Why the choice of Certification Body matters
Cyber Essentials is a standardised certification scheme. Every applicant is assessed against the same current requirements, and a successful result should mean the same thing whichever Certification Body carries out the assessment.
The experience of getting there can still differ. Certification Bodies may offer different levels of preparation support, use different ways of communicating and have different experience of cloud services, remote working, outsourced IT and more complex estates. Some organisations want a straightforward route through the assessment. Others need help understanding scope, gathering accurate information and resolving gaps before submission.
The right choice is therefore not about finding easier requirements. It is about finding a Certification Body whose service, communication and practical support suit your organisation while preserving the integrity of the assessment.
What a Cyber Essentials Certification Body does
IASME is the NCSC’s official delivery partner for Cyber Essentials. Licensed Certification Bodies employ qualified Assessors who assess whether organisations meet the scheme requirements and issue certification through the official process.
For the verified Cyber Essentials self-assessment, an organisation completes the assessment questions and a senior person confirms that the answers are accurate. A qualified Assessor reviews the submission and may ask for clarification or further information before making the certification decision.
Cyber Essentials Plus adds an independent technical audit of the in-scope systems. It requires a Certification Body with the relevant qualified capability. The Assessor selects and tests systems in line with the current certification process, with scope and sampling shaped by the organisation being assessed.
A Certification Body may also offer preparation support. This can include explaining questions, helping an organisation understand its scope and identifying areas that may need remediation. Preparation and advice should not turn into a guaranteed outcome: the final decision must still depend on whether the organisation meets the requirements.
Confirm that the provider is licensed
The first question is simple: is the provider an IASME licensed Certification Body for the scheme you need?
Check the current IASME directory rather than relying only on a logo or an old statement. If you need Cyber Essentials Plus, confirm that the provider can deliver that assessment as well as the verified self-assessment. An organisation may offer useful cyber security consultancy without being able to issue Cyber Essentials certification, so it is worth establishing the distinction early.
You should also ask who will manage the engagement and who will assess the submission. A clear point of contact makes it easier to resolve scope questions, coordinate with an IT provider and keep the work moving.
Ask what support is included
Support packages vary. Before comparing prices, establish what each proposal actually includes.
Useful questions include:
- Does the service include the assessment only, or preparation support as well?
- Will someone review scope before the assessment begins?
- Can the provider explain how the questions apply to your environment?
- Is a review of draft answers included?
- What happens if an answer needs clarification?
- Is remediation advice included, and to what depth?
- Are follow-up meetings or retesting included?
- What is explicitly excluded from the price?
An assessment-only service may be entirely appropriate for an organisation with a well-understood environment and experienced internal IT support. A supported route may be more useful where responsibilities are split between the business and an outsourced provider, or where cloud services and remote working make scope less obvious.
Be cautious about vague promises to “handle everything”. The applicant still needs to understand and attest to its environment. Good support should help the organisation provide accurate answers and improve controls, not detach leadership from the process.
Understand how scope will be handled
Scope is one of the most important parts of Cyber Essentials. It affects which devices, services, users and controls must be considered, and it needs to reflect how the organisation actually operates.
Ask how the Certification Body approaches early scope discussions. Can it help identify internet-facing systems, cloud services, remote workers, personally owned devices and services managed by third parties? Will it explain where a proposed scope creates dependencies or exclusions that need attention?
This is especially important for organisations with:
- multiple offices or legal entities;
- remote or hybrid workers;
- Microsoft 365 and other cloud services;
- mixed Windows, macOS, mobile or specialist devices;
- outsourced IT support;
- shared infrastructure;
- systems that cannot be updated or replaced easily.
The objective is not to find the narrowest possible scope. It is to agree an accurate, defensible scope before time is spent preparing the wrong systems or answers.
Check communication and timescales
Certification often sits behind a tender, customer request or renewal date. Ask what the expected timeline is, what information is needed from you and how quickly questions are normally answered.
Timescales should be realistic. They depend not only on the Certification Body, but also on how quickly the organisation can confirm scope, supply accurate information and complete remediation. A provider should be clear about those dependencies rather than promising a date before understanding the environment.
Ask how communication will work during the engagement. A named contact, clear request list and agreed route for technical questions can make a substantial difference, particularly when an internal team and external IT provider both need to contribute.
Make sure costs and exclusions are clear
Compare like with like. One quote may cover only certification, while another includes readiness review, meetings, technical checks or remediation guidance.
Ask for a clear explanation of:
- the certification fee;
- preparation or consultancy charges;
- what affects the final Cyber Essentials Plus price;
- whether travel or on-site work is required;
- what retesting or additional support may cost;
- which activities remain the responsibility of your IT provider;
- how changes to scope may affect the quote.
The cheapest assessment is not automatically poor value, and the most expensive package is not automatically the most suitable. The useful comparison is between the support your organisation needs and what the quoted service will actually deliver.
Cyber Essentials or Cyber Essentials Plus?
Cyber Essentials is a verified self-assessment against five technical control areas. It is commonly used as a recognised baseline for customer assurance, tenders and internal improvement.
Cyber Essentials Plus builds on that foundation with an independent technical audit of the in-scope environment. It may be required by a customer or contract, or chosen where the organisation wants stronger technical assurance.
The two certifications address the same underlying control areas but provide different levels of verification. Our guide to Cyber Essentials versus Cyber Essentials Plus explains the distinction in more detail.
When selecting a Certification Body, confirm which route you need and whether the provider can support the whole path. If Cyber Essentials Plus is likely later, early preparation can help avoid decisions during the self-assessment that make the technical audit harder to organise.
Preparation comes before assessment
An organisation should understand its scope, asset coverage and relevant controls before submitting an assessment. That includes checking supported software, security updates, firewall controls, user access, administrator privileges and multi-factor authentication where required.
For Cyber Essentials Plus, preparation also means making sure in-scope devices are available and representative, and that controls are applied consistently across the environment rather than only to devices likely to be tested. Our Cyber Essentials Plus preparation guide covers the practical areas to review.
A readiness review can find issues early and give the organisation time to correct them. It cannot promise a pass, because certification depends on the evidence and the assessed environment meeting the current requirements.
Organisations seeking a provider with regional context can also read about our Cyber Essentials support in Scotland . Most work can be delivered remotely, so location need not limit the choice of Certification Body.
When broader consultancy may help
Some organisations need more than administration of the certification process. Broader advice may be useful where there are complex Microsoft 365 or cloud configurations, several offices, a mixed device estate, unresolved vulnerabilities or unclear responsibilities between the business and an outsourced IT provider.
It may also help where Cyber Essentials is part of a wider customer assurance programme, or where leadership needs to understand governance and risk-management gaps that sit beyond the certification requirements.
In those cases, ask whether the provider can place the immediate assessment in a wider security context. That might involve a Microsoft 365 Security Review , a vulnerability assessment or a defined cyber security consultancy engagement . The additional work should be proportionate and clearly separated from what is required for certification.
Choosing a provider that fits your organisation
A useful final comparison is whether the service model matches the way your organisation works. Consider whether you want a largely transactional assessment, practical preparation support or access to wider advice if the process uncovers more substantial issues.
Look for clear answers, realistic boundaries and an interest in understanding your environment. A good Certification Body should help you navigate the process without making the certification sound effortless or mysterious.
About Be Secure Cyber
Be Secure Cyber is an IASME licensed Certification Body based in Glasgow, supporting organisations across the UK with Cyber Essentials and Cyber Essentials Plus. We provide practical help with scope, readiness and remediation while keeping preparation support distinct from the certification decision.
Contact Be Secure Cyber to discuss your requirements and the level of support that would be appropriate.