requirements should always be checked against the current scheme documentation before an assessment begins.
Control 1
Firewalls
The organisation must control how devices and networks connect to the internet.
This includes reviewing internet gateways, router or firewall configuration, default passwords, administrative access and unnecessary services.
Simtech may help with:
- Firewall and router review
- Default-password changes
- Administrative-access review
- Internet-facing service review
- Remote-access configuration
- Network-boundary documentation
- Supplier coordination
Control 2
Secure configuration
Devices, applications and accounts should be configured to reduce unnecessary exposure.
This includes removing unused software, changing default credentials, limiting unnecessary features and applying appropriate security settings.
Simtech may help with:
- Device-configuration review
- Removal of unnecessary software
- Default-account review
- Account and permission cleanup
- Microsoft 365 configuration
- Security-policy deployment
- Standard device-build improvement
Control 3
Security update management
Supported software and devices must receive relevant security updates within the required timescales.
Unsupported systems can create a certification obstacle.
Simtech may help with:
- Operating-system inventory
- Software-version review
- Patch-management deployment
- Unsupported-device identification
- Application update review
- Replacement planning
- Update-status reporting
Control 4
User access control
Users should receive only the access needed for their role, with appropriate separation of privileged administration.
Simtech may help with:
- User-account review
- Administrator-account separation
- Privileged-access review
- Starter and leaver processes
- Dormant-account removal
- Microsoft 365 role review
- Access-permission improvement
- Multi-factor authentication support
Control 5
Malware protection
The organisation must use an appropriate method to reduce malware risk on relevant devices.
Simtech may help with:
- Antivirus deployment
- Endpoint detection and response
- Malware-protection review
- Application-control options
- Device-management standards
- Alert monitoring
- Removal of unmanaged devices
DEFINE WHAT IS BEING CERTIFIED
Cyber Essentials begins with a clear assessment scope
Scope determines which organisation, users, devices, networks and cloud services are included in the assessment.
An unclear or unnecessarily complicated scope can create delays and uncertainty.
The correct scope must reflect the organisation being certified and the way its technology connects to the internet.
DEFINING THE CERTIFICATION BOUNDARY
Scope questions may include
-
01
Which legal entity is seeking certification?
-
02
Are all offices and locations included?
-
03
Which remote employees are included?
-
04
Which laptops, desktops, servers and mobile devices are included?
-
05
Are personally owned devices used for business?
-
06
Which cloud services are in use?
-
07
Is Microsoft 365 included?
-
08
Are home routers relevant?
-
09
Are third-party managed systems included?
-
10
Are subsidiaries included?
-
11
Are there segregated networks?
-
12
Are any systems being excluded?
-
13
Can the exclusions be justified technically?
SIMTECH’S ROLE
Simtech can help:
- Identify systems and devices
- Understand the operating environment
- Document the proposed scope
- Identify complicated areas
- Coordinate with other IT suppliers
- Explain likely technical implications
- Prepare information for the Certification Body
FIND THE GAPS BEFORE SUBMISSION
Is your organisation ready for Cyber Essentials?
Submitting before the technical environment has been reviewed can lead to avoidable delays, failed answers or urgent remediation work.
A readiness assessment allows the organisation to compare its current arrangements with the applicable requirements before beginning or completing the formal assessment.
Readiness area 01
Devices
- Device inventory
- Supported operating systems
- Personally owned devices
- Mobile devices
- Servers
- Network equipment
- Remote-working equipment
Readiness area 02
Software
- Operating-system versions
- Business applications
- Browser versions
- Unsupported applications
- Patch-management arrangements
- Automatic-update settings
Readiness area 03
User accounts
- Active users
- Dormant accounts
- Administrator privileges
- Shared accounts
- Starter and leaver processes
- Authentication controls
Readiness area 04
Internet and network
- Firewalls
- Routers
- Default passwords
- Internet-facing services
- Remote access
- Network segregation
Readiness area 05
Malware protection
- Antivirus coverage
- Endpoint security
- Device exclusions
- Alert management
- Unmanaged devices
Readiness area 06
Cloud services
- Microsoft 365
- Cloud administrative access
- Multi-factor authentication
- Supplier responsibility
- Shared-service configuration
ISSUES THAT OFTEN NEED ATTENTION
Common reasons organisations are not ready
Obstacle 1
Unsupported operating systems
Devices using operating systems that no longer receive appropriate security support may need upgrading or replacing.
Obstacle 2
Unsupported applications
Older business software, server applications or browser versions may prevent the organisation from meeting update requirements.
Obstacle 3
Excessive administrator access
Employees may use administrator accounts for everyday work without a clear business need.
Obstacle 4
Unclear device inventory
The organisation may not know which computers, mobile devices or remote-working systems are accessing its services.
Obstacle 5
Inconsistent patching
Some devices may update automatically while others are rarely checked.
Obstacle 6
Shared or dormant accounts
Accounts may remain active after employees leave, or several people may use the same sign-in.
Obstacle 7
Default credentials
Routers, firewalls, devices or services may still use supplier-default passwords.
Obstacle 8
Unmanaged home or personal devices
Employees may access business systems from devices that fall outside normal IT management.
Obstacle 9
Unclear supplier responsibilities
The business may assume that its IT provider, cloud supplier or software vendor manages a control when the responsibility actually remains with the customer.
Obstacle 10
Complicated scope
Multiple entities, sites, networks or outsourced services can make the assessment boundary difficult to define.
FROM READINESS TO CERTIFICATION
How Simtech helps you prepare
Step 1
Initial requirement discussion
We establish why certification is needed, the target date and whether the organisation is seeking Cyber Essentials or Cyber Essentials Plus.
Step 2
Scope review
We identify the organisation, users, devices, locations, cloud services and suppliers likely to fall within scope.
Step 3
Information gathering
Simtech collects available technical and administrative information.
Step 4
Readiness assessment
The current environment is compared with the relevant Cyber Essentials requirements.
Step 5
Gap report
You receive a prioritised list of missing information and technical changes.
Step 6
Remediation proposal
Where Simtech can implement the required improvements, the work is clearly scoped and priced.
Step 7
Technical remediation
Agreed changes are completed, such as patching, device replacement, account cleanup, endpoint protection or configuration improvement.
Step 8
Questionnaire preparation
Simtech helps gather and explain the technical information required to complete the verified self-assessment.
Step 9
Certification Body submission
The organisation submits through the relevant certification process.
The authorised Certification Body reviews the answers and determines the outcome.
Step 10
Further clarification
If the assessor requests clarification or changes, Simtech can help respond to technical questions within the agreed service scope.
Step 11
Certification and ongoing maintenance
Once certification is achieved, the organisation must continue maintaining the controls and plan for annual renewal.
PRACTICAL TECHNICAL SUPPORT
Support before, during and after the assessment
Project stage 1
Preparation
- Explain the likely process
- Review certification objectives
- Help establish scope
- Identify users, devices and services
- Review available documentation
- Coordinate technical information
- Preview likely assessment questions
Project stage 2
Readiness
- Compare current arrangements with the requirements
- Identify technical gaps
- Highlight unsupported software
- Review access and administrator accounts
- Review patching and malware protection
- Review firewall and router arrangements
- Review Microsoft 365 considerations
Project stage 3
Remediation
- Deploy or improve patch management
- Replace or upgrade unsupported devices
- Remove unnecessary administrator access
- Improve account-management processes
- Deploy antivirus or EDR
- Update firewall or router settings
- Improve Microsoft 365 configuration
- Document devices and responsibilities
Project stage 4
Assessment support
- Help prepare technical answers
- Explain terminology
- Gather evidence and configuration information
- Assist with assessor clarification questions
- Coordinate other IT suppliers where required
Project stage 5
Ongoing maintenance
- Device monitoring
- Patch management
- Endpoint protection
- Microsoft 365 administration
- Starter and leaver support
- Annual readiness review
- Managed IT support
- Cybersecurity planning
CLEAR CERTIFICATION BOUNDARIES
Preparation support is not the same as awarding certification
Cyber Essentials certification must be assessed through an authorised Cyber Essentials Certification Body.
Unless Simtech is formally operating as an authorised Certification Body, Simtech does not:
IMPORTANT SERVICE BOUNDARY
Simtech cannot:
Award Cyber Essentials certification
Make the final certification decision
Guarantee that an application will pass
Override assessor decisions
Approve scope exclusions
Issue the certificate
Conduct Cyber Essentials Plus testing
Represent itself as the scheme owner
Provide legal assurance regarding tender eligibility
Guarantee cyber-insurance acceptance
CHOOSE THE REQUIRED LEVEL
What is the difference?
VERIFIED SELF-ASSESSMENT
Cyber Essentials
Cyber Essentials is based on a verified self-assessment questionnaire.
The organisation confirms how it meets the requirements, and the answers are reviewed through the certification process.
May suit organisations that:
- Need a recognised baseline
- Have a customer or tender requirement
- Are seeking certification for the first time
- Want to review common technical controls
- Do not currently require independent technical testing
ADDITIONAL ASSURANCE
Cyber Essentials Plus
Cyber Essentials Plus uses the same technical requirements but adds an independent technical assessment.
The testing process provides additional assurance that the stated controls are operating within the assessment sample and scope.
May suit organisations that:
- Have a specific customer requirement
- Supply government or higher-risk customers
- Need stronger assurance
- Are responding to a tender
- Want independent technical verification
- Have already achieved Cyber Essentials
PREPARE FOR TECHNICAL TESTING
Additional readiness for Cyber Essentials Plus
Cyber Essentials Plus requires more than completing the self-assessment.
An independent assessor tests a sample of relevant systems and controls within the agreed scope.
Preparation should therefore consider whether the actual technical environment reflects the answers provided during Cyber Essentials.
Preparation may include
Cyber Essentials Plus testing must be conducted by an authorised Certification Body with the appropriate assessment capability.
Simtech can help prepare the environment and coordinate technical access but should not describe itself as the independent assessor unless formally authorised.
CLOUD SERVICES ARE PART OF THE SECURITY PICTURE
Microsoft 365 configuration can affect certification readiness
CLOUD AND REMOTE-WORKING CONTROLS
Microsoft 365 may form part of the assessment
Cyber Essentials is not limited to computers in the office.
Cloud services, user accounts, administrator access and remote-working arrangements may all be relevant to the assessment.
For organisations using Microsoft 365, readiness work may include reviewing:
- User accounts
- Administrator roles
- Multi-factor authentication
- Dormant accounts
- Guest users
- Remote access
- Supported devices
- Mobile-device use
- Shared accounts
- Browser and application updates
- Supplier responsibilities
- Business Premium capabilities
MAINTAIN THE CONTROLS AFTER CERTIFICATION
Certification is easier to maintain when everyday IT is managed consistently
ONGOING CYBER ESSENTIALS MAINTENANCE
Certification depends on day-to-day IT management
Many Cyber Essentials requirements depend on regular operational activities.
Devices must remain supported. Security updates must continue. Accounts must be removed when employees leave. New devices must be configured appropriately.
A one-off certification exercise can quickly become outdated if the underlying IT environment is not maintained.
INCLUDED AS STANDARD
Included within Simtech Managed IT
- Device inventory and monitoring
- Patch management
- Antivirus
- Endpoint detection and response
- Microsoft 365 administration
- Starter and leaver support
- User and device support
- Microsoft 365 SaaS backup
- Network and Wi-Fi support
- Annual or six-monthly reviews
PRACTICAL BENEFITS
Benefits of combining services
- Better visibility of devices
- More consistent patching
- Clearer account administration
- Easier identification of unsupported systems
- Central security-tool management
- Improved renewal preparation
- Fewer responsibilities left unmanaged
MANAGED IT CONNECTION
Maintain the controls after certification
Simtech Managed IT brings routine support, endpoint management, Microsoft 365 administration and ongoing cybersecurity oversight into one managed service.
CYBER ESSENTIALS IS RENEWED ANNUALLY
Maintain the controls throughout the certification period
Cyber Essentials and Cyber Essentials Plus certificates are valid for 12 months.
Renewal should not be treated as an exercise that begins shortly before expiry.
Changes to employees, devices, software, cloud services and suppliers can affect readiness during the year.
Ongoing activities
Annual-update point
Cyber Essentials requirements are reviewed and updated periodically.
The organisation should confirm which requirement version applies when beginning each new assessment or renewal.
PLAN AROUND YOUR DEADLINE
How long does Cyber Essentials take?
CERTIFICATION PLANNING
The timetable depends on your current environment
The timescale depends on the condition and complexity of the current environment.
An organised organisation with supported devices, consistent patching and clear account controls may progress quickly.
A business with unsupported systems, missing documentation or a complicated scope may require more substantial remediation.
TIMETABLE VARIABLES
Factors affecting the timetable
Certification deadline
Number of legal entities
Number of users
Number of devices
Number of locations
Remote and home working
Personally owned devices
Unsupported software
Patch-management consistency
Administrator-account use
Microsoft 365 configuration
Availability of technical information
Cooperation of other suppliers
Cyber Essentials Plus testing availability
Remediation and equipment lead times
CLEARLY SCOPED SUPPORT
How much does Cyber Essentials support cost?
CLEARLY SCOPED CYBER ESSENTIALS PRICING
Pricing reflects the organisation and work involved
The cost depends on the number of users, devices, locations, suppliers and technical gaps within the assessment scope.
Simtech therefore confirms pricing after a short discovery conversation.
COMMERCIAL COMPONENTS
Possible pricing components
Readiness review
A fixed-price review of the proposed scope and current technical controls.
Remediation work
Separately priced technical work needed to meet identified requirements.
THIRD-PARTY CHARGE
Certification fee
The Cyber Essentials assessment and certification charge payable through the authorised certification route.
CERTIFICATION BODY CHARGE
Cyber Essentials Plus assessment
A separate charge determined by the authorised Certification Body conducting the technical assessment.
ONGOING SERVICE
Managed IT
Ongoing per-user support that helps maintain devices, patching, endpoint protection and Microsoft 365 administration.
Annual renewal support
A defined review and preparation service before certificate renewal.
PROPOSAL TRANSPARENCY
The Simtech proposal should identify:
- Included organisation
- Assessment scope
- Number of users
- Number of devices
- Locations
- Readiness activities
- Deliverables
- Meetings
- Remediation included
- Remediation excluded
- Third-party fees
- Certification Body responsibility
- Customer responsibilities
- Timescale
- Price and payment terms
TECHNICAL SUPPORT THAT CONTINUES AFTER THE ASSESSMENT
Cyber Essentials support grounded in everyday IT management
Cyber Essentials controls depend on practical activities such as patching devices, managing accounts, maintaining antivirus and replacing unsupported technology.
Simtech combines certification preparation with the ability to implement and maintain many of the underlying technical controls.
CONNECTED IT AND CYBERSECURITY SUPPORT
IT management and cybersecurity are connected
Our team understands how devices, Microsoft 365, users and support processes operate together.
TECHNICAL DELIVERY
Practical remediation is available
Simtech can implement many of the technical improvements identified during readiness work.
MANAGEMENT CLARITY
Clear language for management
Findings are explained as practical actions rather than unexplained technical terminology.
MANAGED SERVICES
Managed services support ongoing compliance
Monitoring, patching, endpoint protection and Microsoft 365 administration can continue after certification.
DIRECT SUPPORT
Support is delivered by our own team
Work is not passed to an anonymous outsourced helpdesk.
ESTABLISHED EXPERIENCE
Supporting organisations for more than 16 years
Simtech has supported organisations through changing IT and security requirements for more than 16 years.
ONE TEAM. CONNECTED RESPONSIBILITY.
Move from one-off preparation to ongoing IT oversight
Combine practical Cyber Essentials support with managed IT, Microsoft 365 administration and day-to-day cybersecurity management.
COMMON SWITCHING QUESTIONS
Cyber Essentials FAQs
Is Cyber Essentials mandatory?
Cyber Essentials is not universally mandatory for every UK business.
However, it may be required by particular customers, tenders, government contracts, supply chains or insurers.
Who runs Cyber Essentials?
Cyber Essentials is a UK Government-backed scheme associated with the National Cyber Security Centre and delivered through IASME and authorised Certification Bodies.
How long does the certificate last?
Cyber Essentials and Cyber Essentials Plus certificates are valid for 12 months.
The organisation must renew to maintain current certification.
What are the five Cyber Essentials controls?
The five technical control themes cover:
– Firewalls
– Secure configuration
– Security update management
– User access control
– Malware protection
Is Cyber Essentials a penetration test?
No.
Cyber Essentials uses a verified self-assessment.
Cyber Essentials Plus adds independent technical testing but is not the same as a broad penetration test.
What is the difference between Cyber Essentials and Plus?
Cyber Essentials is based on a verified self-assessment.
Cyber Essentials Plus uses the same requirements and adds independent technical testing of relevant systems.
Do we need Cyber Essentials before Plus?
Yes.
Cyber Essentials must be achieved before completing the Cyber Essentials Plus assessment.
Can Simtech award the certificate?
Only an authorised Cyber Essentials Certification Body can assess and award certification.
Simtech provides readiness, technical preparation and remediation support unless separately authorised to act as a Certification Body.
Can Simtech guarantee that we will pass?
No.
Simtech can identify gaps and help implement improvements, but the Certification Body makes the final assessment decision.
Can Simtech complete the questionnaire for us?
Simtech can help gather and explain technical information.
The organisation must ensure that its answers are accurate and that the required declaration is completed by an appropriate authorised person.
What information will we need?
The assessment may require information about:
– The organisation
– Scope
– Devices
– Software
– Networks
– Cloud services
– User accounts
– Administrator access
– Security updates
– Malware protection
– Suppliers
Are home workers included?
Remote-working devices and arrangements may be relevant depending on how they access organisational systems and the agreed certification scope.
Are personally owned devices included?
Bring-your-own-device arrangements may be relevant and should be considered carefully during scope and readiness work.
Is Microsoft 365 included?
Microsoft 365 and the devices and accounts used to access it may form part of the assessment scope.
The precise treatment should be confirmed during readiness and certification.
Do mobile phones count?
Mobile devices may be relevant depending on their use, ownership, configuration and access to organisational services.
Do all devices need antivirus?
The applicable malware-protection requirements depend on device type, operating system and the permitted protection approach.
The current scheme requirements should be followed.
What happens if a device is unsupported?
Unsupported systems may need to be upgraded, replaced, removed or appropriately excluded from scope where a valid technical boundary exists.
How quickly must security updates be installed?
The applicable Cyber Essentials requirements define update expectations for relevant vulnerabilities and software.
Because requirements are updated periodically, readiness should always use the current version.
Can we exclude part of the business?
Some exclusions may be possible where there is a clear and acceptable technical separation.
The proposed scope must be described accurately and accepted through the certification process.
Does Cyber Essentials cover GDPR?
No.
Cyber Essentials is a cybersecurity certification and does not demonstrate complete compliance with UK GDPR or other data-protection law.
Does Cyber Essentials guarantee we will not be hacked?
No.
It is designed to reduce exposure to common cyber threats but cannot eliminate all cybersecurity risk.
Will Cyber Essentials reduce our insurance cost?
This depends on the insurer and policy.
Certification may support an application, but Simtech cannot guarantee premium reductions or acceptance.
Can Cyber Essentials help with tenders?
Yes, where certification is requested or recognised by the customer.
The tender requirements should be checked carefully.
How much does certification cost?
Certification and assessment fees are determined through the authorised certification route and may vary according to organisation size and certification level.
Simtech’s readiness and remediation charges are separate.
How much does Simtech support cost?
Pricing depends on scope, users, devices, locations and the amount of remediation required.
A clearly itemised proposal is provided after discovery.
How long does the process take?
The timetable depends on readiness, scope complexity, supplier cooperation and the amount of technical change required.
Cyber Essentials Plus also depends on assessor availability.
What happens if we fail?
The Certification Body will explain the applicable assessment outcome and next steps.
Simtech can help address technical issues and prepare for resubmission where agreed.
Can you help us renew?
Yes.
Simtech can review changes since the last assessment, identify new gaps and assist with renewal preparation.
What happens after certification?
The organisation should continue maintaining the controls, manage changes carefully and begin renewal preparation before the certificate expires.
START YOUR CYBER ESSENTIALS PROJECT
Find out what your organisation needs before applying
Tell us why certification is required, which level you need and when you need to achieve it.
Simtech will discuss your current environment, recommend the appropriate readiness process and provide clearly scoped pricing.
