Written by
Alex Zawalnyski
Technical Review by
Craig MacAlpine
Cyber Essentials is a UK government-backed scheme that helps organizations protect themselves against common cyber threats. The scheme is built around five key technical controls: firewalls, secure configuration, security update management, user access control, and malware protection. In this article, we won’t focus on the tools that help implement those controls, but instead on the platforms that make it easier to document compliance, complete the assessment process, and prepare for certification.
Rather than relying on spreadsheets and one-off evidence gathering, Cyber Essentials compliance solutions can help organizations collect, organize, and document information relevant to the scheme’s requirements. Some of the platforms listed are dedicated Cyber Essentials solutions, while others are broader GRC and compliance platforms that support Cyber Essentials alongside other frameworks.
We’ve assessed multiple Cyber Essentials compliance solutions to understand their ease of use, integration depth, technical support, evidence collection, and other features, identifying the best platform for different use cases. Some are well suited to organizations seeking their first Cyber Essentials certification, while others are stronger choices for MSPs and larger organizations. This article covers the tools and services that can make it easier to achieve and maintain Cyber Essentials certification.
For this list, we have covered a group of companies offering solutions to help organizations get certified to Cyber Essentials. This includes compliance automation platforms (SaaS solutions that collect evidence and automate reporting), consultancy firms (businesses that offer ongoing support, possibly alongside technical controls), device management, third-party risk and vulnerability management solutions that support compliance requirements, and certification bodies that can actually provide Cyber Essentials certification.
Cyber Essentials is owned by the National Cyber Security Centre and delivered by the IASME Consortium, which licenses every Certification Body permitted to assess and award it. Certification runs against a fixed question set and a published requirements document, and the certificate is valid for 12 months. The scheme sets one baseline for every organization, so the questions you answer are the same whether you are a ten-person agency or a 5,000-seat manufacturer. Organization size changes the assessment fee and the scale of the audit, not the standard itself.
The five technical controls are firewalls, secure configuration, security update management, user access control, and malware protection. Scope covers all devices and services that connect to the internet, including end user devices, servers, mobile devices, and cloud services. The April 2026 requirements document, Requirements for IT Infrastructure v3.3, added a formal definition of a cloud service and made clear that cloud services storing or processing your data cannot be excluded from scope. Organizations must now also describe the areas of infrastructure they have excluded and name every legal entity covered by the assessment, with company numbers and addresses.
The current question set is Danzell, published on 13 February 2026 and applying to every assessment account created after 26 April 2026. Accounts opened before that date retain six months to certify against the previous Willow question set. Danzell introduced three auto-fail questions. Multi-factor authentication is mandatory on all cloud services where it is available, whether free, bundled, or paid, and failing to implement it fails the whole assessment. Questions A6.4 and A6.5 require high-risk and critical security updates to be installed within 14 days of release, covering operating systems and router and firewall firmware in A6.4, and applications including associated files and extensions in A6.5. Failing either fails the assessment regardless of every other answer.
Certification itself runs through the IASME assessment portal. You purchase the assessment against your organization's size band, which sets the fee at £320 for 0 to 9 employees, £440 for 10 to 49, £500 for 50 to 249, and £600 for 250 or more, all excluding VAT. You then have six months to complete the questionnaire. A board member or director signs a declaration confirming the answers are accurate and, under the April 2026 wording, acknowledging responsibility for maintaining the controls across the full certification period. A qualified assessor working for a licensed Certification Body marks the submission within three working days and can return it for clarification, with each resubmission reviewed on the same three-day cycle. The certificate is issued immediately on a pass, and the assessment is a point-in-time judgment fixed to the date the certificate is issued.
Cyber Essentials Plus adds an independent technical audit and requires a passing verified self-assessment no more than three months old. The auditor tests a representative sample of user devices, all internet gateways, and all servers running internet-accessible services, checking patch levels, account separation, and malware protection directly on the systems. Two April 2026 changes tightened this. Answers to the verified self-assessment can no longer be amended once technical testing has started, and a failed update-management test now triggers a retest covering both the original sample and a fresh random sample of devices. A second failure revokes the underlying Cyber Essentials certificate.
The platforms in this article divide across three jobs, and no single product covers all of them. Device management and endpoint tools implement and harden the controls, applying configuration baselines, enforcing patch windows, and managing local accounts so the underlying requirements are met before anyone opens the questionnaire. Compliance automation platforms connect to cloud services, identity providers, and endpoints through APIs and agents to gather configuration evidence continuously, map it to the five controls, and flag drift between annual renewals. Certification Bodies and consultancies supply the human work: interpreting scope, answering the questions that no API can answer, and, where they hold an IASME licence, marking the submission and issuing the certificate. Only two products in this article, CyberSmart and GRC Solutions, are IASME-licensed Certification Bodies. Every other platform prepares you for an assessment that a licensed body still has to mark, which is worth confirming before you assume a subscription gets you certified.
Automation also stops short of a meaningful share of the question set. Integrations can evidence MFA status, patch levels, firewall rules, and account privilege reliably. Defining your scope, naming your in-scope legal entities, justifying exclusions, describing how segregated networks are separated, and obtaining a director's signature remain manual, and the auto-fail questions on patching turn on whether updates actually landed across the entire scope rather than on whether a platform recorded them.
Here's a quick comparison of the Cyber Essentials compliance solutions we've reviewed in this article. "Issues Certification" means the vendor is an IASME-licensed Certification Body able to mark your assessment and award the certificate.
| Product | Best For | Issues Certification | Cloud & Identity Integrations | Multi-Client Console |
|---|---|---|---|---|
|
Iru
|
Cyber Essentials on the same platform as device and identity management
|
No
|
Yes
|
No
|
|
ConnectSecure
|
MSPs managing Cyber Essentials across multiple clients
|
No
|
Yes
|
Yes
|
|
CyberSmart
|
Fast, guided certification from a licensed certification body
|
Yes
|
No
|
Yes
|
|
Cynomi
|
MSPs and MSSPs scaling vCISO-led compliance services
|
No
|
No
|
Yes
|
|
Drata
|
Continuous compliance monitoring between renewals
|
No
|
Yes
|
Yes
|
|
GRC Solutions
|
Hands-on consultancy from a certification body
|
Yes
|
No
|
No
|
|
ISMS.Online
|
Combining Cyber Essentials with a wider ISMS
|
No
|
Yes
|
Yes
|
|
Secureframe
|
Cloud configuration scanning and audit support
|
No
|
Yes
|
Yes
|
|
Vanta
|
Automated evidence collection across cloud environments
|
No
|
Yes
|
Yes
|
When assessing Cyber Essentials compliance platforms, we used the scheme’s five technical controls as a starting point. We then looked at how each platform helps organizations document, monitor, or prepare evidence for the relevant requirements, rather than assuming that every platform needs to collect the same evidence in the same way.
We also assessed how each platform supports the Cyber Essentials assessment process, including how much of the self-assessment questionnaire can be completed or supported within the platform, and whether the solution can help organizations prepare for the more rigorous Cyber Essentials Plus assessment, where the five controls are independently tested.
Finally, we looked at how much of the process can be automated, how deeply each platform integrates with an organization’s existing systems, and how much manual evidence collection or configuration is still required.
This guide was written by Alex Zawalnyski and technically reviewed by Craig MacAlpine. You can read more about our methodology at how we test and review products. Read our full methodology
Iru’s compliance product covers eleven frameworks, Cyber Essentials among them. These policies are all managed on the same platform as devices and identities.
Because Cyber Essentials is largely a device configuration standard and Iru is a device management platform first, much of the work is done before the compliance module is involved.
One-click CIS Level 1 and Level 2 templates harden devices, and this gets a UK business most of the way to Cyber Essentials requirements because the two control sets overlap heavily.
We recommend Iru to UK businesses of any size or sector handling Cyber Essentials alongside other frameworks that want compliance on the same platform as their device management, EDR and identity.
We found the console clean and simple to work in, and applying a policy template to a group of devices is a one-click job. Iru is most popular with lean IT teams that operate Mac, iOS, Android and Windows devices.
Applying a CIS template to your fleet is a very useful feature and does most of the Cyber Essentials work before the compliance module is involved. Daily drift monitoring then suggests where controls need updating across the year. This is important, because Cyber Essentials requires annual reassessment.
Compliance can be bought on its own or bundled with Iru’s device management and identity products. Pricing is under $15,000 a year with unlimited frameworks, with startup discounts available.
Best for MSPs managing Cyber Essentials across multiple clients
ConnectSecure is a vulnerability, patch and compliance management platform for MSPs. It provides multi-tenant tracking and reporting for Cyber Essentials compliance across every client environment, accessed from a single dashboard. The dashboard covers monitoring, assessment, prioritization, and remediation. It also supports vulnerability discovery, prioritization, and remediation.
Patch management covers Windows and 600+ third-party applications, alongside asset inventory management and configuration management. EPSS scoring prioritizes vulnerabilities by exploit risk rather than severity alone. The platform generates client-ready compliance documentation without you having to build reports manually.
A self-assessment questionnaire aligned with the IASME assessment helps identify gaps ahead of Cyber Essentials certification.
ConnectSecure is a strong option for MSPs that need to manage multiple Cyber Essentials requirements across different clients simultaneously. The multi-tenant design and compliance reporting features are built around Cyber Essentials’ five controls, making management straightforward and logical.
ConnectSecure helps clients prepare for Cyber Essentials certification, calling itself a “certification toolkit”. The Cyber Essentials assessment itself is independently verified by an IASME-licensed Certification Body, while Cyber Essentials Plus adds an independent technical assessment that can be conducted remotely or on site.
Best for fast, guided Cyber Essentials certification
CyberSmart offers a range of compliance and threat detection software with a managed service designed to support Cyber Essentials and Cyber Essentials Plus certification. CyberSmart says it has completed more than 28,000 Cyber Essentials assessments as of August 2026. This makes it a strong option for SMEs looking for a fast, focused certification platform rather than a broader compliance suite.
A digital questionnaire guides applicants through each compliance requirement with in-platform prompts, and Smart Score reporting flags risks and mitigation steps. Customers get unlimited attempts to achieve certification at no additional cost, with unlimited support from UK-based IASME-assured assessors. Eligible customers can opt in to £25,000 of cyber insurance when they certify through CyberSmart.
CyberSmart is a dedicated Cyber Essentials platform, which we’d recommend for SMEs that want to achieve compliance quickly without needing to manage additional compliance frameworks. The optional £25,000 cyber insurance adds real value for eligible customers, though the policy itself warns that this limit may be inadequate for a serious incident, so it should be viewed as supplementary cover rather than a replacement for a more comprehensive cyber insurance policy.
Best for MSPs and MSSPs scaling vCISO-led compliance services
Cynomi is an AI-powered virtual CISO platform, designed for MSPs, MSSPs, and advisory firms. The platform runs automated assessments mapped to Cyber Essentials’ five technical control areas. It automatically generates client-tailored security and compliance policies and documentation to enforce and prove compliance with frameworks.
Cynomi provides users with graphs, statistics, and risk mapping that make it easier to understand the context and scope of a client’s compliance posture. This framing is a strategic part of Cynomi’s offering: it aims to translate technical vulnerabilities into business risk, helping partners get C-suite buy-in.
Cynomi is a strong platform for MSPs and MSSPs looking for a comprehensive package they can deliver across their client base. The real value isn’t just Cyber Essentials support on its own, it’s that Cynomi lets an MSP or MSSP operationalize compliance across a whole portfolio and fold it into a wider vCISO or security service offering.
Cynomi cites partner-reported gains in service margins alongside reductions in assessment and reporting workload.
Best for continuous compliance monitoring between renewals
Drata is a compliance automation platform that tracks controls, evidence, and ownership between assessments. We think it’s a strong option for organizations looking to layer Cyber Essentials on top of a wider security and compliance program.
Drata provides centralized dashboards for monitoring control status, evidence, tasks, and risk across Cyber Essentials and other supported frameworks. It also supports third-party risk assessments, giving organizations visibility into their partners and suppliers.
Drata is a strong fit for businesses that want Cyber Essentials controls continually enforced. It’s especially useful for organizations looking to address additional frameworks such as ISO 27001 and GDPR alongside Cyber Essentials. It’s a strong choice for teams who are looking to get certified for Cyber Essentials alongside firming up their wider security posture with automations and supplier risk tracking.
Best for hands-on consultancy from a certification body
GRC Solutions, formerly known as IT Governance, is an IASME-licensed Cyber Essentials Certification Body that also provides hands-on consultancy for organizations looking to get certified for Cyber Essentials and Cyber Essentials Plus. This is a consultancy-based offering, with businesses able to choose the level of support they need.
GRC Solutions offers tailored, one-to-one support throughout the certification process.
GRC Solutions is a strong option for organizations that want human guidance from consultants rather than just looking for software automation. Depending on the level of support you need, it can flex from lighter-touch guidance to a fully hands-on, consultant-led engagement. Packages start at £2,055 (+ VAT) for combined Cyber Essentials and Cyber Essentials Plus certification, scaling up based on how much consultant support is included.
Best for combining Cyber Essentials with a wider ISMS
IO (previously ISMS.Online) is a broad compliance management platform that addresses Cyber Essentials, alongside more than 100 other standards, frameworks, and regulations, including ISO 27001, SOC 2, NIS 2, and DORA. Due to the comprehensive nature of the platform, it is best suited to organizations looking to roll out a wider compliance program, rather than focusing exclusively on Cyber Essentials.
ISMS.Online provides pre-built policy and control templates, automatic mapping for relevant standards, and owner assignment. The Headstart feature provides pre-configured policies, controls, and other compliance content out of the box.
ISMS.Online is a strong option for organizations looking to prove compliance with multiple frameworks rather than Cyber Essentials alone. The ability to reuse controls, evidence, and compliance data across multiple frameworks can make this more efficient than running separate tools. Pricing is quote-based rather than publicly listed, so get a quote based on your framework mix and organization size.
Best for cloud configuration scanning and audit support
Secureframe is a compliance automation platform that uses integrations and AI to help organizations manage security, risk, and compliance tasks across multiple frameworks. The platform automates evidence collection and provides continuous monitoring, all managed from a single dashboard.
The platform automatically connects to AWS, Google Cloud, and Azure to monitor configuration status and map findings to Cyber Essentials requirements. It supports both Cyber Essentials and Cyber Essentials Plus: the standard Cyber Essentials self-assessment questionnaire and the more rigorous Cyber Essentials Plus, which adds a third-party technical audit.
Secureframe is a strong option for organizations with cloud infrastructure that need configuration checks across platforms like AWS, Google Cloud, and Azure. Continuous monitoring between certification cycles makes it easier to track ongoing compliance with Cyber Essentials, as well as other compliance frameworks. Fundamentals pricing starts at $7,000/year, while higher-tier pricing is quote-based.
Best for automated evidence collection across cloud environments
Vanta is a compliance automation platform that supports Cyber Essentials as well as SOC 2, ISO 27001, HIPAA, NIST 800-171, and several other frameworks. Its Cyber Essentials framework supports certification with automated evidence collection, control monitoring, remediation guidance, and policy management.
Vanta supports more than 400 integrations out of the box, including AWS, Azure, Cloudflare, GitHub, and Google Cloud. Automated tests run hourly, collecting evidence and flagging issues so organizations can monitor their Cyber Essentials posture between certification cycles.
We think Vanta stands out in this list for its combination of broad integrations, continuous testing, and multi-framework support. We think it’s a particularly strong choice for organizations who need to prove compliance for multiple frameworks, rather than just Cyber Essentials on its own. In our experience, the platform was easy to navigate and we think it’s straightforward for teams of all sizes to get started with.
Pricing in this category splits between fixed-price certification packages and quote-based compliance platforms. Note that platform costs sit on top of the IASME assessment fee, which runs from £320 + VAT for organizations with 0 to 9 employees up to £600 + VAT for those with 250 or more.
| Product | Starting Price | Billing | Link |
|---|---|---|---|
|
Iru
|
Under $15,000/year
|
All frameworks included, startup discounts available
|
|
|
ConnectSecure
|
From $300/month
|
Usage-based tiers (Bronze, Silver)
|
|
|
CyberSmart
|
From £675 + VAT
|
Certification package, annual
|
|
|
Cynomi
|
Contact for quote
|
Client portfolio scale and product package
|
|
|
Drata
|
Contact for quote
|
Tier and framework count
|
|
|
GRC Solutions
|
From £2,055 + VAT
|
Combined CE and CE Plus package; CE alone from £420
|
|
|
ISMS.Online
|
Contact for quote
|
Frameworks selected, organization size
|
|
|
Secureframe
|
From $7,000/year
|
Fundamentals tier (one framework)
|
|
|
Vanta
|
Contact for quote
|
Tier and framework count
|
|
Cyber Essentials solutions can vary considerably in how they work and who they are designed for. Some are best suited to large organizations and MSPs, while others are aimed at smaller organizations that are still getting to grips with compliance and security management. We've identified several areas worth considering when deciding which platform is right for your needs.
Some platforms can actively implement or monitor controls on endpoints through patching, configuration checks, and access management. Others focus more on collecting and organizing evidence that can support the Cyber Essentials assessment. It's important to understand whether you need a platform to help implement the controls themselves, prepare evidence for assessment, or both.
Cyber Essentials is based on a self-assessment with independent verification, while Cyber Essentials Plus adds more rigorous independent technical testing. Some platforms focus on helping organizations complete the Cyber Essentials assessment, while others also help prepare for the additional technical testing required for Cyber Essentials Plus.
Some platforms integrate with hundreds of cloud services and IT systems to collect evidence automatically, while others rely more heavily on questionnaires and manual documentation. If your organization is heavily cloud-based, check whether the platform integrates with the specific systems you use and what information it can collect from them.
Cyber Essentials is one of many security and compliance standards organizations may need to address. Depending on your sector, customers, contractual requirements, and other obligations, you may also need standards such as ISO 27001 or SOC 2. Some compliance platforms allow controls and evidence collected for one purpose to be reused across other frameworks and standards.
The experience of using a compliance solution can vary significantly depending on who it is designed for. A platform built for MSPs managing multiple client environments may offer multi-tenant dashboards, client reporting, and portfolio-level management. That may be less useful to a single organization working through its own certification.
Cyber Essentials certificates are valid for 12 months. The scheme does not require organizations to continuously gather evidence throughout that period, but ongoing monitoring can make it easier to identify changes and prepare for the next certification cycle. Some platforms provide alerts when security controls or configurations drift from the expected state.
Many of the platforms featured in this list do not publish fixed pricing. Make sure you understand the full cost before committing, including any charges for additional users, devices, frameworks, integrations, support, or certification services. Platforms that support Cyber Essentials Plus may also involve additional assessment or testing costs.
Before you weigh up the pros and cons of one platform against another, take the time to decide what your priorities and existing weaknesses are. Do you need a platform that guides you through the assessment process, a tool that actively enforces technical controls, or a combination of both? Your organization’s size, industry, IT environment, and existing security capabilities will all affect which approach makes sense.
Only then should you look at the platforms available and map them against your requirements. Test shortlisted platforms where possible, making sure they fit your existing IT environment and workflows.
It’s also worth considering how your organization may evolve over the coming years. Is Cyber Essentials Plus on your roadmap? Are there other standards you may need to address alongside Cyber Essentials? Consider both your current requirements and your likely direction of travel before committing to a platform.
Further reading on grc and compliance from Expert Insights — buyers' guides, comparison articles, and platform-specific shortlists.
Alex is an experienced journalist and content editor, working alongside software experts to research, write, meticulously factcheck, and edit articles relating to B2B cybersecurity and technology solutions, focusing on topics such as DevSecOps, network security and firewalls, and cloud infrastructure security.
Craig MacAlpine is CEO and Founder of Expert Insights. Before founding Expert Insights in August 2018, Craig spent 10 years as CEO of EPA Cloud, an email security provider that rebranded as VIPRE Email Security following its acquisition by Ziff Davis, formerly J2Global (NASDAQ: ZD) in 2013.
Craig is a passionate security innovator with over 20 years of experience helping organizations to stay secure with cutting-edge information security and cybersecurity solutions.
Using his extensive experience in the email security industry, he founded Expert Insights with the singular goal of helping IT professionals and CISOs to cut through the noise and find the right cybersecurity solutions they need to protect their organizations.