NetManage IT

Get IT Support
+44 (0)3333 030 971
sales@netmanageit.co.uk
NCSC v3.2 “Willow” Standard

Cyber Essentials &
Cyber Essentials Plus Certification

Strengthen your IT infrastructure, safeguard company data, and achieve compliance with expert-led Cyber Essentials certification from NetManageIT.

Whether you need to defend against common cyber threats, comply with central UK government contract requirements, or give client partners confidence in your supply chain security, NetManageIT delivers complete, hands-on guidance from boundary scoping to final accreditation under NCSC v3.2 (Willow) guidelines.

12+ Years Experience
500+ Certifications Delivered
100% Fixed-Fee Guarantee
Why NetManageIT

Your Trusted Partner for Cyber Essentials

Hands-On Technical Remediation

We don't just point out failed controls—our engineers actively fix gaps, hard-patch software, and adjust settings to get you compliant.

Fixed-Fee Commercial Packages

Transparent scoping and fixed rates with zero surprise consultancy bills.

Tailored Scoping Assistance

We establish accurate network boundary parameters, including cloud services and remote user endpoints, ensuring smooth certification.

Dedicated Technical Project Lead

A senior security advisor guides your team step-by-step through every phase to meet your delivery deadline.

v3.2 “Willow”

Current Standards &
Compliance Focus

Our certification process aligns strictly with the National Cyber Security Centre (NCSC) and IASME v3.2 standard.

  • Passwordless & Modern Authentication

    Coverage for biometrics, passkeys, security keys, and push-based MFA.

  • Home & Remote Working Scope

    Full protection and policy oversight for hybrid environments and BYOD access points.

  • Expanded Vulnerability Management

    Mandated 14-day remediation covering registry tweaks, scripts, and software patches for High/Critical flaws.

NCSC v3.2 “Willow”

Active assessment standard


IASME Accredited

Certification body recognition

Certification Tiers

Choose Your Path to Compliance

Direct Assessment

Self-Assessment Tier

Ideal for organisations that already manage robust IT security controls, understand NCSC requirements, and simply need an accredited assessor to review their completed Self-Assessment Questionnaire (SAQ).

  • Comprehensive SAQ verification
  • Feedback on edge cases or boundary clarifications
  • Official certification issuance upon passing
Supported

Certification & Remediation Tier

Designed for organisations seeking guaranteed pass status. We handle gap analysis, perform technical remediations, and walk you through to complete accreditation.

  • In-depth scoping session (cloud, remote staff, BYOD)
  • Gap analysis and technical action plan
  • Configuration and patching support prior to submission
  • Full prep and testing for Cyber Essentials Plus scans
Core Controls

The 5 Core Technical Controls

NCSC v3.2 mandates these five essential security controls for certification.

01
Firewalls & Internet Gateways

Boundary protection to prevent unauthorized network entry and restrict untrusted web traffic.

02
Secure Configuration

Disabling unnecessary ports, removing default admin credentials, and enforcing system hardening standards.

03
User Access Control

Strict role-based privileges, account separation, and multi-factor or passwordless authentication.

04
Malware Protection

Antivirus, sandboxing, and software restriction policies to block malicious code execution.

05
Security Update Management

Ensuring OS, firmware, scripts, and software extensions are patched within 14 days of release.

Process

Certification Roadmap

A clear, five-step journey from discovery to accreditation.

1
Discovery & Scoping

Define organisational boundary, remote devices, and cloud setups.

2
Gap Analysis & Technical Remediation

Audit controls against v3.2 standards and apply necessary fixes.

3
Self-Assessment (SAQ) Submission

Complete and submit verified answers through the IASME portal.

4
Technical Audit (Cyber Essentials Plus)

Conduct external/internal vulnerability scans and sample audits.

5
Accreditation & Registry Listing

Receive official certification badges and listing on the NCSC database.

Comparison

Cyber Essentials vs. Cyber Essentials Plus

Feature Cyber Essentials (Basic) Cyber Essentials Plus
Assessment Method Verified Self-Assessment Questionnaire (SAQ) Hands-on Technical Audit & Vulnerability Scans
Verification Level Assessor review of documented controls On-site/remote scan of sample devices, browsers & emails
Best For Baseline cyber security & basic client trust Public sector tenders (PPN 014), enterprise supply chains
Current Standard NCSC v3.2 “Willow” NCSC v3.2 Test Specification
Validity Period 12 Months 12 Months

Both certifications align with the NCSC v3.2 (“Willow”) standard.

FAQs

Frequently Asked Questions

What is the active Cyber Essentials standard?
Assessments are conducted under the NCSC Requirements for IT Infrastructure v3.2, utilising the “Willow” question set.
How long does certification take?
Basic Cyber Essentials usually takes 5–10 working days after submission. Cyber Essentials Plus takes 2–4 weeks depending on remediation requirements and scan availability.
Is Cyber Essentials required for government tenders?
Yes, under UK Procurement Policy Note 014 (PPN 014), central government contracts involving sensitive data require Cyber Essentials or Cyber Essentials Plus.
What if we fail the Cyber Essentials Plus scan?
NetManageIT provides a clear vulnerability report and assists with technical fixes, offering a free re-scan within the standard retest window.

Ready to achieve Cyber Essentials certification?

Get in touch with our team today for a free scoping consultation.

Fixed-fee packages · NCSC v3.2 accredited · 12-month certification