CyberSecurity

Cyber Essentials, What to Do When a Client, Insurer or Tender Asks for It

Someone has asked you to prove you're not the weak link, an employer hiring through you, a client running supplier checks, an insurer at renewal. Different paperwork, same underlying question. Here's what to actually do about it.

Posted on

27 August 2026


 

Related Topics

More about Blue Saffron’s Cyber Essentials and Cyber Essentials Plus support

 

More about Blue Saffron’s IT Security & Compliance

 

More about Blue Saffron’s Cybersecurity Testing and Audits

 

More about Blue Saffron


 

Get In Touch

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Cyber Essentials has probably landed on your desk for one reason. Someone asked for it. That might be an employer hiring through you, wanting proof you’re not the weak point in their supply chain. It might be a client running supplier checks before signing off a contract. It might be your own insurer at renewal, or a line buried in a tender document. Different paperwork, same underlying question: can you show you’re not an easy target.

If that’s landed on your desk, this is written for exactly that moment. Not the full explainer on what Cyber Essentials is (we’ve got that here), not a breakdown of every cost variable (that’s here too), just what to actually do in the next couple of weeks.

I am text block. Click edit button to change this text. Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.

Why this keeps landing on people's desks

It’s not a coincidence that this is happening more often. UK professional services firms are being targeted at a rate that’s genuinely hard to picture, research from Keeper Security put the figure at more than three attempted attacks a week for the average firm. And the consequences of getting it wrong have got more visible lately too. In October 2025, the ICO fined outsourcing group Capita £14 million after a 2023 ransomware attack exposed the data of 6.6 million people, a case that’s been widely cited across the pensions and professional services sector ever since.

Clients, insurers and procurement teams have noticed. Asking suppliers for Cyber Essentials has become a fairly standard way of getting some assurance that the firms handling their data aren’t an easy target. For recruitment agencies sitting on candidate CVs and payroll data, or accountancy and HR firms handling financial and employee records, that request is only going to become more common, not less.

What Cyber Essentials actually is, in one paragraph

It’s a UK government backed certification built around five technical controls: firewalls, secure configuration, access control, malware protection and patch management. You either self assess against them (Cyber Essentials) or have them independently tested (Cyber Essentials Plus). That’s genuinely most of what you need to know to act on it. If you want the fuller picture, including how the assessment process works, we’ve written about that in detail already.

Which one are they actually asking for

This is where people get stuck, because the request rarely specifies. If a client, insurer or tender document just says “Cyber Essentials,” they usually mean the base certification, a self assessed questionnaire that gets checked and signed off. If they’ve specifically written “Plus,” or the word “audit” or “technical testing” appears anywhere in what they’ve sent you, that’s a different and more demanding process involving an external assessor testing your systems directly rather than taking your word for it.

Worth Checking First

Does the request actually specify a level, or has whoever sent it just said “Cyber Essentials” as shorthand? A quick email back asking which level they need often saves you from over or under delivering.

What it will actually cost

The base certification is priced on a sliding scale by organisation size, and it starts at £320 plus VAT according to the NCSC, rising for larger or more complex organisations. Cyber Essentials Plus doesn’t have a fixed price list. It’s quoted individually based on the size and complexity of your network, and most UK SMEs end up somewhere between £1,500 and £3,000 plus VAT, according to figures published by cybersecurity compliance firm SureCloud.

Recently Updated

The NCSC updated its technical requirements in April 2026, tightening what’s expected around cloud security, authentication and patching. If your organisation is largely cloud based, that update is relevant to you specifically, not just a footnote.

Where to actually start

Before quotes, before picking an assessor, spend an hour checking where you already stand against the five controls. Is MFA switched on everywhere it should be, not just on the systems someone remembers to check? Are software updates actually being applied on a schedule, or does that only happen when something breaks? Who still has admin access to systems they left behind two roles ago?

Most businesses find they’re further along than they expected on two or three controls and further behind than they’d like on one. That gap is what determines your timeline and, honestly, your cost, because remediation work before assessment is usually where the real spend sits, not the certification fee itself.

How long this realistically takes

For a business with reasonably tidy IT already, the self assessed route can be done inside a few weeks. Cyber Essentials Plus takes longer because of the audit itself, typically closer to four to six weeks once you include any remediation. If you’re starting from a genuinely messy setup, add time, not because the certification is complicated, but because fixing years of accumulated shortcuts rarely happens overnight.

Do you need help, or can this be done in house

If your IT is well documented and someone internally has the time to own the process, the self assessed route is entirely doable without outside help. Where it usually makes sense to bring in support is Cyber Essentials Plus specifically, since the technical audit will surface gaps you didn’t know existed, and having someone who’s been through the process before means you’re not discovering those gaps for the first time in front of an assessor. This is exactly the kind of groundwork a managed IT partner handles as a matter of course rather than a one off project, and it’s worth asking your existing provider, if you have one, whether they already cover it.

What happens if you just don't

Nothing dramatic, immediately. But the client who asked won’t necessarily wait around, and the tender you were hoping to win will likely go to someone who could tick the box. For firms in recruitment and professional services specifically, where trust with the data you’re handling is the whole basis of the relationship, that’s a slower kind of cost, but a real one.

If someone’s asked you for this, it’s worth treating as a genuine deadline rather than something to circle back to next quarter.

If you want a clearer picture of where your own setup currently stands against the five controls, that’s exactly what a proper IT security assessment is for, and it’s usually the fastest way to turn “someone’s asked us for this” into an actual plan. Our team works through this with recruitment, accountancy and HR firms regularly, get in touch if it would help to talk it through.

FAQs

What's the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is self assessed. Cyber Essentials Plus adds independent technical testing to verify the same five controls actually work in practice.

How much does Cyber Essentials cost?

The base certification starts at £320 plus VAT, priced by organisation size (NCSC). Cyber Essentials Plus is quoted individually, typically £1,500 to £3,000 plus VAT for most SMEs.

Is Cyber Essentials mandatory for my business?

Not by law, but it’s often required in practice, particularly by clients, insurers or public sector frameworks who want proof of baseline security before working with you.

How long does Cyber Essentials certification take?

A few weeks for the base certification if your IT is reasonably well managed. Cyber Essentials Plus usually takes four to six weeks including the audit and any remediation.

My client specifically asked for Cyber Essentials Plus. Why does that matter?

Plus is a higher bar than the base certification. If Plus has been named specifically, the base certification alone won’t satisfy the request.

Can I get Cyber Essentials certification myself, without an MSP?

Yes, especially the base certification if your documentation and controls are already reasonably tidy. Plus is where outside support tends to help most, since the technical audit often finds gaps worth catching before an assessor does.

A client or insurer asking for Cyber Essentials is easy to say yes to and harder to actually deliver. Get in touch today to find out how Blue Saffron can take the certification process off your hands.