Cyber Essentials is a UK government-backed certification scheme focused on five technical controls for common online threats. Need it for a customer requirement, a tender or your own security baseline? We help assess readiness, plan and remediate gaps, prepare accurate application answers and keep renewal on the calendar.
Certification is assessed and issued by an independent IASME certification body, not OpsHelp. We provide preparation and technical support. OpsHelp is not an IASME certification body, does not act as a certification assessor and does not claim accredited or NCSC-assured Cyber Advisor status. The certification body decides whether the requirements are met; we cannot guarantee a pass.
Readiness assessment
We agree the organisation and systems to review, then work through the current scheme requirements and question set with you. The review may need to cover devices, networks, accounts and cloud services as well as websites. A website-only assessment is not a substitute for the certification scope.
Cyber Essentials covers five technical control areas:
- Firewalls.
- Secure configuration.
- Security update management.
- User access control.
- Malware protection.
We compare the controls and records you can provide with the requirements, document gaps and unknowns, and give you a prioritised action plan. Where access or evidence is missing, we flag it rather than inventing a compliant answer. The certification body remains the authority on the application and its scope.
Gap remediation
We can implement agreed configuration, access, update and protection changes where we have the appropriate access and expertise. For systems managed by your existing IT team, MSP or cloud provider, we can help describe the required action and review the result with them.
Remediation is separately scoped around the findings, change permissions, backups and rollback. Unsupported equipment, licensing, third-party work and anything outside our capability are identified before commitments are made. This does not require replacing your existing IT provider or buying a general managed-IT package.
Application guidance
We help you understand the questions, gather the relevant information and describe your actual setup accurately. We can organise the application tasks and help you respond to requests for clarification. Your organisation reviews and signs off its answers; support is not permission to state that an unimplemented control is in place.
You arrange certification through IASME or an authorised certification body. Their assessment and certification fees are separate from OpsHelp's support fees. If a customer, tender or insurer has specified a requirement, confirm the certification level, scope and deadline with them: preparation support alone does not satisfy a requirement to hold a certificate.
Annual renewal support
Certification is valid for 12 months. We help plan annual renewal, check what has changed in your organisation or the scheme requirements, revisit the relevant controls and prepare updated application information. This can be a one-off renewal project or an agreed recurring review. We do not automatically renew or issue your certificate.
Cyber Essentials and Cyber Essentials Plus
Cyber Essentials uses a verified self-assessment. Cyber Essentials Plus adds independent technical testing of the controls. We can help prepare and coordinate remediation, but the authorised provider handles the formal assessment and any Plus testing. Neither our readiness review nor our web security assurance is a substitute for those processes.
See the NCSC Cyber Essentials overview, the current self-assessment questions and the certification body directory. Check the current requirements before starting rather than relying on an old questionnaire.
Scope, fees and the next step
Tell us your approximate staff and device counts, main cloud services, whether you are applying for the first time or renewing, and any stated requirement or deadline. Keep credentials, device exports and confidential application evidence out of the public enquiry form; we agree a suitable transfer route after scoping.
We quote readiness work, remediation, application guidance and renewal support around your actual setup. Certification-body charges, replacement equipment and third-party licences are identified separately. Your quote sets out what is included; support fees do not buy or guarantee a certificate.
Need deeper attention to websites, web apps, DNS/TLS, email controls or accessible hosting? Web & Infrastructure Security Assurance is a separate, complementary service. A suspected compromise should go through Cyber Incident Response & Recovery, subject to confirmed availability.