Stronger Protection, Verified Security

Cyber Essentials Certification from Arcanum

Government-backed cybersecurity certification to safeguard your organisation and build customer trust.

Cyber Essentials is the UK government’s baseline cybersecurity standard for organisations of all sizes. It is a government-backed certification scheme that guides you to implement five key security controls and prevent around 80% of common cyber attacks.

 

Cyber Essentials Logo

Why get Cyber Essentials?

By achieving Cyber Essentials, you demonstrate to customers and partners that you take cyber security seriously and have essential protections in place. This not only helps secure your own systems against threats, but also reassures clients and stakeholders that their data is safe in your hands.

For many UK businesses, from SMEs to large enterprises and public sector suppliers, Cyber Essentials is a valuable credential, and it’s even required for certain government contracts.

Arcanum cyber security Cyber Essentials Banner

The Five Key Controls of Cyber Essentials

To achieve Cyber Essentials certification, your organisation must prove these five controls are in place and working effectively. They’re designed to stop the most common cyber attacks before they can cause harm.

Cyber Essentials Plus - #1

Firewalls and Internet Gateways

Put barriers in place between your network and the internet to block unauthorised access while allowing safe, necessary traffic through.

Cyber Essentials Plus - #2

Secure Configuration

Configure systems securely from the outset, removing unnecessary services, ports, and accounts to reduce vulnerabilities.

Cyber Essentials Plus - #3

User Access Control

Restrict system access so only authorised users can log in, with permissions set according to their role.

Cyber Essentials Plus - #4

Malware Protection

Defend your devices against viruses, ransomware, and other malicious software using approved security tools and safeguards.

Cyber Essentials Plus - #5

Security Update Management

Keep all software and devices updated with the latest security patches to close known vulnerabilities quickly.

Why Your Organisation Should Get Certified?

Government-backed cybersecurity certification to safeguard your organisation and build customer trust.

1 2

Prevent Common Cyber Attacks

Implementing Cyber Essentials’ five controls (firewalls, secure configuration, user access control, malware protection, and patch management) creates a strong security foundation. These measures can block the vast majority of basic cyber threats, reducing the risk of a breach by up to 80% . You’ll gain a clear picture of your security posture and address vulnerabilities before attackers can exploit them.

2

Build Customer Trust

Achieving certification lets you display the Cyber Essentials badge on your website and marketing materials, proving to customers and the public that you follow cybersecurity best practices. This credibility boost can be a differentiator, showing that you value data security and are proactively protecting personal data. In turn, it can attract new business for your organisation.

3

Win Government Contracts & Meet Compliance

Cyber Essentials certification is increasingly becoming a minimum requirement in supply chains. Many UK government, MoD, NHS and local authority contracts require at least Cyber Essentials (and often Cyber Essentials Plus) as a condition . By certifying, your organisation qualifies to bid for a growing number of opportunities that demand robust cybersecurity. You’ll also stay ahead of regulatory or industry expectations for baseline cyber hygiene.

4

Eligibility for Cyber Insurance

Certification comes with free cyber liability insurance for eligible organisations. This policy – provided you certify your whole organisation – offers an extra safety net in case of incidents. It’s an added benefit at no extra cost to help you recover should the worst happen.

(Terms apply; only available upon successful certification for eligible companies.)

Why Choose Arcanum

for Cyber Essentials Certification?

1 2

Over a Decade of Cyber Security Expertise

We have been an approved Cyber Essentials certification body since 2014, helping organisations of all sizes achieve compliance.

Cyber Essentials Plus - #2

We train the assessors

Our Lead Penetration Tester is an assessor for IASME, and ensures that other assessors meet the standards required. We ensure that we deliver our work to the highest standards, and we lead the way for others in the industry too.

Cyber Essentials Plus - #3

Tailored Assessments for Complex IT Environments

Unlike generic certification bodies, we specialise in helping enterprises with intricate IT infrastructures, cloud security challenges, and operational technology (OT) security.

4

Guided Support & Pre-Audit Readiness

We don’t just test—we help you prepare. Our assessors provide expert advice and guidance to ensure you are in the best possible position to pass the first time.

5

Efficient Certification Process

We help businesses achieve certification quickly and smoothly, minimising operational disruption.

6

Recognised by IASME, NCSC, and CREST

We are a government-approved certification body, ensuring your Cyber Essentials Plus certification meets all regulatory standards.

Accreditations

IASME Cyber Assurance
37838 Crest icons 2022 4 PT e1711554665305

For a full list of Arcanum’s accreditations, please go to our accreditations page

Working with ZSL

On their cyber essentials plus certification

Mark Eagles, Information Security Analyst, ZSL:

“ZSL has benefitted a huge amount from this assessment and your patient support and advice over the past year, which has left us in a much better state for Cyber Security than when we started. Please accept my sincere thanks to the penetration testing team and everyone that helped from Arcanum throughout the assessments over the past year, and for your support with Cyber Essentials Plus. We look forward to working with you again in the future.“

Our Cyber Essentials Packages

We offer two flexible certification packages to suit your needs. Both options result in the same Cyber Essentials certification; the difference is the level of support you prefer during the process. All packages include the IASME-set certification fee and two submission attempts, plus the official certificate and Cyber Essentials branding upon success.

 

Cyber Essentials:

Self Assessment Only

This is the standard package for organisations comfortable handling the process internally. It includes access to the online self-assessment portal and an official certification assessment by our team. You complete the question set on your own, at your own pace.

Choose this option if you have a good grasp of your IT security and just need the certification.

Micro

0-9 Employees

£320 + VAT

  • Government-backed certification
  • Official IASME assessment
  • Complete online in 48 hours

Small

10-49 Employees

£440 + VAT

  • Government-backed certification
  • Official IASME assessment
  • Complete online in 48 hours

Medium

50-249 Employees

£500 + VAT

  • Government-backed certification
  • Official IASME assessment
  • Complete online in 48 hours

Large

250+ Employees

£600 + VAT

  • Government-backed certification
  • Official IASME assessment
  • Complete online in 48 hours

Cyber Essentials:

Certification with Expert Support

This enhanced package is ideal if you’d like additional guidance to ensure a smooth path to certification. It includes everything in the standard self-assessment package plus two one-on-one consultation sessions with a qualified Arcanum assessor. In these sessions (conducted via phone or video call at stages of your choosing), our expert will provide advice, answer questions, and review your preparedness before you submit. We’ll essentially coach you through the tougher parts of the questionnaire, which can significantly boost your confidence and first-time pass rate.

This extra support is perfect for organisations with limited IT/security expertise, or anyone who values having an expert on call.

What's the difference in CE and CE+?

Cyber Essentials vs Cyber Essentials Plus

Cyber EssentialsCyber Essentials Plus
Self-assessment questionnaireIndependent hands-on technical verification
Basic level of assuranceHigher level of assurance with audit
Demonstrates awareness of basic security controlsDemonstrates effective implementation of controls
Low cost, entry-level certificationMore rigorous and comprehensive certification
Usually completed internally by organisationConducted by a licensed Certification Body
Valid for 12 monthsValid for 12 months
Required for many SMEs to show cyber hygieneRequired for UK government contracts and MOD suppliers
No technical auditIncludes vulnerability scans and system testing
Covers five key security controlsAssesses those controls with practical validation
Ideal for small organisations starting outIdeal for organisations handling sensitive data or large supply chains
A modern office | Cyber essentials certification for SME SMB from Arcanum Cyber

FAQs

What is Cyber Essentials certification?

Cyber Essentials is a UK government-backed scheme (supported by the NCSC and delivered via IASME) designed to protect organisations against approximately 80% of common internet-based cyber threats by implementing five basic security controls such as firewalls, secure configuration, access control, malware protection, and patch management.

How do I achieve Cyber Essentials certification?

You complete an online self-assessment questionnaire (SAQ) via IASME’s portal and submit it for review by an accredited certification body. Once verified, you’ll receive your certificate typically within 1–2 days if fully prepared – with three months to complete your assessment before account expiry.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

  • Cyber Essentials (Basic): Self-assessment and online verification.
  • Cyber Essentials Plus: Includes all Basic requirements plus a hands-on technical audit—vulnerability scans and device testing—conducted by certified assessors. This provides a higher assurance of your security implementation  .

(Find out more on our dedicated Cyber Essentials Plus page.)

How much does Cyber Essentials certification cost?

Pricing is set by IASME based on organisation size:

  • Micro (0–9 employees): ~£320 + VAT
  • Small (10–49): ~£440 + VAT
  • Medium (50–249): ~£500 + VAT
  • Large (250+): ~£600 + VAT  .

Prices for Plus and packages with consultancy vary depending on scope and support.

How long is the certification process and validity?

  • You have 3 months to complete your assessment from registration.
  • Once certified, the certificate is valid for 12 months—annual renewal is required to stay compliant.

Certification can be achieved in as little as 1–2 days, though most organisations take around 1–2 weeks depending on their readiness.

What happens if we fail the assessment?

If your self-assessment questionnaire responses don’t fully meet the requirements, the assessor will highlight areas to fix. You’ll have 2 working days to update and resubmit. If further attempts still fail, a new registration will be required.

Can we use legacy software or out-of-date systems and still comply?

Yes—in some cases. Commonly, legacy systems can be kept out of scope if they are isolated on separate networks without direct internet access. However, if they connect to your primary network, discuss with us how they can be appropriately segregated and removed from scope.

Do organisations of all sizes qualify for Cyber Essentials?

Absolutely. From sole traders to global corporations, Cyber Essentials scales to fit every kind of organisation. The certification and controls are fully adaptable to your size and complexity.

Does Cyber Essentials help with GDPR compliance or cyber insurance?

  • Yes, it supports GDPR compliance by demonstrating effective security controls for protecting personal data.

It also qualifies eligible UK organisations (turnover under £20M) for included cyber liability insurance, which covers incident response support.

When is Cyber Essentials mandatory?

  • It’s often required in government, MoD (a prerequisite to achieve DCC) and large corporate supply chains.
  • While not legally mandated for all UK organisations, many industries and clients consider it standard due diligence.

How often does Cyber Essentials update its scheme?

The scheme is usually updated each year, with the new question set taking effect from April. Any changes are usually announced in November. Reach out to us to discuss how any upcoming changes might affect you.

Ready to Secure Your Organisation?

Whether you prefer our convenient self-service approach or require expert consultation, Arcanum Cyber is here to assist you every step of the way.

Contact us today to buy or discuss your needs:

Get in touch about Cyber Essentials today