
Government-backed certification that protects your business from the most common cyber attacks — with hands-on support from a local team that already manages networks, firewalls and security for businesses across Hythe, Folkestone, Kent and the South East.
Not sure where to start? Book a free, no-obligation Cyber Essentials readiness check and we’ll tell you exactly where you stand.
Why Small Businesses Are a Prime Target for Cyber Attacks
Small and medium businesses are increasingly targeted precisely because they tend to have weaker defences than larger organisations — fewer dedicated IT security staff, outdated software, and less consistent patching. Phishing emails and ransomware remain the most common routes in, and the consequences go well beyond the initial disruption: lost revenue while systems are down, the cost of recovery, reputational damage with clients, and potential scrutiny from the Information Commissioner’s Office (ICO) if personal data is involved.
According to the UK Government’s Cyber Security Breaches Survey 2025/2026, 43% of UK businesses identified a cyber security breach or attack in the past 12 months — around 612,000 businesses. Micro businesses (1–9 staff) reported a 42% breach rate and small businesses (10–49 staff) 46%, with phishing remaining by far the most common type of attack, experienced by 38% of businesses. Our own blog covers this in more detail in our breakdown of what the survey means for Kent SMEs.
What Is Cyber Essentials?
Cyber Essentials is a UK Government-backed certification scheme, developed by the National Cyber Security Centre (NCSC) and delivered through IASME and its network of certification bodies. It sets out five technical controls designed to protect against the most common internet-based attacks — the kind that make up the vast majority of incidents reported by small businesses every year.
Achieving certification means working through a self-assessment questionnaire covering:
- Firewalls — keeping unauthorised access out of your network
- Secure configuration — devices and software set up securely, not left on risky defaults
- User access control — the right people have the right level of access, nothing more
- Malware protection — defences against viruses and other malicious software
- Security update management — keeping software patched and up to date
We already manage these exact controls for clients every day through our Firewalls & Security and Networking & Hardware services, so Cyber Essentials readiness support is a natural extension of work we’re already doing for most of our clients. Read more about the scheme itself on the official NCSC Cyber Essentials page.
Cyber Essentials vs Cyber Essentials Plus: Which Do You Need?
| Cyber Essentials | Cyber Essentials Plus | |
|---|---|---|
| Assessment type | Verified self-assessment questionnaire | Same controls, plus an independent hands-on technical audit |
| Who verifies | A licensed certification body reviews and marks your submission | An assessor tests your systems directly — internal/external scans and device checks |
| Best for | Most SMEs, micro businesses and sole practitioners | Firms handling more sensitive data, larger contracts, or where clients need higher assurance |
| Validity | 12 months | 12 months |
| Prerequisite | None | Current Cyber Essentials certification |
Most of the small businesses, accountants and bookkeepers we work with start with standard Cyber Essentials — it covers the essentials (literally) without the cost and time of a full technical audit. If you’re bidding for contracts that specifically require Cyber Essentials Plus, or you handle particularly sensitive client data, we can talk you through whether it’s worth the extra step.
Who Should Get Cyber Essentials Certified?
Cyber Essentials isn’t a legal requirement for private businesses, but it’s increasingly expected — by clients, insurers, supply chains and, for many public sector contracts, by the buyer itself. We support businesses across Kent and the South East including:
- Accountants — holding sensitive client financial data brings real UK GDPR responsibilities, and certification demonstrates due diligence to clients and professional indemnity insurers alike.
- Bookkeepers and sole practitioners — working across cloud accounting platforms like Xero, QuickBooks and Sage, often from home, with client logins to protect. Certification is achievable and affordable even for a one- or two-person practice.
- Small and medium businesses generally — baseline protection that’s increasingly expected by customers and often required by cyber insurance policies.
- Government and public sector suppliers — many central government contracts handling personal or sensitive information require Cyber Essentials as a condition of tender.
- Builders and local government contractors — local councils and public sector bodies increasingly require Cyber Essentials as part of tender prequalification, especially for contracts involving site access, shared systems or resident data.
- Solicitors, financial advisers and other regulated firms — where client trust and regulatory expectations both point the same way.
- Charities, schools and healthcare practices — handling sensitive data on often limited IT budgets.
Benefits of Cyber Essentials Certification
- Protection against the most common attacks — the five controls specifically target how the vast majority of breaches actually happen.
- Win government and supply-chain contracts — certification is a tender requirement for many public sector contracts.
- Build trust with clients — display the certification badge and demonstrate you take data protection seriously.
- Support your UK GDPR compliance — the technical controls overlap significantly with the “appropriate technical measures” UK GDPR expects you to have in place.
- Cyber liability insurance — UK organisations with turnover under £20m that certify their whole organisation through the scheme are automatically entitled to cyber liability insurance arranged by IASME. Ask us for the current details when you enquire.
- Fewer headaches at insurance renewal — more insurers are asking about Cyber Essentials status as standard, and certification can make renewal conversations considerably easier.
How to Get Cyber Essentials Certified in 4 Simple Steps
- Free readiness check — a short call to understand your current setup and flag any obvious gaps before you spend a penny on certification.
- Gap remediation — we help you fix what needs fixing: multi-factor authentication, patching, firewall configuration, tidying up admin accounts, retiring unsupported software.
- Assessment — we help you complete the self-assessment questionnaire accurately, then submit it through a licensed certification body for review.
- Certified — you receive your certificate and badge, and your business is added to the public Cyber Essentials register.
Most straightforward small businesses can be certification-ready within a few weeks, though it depends entirely on your starting point and how much remediation is needed.
Cyber Essentials Support & Ongoing Compliance
We offer tailored packages depending on how much support you need:
- Readiness check & guidance — a gap assessment against the five controls, with a clear, prioritised action plan you can work through yourself or hand to us.
- Fully supported certification — we handle remediation and questionnaire completion, and guide you through submission with a licensed certification body, start to finish.
- Cyber Essentials Plus support — everything above, plus preparation for the independent technical audit.
Beyond certification itself, we also offer ongoing cyber security support: managed security, annual recertification reminders, staff phishing awareness training, multi-factor authentication rollout, Microsoft 365 hardening, backup checks via our Cloud Backups service, and straightforward incident response planning.
Every business is different, so we don’t publish one-size-fits-all pricing for this — get in touch and we’ll give you a tailored quote based on your current setup and which route makes sense for you.
Why Choose Meridian Micro for Cyber Essentials Support?
We’re an established IT support company based in Saltwood, Hythe, serving businesses across Kent and the South East with networking, server support, firewalls and security, CCTV and access control, and cloud backups — so Cyber Essentials readiness isn’t a bolt-on service for us, it’s a natural extension of the security work we already do for clients every day.
We’re available 7 days a week until 7:30pm and can typically be onsite within hours if something needs hands-on attention. If you’d rather talk it through first, our IT Support Services and CCTV & Security Systems pages cover the wider security work we do alongside Cyber Essentials support.
Cyber Essentials FAQs
What is Cyber Essentials certification?
Cyber Essentials is a UK Government-backed certification scheme, overseen by the National Cyber Security Centre and delivered through IASME, that verifies your business has five key technical controls in place to protect against the most common cyber attacks.
How much does Cyber Essentials cost?
Certification fees are tiered by organisation size under the scheme itself, and our support packages are tailored to how much remediation work your business needs. Get in touch for a quote based on your current setup — we don’t publish a flat price because it genuinely varies that much.
How long does it take to get Cyber Essentials certified?
For most straightforward small businesses, a few weeks from readiness check to certificate — though it depends on your starting point and how much remediation work is needed before submission.
Is Cyber Essentials mandatory?
No, it’s not a legal requirement for private businesses. However, it’s required for many government and public sector contracts, and increasingly requested by clients, supply chains and insurers as proof of a baseline level of security.
Do accountants need Cyber Essentials?
It’s not a legal requirement, but given the sensitive client financial data accountants hold and the UK GDPR responsibilities that come with it, certification is strongly recommended and increasingly expected by clients and professional indemnity insurers.
Do bookkeepers and sole traders need Cyber Essentials?
It’s not mandatory, but it’s well suited to bookkeepers and sole practitioners — certification is affordable and achievable even for a one- or two-person practice, and it directly addresses the cloud accounting and remote-working risks that come with the territory.
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is a verified self-assessment questionnaire. Cyber Essentials Plus covers the same five controls but adds an independent, hands-on technical audit of your systems. Most SMEs start with standard Cyber Essentials; Plus suits firms with higher assurance needs or specific contract requirements.
How long is the certificate valid for?
Twelve months, for both Cyber Essentials and Cyber Essentials Plus, after which you’ll need to recertify to maintain your status.
What happens if we fail the assessment?
You’ll get clear feedback on what needs fixing, then an opportunity to address the gaps and resubmit. This is exactly why a readiness check before you formally apply is worthwhile — it catches issues in advance rather than at assessment.
Does Cyber Essentials help with UK GDPR compliance?
Yes, indirectly. The technical controls Cyber Essentials requires — access control, malware protection, patching and so on — overlap significantly with the “appropriate technical measures” that UK GDPR expects organisations to have in place to protect personal data.
Does Cyber Essentials include cyber insurance?
UK organisations with turnover under £20m that certify their whole organisation are automatically entitled to cyber liability insurance arranged by IASME as part of the scheme. Terms and eligibility can change, so we’ll confirm the current position when you enquire.
Do home workers and personal devices (BYOD) need to be included?
Generally yes — any device used to access your organisation’s data or services, including personal devices used for work and equipment used by home workers, falls within scope and needs to meet the same five controls.
Do cloud services like Microsoft 365 and Xero count as in scope?
Yes. Cloud services you use to store or process business data are within scope, and how you configure and access them — user permissions, multi-factor authentication and so on — forms part of the assessment.
Get Cyber Essentials Certified — Book Your Free Readiness Check
No obligation, no jargon — just a clear picture of where you stand and what it would take to get certified. Get in touch and we’ll get back to you promptly.
Serving businesses across Hythe, Folkestone, Kent and the South East.