lead-forensics
address

Chamber Hub - Devere House Vicar Lane, Little Germany Bradford BD1 5AH

customer support

Contact Us Today   01274 925361

Do Consultants Need A Cyber Essentials Certification?

CyberSecurity

Do Consultants Really Need Cyber Essentials?

Two consultants pitch for the same contract with a mid-sized firm in Leeds. Same expertise, similar price, both impressive in the room. Then the client’s procurement team sends over a supplier questionnaire, and one question stops the first consultant cold: “Do you hold Cyber Essentials certification?”

She doesn’t. She’s not entirely sure what it is. So she writes “not currently” and hopes it won’t matter.

It matters. The second consultant ticks yes, attaches the certificate, and clears the other fifteen security questions in an afternoon and because the certificate already answers most of them. Guess who gets the work.

If you’ve never been asked that question, you might be soon. And if you have been asked, and quietly fudged the answer, you already know the small jolt of realising your setup might be costing you work you’d otherwise win.

So here’s the honest, jargon-free version: what Cyber Essentials actually is, whether you really need it, and what it does for a consultancy that has it.

So what is Cyber Essentials, in plain English?

Cyber Essentials is a UK government-backed certification, run by the National Cyber Security Centre. It isn’t a gruelling audit. It’s a check that you’ve got five basic protections in place: firewalls, secure device settings, up-to-date software, controlled access to your accounts, and malware protection.

Get those right and you’ve shut the door on the large majority of everyday cyber attacks.

There are two levels. Standard Cyber Essentials is a self-assessment you complete and submit. Cyber Essentials Plus is the same controls, but independently verified by an assessor. For most consultancies, standard is the sensible starting point.

“Isn’t that just for government suppliers and big companies?”

It used to feel that way. Not anymore.

Since 2014, the government has required Cyber Essentials from suppliers bidding on contracts that involve personal or sensitive data – a rule now set out in Procurement Policy Note 014, which came into force in February 2025. For that kind of public-sector work, the maths is blunt: no certificate, no bid.

But the bigger shift is happening beyond government. In October 2024, six major UK banks – Barclays, Lloyds, Nationwide, NatWest, Santander UK and TSB – signed a joint commitment asking the firms in their supply chains to get certified. The NHS is asking the same of its suppliers. And the NCSC notes a steadily growing number of private organisations now expect it before they’ll hand over work.

Here’s why that matters to you specifically. As a consultant, you are the third party in someone else’s supply chain. When a larger client brings you in, their security is only ever as strong as yours — so, increasingly, they check.

 

“But I’m a small consultancy. Surely I’m too small to bother?”

Often it’s the opposite. A one-person consultancy holding a blue-chip client’s board papers is exactly the kind of supplier a security team worries about. Being small doesn’t make you look lower-risk in their eyes – it can make you the weak link they feel they have to tick off.

Certification is simply how you take that worry off the table, before it quietly becomes a reason to choose someone else.

The part most people miss: it wins work – it doesn’t just prevent disaster

Most conversations about cyber security run on fear: the breach, the ransom demand, the reputational hit. All real. But for consultants, there’s a more useful angle – the commercial one.

Cyber Essentials:

  • Unblocks deals you’d otherwise be screened out of, often before your price is even looked at.
  • Answers most of a client’s security questionnaire in one go, so you reply in an afternoon instead of a fortnight and look sharp doing it.
  • Signals at a glance that you take your clients’ data as seriously as they do. In a business built entirely on trust, that’s far from a small thing.

One survey of the banking supply chain found 61% of buyers already prefer certified suppliers, and a third plan to make it mandatory. The direction of travel isn’t subtle.

 

What’s coming next

There’s more on the horizon. The Cyber Security and Resilience Bill, expected to land later in 2026, will extend baseline security requirements across a much wider range of UK organisations and Cyber Essentials has already been updated to line up with it. So getting certified now isn’t only about the contract in front of you. It’s getting ahead of where the whole market is clearly heading.

How hard is it, really?

Less daunting than you’d fear, with the right help. The five controls are straightforward when someone sets them up properly, and the self-assessment is perfectly manageable. The catch is that word “properly”: a lot of the failed assessments we see come down to small configuration gaps nobody knew were there.

That’s where we come in. For Singularitee clients, the core Cyber Essentials controls come as standard, they’re built into the way we set your IT up from day one. So when a prospect sends over that questionnaire, you’re not scrambling. You’ve already got the answer, and the certificate to back it up.

Ready to stop being caught out by the security question?

If you’ve ever hesitated over a client’s security question or you’d simply rather never be caught out by one again, let’s have a chat. Fifteen minutes, no jargon, no pressure. We’ll tell you honestly where you stand and what, if anything, it would take to get you certified and winning the work you deserve.

Cyber Essentials for Consultants: Your Questions, Answered

9b39c956 8cda 4733 b256 df10f92afe56

The cyber essentials security comes as standard with your Singularitee IT Support.

It’s the certificate itself that you are paying for and it’s surprisingly affordable.

The bigger part of the job is usually getting your setup ready to pass, which is exactly the bit we take care of for our clients.

Once your controls are properly in place, the assessment can be turned around in a couple of weeks – the variable is preparation, not paperwork. We usually allow 4-8 weeks for the full process.

Your certificate is valid for 12 months, so it’s an annual renewal, which keeps you current as the requirements evolve.

Standard Cyber Essentials is a self-assessment that’s reviewed by a certified assessor. Cyber Essentials Plus is the same five controls, but an assessor independently tests your devices and accounts to confirm it. Most consultancies start with standard, and only move to Plus if a specific client contract asks for it – we’ll tell you honestly which one your situation actually calls for.

No – they cover different things, and you need both. Think of it this way: GDPR is the rulebook for what you’re allowed to do with people’s personal data – how you collect it, store it, share it, and what happens if it goes wrong.

Cyber Essentials is about the locks on the doors – the technical protections that stop that data being stolen in the first place. GDPR actually requires you to have “appropriate security measures,” and Cyber Essentials is a recognised way to show you’ve got them. So being certified helps you evidence part of your GDPR duties, but it doesn’t make you GDPR compliant on its own.

Yes. People assume “no office server means nothing to certify,” but a laptop and a Microsoft 365 account are exactly what Cyber Essentials checks. In practice that means things like: multi-factor authentication switched on for your 365 login, your laptop set up securely and kept patched, your admin accounts locked down, and antivirus running.

Having no physical server doesn’t take you out of scope – those five controls just apply to your laptop and your cloud apps instead. If anything, a lean cloud-only setup is often the quickest to get certified, because there’s less to check.

Adam Transparent 2

Adam Bovan

During my time as an IT specialist in the Navy, downtime simply wasn’t an option.