Northgate Compliance
All services

Cyber Essentials Certification

£995-£1,495·2-4 weeks

The full hand-held route to UK government-backed Cyber Essentials certification. We do the technical work, write the policies, and answer the IASME assessor's questions. You answer some scoping questions at the start and approve the submission at the end.

Founding Client pricing - first ten engagements. Prices increase once Northgate Compliance achieves NCSC Assured Cyber Advisor status.

Includes Cyber Liability Insurance through IASME's underwriter, free of charge, for UK-based organisations under £20m turnover. Most buyers don't know this comes with the badge. It does.

Who this is for

  • Defence supply chain businesses facing DEFCON 658 or Cyber Security Model (CSM) v4 requirements from BAE Systems, Babcock, or other Tier 1 primes.
  • Suppliers to NHS Trusts where CE is a prerequisite for the DSP Toolkit or framework agreements.
  • Professional services firms (solicitors, accountants, IFAs) under pressure from professional indemnity insurers or regulators.
  • Manufacturers and logistics businesses facing customer audits from larger Tier 1 partners.
  • Any UK SMB that needs to demonstrate baseline cyber controls to win or keep contracts.

What's included

  • Scope definition

    We decide with you exactly which devices, users, and cloud services are in scope. Done badly, this is where most certifications fail.

  • Gap assessment

    A practical review of your current setup against all five CE technical controls. You get a written gap list before any remediation starts.

  • Remediation guidance

    Plain-English instructions for fixing each gap, or we do it for you on managed devices.

  • Policy pack

    The minimum set of written policies the IASME assessor expects (password policy, acceptable use, BYOD if applicable).

  • Questionnaire completion

    We complete the 70+ question IASME self-assessment on your behalf and walk you through every answer before submission.

  • Submission and assessor liaison

    We submit to IASME on your authorisation and handle any follow-up questions from the assessor.

  • Your certificate

    Issued by IASME on successful assessment. Valid for 12 months.

  • Cyber Liability Insurance

    Included free for UK organisations under £20m turnover, via the IASME-bundled policy.

What's not included

  • Hardware or software purchases. If your remediation needs a new firewall, MDM, or antivirus licence, that's your spend.
  • Cyber Essentials Plus testing. Separate certification - see CE Plus.
  • Penetration testing. Not required for CE. Quoted separately if you want it.
  • Ongoing maintenance. Covered by the Annual CE Renewal or Compliance Retainer.

The five controls we'll work through

  1. 1

    Firewalls

    Boundary and software firewalls correctly configured on every device.

  2. 2

    Secure configuration

    Default passwords removed, unnecessary software disabled, devices hardened.

  3. 3

    User access control

    Admin rights restricted to who needs them, separate accounts where required.

  4. 4

    Malware protection

    Active anti-malware on every in-scope device.

  5. 5

    Security update management

    Critical patches applied within 14 days, end-of-life software removed.

Process

  1. Week 1

    Scope and gap assessment

    60-minute scoping call. We map your environment, identify in-scope assets, and produce a written gap report within five working days.

  2. Week 2

    Remediation

    We work through the gap list with you. For managed cloud setups we can usually fix everything remotely. For local hardware we either guide your IT contact or attend on-site.

  3. Week 3

    Questionnaire and submission

    We complete the IASME self-assessment, walk you through every answer, and submit on your authorisation.

  4. Week 4

    Assessor questions and certification

    If the assessor raises queries, we handle them. On pass, you receive your certificate and insurance certificate by email.

What we need from you

  • A single point of contact who can answer questions about your IT setup.
  • Access to representative devices for the gap assessment (read-only is fine).
  • Decisions on remediation items where we can't act unilaterally (e.g. removing software a user depends on).
  • A few hours of your time across the engagement, not days.

Pricing

Your businessPrice
1-10 employees, single office or fully remote, mainstream cloud setup (Microsoft 365 or Google Workspace)£995
11-50 employees, multiple sites, or mixed cloud/on-premises setup£1,495

Fixed price. No hourly billing. No surprise add-ons. If your situation falls between these tiers or doesn't fit either, book a free discovery call and we'll confirm which tier applies.

Frequently asked questions

What happens if we fail the assessment?
If we've done the gap assessment properly, failure is rare. If it does happen, the IASME assessor allows a short window to fix the flagged items and resubmit at no extra cost from us. We handle the coordination and the fixes.
Can we just do this ourselves through IASME direct?
Yes, in theory. Self-assessment costs around £300 in IASME fees and takes a competent IT lead 20-40 hours: reading the standard, mapping the environment, writing policies, completing the 70+ question questionnaire, and handling assessor follow-ups. Most SMBs either don't have that time, or submit and fail on technical detail they hadn't anticipated. Our value is in the pass rate and the hours of yours we save - same certificate, much less of your time.
How long does the certificate last?
12 months. Renew via our Annual CE Renewal package or let it lapse, your call.
Do we need Cyber Essentials before Cyber Essentials Plus?
Yes. CE is a prerequisite for CE Plus. If you need both, the CE + CE Plus Bundle is cheaper than buying them separately.
Is the IASME Cyber Liability Insurance any good?
It's £25,000 of cover, UK-only, with a £1,000 excess. Not a substitute for proper cyber insurance, but useful baseline cover and a genuine cost saving for smaller businesses.
Can you certify if our IT is outsourced to a managed service provider?
Yes. We coordinate with your MSP. Many MSPs aren't familiar with CE specifics - we handle the translation.
Do you work with businesses outside the North West?
We focus on the North West for on-site work. For cloud-only setups we can deliver remotely UK-wide.

Ready to start?

Book a free 30-minute discovery call. We'll scope your situation and confirm which tier applies. No obligation, no sales pressure.