THROWAWAY PROOF-OF-CONCEPT · Astro frontend + self-hosted Payload CMS · content served live from the Payload REST API

Cyber Essentials Certification

Cyber Essentials Certification for UK Businesses

Certified once. Compliant all year.

A customer, an insurer or a framework is asking for Cyber Essentials, and you have not got it yet. The deadline is real, the contract or the cover depends on it, and you need someone to get you there without the guesswork. That is what we do. HGC helps UK businesses achieve and maintain Cyber Essentials and Cyber Essentials Plus, then keeps you compliant every day after, not just the week before the assessment. We certify and monitor you through CyberSmart, the accredited platform we work on, backed by a UK team that already runs the five technical controls the scheme tests. Whether you are a small business getting certified for the first time or renewing under the new April 2026 rules, we get you certified via an accredited body and keep you in the passing state, year round.

  • Microsoft Partner Cloud Solution Provider (CSP)
  • Cyber Essentials we hold it ourselves
  • UK team no overseas call centre
  • All year continuous compliance, not one-off

Book a Cyber Essentials readiness call Download the Cyber Essentials readiness checklist

HGC IT engineer helping a UK business achieve Cyber Essentials certification

Who issues your certificate

HGC helps you achieve and maintain certification. The certificate itself is issued by an IASME-accredited body through our partner platform, CyberSmart. We do the work that gets you there, and the work that keeps you there.

An HGC IT specialist reviewing a UK business's Cyber Essentials readiness on a laptop, doing the hands-on work that gets clients certified through the CyberSmart platform

Why UK Businesses Need Cyber Essentials Now

For a growing number of firms, Cyber Essentials has stopped being optional. A contract, an insurer or a regulator is setting the date, and missing it costs real work. If any of these sound like you, this is exactly the pressure we take off your desk.

You cannot bid without it

More and more tenders now list Cyber Essentials as a straight pass or fail. Under the government's procurement rules (PPN 014), certification is required on many public-sector contracts, and that requirement cascades down the supply chain, so if you subcontract to a certified prime, you need it too. No certificate, no bid. Firms are being quietly locked out of work they could easily win, often finding out only when the tender lands.

Regulated and public-sector supply chains are setting hard dates

If you supply the Ministry of Defence, its industry partners have been asked to reach Defence Cyber Certification Level 0 by the end of December 2026, which includes Cyber Essentials for applicable business-critical systems and flows down every tier of the defence supply chain. If you handle NHS data, the NHS Data Security and Protection Toolkit and a Cyber Essentials Plus expectation are now treated as separate evidence streams you have to satisfy. Both come with dates you do not control.

Your cyber-insurance renewal is getting harder

Insurers increasingly ask for Cyber Essentials at renewal, and some price it in or decline cover without it. Renewal is a predictable annual trigger, and turning up to it uncertified is fast becoming an expensive place to be. Certification is becoming part of the price of staying insured.

The April 2026 rules just changed the bar

The scheme's v3.3 requirements took effect on 27 April 2026. Multi-factor authentication (MFA) is now mandatory across all your cloud services, cloud can no longer be scoped out, and scoping is tighter. In plain terms, certification now depends on how your systems are actually configured and kept configured. Plenty of firms that passed last year will not pass their renewal without work, and the MFA gate is where most of them get caught.

Certified last year, and nothing has been maintained since

A certificate is a snapshot of one day. The moment a new laptop is set up wrong, a starter is added without MFA, or a patch is missed, your real-world state drifts away from the state you certified. One-off certifiers hand you the certificate and leave you with the problem twelve months later, when renewal turns into a scramble. This is the exact pain our year-round approach exists to kill.

How HGC Helps You Achieve and Maintain Cyber Essentials

Cyber Essentials tests five technical controls. For the businesses we look after, these are not a project we bolt on the week before an assessment, they are what we run every day. Below is what each control means in plain English and how we get it into the passing state and keep it there, whether you need Cyber Essentials or the hands-on Cyber Essentials Plus audit. We prepare, harden and evidence your environment; your assessment and certificate are then issued by an IASME-accredited body through CyberSmart, the platform we certify and monitor you through. It starts with a short readiness call, so you know exactly what is needed before you commit to anything.

Firewalls and network boundaries

The first control is a properly configured boundary between your systems and the internet. We make sure your firewalls and internet-facing devices are locked down to only what your business actually needs, default passwords are gone, and nothing is left open that an automated scan could walk through. For clients we manage, this is set up correctly from day one and checked continuously, not rediscovered at renewal.

Secure configuration

Devices and software ship with settings built for convenience, not security. This control is about removing what you do not use, turning off what you do not need, and setting everything up to a safe standard. We standardise how laptops, servers and cloud services are built and maintained, so your estate stays in a known-good state instead of drifting into the gaps assessors look for.

Access control and multi-factor authentication

Only the right people should reach your systems, and a password alone is no longer enough. This is the control the April 2026 rules tightened most, with MFA now mandatory across all cloud services. As a Microsoft Cloud Solution Provider, configuring and managing MFA and access controls in your Microsoft 365 is core to what we do every day, so the control the scheme now hinges on is one we already own.

Malware protection

Your devices need reliable protection against malware and ransomware, kept active and up to date across the whole estate. We deploy and manage this consistently on every machine, so there are no forgotten laptops running without cover, and no gaps between "we bought antivirus" and "it is actually working everywhere".

Security update management (patching)

Attackers rely on known flaws in software that has not been updated. This control requires that supported software is kept patched and that anything out of support is removed. We manage patching continuously, so critical updates are applied promptly and your systems stay current, which is also the single biggest reason a maintained estate sails through renewal while an unmaintained one fails.

Why Choose HGC for Cyber Essentials

Plenty of people can get you a certificate. Far fewer can keep you certified. Our advantage is simple: we already run the controls Cyber Essentials tests, so passing is not a one-off event we cram for, it is the state we keep your business in all year. Here is what that means for you.

We already run the controls the scheme tests

Cyber Essentials assesses firewalls, secure configuration, access control and MFA, malware protection and patching. For a business we manage, those are not extras we introduce for the assessment, they are what we operate every day. That is why renewal becomes a formality rather than a fire drill, and why the April 2026 changes are our home ground rather than a problem to solve.

Microsoft Partner and CSP, on the controls that now matter most

As a Microsoft Partner and Cloud Solution Provider, we configure and manage the MFA, Conditional Access and secure configuration inside your Microsoft 365 tenant. Those are precisely the access and configuration controls the scheme now hinges on after April 2026, so this is not a generic badge, it is direct competence on the exact controls you are being assessed against.

We hold Cyber Essentials ourselves

We have been through certification for our own business, so we know the process from the inside and we practise what we recommend. When we tell you what good looks like, it is because we hold ourselves to the same standard.

You deal with HGC, not a platform

You have one relationship and one accountable UK team: us. CyberSmart is the accredited platform we use to certify and monitor you, and an IASME-accredited body issues your certificate through it. Think of it the way you think of your accountant: we do the work and own the outcome, the platform is the system we file through. One throat to choke, real accreditation behind it.

A named UK team, not an overseas call centre

You work with real people you can reach, based here in the UK. We are headquartered in Dorset and support businesses across the country, so you get local accountability with national reach, and never a ticket lost in an overseas queue.

Continuous compliance, not a certificate mill

We help you achieve certification properly, through an accredited body, and then we keep the estate in the passing state between certificates instead of handing you a PDF and walking away. That is the whole point: certified once, compliant all year, so the certificate you paid for still means something in month eleven.

Cyber Essentials: Frequently Asked Questions

Straight answers to what UK businesses ask us most about getting, and keeping, Cyber Essentials.

What is Cyber Essentials certification?

Cyber Essentials is a UK government-backed certification that shows your business has the core technical controls in place to defend against the most common cyberattacks. It covers five areas: firewalls, secure configuration, access control and multi-factor authentication, malware protection, and keeping software updated. It is widely recognised, increasingly required to win contracts, and a practical baseline that stops the majority of everyday threats. HGC helps you achieve it and, just as importantly, keeps you compliant with it all year.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a self-assessment: you complete a verified questionnaire confirming your controls are in place, and it is a faster route to certification. Cyber Essentials Plus covers the same five controls but adds an independent, hands-on technical audit where an assessor checks your systems directly, so it carries more assurance and takes a little longer. CE Plus is often the level required by larger contracts and by defence and NHS-adjacent supply chains. Not sure which you need? That is exactly what the readiness call is for.

How much does Cyber Essentials cost?

The honest answer is that it depends on the size of your organisation and the state of your systems today, so we scope it per business rather than quote a headline figure. There is a certification assessment fee set by IASME that is tiered by organisation size, and then there is any remediation work needed to get your controls into the passing state. Our model is built around predictable, ongoing cost with no surprise remediation bills: after a short readiness call we tell you exactly what is needed before you commit to anything, so you never get a nasty invoice after the fact.

Do I need Cyber Essentials to win contracts?

Increasingly, yes. Under the government's procurement rules (PPN 014), Cyber Essentials is required on many public-sector contracts, and that requirement cascades down supply chains to subcontractors. Ministry of Defence suppliers face Defence Cyber Certification expectations that include it, NHS-data suppliers face related assurance requirements, and many private-sector buyers now ask for it too. If you bid for work, there is a good chance a customer will ask for your certificate, and without it you can be ruled out before you start.

What is changing with Cyber Essentials in April 2026?

The scheme's v3.3 requirements took effect on 27 April 2026. The headline changes are that multi-factor authentication is now mandatory across all your cloud services, cloud services can no longer be left out of scope, and scoping rules are tighter overall. In practice this means certification depends more than ever on how your systems are set up and kept set up, and many businesses that passed previously will need work, particularly around MFA, to pass their next renewal. Keeping those controls current continuously is exactly what we do.

Does HGC issue the Cyber Essentials certificate?

No, and we will always be straight with you about that. HGC is not the certification body. What we do is prepare, harden and evidence your environment so you meet the standard, and then your assessment and certificate are issued by an IASME-accredited body through our partner platform, CyberSmart. You get proper, accredited certification, managed end to end by your UK team. We are the people who get you there and keep you there; the accredited body issues the certificate.

How long does Cyber Essentials certification take?

It depends on the state of your systems today and which level you need, so we will not put a fixed number on it before we understand your setup, and we will be straight with you about your timeline once we do. As a guide, Cyber Essentials is a self-assessment and is the faster route, while Cyber Essentials Plus involves an independent technical audit and takes longer to arrange. Tell us your deadline on the readiness call and we will tell you honestly whether we can hit it, and the call surfaces any gaps first, so you know what is needed before you spend anything.

What happens after we are certified?

This is where we are different from a one-off certifier. A certificate is a snapshot of one day, and your real-world security drifts the moment a device is set up wrong or a patch is missed. We keep the five controls in the passing state continuously through the CyberSmart platform and the team that runs your IT, so renewal is a formality rather than a scramble, your insurer and your customers keep getting the answer they expect, and the certificate you paid for still holds up all year. Certified once, compliant all year.

Which industries do you help with Cyber Essentials?

We work across UK sectors, with particular focus on professional services (legal, accountancy, consultancy, architecture and engineering), finance and accountancy, healthcare-adjacent organisations, and the defence and engineering supply chain, where MOD requirements are a live driver. These are the sectors where certification is most often demanded by contracts, regulators and insurers, and where "done for you and kept current" matters most. If you are not sure whether it applies to your business, the readiness call will tell you.

Not ready to book? Get the free readiness checklist

Explore more

Cyber Essentials sits alongside the rest of your security and IT, so it works best when everything is joined up. If you want protection that goes beyond the certificate, our managed cybersecurity covers ongoing monitoring and threat defence. The access and MFA controls Cyber Essentials now hinges on live inside your tenant, which is why our Microsoft 365 support matters to certification. Many firms also choose to have the whole estate looked after by one UK team through our managed IT support. And if you would like a local team, here is how we deliver local IT support across Dorset.

Get Cyber Essentials ready

Book a short, no-obligation Cyber Essentials readiness call with our UK team. We will talk through your deadline, look at where you are today, and give you a plain-English view of what it takes to get certified and stay certified. No jargon, no pressure, and no surprise bills: you will know exactly what is needed before you commit to anything. Certified once, compliant all year.

  • Free, no-obligation readiness call
  • Done for you, by a UK team
  • Kept compliant all year, not just at renewal
  • No surprise remediation bills, you know the plan before you commit

Book a Cyber Essentials readiness call

Call 01305 310006 · Email hello@hgcit.co.uk