Frequently Asked Questions

Book Free Consultation ›

Cyber Essentials helps organisations put essential security measures in place and show they take cyber threats seriously. Evolve North provides straightforward guidance and support throughout the certification process. As an IASME partner we cover all four standards and frameworks.

This list of FAQs covers the key questions businesses often ask, but if you don’t see what you’re looking for here, we’re always happy to chat, just get in touch.

Cyber Essentials FAQs

What is Cyber Essentials?

Cyber Essentials is a simple but effective Government-backed scheme that helps organisations, regardless of size, to protect themselves against a range of the most common cyber attacks. It is managed by IASME as the sole delivery partner on behalf of the National Cyber Security Centre (NCSC).

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials consists of a self-assessment questionnaire which is assessed by an approved certification body. The questionnaire assesses your organisation’s IT systems against five core controls: firewalls and gateways, malware protection, security update management, secure configuration, and access control. Cyber Essentials Plus requires you to have already achieved Cyber Essentials certification and verifies the core security controls you have in place. It consists of a series of vulnerability assessments and malware response evaluations, ensuring that the controls you have described in the Cyber Essentials self-assessment questionnaire are working at an acceptable level.

How much does a Cyber Essentials assessment cost?

Our Cyber Essentials package prices vary depending on the size of the organisation and the support you need. At the most basic level of support, Cyber Essentials costs £320 plus VAT for a micro organisation of 0 to 9 employees, £440 plus VAT for a small organisation of 10 to 49 employees, £500 plus VAT for a medium organisation of 50 to 249 employees, and £600 plus VAT for a large organisation of 250 or more employees. Contact us for a tailored quote based on your specific requirements.

How much does a Cyber Essentials Plus assessment cost?

Cyber Essentials Plus pricing varies based on the size of the organisation, the support required, and the complexity of the IT environment being assessed. Because Cyber Essentials is a prerequisite for Cyber Essentials Plus, our pricing includes the cost of Cyber Essentials as standard. At the most basic level of support, Cyber Essentials Plus costs £1,220 plus VAT for a micro organisation (0 to 9 employees), £1,340 plus VAT for a small organisation (10 to 49 employees), £1,400 plus VAT for a medium organisation (50 to 249 employees), and £1,500 plus VAT for a large organisation of 250 or more employees.

How long does Cyber Essentials certification take to complete?

The time it takes to achieve compliance varies significantly, largely depending on how closely your current practices already align with the Cyber Essentials requirements. While we respond to feedback requests promptly, the speed of the certification process also depends on how quickly your organisation addresses our feedback. Organisations using a lot of outdated software and hardware may take longer, as these will need to be updated or replaced. We recommend reviewing our gap analysis service to assess your current alignment with the standard.

How many questions do I need to get right to pass Cyber Essentials?

Questions in the Cyber Essentials self-assessment questionnaire are graded as Compliant, Non-compliance, Fail, or More Information Required. An organisation can receive two or fewer Non-compliance grades and still pass, but cannot pass with any Fail grades. If an organisation receives a More Information Required grade, they will be asked to supply additional information before their application is submitted. Evolve North reviews your application before submission and provides feedback to help you become compliant on any non-compliant or failing questions.

Where can I get more information about the included Cyber Insurance?

Successful Cyber Essentials certification optionally includes free Cyber Liability Insurance for UK-domiciled organisations with a turnover under £20 million. As standard, this has a £25,000 total limit of indemnity, which can optionally be upgraded to £250,000 of indemnity for an additional fee. You can read more on the IASME Cyber Liability Insurance page, or contact Sutcliffe and Co. Insurance Brokers, who administer the Cyber Essentials insurance, on 01905 21681 or cyberessentials@sutcliffeinsurance.co.uk.

How long do I have to complete and submit my assessment?

Once you have started the process with Evolve North, you have up to 12 months to complete Cyber Essentials certification. For Cyber Essentials Plus, you have three months from the issue of your Cyber Essentials certificate to complete the additional certification.

How long does Cyber Essentials certification last?

Cyber Essentials and Cyber Essentials Plus certificates are each valid for one year. After this period, organisations need to recertify to maintain their certified status and continue demonstrating compliance with the scheme’s requirements.

Can we use our existing vulnerability scanning results for Cyber Essentials Plus certification?

Yes, provided the vulnerability scanning software in use is approved. We can use your existing scanning software to perform our assessment and will send instructions on how to do this. Common vulnerability scanning tools we support include Qualys and Nessus. If you are using Qualys, let us know and we can provide a query to build a Cyber Essentials dashboard to help you track compliance.

What happens if we change our organisation name or trading address during certification?

If you change organisation name or address during your application, Evolve North can update this before submitting for final assessment. If you change name after application, and provided the scope of certification has not changed significantly (for example, you have not merged with another company or moved to a new office), it is possible to update your certificate to reflect this for a nominal admin fee charged by IASME. If the scope has changed, you will need to undergo recertification.

If we fail the Cyber Essentials assessment, will we have to pay again?

Evolve North provides all Cyber Essentials services as part of a package, which means we work with you to ensure the highest chances of passing successfully. Before any formal assessment is performed, we review your current controls and, for Cyber Essentials Plus, perform pre-audits to ensure you are in good standing. It is therefore unlikely you will fail an assessment unless you run out of time.

Do I need a penetration test for Cyber Essentials Plus?

No, neither Cyber Essentials nor Cyber Essentials Plus mandate a penetration test. In the past, the scheme was run by multiple NCSC delivery partners with varied requirements, but since April 2020 IASME has been the sole delivery partner, and penetration testing is not a requirement under their management. Cyber Essentials Plus includes an independent technical audit with vulnerability scanning. You can read more about the difference between vulnerability scanning and penetration testing on our blog.

need more information? Visit our Cyber Essentials home page – Call 01748 905 002

CLICK HERE

Arrange a FREE Consultation

Evolve North provides a simple and streamlined system to achieving Cyber Essentials with a focus on small to medium sized organisations. Our personal approach ensures you are informed and guided throughout the process.