Cyber Essentials · Government-backed certification

Cyber Essentials, explained properly

It’s the government-backed certification that contracts, customers and insurers increasingly ask for. And the moment somebody asks, you either have it or you’re out of the running. Here’s what it actually is, what it unlocks, and why it costs far less to hold it before the question arrives.
Thirty minutes with Adam. Straight answers, no jargon, and a clear view of where you stand.
Video call. Thirty minutes. No obligation and no sales script.
We hold the certification we sell, including the Plus.
What it actually is

What Cyber Essentials actually is

Cyber Essentials is a UK government-backed certification. Strip away the name and it asks one fair question. Are the five basic protections the scheme is built around genuinely switched on in your business? Not the exotic stuff. The basics, done properly. Break-ins tend to happen through an unlocked door, and these five controls are the doors.

Firewalls

Something sensible sitting between your business and the open internet, so the rest of the world can’t wander straight in.

Secure settings

New laptops, routers and cloud accounts arrive set up for convenience rather than safety, so the default settings and unused features get tightened up.

Who can access what

Everyone gets the access their job needs and nothing more, so one borrowed password doesn’t hand over the whole business.

Protection against malware

Something actively watching for and blocking the malicious software that arrives by email, by download, or on a memory stick somebody plugs into a laptop.

Keeping software up to date

Every device, app and phone gets its updates installed, because attackers routinely rely on holes that were fixed months ago.

That’s it. Five controls, and a certificate that says an independent scheme agrees you’ve got them.
Attacks on small businesses rarely need anything clever. They need one door left open.
What it gets you

What having it actually gets you

A certificate is only worth what it does for the business. Here’s what this one does.
Woman, smile and portrait in creative office for startup, artist and happy for small business agency. Manager, workshop and a
Senior, happy man and call center with headphones in customer service, support or telemarketing at office. Mature businessman
Business, people and explain with computer at night for training, finance report and budget. Staff, pc and coaching for audit

01

You can bid for the work that requires it

Public sector contracts, larger private clients, framework applications, grant-funded projects. More and more of them list Cyber Essentials as a condition of entry rather than a nice-to-have. Without it you’re not being outbid, you’re being filtered out before anyone reads your price. With it, you tick the box and get judged on the thing you’re actually good at.

02

You answer security questionnaires in one line

You know the one. The eight-page supplier security questionnaire from your biggest customer’s procurement team, the one that lands on a Friday afternoon and eats your whole weekend. Certification turns most of it into a single sentence and an attached certificate. Insurers ask the same questions, and some now factor the answers into your premium.

03

You stop being the easy way into a bigger customer

Attackers have worked out that a reliable route into a large organisation is through one of its smaller suppliers. Your customers have worked that out too, which is exactly why they’ve started asking. Certification is how you show you’re the link in the chain that holds, and it’s a genuinely good reason for a big client to keep you.

04

You know the basics are in place, instead of hoping

Most owners we speak to think they’re probably fine. “Probably” is doing a lot of work in that sentence. Certification replaces it with evidence: every device up to date, access controlled, malware protection running, and someone who can prove it. That’s worth something on a Sunday night, whether or not a customer ever asks.
The usual timing

Most businesses call us three weeks before a tender deadline

By then the bid is half written and page four says supplier must hold current Cyber Essentials certification. We often get there. But certification isn’t a form you fill in, it’s a set of controls that has to be genuinely true, and fixing those takes time a deadline won’t give you.
Left to the deadline

What the self-assessment usually turns up

Certified in advance

What doing it early buys you

The businesses that win this work aren’t the ones who move fastest when asked. They’re the ones who were already certified when the question came.
Video call with Adam. Thirty minutes. Nothing to prepare.
What's involved

What's actually involved

No mystery, and no consultant-speak. Three stages.
question mark on a sticky note against grained wood
The self-assessment​

You work through a structured assessment against the five controls, covering every device, user and cloud service in the business. We sit on the call and do it with you, translating the questions into plain English as we go. It's usually the first time an owner sees the whole picture in one place.

1
Fixing the gaps

Almost nobody passes cleanly first time, and that's the point. The assessment produces a specific, finite list of things that aren't right yet. We'll tell you honestly which items we can put right for you and which are yours to decide on, and then they get fixed. No gap gets ticked off on paper only.

2
Certification

Once the controls are genuinely in place, the assessment goes in for certification. You get the certificate, the badge for your website and email signature, and a straight answer for the next person who asks. It's renewed annually, so it stays true instead of gathering dust.

 
3

What about Cyber Essentials Plus?

Cyber Essentials Plus is the same five controls, independently checked by hand. Instead of taking your word for it, an assessor gets onto a sample of your actual devices, runs the scans, and verifies that multi-factor authentication really is enforced and the updates really are current.
Cyber Essentials Plus always sits on top of Cyber Essentials, never instead of it. A valid Cyber Essentials certificate is a prerequisite for the Plus assessment, so the two go together. You can’t buy Plus on its own, and anyone telling you otherwise has misunderstood the scheme.
Some contracts and insurers specifically require the Plus. Plenty of businesses get asked for it without realising. It’s one of the first things we’ll check on the call.
Local proof

We're local, and we're certified ourselves

We Do Your Group is based at 20 Apex Court, Bradley Stoke, on the same business park as Mrs B’s café, which we’re proud to sponsor. Most of the businesses we look after are within a few miles of that coffee machine. Trades, salons, garages, accountants, small manufacturers and charities, typically somewhere between one and fifty staff, most of them running Microsoft 365, and very few with anyone in-house looking after IT.
We’re an NCSC Assured Service Provider and an IASME-certified Cyber Advisor, and we hold Cyber Essentials Plus, ISO 27001 and ISO 9001 ourselves. We’re not going to ask you to do anything we haven’t already done to our own business.

213

local businesses certified

20 years

supporting businesses in Bristol

NCSC Assured

Service Provider

Cyber Essentials Plus

certified ourselves
Real clients, real names, used with permission.
Small enough to care, big enough to support.

Thirty minutes, and you'll know exactly where you stand

Book a video call with Adam Gillett. He’ll explain how Cyber Essentials applies to your business specifically, tell you honestly whether the basics are already close, flag whether your contracts are likely to need the Plus, and set out what certification would actually involve for you.
No slide deck. No obligation. And if it turns out you don’t need it yet, he’ll tell you that too.

Or just call. 0117 911 8808, and a human answers.