FREE TOOL

How Ready Is Your Business for Cyber Essentials?

Most SME owners assume their IT is “secure enough” until something goes wrong. Cyber Essentials exists to close that gap — a government-backed standard covering the five controls that stop the vast majority of everyday cyber attacks. This free checker walks through those same five areas and gives you an honest, plain-English readiness score in about two minutes, with no email address needed to see your result.

Why It Matters

More Than a Badge on Your Website

Cyber Essentials was built by the UK government's National Cyber Security Centre for a simple reason: most successful cyber attacks on small and medium businesses don't involve sophisticated hackers — they exploit basic, preventable gaps. Certification forces a business to close five of the most common ones.

It also does three practical things for you commercially:

  • Wins you work. Many public sector contracts and an increasing number of private enterprise clients now require suppliers to hold Cyber Essentials before they'll sign a contract or even send an RFP.
  • Lowers your risk. The controls covered map directly onto how most ransomware, phishing and unauthorised-access incidents actually happen.
  • Can reduce your cyber insurance premium. Several insurers now ask about Cyber Essentials status directly during underwriting, and some offer preferential terms to certified businesses.

Firewalls

Controlling what can reach your network from the internet.

Secure configuration

Devices set up to minimise their attack surface, not left on default settings.

User access control

The right people have the right level of access, and no more.

Malware protection

Active defences against malicious software on every device.

Security update management

Patches applied before attackers can exploit known flaws.

FAQ

Common Questions

Cyber Essentials is a self-assessed questionnaire, verified by an external assessor. Cyber Essentials Plus adds a hands-on technical audit of your systems, so it carries more weight with clients and insurers who want independent verification rather than a self-declaration.

Cyber Essentials itself can often be achieved within a few weeks once the underlying controls are in place. Cyber Essentials Plus takes longer, since it includes on-site or remote technical testing — timeframes depend on how much remediation is needed first.

No. This is a quick self-assessment to give you an honest early read on where you stand. The official process is more thorough and independently verified. Think of this tool as a way to walk in prepared, rather than a substitute for certification.

Smaller businesses are disproportionately targeted precisely because attackers expect weaker defences. Certification is scaled to be achievable for small teams, and the fixes it requires are largely process and configuration changes rather than expensive new infrastructure.

That's the point of checking early. Most gaps we see are quick to close — a firewall rule, enforcing MFA, tightening admin access — and ITERTECH can help prioritise and fix them before you go for formal assessment.

Yes. Cloud-based user accounts, admin access and configuration settings fall within scope, which is why MFA and access control are assessed alongside traditional network and device security.

Get Certified

Get Certified Without the Guesswork

ITERTECH supports SMEs across Surrey, Hampshire, Berkshire and the wider South East through Cyber Essentials and Cyber Essentials Plus certification — from closing the gaps this checker identifies through to passing formal assessment.