Skip to content
Cyber Essentials & Cyber Essentials Plus · Bristol & Bath · Since 2000

Cyber Essentials — for Bristol & Bath Businesses

The UK Government's cybersecurity certification scheme. Two levels — basic and Plus. We're certified to Plus ourselves, and we help our clients get certified at either level.

Or call us on 0117 958 5964

Cyber Essentials Plus Certified

What is Cyber Essentials?

Cyber Essentials is a UK Government cybersecurity certification scheme, administered by IASME and endorsed by the National Cyber Security Centre. It sets out five technical controls that, done well, block the vast majority of common cyber attacks.

There are two levels: Cyber Essentials (self-assessed via questionnaire — which we can complete on your behalf), and Cyber Essentials Plus (externally audited — an IASME-accredited assessor tests your systems and verifies the controls work).

The "Plus" means the assurance is real. Not "we say we do this" but "an independent auditor tested it and it does".

Smooth IT is certified to Cyber Essentials Plus — the stronger of the two — and we help our clients achieve certification at either level.

Cyber Essentials vs Cyber Essentials Plus

Same five controls. Very different level of assurance.

Aspect Cyber Essentials Cyber Essentials Plus
Assessment type Self-assessment questionnaire External technical audit + vulnerability testing
Assurance level "We say we do this" "An auditor verified we do this"
Typical cost £320–£600 + VAT assessment fee £1,500–£4,000+ + VAT assessment fee
Preparation time Days to weeks Weeks to months
Validity 12 months 12 months
Held by (% UK businesses) ~5–10% Less than 10% of those

The five technical controls

What Cyber Essentials is actually assessing — at both levels. All five must be genuinely in place, and for the Plus tier, provable under external audit.

Firewalls & internet gateways

Properly configured firewalls on every device that connects to the internet, with default passwords changed and administrative interfaces protected.

Secure configuration

Devices and software set up to reduce attack surface — unnecessary services disabled, default accounts removed, secure baseline enforced.

User access control

Users have only the access they need to do their job. Admin accounts separated from day-to-day accounts. Multi-factor authentication where it counts.

Malware protection

Endpoint protection on every workstation and server, kept up to date, actively monitoring and blocking known threats.

Security update management

Operating systems and applications patched promptly — typically within 14 days of a critical patch release. No unsupported software left running.

Why businesses pursue Cyber Essentials

Four common drivers. Most clients we help have at least two of these on their radar.

Public sector & government contracts

Many public-sector contracts require Cyber Essentials or Cyber Essentials Plus. MoD contracts handling personal information typically require CE Plus. If you're bidding for that work, this is often the gate.

Cyber insurance requirements

Many cyber insurers now require Cyber Essentials as a minimum to write a policy. Some discount premiums significantly for CE Plus holders — the difference can be material at renewal.

Supply chain demands

Larger customers increasingly require their suppliers to hold CE or CE Plus. If you sell into enterprise, professional services, or the public sector, you may find this appearing in tender documents.

Due diligence & board reporting

For boards, insurers, and post-incident scrutiny, holding a current, externally audited certification is powerful evidence you took security seriously. It doesn't prevent every incident — but it does demonstrate reasonable care.

How we help you get certified

We've been through Cyber Essentials Plus ourselves. We know what auditors actually look for, what tends to trip businesses up, and how to prepare without wasting time on things that don't affect the outcome.

1

Initial scoping call

Free, no obligation. We understand your business, existing setup, and target timeline. We're honest about whether CE Plus is worth the effort for you, or whether basic CE would suit better.

2

Gap assessment

We map your current controls against the five requirements and give you a plain-English list of what's already there, what needs adjusting, and what has to be added. Quoted transparently.

3

Remediation

We fix the gaps — firewall config, MFA setup, patching regime, endpoint protection deployment, whatever needs doing. Billed by the minute at our standard rate; you see exactly what you're paying for.

4

Audit & certification

The IASME-accredited assessor does their thing — vulnerability scans, configuration checks, verification calls. We support you through the process and remediate anything that surfaces.

5

Annual renewal

CE Plus is valid for 12 months. We keep your setup maintained through the year and manage the renewal audit ahead of expiry so certification never lapses.

Why work with us on Cyber Essentials?

We hold it ourselves

Cyber Essentials Plus certified. We know what "passing" actually looks like because we live it — externally audited annually to the same standard we recommend to you.

Independent of IT support

You don't need to move your IT to us. We work with your existing team or provider on certification, and only take over the broader support if that's what you want.

Honestly quoted

Prep work billed by the minute at our standard hourly rate — no bloated project fee. You see exactly what you're paying for, no minimums, no monthly retainer.

Bristol-based, since 2000

Local IT support business, 25 years running. On-site if you need it. Same engineers on your certification this year and next.

Cyber Essentials — common questions

What's the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials (basic) is self-assessed — a questionnaire is completed, an assessor reviews it, and if the answers meet the standard the certification is issued. We can complete the questionnaire on your behalf. Cyber Essentials Plus is externally verified: an IASME-accredited auditor tests your systems directly, runs vulnerability scans against your devices, and confirms the controls are actually in place. Same five technical controls; the "Plus" is the audited assurance that they're real.
How long does the certification process take?
For a well-prepared business with our IT infrastructure already in place, Cyber Essentials Plus certification typically takes 2–4 weeks end to end: a preparation phase, the assessor's technical audit, and issuance of the certificate. For businesses starting from scratch — needing to change firewall rules, harden device configurations, sort out patching — allow 6–10 weeks to do it properly.
What does it cost?
The IASME assessment fee is typically £320–£600 + VAT for basic Cyber Essentials, and £1,500–£4,000+ + VAT for Cyber Essentials Plus, depending on the size of your business. Our preparation and remediation work is billed at our standard hourly rate, and depends entirely on where you're starting from — for clients with modern, well-managed IT, prep is usually a handful of hours. For businesses inheriting older or less-well-managed IT, more. We quote transparently once we've done an initial scoping call.
Do we need to be an existing Smooth IT client?
No. We help both existing IT support clients and businesses whose IT is managed elsewhere. If you have an internal IT team or another provider, we work alongside them for the certification prep. If you'd like us to take over the IT support side as part of the exercise, that's also an option.
What if we fail the audit?
Then you get a list of specific things to fix. That's actually the value of Cyber Essentials Plus — the audit finds the gaps, we remediate, you re-test. In our experience, businesses that prepare properly with us don't fail; but if issues surface during the audit, we sort them and re-submit. IASME allows a reasonable window for remediation.
Is basic Cyber Essentials enough for our business?
For some businesses, yes. If your customers don't specifically ask for CE Plus, your insurance doesn't require it, and you're not bidding for public-sector work, basic Cyber Essentials may cover your needs. That said, the delta in effort between CE and CE Plus is usually less than businesses fear — and the credibility uplift is significant. We'll advise honestly once we understand your situation.
How often do we need to renew?
Annually. Both Cyber Essentials and Cyber Essentials Plus certificates are valid for 12 months from issue. Most clients keep the same auditor and cycle through renewal in the same month each year — the second and subsequent audits are generally faster than the first.
Can you help with Cyber Essentials only (not Plus)?
Yes. Some clients start with basic Cyber Essentials to test the water, then upgrade to CE Plus at renewal once they've seen the process. We support either path.

Ready to talk about Cyber Essentials?

The first scoping call is free. We'll tell you honestly whether basic Cyber Essentials or the Plus tier is right for you, roughly what it will take, and where you stand today.

Or call us on 0117 958 5964