Cyber Essentials Certification Pack
Get Cyber Essentials or Cyber Essentials Plus certified on the first attempt - the v3.3 controls mapped to your Microsoft 365 estate, hardened and evidenced, or we fix the gaps free.
No cost, no obligation - a first look at where your Microsoft 365 estate stands against Cyber Essentials v3.3. You keep the findings either way.
The promise
attempt, or we fix the gaps and support your resubmission free
- The v3.3 controls mapped to your Microsoft 365 estate
- Hardened and evidenced, not just self-declared
- Scoped to the date you need the certificate
The problem
Cyber Essentials is the UK government-backed certification your insurer, your customers, and your bids increasingly ask for by name - and since v3.3 came into force in April 2026 it demands mandatory MFA and stronger proof that each control actually works. On a Microsoft 365 estate the gap between 'we think we pass' and a clean submission is usually the same handful of things: MFA coverage that misses shared mailboxes and admins, unmanaged devices, missing patch cadence, and controls nobody has evidenced. A failed assessment is time, cost, and a resubmission - and the certificate you needed for the renewal or the tender is still not in hand.
What's Included
- Your Microsoft 365 estate assessed against every Cyber Essentials v3.3 control - identity, devices, patching, malware protection, and access control
- MFA brought to full coverage, including shared mailboxes, service accounts, and privileged roles, to the standard v3.3 now requires
- Microsoft Intune device compliance and Microsoft Defender configuration to meet the device and malware-protection controls
- Patch and update cadence evidenced against the 14-day requirement
- An evidence pack mapping each control to the exact assessment question, ready for the self-assessment or the Cyber Essentials Plus audit
- Submission support through certification - and, for Cyber Essentials Plus, preparation for the external assessor's technical audit
What This Assumes
- A defined Cyber Essentials scope boundary - which users, devices, and locations are in scope
- Microsoft Intune and Microsoft Defender licensing for the device and malware-protection controls; non-Windows devices (macOS, Linux, mobile) are covered by agreement
- Administrative access and device-enrolment cooperation from your team
Not Included
- The external Certification Body's assessment and certificate fee - the pack is preparation, evidence, and assessor liaison; the certification decision and its fee sit with the accredited body
- Replacement of legacy systems that cannot meet a v3.3 control without being upgraded or retired
Baselines & Accreditations
We specialise in aligning your estate with the baselines and accreditations that matter most to your business.
Cyber Essentials
The UK government-backed certification, self-assessed and independently verified, that insurers and customers increasingly require by name.
Cyber Essentials Plus
The audited tier - the same controls, confirmed by an external assessor's hands-on technical test rather than self-declared.
Cyber Essentials v3.3 (April 2026)
The current requirements, which mandate MFA across cloud services and demand stronger technical proof that each control is enforced.
Microsoft Security Baseline
Microsoft's recommended configuration for Windows, Microsoft 365, and Microsoft Entra, applied so the Cyber Essentials controls hold as a consistent baseline.
Partners
We work with specialist tooling partners for audit and independent verification, so the picture of your posture is evidence-based rather than opinion.
Automated posture audit
Audit & reportingAutomated posture audit that shows where your Microsoft 365 estate stands against the controls before the assessment.
Continuous compliance monitoring
Third-party verificationContinuous compliance monitoring so the controls stay in place between annual recertifications.
Outcomes
- Cyber Essentials or Cyber Essentials Plus achieved on the first attempt
- MFA and device controls at the coverage v3.3 requires, evidenced not asserted
- The certificate your insurer, customers, and tenders ask for, in hand before the deadline
- A repeatable baseline that makes next year's recertification a re-run, not a rebuild
Who It's For
- Finance, insurance, and other teams on Microsoft 365 that need Cyber Essentials for a cyber-insurance renewal, a customer, or a tender
- Organisations whose last self-assessment failed, stalled, or scraped through without confidence it would hold
- Managed Service Providers (MSPs) and Cloud Solution Providers (CSPs) certifying many client tenants to a consistent standard
How to Start
Most engagements begin with the free audit and go no further until you have seen where you stand.
Readiness Check
Free
A no-cost first look at your Microsoft 365 estate against Cyber Essentials v3.3, followed by a call to talk through what would fail today.
- A take-away report of where you stand against the v3.3 controls
- The gaps most likely to fail an assessment, identified with you
- A conversation about what getting to a clean submission would involve
No cost, no obligation. We onboard a limited number of new estates each month, and return your findings within 5 working days of read access.
The Cyber Essentials Certification Pack
from £3,500 / $4,500
A fixed-price engagement that hardens and evidences the v3.3 controls and gets you certified on the first attempt.
- Every Cyber Essentials v3.3 control hardened on your Microsoft 365 estate, MFA coverage included
- An evidence pack mapped to the assessment questions, ready to submit
- Submission support through certification, including Cyber Essentials Plus audit preparation
Self-assessed tier, independently verified. Guarantee: if a scoped control causes a fail, we remediate it and support your resubmission free.
The Cyber Essentials Plus Pack
from £6,500 / $8,300
The audited tier - everything in the Certification Pack, plus preparation for and support through the external assessor's hands-on technical test, so Plus is passed on the first attempt.
- Every Cyber Essentials v3.3 control hardened and evidenced, then dry-run against the Plus audit's technical tests
- Sampled-device and account testing rehearsed before the assessor arrives, so there are no surprises on the day
- Assessor liaison and remediation support through to the certificate in hand
Audited tier. Guarantee: if a scoped control causes a fail, we remediate it and support your resubmission free.
Continuous Evidence
from £3,500 / $4,500
An ongoing retainer that keeps the controls in place and recertification a re-run rather than a rebuild each year.
- A fixed amount of expert time each month on the highest-priority security work
- Controls and evidence kept current, with drift caught before recertification
- A forward plan of security initiatives, reprioritised every month
Next year's recertification is handled inside the retainer, not rebuilt as a fresh pack. Month one: a posture baseline and a first evidence pack.
Engagement Model
A fixed-price engagement scoped to when you need the certificate, in two tiers: Cyber Essentials (self-assessed and independently verified) from £3,500 / $4,500, and Cyber Essentials Plus (the audited tier, where an external assessor hands-on tests the controls) from £6,500 / $8,300. Defined deliverables, a fixed price, no day rates. And it is guaranteed: if a control we scoped in causes a fail, we remediate it and support your resubmission at no extra charge. And it graduates into Continuous Evidence, so next year's recertification is a re-run inside the retainer, not a rebuild.
Pricing: from £3,500 / $4,500 - larger engagements are tailored to scope.
Related
The Cyber-Insurance Renewal Pack
Cyber Essentials is often one control on a wider insurer questionnaire. The renewal pack covers the whole thing, guaranteed before your date.
Microsoft 365 Security & Hardening
The broader identity, device, and data hardening the certification draws on, sold as an ongoing capability.
Cyber Essentials Self-Check
Prefer to look first yourself? The free self-check of the five control areas, the two answers that now fail an assessment outright, and where each control lives in Microsoft 365.
Microsoft Secure Score is a starting line, not a finish line
Why a certificate should be evidence of repeatable hardening, not a number chased once a year.
Get started
Find out where you stand, free
Most engagements start with a no-cost posture audit against the baselines that matter to you. If a fixed-fee roadmap is the right next step, we'll say so - and if it isn't, we'll say that too.