UK CYBER SECURITY CONSULTANCY – ASSESSMENT
We check your systems against the five Cyber Essentials controls, help close whatever’s missing, and guide you through submission — or the on-site technical audit, if you’re going for Cyber Essentials Plus. You come out the other side with a certificate backed by controls that actually work.
WHO IT’S FOR
Cyber Essentials support for SMEs, first-time applicants and renewals.
SMEs pursuing Cyber Essentials or Cyber Essentials Plus for the first time.
Businesses that started the self-assessment questionnaire and got stuck, or failed.
Organisations renewing an existing certificate under the updated requirements.
Suppliers who need certification to bid for contracts or meet customer due diligence.
COMMON TRIGGERS
A customer, tender or government contract requires Cyber Essentials certification.
Your cyber insurance renewal asks for it.
You attempted the questionnaire yourself and weren’t confident in the answers.
Your certificate is due for annual renewal and the requirements have moved on since last time.
WHAT’S INCLUDED
Firewalls, secure configuration, security update management, user access control and malware protection — checked against where you stand today.
Hands-on support closing the gaps identified, not just a list of what’s wrong.
We complete the self-assessment questionnaire with you, so nothing gets misanswered.
Preparation for the assessor’s technical audit, where Plus is required.
Guided through to certificate issue, start to finish.
HOW IT WORKS
TYPICAL OUTCOMES
A valid Cyber Essentials or Cyber Essentials Plus certificate, backed by evidence rather than guesswork
Security measures that stand up if a customer, insurer or assessor ever asks to see them
Reassurance going into tenders, insurance renewals and customer due diligence, not just at certification time
A repeatable process, so next year’s renewal is a formality rather than a scramble
CERTIFIED AGAINST
We assess and prepare you against the NCSC’s Cyber Essentials scheme, delivered by IASME. This includes the April 2026 (v3.3) requirement updates, which introduced a 12-character minimum password length and made multi-factor authentication mandatory on all cloud services that offer it.
Cyber Essentials is self-assessed: you complete a questionnaire, which is then independently reviewed. Cyber Essentials Plus goes further, adding vulnerability scanning and on-site testing by a licensed assessor. Both certifications require the same five controls, to the same standard — Plus is simply the version where someone checks. Already hold Cyber Essentials and want to move up to Plus? You have 90 days from your certification date to do it under the same window.
YOUR ASSESSOR
Carl brings honest, open dialogue to every engagement — no tech talk, just a common understanding.
Carl has spent 30 years in the IT industry, rising through the ranks across a wide variety of roles before reaching board level as IT Director for a FTSE 250-listed international business, prior to founding TSP. That route means the assessment is grounded not just in how businesses run IT day to day, but in why protecting your business assets and data has become paramount in today's threat landscape.
RELATED SERVICES
Cyber Security Assessment
Learn more >
ISO 27001 & ISMS Consultancy
vCISO & Cyber Advisory
Incident Readiness
Cyber Essentials is a self-assessed questionnaire, reviewed independently. Cyber Essentials Plus adds a hands-on technical audit, including vulnerability scanning and on-site testing by a licensed assessor, to confirm the same five controls are genuinely working in practice.
The certification body (IASME) sets a fixed assessment fee based on your organisation’s size, currently ranging from £330+VAT to £500+VAT for Cyber Essentials, and £1,500–£4,250+VAT for Cyber Essentials Plus. Our support (the readiness review, gap closure and submission guidance) is a separate fee, confirmed on your Cyber Clarity Call.
Twelve months. Requirements are reviewed periodically by the NCSC and IASME, so it’s worth taking renewal seriously each year rather than treating it as a rubber stamp. The 2026 update, for example, introduced longer minimum password lengths and mandatory MFA on cloud services.
Not always. It depends on what your customers, insurer or contracts require — some organisations hold Cyber Essentials for years without ever needing Plus, others are asked for it specifically. We’ll help you work out which applies to you on the Cyber Clarity Call.
That’s what the gap closure phase is for. We flag what would cause a fail before you submit, and help you fix it, so you’re not finding out from a rejected application.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
These cookies are needed for adding comments on this website.
Google reCAPTCHA helps protect websites from spam and abuse by verifying user interactions through challenges.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and .