Skip to content

Cyber Essentials Certification Pack

Get Cyber Essentials or Cyber Essentials Plus certified on the first attempt - the v3.3 controls mapped to your Microsoft 365 estate, hardened and evidenced, or we fix the gaps free.

No cost, no obligation - a first look at where your Microsoft 365 estate stands against Cyber Essentials v3.3. You keep the findings either way.

The promise

1st

attempt, or we fix the gaps and support your resubmission free

  • The v3.3 controls mapped to your Microsoft 365 estate
  • Hardened and evidenced, not just self-declared
  • Scoped to the date you need the certificate

The problem

Cyber Essentials is the UK government-backed certification your insurer, your customers, and your bids increasingly ask for by name - and since v3.3 came into force in April 2026 it demands mandatory MFA and stronger proof that each control actually works. On a Microsoft 365 estate the gap between 'we think we pass' and a clean submission is usually the same handful of things: MFA coverage that misses shared mailboxes and admins, unmanaged devices, missing patch cadence, and controls nobody has evidenced. A failed assessment is time, cost, and a resubmission - and the certificate you needed for the renewal or the tender is still not in hand.

What's Included

  • Your Microsoft 365 estate assessed against every Cyber Essentials v3.3 control - identity, devices, patching, malware protection, and access control
  • MFA brought to full coverage, including shared mailboxes, service accounts, and privileged roles, to the standard v3.3 now requires
  • Microsoft Intune device compliance and Microsoft Defender configuration to meet the device and malware-protection controls
  • Patch and update cadence evidenced against the 14-day requirement
  • An evidence pack mapping each control to the exact assessment question, ready for the self-assessment or the Cyber Essentials Plus audit
  • Submission support through certification - and, for Cyber Essentials Plus, preparation for the external assessor's technical audit

What This Assumes

  • A defined Cyber Essentials scope boundary - which users, devices, and locations are in scope
  • Microsoft Intune and Microsoft Defender licensing for the device and malware-protection controls; non-Windows devices (macOS, Linux, mobile) are covered by agreement
  • Administrative access and device-enrolment cooperation from your team

Not Included

  • The external Certification Body's assessment and certificate fee - the pack is preparation, evidence, and assessor liaison; the certification decision and its fee sit with the accredited body
  • Replacement of legacy systems that cannot meet a v3.3 control without being upgraded or retired

Baselines & Accreditations

We specialise in aligning your estate with the baselines and accreditations that matter most to your business.

  • Cyber Essentials

    The UK government-backed certification, self-assessed and independently verified, that insurers and customers increasingly require by name.

  • Cyber Essentials Plus

    The audited tier - the same controls, confirmed by an external assessor's hands-on technical test rather than self-declared.

  • Cyber Essentials v3.3 (April 2026)

    The current requirements, which mandate MFA across cloud services and demand stronger technical proof that each control is enforced.

  • Microsoft Security Baseline

    Microsoft's recommended configuration for Windows, Microsoft 365, and Microsoft Entra, applied so the Cyber Essentials controls hold as a consistent baseline.

Partners

We work with specialist tooling partners for audit and independent verification, so the picture of your posture is evidence-based rather than opinion.

Automated posture audit

Audit & reporting

Automated posture audit that shows where your Microsoft 365 estate stands against the controls before the assessment.

Continuous compliance monitoring

Third-party verification

Continuous compliance monitoring so the controls stay in place between annual recertifications.

Outcomes

  • Cyber Essentials or Cyber Essentials Plus achieved on the first attempt
  • MFA and device controls at the coverage v3.3 requires, evidenced not asserted
  • The certificate your insurer, customers, and tenders ask for, in hand before the deadline
  • A repeatable baseline that makes next year's recertification a re-run, not a rebuild

Who It's For

  • Finance, insurance, and other teams on Microsoft 365 that need Cyber Essentials for a cyber-insurance renewal, a customer, or a tender
  • Organisations whose last self-assessment failed, stalled, or scraped through without confidence it would hold
  • Managed Service Providers (MSPs) and Cloud Solution Providers (CSPs) certifying many client tenants to a consistent standard

How to Start

Most engagements begin with the free audit and go no further until you have seen where you stand.

Readiness Check

Free

A no-cost first look at your Microsoft 365 estate against Cyber Essentials v3.3, followed by a call to talk through what would fail today.

  • A take-away report of where you stand against the v3.3 controls
  • The gaps most likely to fail an assessment, identified with you
  • A conversation about what getting to a clean submission would involve

No cost, no obligation. We onboard a limited number of new estates each month, and return your findings within 5 working days of read access.

The Cyber Essentials Certification Pack

from £3,500 / $4,500

A fixed-price engagement that hardens and evidences the v3.3 controls and gets you certified on the first attempt.

  • Every Cyber Essentials v3.3 control hardened on your Microsoft 365 estate, MFA coverage included
  • An evidence pack mapped to the assessment questions, ready to submit
  • Submission support through certification, including Cyber Essentials Plus audit preparation

Self-assessed tier, independently verified. Guarantee: if a scoped control causes a fail, we remediate it and support your resubmission free.

The Cyber Essentials Plus Pack

from £6,500 / $8,300

The audited tier - everything in the Certification Pack, plus preparation for and support through the external assessor's hands-on technical test, so Plus is passed on the first attempt.

  • Every Cyber Essentials v3.3 control hardened and evidenced, then dry-run against the Plus audit's technical tests
  • Sampled-device and account testing rehearsed before the assessor arrives, so there are no surprises on the day
  • Assessor liaison and remediation support through to the certificate in hand

Audited tier. Guarantee: if a scoped control causes a fail, we remediate it and support your resubmission free.

Continuous Evidence

from £3,500 / $4,500

An ongoing retainer that keeps the controls in place and recertification a re-run rather than a rebuild each year.

  • A fixed amount of expert time each month on the highest-priority security work
  • Controls and evidence kept current, with drift caught before recertification
  • A forward plan of security initiatives, reprioritised every month

Next year's recertification is handled inside the retainer, not rebuilt as a fresh pack. Month one: a posture baseline and a first evidence pack.

Engagement Model

A fixed-price engagement scoped to when you need the certificate, in two tiers: Cyber Essentials (self-assessed and independently verified) from £3,500 / $4,500, and Cyber Essentials Plus (the audited tier, where an external assessor hands-on tests the controls) from £6,500 / $8,300. Defined deliverables, a fixed price, no day rates. And it is guaranteed: if a control we scoped in causes a fail, we remediate it and support your resubmission at no extra charge. And it graduates into Continuous Evidence, so next year's recertification is a re-run inside the retainer, not a rebuild.

Pricing: from £3,500 / $4,500 - larger engagements are tailored to scope.

Related

Get started

Find out where you stand, free

Most engagements start with a no-cost posture audit against the baselines that matter to you. If a fixed-fee roadmap is the right next step, we'll say so - and if it isn't, we'll say that too.