Cyber Security Services
Cyber Essentials Certification
The UK government's baseline cyber security standard — required for government contracts, legal panel memberships, NHS supply chain and cyber insurance renewals across London and the South East. We build the environment that earns the certificate. And keeps it.
CE
Certified ourselves
We hold Cyber Essentials certification
1st
UK MSP independently verified
On security & service quality
5
Technical controls assessed
Firewalls to patch management
CE+
Plus available
Independent technical audit
What it covers
Five controls. One certificate. The baseline the UK government trusts.
Cyber Essentials assesses five technical controls that, between them, protect against the most common cyber attacks. Every device in scope — including home working devices — must meet all five.
Firewalls
Every device that connects to the internet needs a boundary firewall — correctly configured to block traffic that has no reason to reach it. This includes devices working from home, not just those in the office.
Secure Configuration
Devices and software must be configured securely before deployment. Default passwords changed, unnecessary features disabled, accounts removed when no longer needed. Most breaches exploit the defaults that nobody changed.
User Access Control
Only people who genuinely need access to a system or dataset should have it. Standard accounts for day-to-day work, admin accounts only used when necessary, and access removed promptly when someone leaves.
Malware Protection
Protection against malicious code — through anti-malware software, application whitelisting, or sandboxing — applied consistently across all devices in scope.
Patch Management
Software vulnerabilities are published regularly and exploited fast. Cyber Essentials requires that operating systems and software are kept up to date — patches applied within fourteen days of release for high-severity vulnerabilities.
Which level do you need?
Cyber Essentials and Cyber Essentials Plus — what's the difference?
Self-assessed
Cyber Essentials
- →Self-assessment questionnaire against the five controls
- →Verified and certified by an accredited certification body
- →Annual renewal
- →Required for central government contracts involving personal data or ICT services
- →Accepted by most cyber insurers as evidence of baseline security
- →Supports Lexcel, SRA, DSPT and FCA documentation requirements
Independently audited
Cyber Essentials Plus
- →All of Cyber Essentials, plus an independent technical audit
- →External auditor tests devices against the five controls directly
- →Includes vulnerability scanning and hands-on verification
- →Required for NHS supply chain and certain higher-risk government contracts
- →Carries stronger weight with insurers and enterprise procurement teams
- →Demonstrates controls are genuinely in place, not just attested to
Why your sector needs it
Cyber Essentials is required, expected or rewarded in every sector we serve.
The trigger is different in each sector. The underlying requirement — documented, verified security controls — is the same.
How we do it
We build the environment first. The certificate follows.
Most Cyber Essentials providers help you fill in the questionnaire. We take a different approach: we start by building the IT environment that genuinely meets the five controls, then guide you through the certification process. The certificate reflects reality — which matters when your panel membership sponsor, indemnity insurer or enterprise client actually looks behind it.
A pre-assessment check identifies where your current environment falls short of the five controls. We close those gaps — correctly configuring firewalls, tightening access controls, ensuring patch management meets the required window, reviewing devices in scope including those used at home. Once your environment genuinely meets the standard, the assessment itself is straightforward.
Cyber Essentials certification also maps directly to your Technology Resilience Score™. The five controls cover security protection, passwords and access control, and device management — areas the TRS™ measures independently. Achieving certification typically moves a firm from a TRS™ of 2–3 to 3.5 or above in those dimensions. It is the baseline. Your score shows what comes next.
Why businesses choose us
Certified ourselves
Little Big Tech holds Cyber Essentials certification — and is the first UK MSP independently verified on both security and service quality.
Environment first
We build the environment that meets the controls before you apply. No surprises at assessment.
Ongoing, not one-off
Cyber Essentials requires annual renewal. Your managed IT package keeps the controls current, so recertification is not a project — it just happens.
Sector-specific
We understand the specific triggers — panel membership, DSPT, FCA, insurer requirements — so the work we do is targeted to what you actually need to evidence.
How close is your firm to Cyber Essentials certification today?
Get your firm's free scoreGot questions?
We're straight with you
Can't find what you're looking for? Talk to us directly — no sales pitch, no obligation.
By sector
IT support built around your sector's specific compliance requirements
Certification is the start, not the finish.
A Cyber Essentials certificate tells your clients, insurers and regulators you've covered the basics. Your Technology Resilience Score™ shows what's next. Take the free assessment and see where your organisation stands today.
Get Your Free Resilience Score
