Searching for the best Cyber Essentials consultant in the UK is really about finding the right support for your organisation, rather than finding somebody at the top of an arbitrary league table.
A good consultant should help you understand the requirements, identify gaps before assessment, fix the underlying problems and leave your business in a better security position afterwards.
Cyber Essentials is deliberately focused. It looks at a defined set of technical controls intended to protect organisations against common internet-based attacks.
That does not mean certification is always straightforward. Device estates, unsupported software, patching, cloud services, user privileges, remote access and scope can all turn what looked like a simple questionnaire into a considerably more interesting exercise.
I provide Cyber Essentials and Cyber Essentials Plus support myself, so I am not going to pretend this is an independent ranking of me against my competitors. Instead, this guide explains what I think you should look for when comparing me or anybody else.
What should a Cyber Essentials consultant actually do?
There is a substantial difference between helping somebody fill in a questionnaire and actually helping an organisation become ready for Cyber Essentials.
A useful consultant should be able to look beyond the wording of an assessment question and understand what is happening technically underneath it.
Good Cyber Essentials support should include:
- Helping you establish the correct assessment scope
- Reviewing your environment against the current Cyber Essentials requirements
- Identifying technical and administrative gaps before submission
- Explaining requirements in terms your IT team can act on
- Providing practical remediation advice where controls are not compliant
- Helping you gather accurate information and evidence
- Preparing you for Cyber Essentials Plus testing where required
- Helping avoid the same problems reappearing at annual renewal
1. Look for current Cyber Essentials experience
Cyber Essentials is not something I would choose a provider for purely on the basis that they understand cyber security generally.
The assessment has its own requirements, terminology and interpretation. You want somebody who works with the scheme regularly enough to recognise the common failure points and understand what assessors are actually looking for.
Ask how recently they have supported Cyber Essentials or Cyber Essentials Plus engagements and whether they regularly work with organisations like yours.
2. Make sure they can understand your technology
Cyber Essentials deals with practical technical controls. That means your consultant needs enough technical understanding to work through the reality of your environment.
For a small organisation this might be Microsoft 365, a handful of laptops and some cloud services. Another company may have managed devices, BYOD, servers, remote workers, multiple cloud environments and a much more complicated network boundary.
The useful question is not just "do you meet this requirement?" It is often:
"What is actually deployed, how is it configured, who manages it and does that meet the requirement?"
3. Look for remediation support, not just gap identification
Finding a problem is useful. Knowing what to do about it is rather more useful.
If an assessment uncovers unsupported software, excessive privileges, poor patching, insecure configuration or a device that should not be in scope, you need a clear route to resolution.
That does not necessarily mean the consultant has to make every technical change themselves. They should, however, be able to explain the problem clearly enough for your IT team or managed service provider to fix it.
Ask prospective providers:
- Will you identify gaps before we formally submit?
- Do you explain how failed controls can be remediated?
- Can you work directly with our IT provider?
- Will you review fixes before assessment?
- What happens if something fails during Cyber Essentials Plus testing?
4. Understand the difference between consultancy and certification
This is worth clearing up before comparing providers because the words are often used interchangeably.
You may be buying readiness consultancy, the formal Cyber Essentials assessment, Cyber Essentials Plus technical testing, or a package combining several of these things.
They are different activities.
| Service | What it is | Why you might need it |
|---|---|---|
| Readiness review | A check of your environment before formal assessment | You want to identify and fix problems before submitting |
| Remediation support | Practical help resolving gaps against the requirements | Your team needs guidance getting controls into shape |
| Cyber Essentials | Formal verified self-assessment against the scheme requirements | You need baseline Cyber Essentials certification |
| Cyber Essentials Plus | The same requirements with independent technical verification | You need a greater level of assurance or it is contractually required |
Before accepting a quote, establish exactly which of those activities are included.
5. Ask how Cyber Essentials Plus preparation works
If you are going for Cyber Essentials Plus, preparation becomes more important because the controls are technically tested rather than simply described through the self-assessment process.
The best time to discover a problem with patching, configuration, user privileges or malware protection is before the assessment begins.
A useful readiness exercise therefore needs to look at the estate much more like an assessor will.
Ask what preparation is included, how devices are sampled, what evidence is reviewed and what help you receive if issues are identified.
6. Find out who will actually support you
As with most consultancy, the company name matters less than the person doing the work.
There is nothing wrong with using a larger provider. Equally, there can be advantages to working directly with an individual specialist.
The important thing is knowing what you are buying.
| Delivery model | Often suits | Things to check |
|---|---|---|
| Independent / principal-led consultant | SMEs wanting direct senior support | Availability, capacity and route to formal certification |
| Certification body | Organisations wanting assessment and related support in one place | Exactly what preparation and remediation assistance is included |
| Cyber security consultancy | Businesses with wider security requirements | Whether Cyber Essentials is a regular part of their work |
| Managed IT provider | Organisations whose MSP already controls most of the estate | Depth of Cyber Essentials knowledge and independence of assessment |
7. Avoid treating Cyber Essentials as a paperwork exercise
There is inevitably paperwork involved, but the important bits are technical.
If a device is running unsupported software, a user has inappropriate administrative privileges or security updates are not being applied properly, changing the wording in a questionnaire does not solve the problem.
The strongest Cyber Essentials engagements use certification as an opportunity to tidy up the estate and put repeatable processes around the five control areas.
That makes renewal considerably less painful too.
Questions to ask before choosing a Cyber Essentials consultant
- How often do you work on Cyber Essentials and Cyber Essentials Plus?
- Will you help us determine our assessment scope?
- Do you carry out a readiness review before formal submission?
- Will you help us remediate technical gaps?
- Can you work directly with our internal IT team or MSP?
- What evidence will we need to provide?
- What preparation do you provide for Cyber Essentials Plus?
- Who actually carries out the work?
- Which parts of the formal certification process are included?
- What happens if an issue is found during assessment?
- Do you provide any support around annual renewal?
Warning signs
None of these automatically make a provider unsuitable, but I would ask more questions if you encounter them.
- The conversation is almost entirely about completing the questionnaire
- Nobody asks detailed questions about the technology actually in scope
- There is no readiness check before formal assessment
- Remediation support is vague or excluded completely
- You are not clear who will actually deliver the work
- The provider cannot explain what will happen during Cyber Essentials Plus
- Consultancy and formal certification are presented as though they are the same thing
- The focus is entirely on obtaining the badge rather than satisfying the technical controls
Some Cyber Essentials providers to compare
This is deliberately not a ranking. There is no universal "best Cyber Essentials consultant" because different organisations need different things.
A small business looking for hands-on preparation has different requirements from a defence supplier pursuing Cyber Essentials Plus, or a larger organisation looking for a provider with broader assurance capability.
Paul Reynolds
I provide practical Cyber Essentials and Cyber Essentials Plus support, particularly for UK SMEs and organisations where certification forms part of wider customer, regulatory or supplier assurance.
I tend to work directly with the organisation and its IT team or MSP, looking at the underlying technical environment rather than treating the exercise purely as completion of a questionnaire.
Potentially a good fit if:
- You want direct access to the senior consultant doing the work
- You want gaps identified before formal assessment
- You need practical remediation guidance
- You are preparing for Cyber Essentials Plus
- Your environment is slightly more complicated than the questionnaire initially makes it look
- You want certification to improve security rather than simply produce a badge
I obviously cannot provide an impartial review of my own service. If that delivery model sounds useful, you can read more about my Cyber Essentials support or use the Cyber Essentials readiness assessment.
IASME
IASME operates the Cyber Essentials scheme on behalf of the National Cyber Security Centre and works through a network of certification bodies.
It is the useful starting point if you want to understand the scheme itself, the certification process or the available certification routes.
Bulletproof
A UK security provider offering Cyber Essentials services alongside broader cyber security and technical testing.
Worth comparing if you want Cyber Essentials support from a provider that also offers wider technical security services.
Ascentor
A UK security consultancy with experience in higher-assurance environments, including defence and public-sector supply chains.
Potentially relevant where Cyber Essentials Plus forms part of a broader assurance or supply-chain requirement.
BCN
A managed technology and security provider offering Cyber Essentials services alongside broader IT support.
Worth considering where you want certification support closely connected to ongoing management of the underlying technology estate.
Pentest People
A UK technical security testing provider that also offers Cyber Essentials services.
Potentially suitable if certification sits alongside penetration testing or other technical assurance requirements.
Secarma
A UK cyber security consultancy offering security assessment and testing services alongside wider advisory work.
Worth comparing where Cyber Essentials is one part of a broader security programme rather than the only requirement.
Cyber Essentials or Cyber Essentials Plus?
Both are based on the same core technical requirements. The important difference is the level of verification.
| Option | What it involves | Usually appropriate when |
|---|---|---|
| Cyber Essentials | Verified self-assessment against the scheme requirements | You need baseline certification or a customer/tender requires Cyber Essentials |
| Cyber Essentials Plus | The same requirements with independent technical testing | You need stronger assurance or Plus is specifically required |
| Readiness review | A practical check before certification | You want to find and fix problems before entering formal assessment |
If you are unsure whether your current environment is ready, starting with a Cyber Essentials readiness assessment is usually safer than discovering the gaps during formal assessment.
So who is the best Cyber Essentials consultant?
There isn't one provider that is objectively best for every organisation.
If you have a simple environment and a capable internal IT team, you may need very little consultancy at all. If your estate is complicated, you have repeatedly struggled with certification or you are preparing for Cyber Essentials Plus, experienced preparation can save considerable time.
The useful test is whether the provider can help you understand your scope, identify the real technical gaps, explain what has to change and prepare you properly for assessment.
And preferably, at the end of the exercise, your security should actually be better.
When my approach may be a good fit
I work directly with organisations that want practical help getting the technical controls right before assessment rather than finding out what is wrong during it.
- You are a UK SME or growing organisation
- You need Cyber Essentials or Cyber Essentials Plus
- You want a readiness check before formal assessment
- You need help resolving technical gaps
- You have an IT team or MSP that needs clear remediation guidance
- You want direct access to an experienced security consultant
Frequently asked questions
Look for current scheme experience, technical understanding of the five control areas, practical remediation support and clear preparation for whichever certification route you need. Make sure you also understand exactly which consultancy and certification activities are included.
A consultant can review your environment, explain the requirements, identify gaps, help your team remediate them, support the self-assessment process and prepare you for Cyber Essentials Plus testing where required.
Cyber Essentials is based on a verified self-assessment. Cyber Essentials Plus applies the same requirements but adds independent technical testing. Which you need usually depends on customer, tender, contractual or assurance requirements.
The five control areas are firewalls, secure configuration, user access control, malware protection and security update management.
Not necessarily. Readiness consultancy, formal certification and Cyber Essentials Plus testing are different activities. Before appointing a provider, make sure you know which role they are performing and exactly what is included.
Yes. I can review your current position, identify gaps, explain what needs fixing and work with your team or IT provider to prepare before formal assessment.