This document sets out what's included in our Cyber Essentials Accreditation service.
The certification fee required to have the questionnaire assessed via a certified IASME assessor to the current Cyber Essentials standard is included in our Advanced Cyber Security service.
Our team will undertake the following activities to support a customer's organisation in achieving Cyber Essentials (CE) certification:
Initial review and assessment of relevant systems, controls and security measures in place
Report back findings as a gap analysis, highlighting areas that must be corrected to achieve CE certification
Working together to build an action plan to remediate the required items
Where we are the IT Managed Services Provider, a list of items that can be completed within the service specification will be provided, and any items outside this will be given an estimated cost for implementation
Once all required gaps have been addressed, our team will assist in completing the self-assessment questionnaire
Contact a certified CE assessor and co-ordinate all activities
Assist with any clarification queries or recommendations
The following items are specifically excluded from this service:
Creation of internal organisational policies
Implementation of physical security controls, such as access badges or CCTV
Conducting penetration testing or vulnerability assessments
Assisting with any other compliance standards, such as ISO 27001
Investigating or remediating any pre-existing security issues
If a customer wishes to undertake Cyber Essentials Plus certification, this can be completed at an additional cost. These certifications are based on an estimate and will be billed on a time-and-materials basis, due to their complex nature.
Cyber Essentials Plus must be completed within 90 days of achieving Cyber Essentials accreditation, if desired.