Strengthen your IT infrastructure, safeguard company data, and achieve compliance with expert-led Cyber Essentials certification from NetManageIT.
Whether you need to defend against common cyber threats, comply with central UK government contract requirements, or give client partners confidence in your supply chain security, NetManageIT delivers complete, hands-on guidance from boundary scoping to final accreditation under NCSC v3.2 (Willow) guidelines.
We don't just point out failed controls—our engineers actively fix gaps, hard-patch software, and adjust settings to get you compliant.
Transparent scoping and fixed rates with zero surprise consultancy bills.
We establish accurate network boundary parameters, including cloud services and remote user endpoints, ensuring smooth certification.
A senior security advisor guides your team step-by-step through every phase to meet your delivery deadline.
Our certification process aligns strictly with the National Cyber Security Centre (NCSC) and IASME v3.2 standard.
Coverage for biometrics, passkeys, security keys, and push-based MFA.
Full protection and policy oversight for hybrid environments and BYOD access points.
Mandated 14-day remediation covering registry tweaks, scripts, and software patches for High/Critical flaws.
Active assessment standard
Certification body recognition
Ideal for organisations that already manage robust IT security controls, understand NCSC requirements, and simply need an accredited assessor to review their completed Self-Assessment Questionnaire (SAQ).
Designed for organisations seeking guaranteed pass status. We handle gap analysis, perform technical remediations, and walk you through to complete accreditation.
NCSC v3.2 mandates these five essential security controls for certification.
Boundary protection to prevent unauthorized network entry and restrict untrusted web traffic.
Disabling unnecessary ports, removing default admin credentials, and enforcing system hardening standards.
Strict role-based privileges, account separation, and multi-factor or passwordless authentication.
Antivirus, sandboxing, and software restriction policies to block malicious code execution.
Ensuring OS, firmware, scripts, and software extensions are patched within 14 days of release.
A clear, five-step journey from discovery to accreditation.
Define organisational boundary, remote devices, and cloud setups.
Audit controls against v3.2 standards and apply necessary fixes.
Complete and submit verified answers through the IASME portal.
Conduct external/internal vulnerability scans and sample audits.
Receive official certification badges and listing on the NCSC database.
| Feature | Cyber Essentials (Basic) | Cyber Essentials Plus |
|---|---|---|
| Assessment Method | Verified Self-Assessment Questionnaire (SAQ) | Hands-on Technical Audit & Vulnerability Scans |
| Verification Level | Assessor review of documented controls | On-site/remote scan of sample devices, browsers & emails |
| Best For | Baseline cyber security & basic client trust | Public sector tenders (PPN 014), enterprise supply chains |
| Current Standard | NCSC v3.2 “Willow” | NCSC v3.2 Test Specification |
| Validity Period | 12 Months | 12 Months |
Both certifications align with the NCSC v3.2 (“Willow”) standard.
Get in touch with our team today for a free scoping consultation.
Fixed-fee packages · NCSC v3.2 accredited · 12-month certification