Get Cyber Essentials without the last-minute scramble

We help you choose the right level, fix the gaps and submit with confidence. You see the likely work and the full cost before the assessment starts.

Cyber Essentials is the UK government-backed minimum cyber security standard built around five technical controls. Nerdster offers a certification review from £795 + VAT, guided readiness and certification from £1,495 + VAT, and Cyber Essentials Plus support from £2,995 + VAT for a small organisation. We confirm the scope and any remediation costs before work begins; certificates last 12 months and current applications use the v3.3 requirements.

From £795
Certification review package, excluding VAT
5 controls
The practical security basics every organisation should have
12 months
How long the certificate remains valid
2–6 weeks
A realistic range, depending on the gaps we find

Clear starting prices

Choose the level of help you need.

If you are already ready, do not pay for a large consultancy project. If you need help fixing gaps, scope that work before the assessment clock starts.

Certification review

£795 + VAT

Best when your controls are already in place

The certification fee plus a human review of your answers before submission.

  • Cyber Essentials certification fee
  • Review of your assessment answers
  • Clear corrections before submission
  • Support through the assessment decision
Get a fixed quote
Most popular

Readiness & certification

£1,495 + VAT

Most popular for small organisations

A proper readiness review, a prioritised plan and guided certification support.

  • Everything in Certification review
  • Scope and readiness workshop
  • Gap and evidence review
  • Prioritised remediation plan
  • Guided submission support
Get a fixed quote

Cyber Essentials Plus

From £2,995 + VAT

For contracts that explicitly require Plus

Cyber Essentials, Plus assessment and hands-on preparation as one managed project.

  • Cyber Essentials certification
  • Plus technical assessment fee for 1–9 users
  • Pre-audit technical review
  • Evidence and assessor coordination
  • Support during the audit window
Get a fixed quote
Are there any additional Cyber Essentials certification costs?

Sometimes. The fixed quote separates the certification and readiness service from anything your environment actually needs to change. Possible extras are technical remediation, replacement of unsupported hardware or software, new security licences, and an in-person Plus audit where required. Plus assessment fees also rise with organisation size and complexity.

We show every expected cost before you approve the work. Nothing is added simply because an assessment has started.

What could change the final price?

Plus pricing rises with organisation size and technical complexity. Remediation work, new licences or hardware, and an in-person audit are separate. We identify those costs before you approve the project—never on assessment day.

Starting prices apply to a straightforward UK scope and are confirmed in writing after the readiness call. Certification renews annually.

Meet the requirements you will be assessed against

Firewalls and internet gateways

Every device that connects to the internet needs a properly configured firewall. We check default passwords, unnecessary services and the laptops people use away from the office.

Secure configuration

Devices and cloud services should not be left with easy openings. We remove what is not needed, close dormant accounts and make sure default settings have been changed.

User access control

People should have the access their role needs—and no more. Admin accounts stay separate, leavers are removed promptly and multi-factor authentication is enabled where required.

Malware protection

Devices need an accepted form of malware protection, kept active and up to date. We check the control works across the estate rather than relying on a dashboard that merely looks green.

Security update management

High-risk and critical updates must be applied within 14 days. Software also needs to be licensed and supported; an old system can block the whole assessment.

Cloud services in scope

Microsoft 365, Google Workspace, your CRM and other services holding company data can all fall inside the scope. We map them before the answers are submitted.

The straightforward version

Cyber Essentials is not meant to turn a small business into a security department. It checks five sensible controls that stop many common attacks: secure firewalls, safe settings, controlled access, malware protection and prompt security updates.

The certificate is useful when a customer, tender, insurer or board wants independent evidence that those basics are in place. It is also a practical deadline for fixing security jobs that have been sitting on a list for too long.

Our role is simple: work out what you actually need, find the gaps before the assessor does, and make the route to certification manageable.

Book a free 15-minute readiness call if you have a deadline, or ask for a fixed quote if you already know which level you need.

Cyber Essentials or Cyber Essentials Plus?

There are two levels. The right one is normally decided by the wording in your contract—not by which badge sounds more impressive.

Cyber Essentials Cyber Essentials Plus
How it is checked Your self-assessment is independently reviewed A qualified assessor also tests the controls
Best for General supplier checks, insurance and a security baseline Contracts or customers that explicitly require stronger assurance
Technical audit No hands-on audit Device sampling, vulnerability checks and control testing
Valid for 12 months 12 months
Starting Nerdster package £795 + VAT £2,995 + VAT for 1–9 users

If somebody asked only for “Cyber Essentials”, standard certification is usually the answer. We will not recommend Plus unless the requirement names it or the additional assurance makes sense for your organisation.

You cannot skip the first level and buy Plus on its own. Cyber Essentials comes first, and Plus needs to follow within the scheme’s permitted window, so it is best planned as a single project.

What you are paying Nerdster to do

You are not paying us merely to send you a questionnaire. Depending on the package, we:

  • confirm which devices, people, networks and cloud services belong in scope;
  • review the answers and evidence before the assessor sees them;
  • find blockers such as unsupported software, missing MFA or weak admin access;
  • turn the gaps into a practical, prioritised remediation plan;
  • coordinate the certification and answer technical questions; and
  • prepare Plus customers for the hands-on audit.

The £795 package is deliberately lean for organisations that are already ready. The £1,495 readiness package adds the review and planning most small organisations need. Technical remediation is scoped separately because one business may need two settings changed while another needs an operating system upgrade across fifty devices.

What is included—and what is separate

Every proposal shows the certification fee, Nerdster’s work and any likely third-party costs as separate lines.

Included in the chosen package: the work listed on the pricing card, the agreed certification support and a written scope.

Potentially separate: fixing technical gaps, replacing unsupported devices or software, new security licences, an in-person Plus audit, or work outside the agreed organisation and network scope.

Nothing starts without approval. If the readiness call shows that you can sensibly complete the self-led route, we will say so.

The five blockers we find most often

Most delays are ordinary and fixable:

  • MFA is missing on one cloud service or administrator account.
  • Software is out of support, even though it still appears to work.
  • Critical patches miss the 14-day window on laptops that rarely connect to the office.
  • Nobody has a complete device or cloud-service list, so the assessment scope is wrong.
  • Everyday users have administrator access they no longer need.

Finding these before the assessment is cheaper and calmer than discovering them after the submission clock has started.

How the project runs

  1. Free readiness call. We ask why you need certification, your deadline, headcount and current IT setup.
  2. Written scope and price. You see what is included, what may be separate and the assumptions behind the quote.
  3. Readiness review. We check the environment against the current questions and technical requirements.
  4. Fix and evidence. Your IT team or ours closes the agreed gaps and gathers the right evidence.
  5. Assessment and certificate. We support the submission and, for Plus, coordinate the technical audit.

A reasonably well-managed environment often completes in two to four weeks. We quote a wider two-to-six-week range because legacy software, unmanaged personal devices and unclear cloud ownership can add work. A fixed date is confirmed only after we understand the scope.

Current 2026 requirements

Applications started from 27 April 2026 use version 3.3 of the NCSC Requirements for IT Infrastructure and the Danzell question set.

The practical message is not “buy more security software”. It is to make sure cloud services are included in scope, MFA is applied correctly, accounts are controlled and supported software is updated on time. We check the live requirements when your project starts instead of relying on last year’s answers.

For the detail, read what changed in Cyber Essentials v3.3. If you want a quick indication of readiness first, use the free Cyber Essentials readiness checker.

Ready to make a sensible plan?

Bring us the contract wording, renewal date or customer request. We will tell you which level you need, whether the timeline is realistic and what the first step should be.

Book a free 15-minute Cyber Essentials call or request a fixed quote. No obligation, and no pressure to buy Plus when standard certification is enough.

If you already have an IT provider, bring them into the conversation. We are happy to handle the certification while they complete the technical work.

Last updated:

FAQ

Frequently asked questions

What is Cyber Essentials?

Cyber Essentials is a UK government-backed certification scheme developed by the National Cyber Security Centre. It independently verifies that five baseline controls are in place: firewalls, secure configuration, security update management, user access control and malware protection. It is the minimum cyber security standard the NCSC recommends for organisations of every size.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a verified self-assessment. Cyber Essentials Plus covers the same five controls but adds independent technical testing by a qualified assessor. Standard certification confirms your answers have been reviewed; Plus tests that the controls work in practice. Only buy Plus when a contract requires it or the stronger assurance is genuinely valuable to you.

How much does Cyber Essentials cost with Nerdster?

Our Certification review starts at £795 + VAT and includes the certification fee plus a review of your answers. Readiness and certification starts at £1,495 + VAT. Cyber Essentials Plus starts at £2,995 + VAT for an organisation with 1–9 users. Plus pricing rises with organisation size and complexity, so we confirm the fixed price after a free readiness call.

Can I buy Cyber Essentials directly for less?

Yes. The NCSC says self-led certification starts at £320 + VAT, depending on organisation size. If your controls are already in place and you are comfortable answering without support, that can be the cheaper route. Nerdster's packages cost more because they include review, practical guidance and, at the higher levels, readiness work. We would rather tell you when the self-led route is enough than sell you help you do not need.

Can we go straight to Cyber Essentials Plus?

No. You need Cyber Essentials before Plus, and the Plus assessment must follow within the scheme's permitted window. We normally plan both as one project so the scope, evidence and technical work do not have to be repeated. We confirm the current timing rule when the project is scoped.

How long does certification take?

A straightforward self-assessment can be completed quickly once you are ready. Most supported projects take two to six weeks because preparation—not the form—is the variable. Unsupported software, missing MFA, unclear device ownership and patching gaps are the usual causes of delay. We will give you a realistic timetable after the readiness call.

What happens if we fail the assessment?

A failed answer or test normally means a control needs correcting and evidence needs resubmitting. Our readiness review is designed to find that before submission. Assessment resubmission support is included within the agreed package; the technical work needed to fix a failed control may be separate if it was outside the original scope.

What changed in Cyber Essentials for 2026?

Applications started from 27 April 2026 use version 3.3 and the Danzell question set. The update makes cloud scope and multi-factor authentication expectations clearer and updates the password guidance. We check your environment against the current question set rather than reusing last year's answers.

Is multi-factor authentication mandatory?

MFA is required for cloud services where the current requirements say it must be used, including administrator access and supported cloud-user scenarios. We map the services and account types in scope so an overlooked login does not derail the application.

How often do we need to recertify?

Every 12 months. Renewal is assessed against the requirements current at that time, so it is worth checking the controls before simply copying the previous answers. We can handle renewal as a one-off review or keep the controls healthy throughout the year.

We already have IT support. Can you still help?

Absolutely. We regularly work alongside an internal IT team or another support provider. We can handle the certification scope, readiness review, evidence and assessor coordination while your existing team completes the fixes—or we can quote for the remediation if they would rather we do it.

Tell us what you need the certificate for

Share your deadline, organisation size and whether a contract asks for Plus. A London-based engineer will reply within 2 business hours with the sensible next step.

We respond within 2 hours during business days. Your data is handled per our privacy policy.

Contact details

0330 043 7414

Mon-Fri 8am-6pm

[email protected]

We reply within 2 hours

71-75 Shelton Street

Covent Garden, London WC2H 9JQ

IT assessment

A review of your IT, your security posture and your compliance readiness, free of charge.

  • 30-minute consultation call
  • Infrastructure & security review
  • Compliance gap analysis
  • Custom recommendations report
Replies the same business day

Know the route, price and likely blockers before you start

Book a free 15-minute call. We will confirm whether you need Cyber Essentials or Plus and what has to happen next.

  • No callout fees
  • No-obligation assessment