Cyber security / Cyber Essentials

Cyber Essentials & Cyber Essentials Plus certification support

DMS supports UK organisations through Cyber Essentials and Cyber Essentials Plus certification — from initial gap assessment through to certificate.

Unlimited Cyber Essentials resubmissions when you certify through DMS. Book a free call to discuss your requirements.

“They don’t do technospeak — staff are comfortable calling them because they know their questions will be heard.” — David, D&M Contractors

Book a Free call

Fill in your details and we’ll call you back within one working day. We’ll ask a few questions about your current setup and what’s not working — and go from there.

Fields marked * are required. We’ll call you back within one working day.

DMS certified
ISO 27001
Controls assessed
5
CE Plus window
90 days
In IT Services
2005
What is Cyber Essentials

Cyber Essentials certification is different from other security frameworks

Cyber Essentials is a UK government-backed certification scheme, delivered by IASME, the NCSC’s official Cyber Essentials Delivery Partner, that helps UK organisations demonstrate they have the technical controls in place to defend against the most common cyber attacks. Certification is valid for 12 months and must be renewed annually.

Unlike broader frameworks such as ISO 27001, Cyber Essentials is accessible to organisations of any size — and for many UK organisations it is the logical first step toward demonstrating a defensible security posture to clients, insurers, and procurement bodies.

What You Can Expect From DMS

Gap assessment carried out before submission
DMS carries out a gap assessment of your environment against the five controls before any submission — so you know exactly where you stand before committing.

Unlimited Cyber Essentials resubmissions with DMS
If your Cyber Essentials submission is unsuccessful, DMS resubmits on your behalf at no additional charge — with no limit on resubmissions until you certify. Cyber Essentials Plus has different resubmission terms — speak to us before proceeding.

Renewal managed for you
Annual renewal keeps your Cyber Essentials certification current. DMS manages the process so your tendering position is never at risk from a lapsed certificate.

Get in touch — we'll establish next steps and what the process looks like for your organisation.

Sounds like a good fit?

Why organisations certify

Why do UK organisations get Cyber Essentials certified?

Certification is driven by commercial necessity as much as security — here are the most common reasons UK organisations get certified.

Government and public sector contracts

Cyber Essentials certification is mandatory for UK government contracts involving personal data or certain technical services. Without certification your organisation cannot bid for a significant portion of public sector work.

Supply chain requirements

Enterprise clients and Tier 1 contractors increasingly require Cyber Essentials certification from suppliers as a condition of doing business. Certification removes a common barrier to winning larger contracts.

Cyber insurance

Many insurers require Cyber Essentials as a minimum standard before issuing a cyber liability policy. Cyber Essentials certification can also reduce premiums and simplify the claims process following an incident.

GDPR compliance support

The five technical controls directly support your GDPR obligations around technical measures to protect personal data under Article 32. Cyber Essentials certification provides documented evidence of a baseline security posture.

Free cyber liability insurance

UK organisations with a turnover under £20m that certify their whole organisation receive 12 months of free cyber liability insurance arranged by IASME. This includes 24/7 incident response support covering technical, legal, and crisis management services.

Building client and stakeholder confidence

Displaying the Cyber Essentials badge on your website and in proposals signals to clients and stakeholders that your organisation takes data security seriously — a reassurance many competitors cannot offer.

Get in touch — we'll establish next steps and what the process looks like for your organisation.

Sounds like a good fit?

What we deliver

What does DMS deliver as part of Cyber Essentials certification?

Gap Assessment

Gap assessment

DMS reviews your IT environment against the five controls before any submission — identifying what is in place and what needs to change.

— Assessment against all five controls
— Cloud services and remote working included
— Summary of findings provided
— Remediation recommendations where required

Remediation

Remediation

Where gaps exist, DMS implements the necessary changes. Scoped and priced on what is actually required — for many organisations it is minimal.

— Firewall and network configuration
— Secure device and software configuration
— User access control and MFA
— Patch and update management

Certification submission

DMS manages the submission on your behalf. Unlimited Cyber Essentials resubmissions included — no additional charge until you certify

— Full submission management
— Unlimited CE resubmissions with DMS
— Board sign-off coordinated
— Certificate issued digitally on success

Annual Renewal

Annual renewal

DMS manages renewal so your certification never lapses and your tendering position remains protected year on year.

— Renewal reminder and scheduling
— Annual gap review before resubmission
— Consistent certification record
— Pricing based on organisation size

Cyber Essentials Plus

Cyber Essentials Plus

DMS prepares your organisation for Cyber Essentials Plus — an independent technical audit carried out by an IASME-licensed Certification Body. Must complete within 90 days of CE.

— Pre-audit preparation and gap review
— Coordination with IASME Certification Body
— Must complete within 90 days of CE
— Pricing based on organisation size

Ongoing Compliance

Ongoing compliance management

DMS helps maintain the controls required for certification throughout the year — reducing the risk of gaps appearing before renewal.

— Continuous RMM monitoring
— Patch and update management
— Access control reviews
— Annual compliance health check

Did you know Cyber Essentials certification includes free cyber liability insurance?

UK-domiciled organisations with a turnover under £20m that certify their whole organisation can opt in to receive 12 months of free cyber liability insurance arranged by IASME, underwritten by AIG. Cover runs from your certification date and includes a £25,000 limit of indemnity. You must opt in during the assessment process to activate cover.

The Process

How to get Cyber Essentials certified with DMS

Here is how to get Cyber Essentials certified — from first contact through to certificate.

1

Get in touch

Call, email, or book online. We’ll call you back within one working day to ask a few questions about your current setup and establish next steps.

2

Gap assessment

DMS carries out a gap assessment of your IT environment against the five Cyber Essentials controls and identifies what, if anything, needs to change before submission.

3

Remediation and submission

Where gaps exist, DMS implements the necessary changes. Once ready, DMS submits on your behalf. If unsuccessful, DMS resubmits at no additional charge — with no limit on Cyber Essentials resubmissions until you certify.

4

Certificate issued

Your Cyber Essentials certificate is issued and valid for 12 months. Cyber Essentials Plus is available within 90 days if required. DMS manages annual renewal.

Common questions

Frequently asked questions about Cyber Essentials certification

For a well-prepared organisation of around 50 users, the process typically takes a couple of days of work, excluding any remediation. Larger or more complex environments take longer. A gap assessment at the outset gives a clear picture of the time and effort involved before you commit.

Cyber Essentials is a self-assessment questionnaire verified by an accredited assessor. Cyber Essentials Plus includes an independent technical audit of your systems carried out by an IASME-licensed Certification Body, confirming the controls declared are actually in place. Cyber Essentials Plus must be completed within 90 days of your Cyber Essentials certificate. Under current scheme rules, a second failure at CE Plus assessment results in revocation of the underlying Cyber Essentials certificate — meaning recertification at CE level would be required before attempting CE Plus again. Thorough preparation before CE Plus is therefore essential.

The five Cyber Essentials controls are: firewalls, secure configuration of devices and software, user access control, malware protection, and security update management. User access control now includes mandatory multi-factor authentication for all cloud services where it is available. All five controls must be correctly implemented across your IT environment, including cloud services and remote working devices.

Yes. The current Cyber Essentials scheme covers cloud services including Microsoft 365 and Google Workspace, as well as devices used for remote working. All devices that can access organisational data are in scope. Personal devices used for work are in scope where they access organisational data, unless your organisation enforces a technical policy preventing organisational data from being stored on unmanaged devices.

For most SMEs, standard Cyber Essentials certification is sufficient. Cyber Essentials Plus is typically required when a client or procurement framework specifically requires it, or when handling particularly sensitive data. DMS advises on which level is appropriate during the initial call.

For Cyber Essentials, if your submission is unsuccessful DMS identifies the controls that need attention, supports remediation, and resubmits on your behalf — with no limit on Cyber Essentials resubmissions when certifying through DMS. For Cyber Essentials Plus the position is different: a second assessment failure results in revocation of your Cyber Essentials certificate under current scheme rules, meaning you would need to recertify at CE level before attempting CE Plus again. DMS ensures thorough preparation before any CE Plus assessment to minimise this risk.

The cost of Cyber Essentials certification depends on the size of your organisation and whether any remediation work is required before submission. DMS will confirm pricing once we understand your environment — get in touch and we’ll establish what’s involved before any commitment.

Cyber Essentials certification is increasingly recognised by insurers as evidence of a baseline security posture. Some insurers require it as a condition of cover, while others offer reduced premiums for certified organisations. Additionally, UK organisations with a turnover under £20m that certify their whole organisation can opt in to receive 12 months of free cyber liability insurance arranged by IASME, underwritten by AIG, with a £25,000 limit of indemnity.

Cyber Essentials certification is most commonly required in construction, education, financial services, healthcare, legal and professional services, and any organisation supplying into government or enterprise supply chains. This includes construction companies and civil engineering firms, schools and education providers, financial services organisations, legal firms and solicitors, healthcare and social care organisations, charities handling personal data, and professional services firms. It is also increasingly required by cyber insurers as a condition of cover.

Get Started

Talk to us about Cyber Essentials certification

Get in touch and we’ll establish next steps, what gaps exist if any, and what the process looks like for your organisation. No obligation, no hard sell.

Latest Blogs

Keep up with the latest tech developments and insights by reading our blog posts