UK CYBER SECURITY CONSULTANCY – ASSESSMENT

Readiness reviews, gap closure and submission support for Cyber Essentials

We check your systems against the five Cyber Essentials controls, help close whatever’s missing, and guide you through submission — or the on-site technical audit, if you’re going for Cyber Essentials Plus. You come out the other side with a certificate backed by controls that actually work.

Cyber Essentials certification process

WHO IT’S FOR

Cyber Essentials support for SMEs, first-time applicants and renewals.

SMEs pursuing Cyber Essentials or Cyber Essentials Plus for the first time.

Businesses that started the self-assessment questionnaire and got stuck, or failed.

Organisations renewing an existing certificate under the updated requirements.

Suppliers who need certification to bid for contracts or meet customer due diligence.

COMMON TRIGGERS

Signs you need Cyber Essentials certification support.

A customer, tender or government contract requires Cyber Essentials certification.

Your cyber insurance renewal asks for it.

You attempted the questionnaire yourself and weren’t confident in the answers.

Your certificate is due for annual renewal and the requirements have moved on since last time.

WHAT’S INCLUDED

What’s included in TSP’s Cyber Essentials support.

Gap analysis against the five controls

Firewalls, secure configuration, security update management, user access control and malware protection — checked against where you stand today.

Prioritised remediation plan

Hands-on support closing the gaps identified, not just a list of what’s wrong.

Guided questionnaire completion

We complete the self-assessment questionnaire with you, so nothing gets misanswered.

Cyber Essentials Plus readiness

Preparation for the assessor’s technical audit, where Plus is required.

Submission support

Guided through to certificate issue, start to finish.

HOW IT WORKS

How Cyber Essentials certification works with TSP.

TYPICAL OUTCOMES

What you gain from a valid Cyber Essentials certificate.

A valid certificate, not just a checklist

A valid Cyber Essentials or Cyber Essentials Plus certificate, backed by evidence rather than guesswork

Controls that hold up under scrutiny

Security measures that stand up if a customer, insurer or assessor ever asks to see them

Confidence when it's tested

Reassurance going into tenders, insurance renewals and customer due diligence, not just at certification time

A renewal you're ready for

A repeatable process, so next year’s renewal is a formality rather than a scramble

CERTIFIED AGAINST

Benchmarked against recognised frameworks.

Certified Against the NCSC’s Cyber Essentials Scheme.

We assess and prepare you against the NCSC’s Cyber Essentials scheme, delivered by IASME. This includes the April 2026 (v3.3) requirement updates, which introduced a 12-character minimum password length and made multi-factor authentication mandatory on all cloud services that offer it.

Cyber Essentials vs Cyber Essentials Plus

Cyber Essentials is self-assessed: you complete a questionnaire, which is then independently reviewed. Cyber Essentials Plus goes further, adding vulnerability scanning and on-site testing by a licensed assessor. Both certifications require the same five controls, to the same standard — Plus is simply the version where someone checks. Already hold Cyber Essentials and want to move up to Plus? You have 90 days from your certification date to do it under the same window.

YOUR ASSESSOR

Led personally by Carl Pugh, founder of TSP.

Picture of Carl Pugh

Carl Pugh

Carl brings honest, open dialogue to every engagement — no tech talk, just a common understanding.

Carl has spent 30 years in the IT industry, rising through the ranks across a wide variety of roles before reaching board level as IT Director for a FTSE 250-listed international business, prior to founding TSP. That route means the assessment is grounded not just in how businesses run IT day to day, but in why protecting your business assets and data has become paramount in today's threat landscape.

RELATED SERVICES

Where to go next.

Cyber Security Assessment

Learn more >

ISO 27001 & ISMS Consultancy

vCISO & Cyber Advisory

Incident Readiness

Cyber Essentials Support FAQs

Cyber Essentials is a self-assessed questionnaire, reviewed independently. Cyber Essentials Plus adds a hands-on technical audit, including vulnerability scanning and on-site testing by a licensed assessor, to confirm the same five controls are genuinely working in practice.

The certification body (IASME) sets a fixed assessment fee based on your organisation’s size, currently ranging from £330+VAT to £500+VAT for Cyber Essentials, and £1,500–£4,250+VAT for Cyber Essentials Plus. Our support (the readiness review, gap closure and submission guidance) is a separate fee, confirmed on your Cyber Clarity Call.

Twelve months. Requirements are reviewed periodically by the NCSC and IASME, so it’s worth taking renewal seriously each year rather than treating it as a rubber stamp. The 2026 update, for example, introduced longer minimum password lengths and mandatory MFA on cloud services.

Not always. It depends on what your customers, insurer or contracts require — some organisations hold Cyber Essentials for years without ever needing Plus, others are asked for it specifically. We’ll help you work out which applies to you on the Cyber Clarity Call.

That’s what the gap closure phase is for. We flag what would cause a fail before you submit, and help you fix it, so you’re not finding out from a rejected application.

Know your risks. Strengthen your defences.

You can’t protect your business effectively if you don’t know where the real risks are. And those risks are constantly changing. A TSP Cyber Security Assessment gives you a clear view of your current security position, highlighting vulnerabilities, gaps and areas that need attention before they become bigger problems.

We review the technology, processes and protections you already have in place, then explain our findings in straightforward business language. You’ll receive practical, prioritised recommendations, so you know what needs addressing first and what can follow later. No scaremongering. No confusing technical report. Just a clear understanding of your cyber risk and a sensible plan for strengthening your defences.

Book a time that suits you and let’s talk about your Cyber Security Assessment. No pressure, just a straightforward conversation (brew optional).

Our Partners