Trustsmart IT Trustsmart IT

Cyber Essentials

Cyber Essentials, achieved and maintained

The government-backed baseline more buyers, insurers and regulators now expect to see, handled end to end by a team that's been configuring the underlying controls in regulated environments for twenty years.

20 years in regulated IT CE & CE+ delivery Rated 5.0 on Google
Cyber Essentials certification delivered by Trustsmart IT

20 years in regulated IT · 50+ practices supported · Rated 5.0 on Google

Angle House OrthodonticsMoira Wong OrthodonticsSutton OrthodonticsCelltrion HealthcareDevon Square Orthodontics

A government-backed baseline of five technical controls

Cyber Essentials is a UK government-backed scheme that sets out five technical controls designed to protect against the most common types of cyber attack. It isn't a marketing badge dressed up as a standard; it's a defined set of configurations and practices, audited by certification bodies licensed by IASME on behalf of the National Cyber Security Centre.

The controls are deliberately practical, the kind of things any well-run business should already have in place. The scheme exists to make sure they actually are in place, and that you can evidence it. That's why certification is increasingly the answer your buyers, insurers and tender forms are looking for.

Firewalls and internet gateways

Boundary protection configured properly, admin interfaces locked down, inbound rules tightened, remote access restricted to people and services that need it.

Secure configuration

Devices and software set up to remove unnecessary risk, unused services disabled, default accounts dealt with, a clean baseline from day one.

User access control

The right people with the right access. Admin rights off everyday accounts, MFA enforced on what matters, joiners and leavers handled cleanly.

Malware protection

Endpoint protection in place, kept current, and actually monitored, with alerting wired up so anything out of the ordinary gets a response.

Security update management

Operating systems and applications patched promptly on a managed schedule. Unsupported software identified and dealt with before it becomes the gap an assessor flags.

Less optional than it used to be

The conversation has moved on, and the businesses that are ahead of it have less friction in their procurement, their insurance and their tenders.

Regulated buyers now expect it

Procurement teams in healthcare, finance and the public sector increasingly ask for Cyber Essentials before they'll sign. It's become a tender prerequisite.

Insurance and contracts reference it

Cyber insurance renewals and supplier-due-diligence questionnaires now reference Cyber Essentials by name. Holding it makes premiums more predictable and paperwork lighter.

Central government tenders require it

Any UK central government contract handling personal information or certain technical services requires Cyber Essentials. For public-sector work, it's the gate.

Want a clear-eyed view of where you stand today?

A gap assessment is the honest place to start. No commitment, no jargon.

Book a gap assessment

From "where do we start" to "certificate on file"

The same controls we've configured across 50+ orthodontic practices over twenty years, for CQC, DSPT, Information Governance and the kind of regulated-sector scrutiny that makes the CE bar look like a sensible starting point. This is how the engagement actually runs.

1. Gap assessment

We review your setup against the five controls and give you an honest written summary, what's in shape, what needs work.

2. Close the gaps

We put the missing controls in place, configuration, MFA, patch management, access reviews, endpoint protection, owned end to end.

3. Certification

We prepare the answers, marshal the evidence, brief whoever's signing, and submit to an IASME-accredited body. You get the certificate.

4. Maintain it

Cyber Essentials lasts twelve months. We keep the controls current between assessments so re-certification is a continuation, not a scramble.

Got a deadline already in the diary?

Tender, insurance renewal, board commitment, tell us what's on the clock.

Let's talk timelines

The audited tier, when the bar is higher

Cyber Essentials Plus is the same five controls, but with an independent assessor hands-on with your environment rather than reviewing a self-assessed declaration. Same scheme, higher bar of evidence, and the tier specified by an increasing number of NHS, central-government and enterprise procurement processes.

We work with you to achieve Plus to the same standard as base certification, properly configured controls first, the audit second. If you're not sure which tier you actually need, we'll be honest with you about it; there's no commercial sense in pushing you up a tier you don't have to be on.

An external assessor verifies the controls

Standard Cyber Essentials is a self-assessment signed off by a senior person in your business. Cyber Essentials Plus adds an independent hands-on audit, the assessor tests your controls on real devices, not just on paper. The same five controls; a higher bar of evidence.

When regulated buyers ask for the audited tier

Some NHS contracts, larger enterprise procurement processes and public-sector frameworks specify Cyber Essentials Plus rather than the base certification. If your pipeline is heading that way, we'll be honest about it early, and recommend the right tier for what you're actually being asked to evidence.

Built on the same foundation

Plus isn't a different scheme; it's the same five controls audited more rigorously. If we've configured your environment properly for base Cyber Essentials, the step up to Plus is shorter than most firms make it sound. We can take you straight there, or stage it.

Trusted by the businesses we've certified

Twenty years of configuring the controls that Cyber Essentials measures, across orthodontic practices, healthcare clinics and regulated SMEs.

The questions buyers actually ask

The shape of every CE project is different. If your scenario isn't covered, a short conversation is the fastest way to a clear answer.

How long does getting Cyber Essentials actually take?

It depends entirely on your starting point, and we'll only commit to a timeline after the gap assessment. For a business with a tidy Microsoft 365 environment, MFA already in place and reasonable patch discipline, it's often a matter of a few weeks. For a setup that needs real remediation work, it can be longer. We won't quote a date on this page because we'd rather give you an honest one in person.

How much does Cyber Essentials cost?

There are two parts: the certification body's assessment fee (a published rate tied to the size of your business), and the work to close any gaps the assessment surfaces. The first is fixed; the second is genuinely variable. We'll quote both transparently after the gap assessment so you can see exactly what you're paying for, with no surprises and no padding.

What happens if we don't pass first time?

We design the work so that doesn't happen, the whole point of the gap assessment and remediation phase is that the formal submission is essentially a confirmation, not a test. If something does come back from the assessor needing adjustment, we deal with it as part of the engagement, not as a separate billable. We don't put clients in to fail.

Do you certify us yourselves, or work with an assessor?

The certification itself is issued by an IASME-accredited certification body, that's how the scheme works; the badge isn't something a delivery partner like us can issue directly. We handle the preparation, the controls, the evidence and the submission, and partner with an accredited assessor for the formal sign-off.

Does Cyber Essentials last forever once we've got it?

No, certification lasts twelve months. After that you re-certify annually, which is the part most businesses underestimate. The reason we package maintenance with the initial certification is precisely because the controls have to stay in place to be worth anything. If they drift, the badge stops reflecting reality, and the next assessment becomes another scramble.

Is Cyber Essentials enough on its own?

For many businesses, yes, it's the right baseline and the answer most buyers and insurers are actually asking for. For some sectors and some contracts, Cyber Essentials Plus is the right tier instead. Beyond that, ISO 27001 or sector-specific frameworks come into play. We'll be honest with you about which tier your business genuinely needs, and won't oversell.

Can you do this even if we don't use you for managed IT?

Yes. Cyber Essentials delivery is a project engagement and we run it as one, there's no requirement to switch your day-to-day IT support to us. That said, the annual re-certification works best when the controls are being maintained by a team that understands the scheme, and many clients move that piece to us afterwards. No pressure either way.

We've been told we need it for an NHS / government contract, can you help?

Yes, and this is the most common reason businesses come to us for Cyber Essentials. The procurement document usually specifies which tier, base certification or Plus, and a deadline. We'll work backwards from your deadline, scope the gap assessment promptly, and target the right tier first time. We've done this enough to know where the time goes.

Let's talk

Cyber Essentials, achieved and maintained

Twenty years of regulated-sector IT discipline, applied to the certification more buyers, insurers and regulators now expect. A clear path, an honest gap assessment, and a team that stays with you through re-certification.

Or call us directly on 01784 776472

Message us on WhatsApp