CYBER ESSENTIALS | HAMPSHIRE
Cyber Essentials in Hampshire
Prepare for customer checks
Need Cyber Essentials certification for a tender or customer requirement? Our Whiteley team checks your systems, helps fix gaps and guides you through assessment questions. We support Cyber Essentials and Cyber Essentials Plus preparation across Southampton, Portsmouth, Winchester, Basingstoke and Farnborough.
Get a free IT reviewWHAT IS CYBER ESSENTIALS
Cyber Essentials certification: give buyers evidence of security
Our Cyber Essentials Hampshire service helps you check requirements, fix gaps and prepare for certification. Cyber Essentials is a UK Government-backed scheme covering basic protection against common cyber attacks. We explain what your business needs to meet the standard and help you prepare your assessment answers.
The National Cyber Security Centre (NCSC) developed the scheme, which IASME delivers. It suits small and medium organisations. Your certificate gives customers, insurers and suppliers evidence that the systems assessed meet the scheme's security requirements. Our business holds Cyber Essentials too.
We review your devices, firewall, cloud services and Microsoft 365 settings against the current requirements. We establish which systems must be included in your assessment and identify what needs changing. We fix gaps or guide your team through the work, then help you prepare your submission.
KEY AREAS COVERED
Cyber Essentials requirements: know what your systems must meet
Check five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. These cover the devices and services included in your assessment.
Firewalls
Every device that connects to the internet sits behind a correctly set up firewall, including home workers' laptops. Default admin passwords are changed and unused ports are closed, so attackers have fewer ways in from outside your network.
Secure configuration
Remove default accounts, unused software and auto-run features. Lock every device with a PIN, password or biometric, so a lost or stolen laptop does not turn into a data breach. Every setting you remove is one less weakness.
Security update management
Operating systems, firmware and apps stay supported and get high-risk and critical patches within 14 days. Under the 2026 rules a single missed patch is an automatic fail, so updates need tracking across every device you use.
User access control
Staff only get the access they need. Admin accounts are kept separate from everyday accounts. Multi-factor authentication (MFA) is switched on for every cloud service that supports it, Microsoft 365 included, which is now an automatic fail item.
Malware protection
Anti-malware runs on every in-scope device, or application allow-listing controls what software can run. Either approach helps stop ransomware and malicious downloads before they execute, and both need keeping up to date as part of your routine.
Scope and cloud services
Cloud services that hold your business data, such as Microsoft 365, Google Workspace and Xero, are firmly in scope. Personal (BYOD) devices that reach business data need technical controls, or must be kept out of scope with clear separation.
WHY IT MATTERS
Meet tender requirements with Cyber Essentials certification
Certification helps you demonstrate your security controls when bidding for contracts that require it. Larger employers, councils, NHS trusts and defence suppliers may request Cyber Essentials before awarding work. This includes aerospace and defence buyers around Farnborough and Portsmouth. Check whether your tender requires Cyber Essentials or Cyber Essentials Plus before applying.
- Contracts and tenders: required for many central government contracts that handle personal data, and often asked for in private supply chains.
- Fewer successful attacks: the five controls defend against common internet-based attacks such as phishing and malware.
- Customer trust: your certificate appears on the public IASME register, and you can show the badge on your website and proposals.
- Insurance: eligible organisations have been able to claim free cyber liability insurance, so check current terms with IASME.
HOW IT WORKS
Prepare for Cyber Essentials with a clear plan of action
Four steps: review your systems, identify gaps, make changes and prepare your submission. Our local engineers explain the work needed at each stage.
Discovery call
A short call about your devices, cloud services and why you need certification, such as a tender or insurance renewal. We agree the scope and quote for it.
Pre-assessment gap analysis
Our engineers check your setup against the Danzell question set, including MFA, patching, BYOD and admin rights. We fix the gaps or show your team what to change.
Submission and assessment
We help you answer the questionnaire accurately. An independent IASME Certification Body then marks it and confirms your result.
Certification achieved
You receive your certificate and badge, valid for 12 months. Our managed IT plans can keep your controls in shape between renewals.
CERTIFICATION LEVELS
Cyber Essentials or Cyber Essentials Plus?
Choose the level your customer or contract requires. Cyber Essentials uses an assessor-reviewed self-assessment. Cyber Essentials Plus adds independent technical testing of the same controls.
Cyber Essentials certification
A verified self-assessment that suits most small businesses and first-time applicants. You answer a questionnaire covering all five controls, a director signs it off, and an IASME Certification Body marks it.
- Certificate and badge valid for 12 months
- Suits first-time certification and most tenders
- IASME scheme fees from £320 + VAT for micro organisations (0-9 staff)
Cyber Essentials Plus certification
The same controls, plus a hands-on technical audit that proves they work. An assessor tests a sample of devices, runs internal and external scans and checks MFA on your cloud services.
- Must be completed within 3 months of your Cyber Essentials certificate
- Often asked for in defence, NHS and larger supply chain contracts
- Price depends on devices and sites, so we quote after scoping
Frequently asked questions
Cyber Essentials: your questions answered
How long does Cyber Essentials certification take?
The time needed depends on how much work your systems require before assessment. If your controls already meet the requirements, preparation focuses on checking them and completing the questionnaire. Introducing multi-factor authentication (MFA), updating systems or replacing unsupported equipment adds time. We give you a realistic timetable after reviewing the gaps. Cyber Essentials Plus also needs time for independent testing.
How much does Cyber Essentials certification cost?
The IASME assessment fee starts at £320 plus VAT for organisations with 0-9 employees. IASME sets the fee by organisation size. Your total Cyber Essentials cost also depends on any preparation and fixes needed. We quote our gap analysis, agreed changes and submission support after your discovery call. Cyber Essentials Plus costs more and requires a separate testing quote based on your network size, complexity and assessment scope.
What changed in Cyber Essentials in 2026?
The 2026 changes introduced stricter marking for MFA and security updates, alongside clearer assessment scope requirements. The Danzell question set and Requirements v3.3 apply to assessment accounts created from 27 April 2026. Missing MFA on an included cloud service where it is available results in automatic failure. This applies even when MFA requires a paid option. High-risk or critical security updates must be installed within 14 days of release. Failure to meet that requirement also results in automatic failure. Older Willow assessment accounts have six months from creation to complete certification.
What are the Cyber Essentials requirements?
You need five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. These apply across the devices and services included in your assessment. Your devices and software must have manufacturer support. A board member or director must confirm your answers before submission. They must also acknowledge responsibility for maintaining the controls throughout the certification period. Our managed cyber security service can help you maintain these controls.
Does Cyber Essentials include cyber insurance?
Yes, eligible organisations can receive free cyber liability insurance when they certify their whole business, subject to the scheme's current terms. Check eligibility and cover with IASME before relying on the policy. Your insurer may also ask whether you hold Cyber Essentials when you renew existing cover.
Do I need Cyber Essentials or Cyber Essentials Plus?
You need whichever certification level your customer or contract specifies. Cyber Essentials uses a self-assessment questionnaire reviewed by an assessor. Cyber Essentials Plus adds independent technical testing to check that the same controls are correctly implemented. Many central government contracts involving personal or sensitive information require certification. Councils, NHS trusts, defence suppliers, insurers and larger customers may also request it. Any UK organisation can apply, regardless of size or sector.
Do Cyber Essentials requirements cover home workers and personal devices?
Yes, home workers' and personal devices are generally included when they access your business data or services. This includes personal phones used for work email. Devices used only for native voice calls, text messages or MFA applications are excluded. We help you identify which devices need controls and how to manage them.
How do I check whether a company holds Cyber Essentials?
Search IASME's public Cyber Essentials certificate register using the company name or certificate number. It lists the certificate reference, certification level, issue date and expiry date. Check that the certificate is current and shows the level you need. Buyers can use the same register to verify your certification.
Related services
Support your certification with ongoing IT security
Get started
Need help preparing for
Cyber Essentials certification?
Call 01252 227232 or ask for your free IT review. Tell us which certification level you need and your deadline. We will explain the checks and changes needed before assessment. We usually respond within the hour, Monday to Friday, 9am to 5pm.