The straightforward version
Cyber Essentials is not meant to turn a small business into a security department. It checks five sensible controls that stop many common attacks: secure firewalls, safe settings, controlled access, malware protection and prompt security updates.
The certificate is useful when a customer, tender, insurer or board wants independent evidence that those basics are in place. It is also a practical deadline for fixing security jobs that have been sitting on a list for too long.
Our role is simple: work out what you actually need, find the gaps before the assessor does, and make the route to certification manageable.
Book a free 15-minute readiness call if you have a deadline, or ask for a fixed quote if you already know which level you need.
Cyber Essentials or Cyber Essentials Plus?
There are two levels. The right one is normally decided by the wording in your contract—not by which badge sounds more impressive.
|
Cyber Essentials |
Cyber Essentials Plus |
| How it is checked |
Your self-assessment is independently reviewed |
A qualified assessor also tests the controls |
| Best for |
General supplier checks, insurance and a security baseline |
Contracts or customers that explicitly require stronger assurance |
| Technical audit |
No hands-on audit |
Device sampling, vulnerability checks and control testing |
| Valid for |
12 months |
12 months |
| Starting Nerdster package |
£795 + VAT |
£2,995 + VAT for 1–9 users |
If somebody asked only for “Cyber Essentials”, standard certification is usually the answer. We will not recommend Plus unless the requirement names it or the additional assurance makes sense for your organisation.
You cannot skip the first level and buy Plus on its own. Cyber Essentials comes first, and Plus needs to follow within the scheme’s permitted window, so it is best planned as a single project.
What you are paying Nerdster to do
You are not paying us merely to send you a questionnaire. Depending on the package, we:
- confirm which devices, people, networks and cloud services belong in scope;
- review the answers and evidence before the assessor sees them;
- find blockers such as unsupported software, missing MFA or weak admin access;
- turn the gaps into a practical, prioritised remediation plan;
- coordinate the certification and answer technical questions; and
- prepare Plus customers for the hands-on audit.
The £795 package is deliberately lean for organisations that are already ready. The £1,495 readiness package adds the review and planning most small organisations need. Technical remediation is scoped separately because one business may need two settings changed while another needs an operating system upgrade across fifty devices.
What is included—and what is separate
Every proposal shows the certification fee, Nerdster’s work and any likely third-party costs as separate lines.
Included in the chosen package: the work listed on the pricing card, the agreed certification support and a written scope.
Potentially separate: fixing technical gaps, replacing unsupported devices or software, new security licences, an in-person Plus audit, or work outside the agreed organisation and network scope.
Nothing starts without approval. If the readiness call shows that you can sensibly complete the self-led route, we will say so.
The five blockers we find most often
Most delays are ordinary and fixable:
- MFA is missing on one cloud service or administrator account.
- Software is out of support, even though it still appears to work.
- Critical patches miss the 14-day window on laptops that rarely connect to the office.
- Nobody has a complete device or cloud-service list, so the assessment scope is wrong.
- Everyday users have administrator access they no longer need.
Finding these before the assessment is cheaper and calmer than discovering them after the submission clock has started.
How the project runs
- Free readiness call. We ask why you need certification, your deadline, headcount and current IT setup.
- Written scope and price. You see what is included, what may be separate and the assumptions behind the quote.
- Readiness review. We check the environment against the current questions and technical requirements.
- Fix and evidence. Your IT team or ours closes the agreed gaps and gathers the right evidence.
- Assessment and certificate. We support the submission and, for Plus, coordinate the technical audit.
A reasonably well-managed environment often completes in two to four weeks. We quote a wider two-to-six-week range because legacy software, unmanaged personal devices and unclear cloud ownership can add work. A fixed date is confirmed only after we understand the scope.
Current 2026 requirements
Applications started from 27 April 2026 use version 3.3 of the NCSC Requirements for IT Infrastructure and the Danzell question set.
The practical message is not “buy more security software”. It is to make sure cloud services are included in scope, MFA is applied correctly, accounts are controlled and supported software is updated on time. We check the live requirements when your project starts instead of relying on last year’s answers.
For the detail, read what changed in Cyber Essentials v3.3. If you want a quick indication of readiness first, use the free Cyber Essentials readiness checker.
Ready to make a sensible plan?
Bring us the contract wording, renewal date or customer request. We will tell you which level you need, whether the timeline is realistic and what the first step should be.
Book a free 15-minute Cyber Essentials call or request a fixed quote. No obligation, and no pressure to buy Plus when standard certification is enough.
If you already have an IT provider, bring them into the conversation. We are happy to handle the certification while they complete the technical work.