Get ready for Cyber Essentials without the jargon. We help Kent SMEs understand the requirements, fix the gaps and submit with confidence, guided by an IRCA ISO 27001 lead auditor.
Cyber Essentials is the UK Government-backed scheme that shows your business has the basic protections in place against the most common cyber attacks. It's run by the National Cyber Security Centre (NCSC) and its delivery partner IASME.
More and more SMEs are being asked for it. It's required for many central government contracts, it's increasingly requested by local councils, the NHS, housing associations and main contractors, and many insurers look more favourably on businesses that hold it.
Cyber Essentials checks five areas of your IT:
Most businesses don't fail Cyber Essentials because their IT is bad. They fail because they misunderstand a question, leave something out of scope, or miss one unsupported laptop. We make sure that doesn't happen.
Your assessment is then marked by an independent, IASME-licensed Certification Body. The certification fee is paid to them separately, and we'll tell you the exact cost up front.
Many businesses go straight to a Certification Body. That works, but many Certification Bodies also sell IT services, software or fixed-price remediation packages, so the company telling you what needs fixing is often the same one selling you the fix.
ISOHS is an independent advisor. We don't sell hardware, software or IT contracts, and we don't earn commission from anyone. That means:
Cyber Essentials Plus uses the same five controls but adds a hands-on technical audit of your systems by a licensed assessor. We help you prepare so your devices and settings are ready before the assessor arrives, reducing the risk of failures and retests.
Cyber Essentials and ISO 27001. Cyber Essentials covers basic technical controls. ISO 27001 is a full information security management system. Cyber Essentials is a quick, affordable first step, and the work you do counts towards ISO 27001 later.
Cyber Essentials and SSIP. Contractors applying for CHAS, SMAS or SafeContractor are often asked about cyber security in the same tender. We can handle both together.
For most small businesses, two to four weeks from first conversation to submission, depending on how much needs fixing. Certification is valid for 12 months.
There are two parts: our support fee, which we quote as a fixed price after the free consultation, and the certification fee paid to the Certification Body, which is set by IASME and depends on the size of your business.
Not always. Many small businesses can make the changes themselves with our guidance. If you have an IT provider, we work alongside them.
You can, and some businesses do. The difference is that we're independent: we don't sell IT products or services, so we show you the different ways to fix each gap and let you choose, rather than offering one fixed package. You stay free to use your own IT provider and pick any Certification Body you like.
The most common problems are unsupported software, such as old versions of Windows, missing multi-factor authentication on Microsoft 365 or Google Workspace, and staff using admin accounts day to day. We check for all of these before you submit.
Yes. We support businesses across Kent and the South East, with on-site visits where helpful and remote support for everything else.
Book a free consultation and we'll tell you how close you already are, and what it will take to pass.