Izerone Solutions Cybersecurity consulting

Cyber Essentials

Practical support to get micro and small UK businesses certified, from someone who assesses submissions for a living.

Ask about certification

Certification support

Cyber Essentials is a UK government-backed scheme, developed by the National Cyber Security Centre and delivered by IASME. It covers five technical controls, and most failed submissions fail on the same handful of misunderstandings rather than on genuinely weak security.

I hold Cyber Essentials Assessor and IASME Cyber Assurance Assessor status, which means I have seen what gets a submission sent back. That is the perspective you are buying.

Where I have supported an organisation through preparation, its formal assessment is carried out independently. Advisory and assessment stay separate.

What support looks like

  1. DiscoveryA short call to understand your setup, your deadline, and why you need certification.
  2. Gap analysisYour current position against the five controls, and a plain-English action plan.
  3. RemediationPractical fixes and policy templates. Where there is no IT team, hands-on implementation within an agreed scope.
  4. SubmissionQuestionnaire walkthrough, evidence review, and a final check before you submit.

Cyber Essentials Plus

For CE Plus I identify the controls required and work with your internal or outsourced IT team to get them implemented and validated ahead of the formal audit. Where no IT team exists, I can provide the implementation support directly as a defined project.

Common questions

How long does certification take?

With guidance, most small organisations complete the self-assessment in one to two weeks, depending on where they are starting from and how quickly remediation can be done.

Does certification really come with free insurance?

For eligible organisations, yes. A UK-domiciled organisation with annual turnover under £20m that certifies its whole organisation and opts in is entitled to cyber liability insurance with a £25,000 limit of indemnity, arranged through IASME. If your turnover is above £20m, or you certify only part of the organisation, it does not apply. Check the current terms on the IASME website before relying on it.

Why do organisations need it?

It reduces exposure to common internet-borne attacks, it is a requirement in many public sector and enterprise procurement processes, and it gives insurers and customers something concrete to point at.

How is the work priced?

Scoped after a discovery call, based on your size and starting position. You get a fixed quote before anything begins.

Start with a conversation, not a proposal

Tell me what you are running and what is worrying you. If I am not the right fit I will say so, and point you at what is.

Get in touch