Security Certification

Cyber Essentials Readiness

At A2Z IT, we take cybersecurity seriously. Our mission is to safeguard your digital assets and protect sensitive data from cyber threats. We recognize that you, the leader, play a crucial role in building a culture of cyber readiness

Free Consultation

The A2Z IT Promise

Threats change and so do our security measures. We keep improving what we do so your security keeps up, without you having to chase it.

Security Framework

The government standard for network security, established by the National Cyber Security Centre.

Industry-Supported

An effective, government-backed initiative protecting organisations of all sizes.

Risk Management

Reduce the risk of being targeted by cybercriminals seeking vulnerable targets.

Policy Development

Controls covering firewalls, secure configuration, user access control and malware protection.

How we get you certification-ready

Practical guidance to protect your organisation against common cyber threats.

01

What Is Cyber Essentials?

Cyber Essentials is the government standard for network security, established by the National Cyber Security Centre. By adhering to these rigorous standards, we ensure that our systems and the data entrusted to us are fortified against cyber attacks.

Government-Backed Scheme

Cyber Essentials is an effective, government-backed initiative designed to protect organisations of all sizes against common cyber threats. It provides practical guidance to prevent basic attacks, which are often carried out by relatively unskilled individuals.

Basic Protection

The self-assessment option under Cyber Essentials shields your organisation against a wide range of common cyber attacks. By implementing these basic controls, you reduce the risk of being targeted by cybercriminals seeking vulnerable targets.

Cyber Essentials logo
Two people shaking hands across a desk
02

Certification Benefits

Reassure Customers - Displaying your Cyber Essentials certification reassures customers that you prioritise cybersecurity. Attract New Business - Potential clients are more likely to engage with businesses that demonstrate robust security practices. Clear Security Picture - Certification provides a clear view of your organisation’s cybersecurity level.

Technical Controls

Cyber Essentials outlines technical controls that address fundamental security aspects. These controls include measures related to firewalls, secure configuration, user access control and malware protection.

Cyber Essentials Plus

For an extra layer of assurance, consider Cyber Essentials Plus. It involves a hands-on technical verification to validate that your security measures are effectively in place.

03

Government Contracts

If you plan to bid for central government contracts, especially those involving sensitive information or technical products/services, Cyber Essentials certification is often a requirement.

Trust Building

Achieving Cyber Essentials certification builds trust between companies and their customers. It demonstrates a commitment to cybersecurity and reassures clients that their data is in safe hands.

Continuous Improvement

Threats change and so do our security measures. We keep improving what we do so your protection keeps pace, backed by reliable Managed IT Services.

The Elizabeth Tower and Great Clock at the Palace of Westminster
Person sheltering under a red umbrella on a rainy city street at night
04

Certification comes with insurance attached

If you qualify, certifying brings £25,000 of cyber liability insurance with it at no extra cost. Scope is where firms trip up. The cover only applies when your certification covers the whole organisation, so certifying a single office or department rules it out and you opt in while you apply rather than afterwards.

  • UK-domiciled organisations with an annual turnover under £20 million
  • Certification covering the whole organisation, not a subset of it
  • A 24-hour incident line, with crisis management and response up to the limit

We are not insurance brokers and the policy sits between you and the insurer. Our part is making sure the scope is decided deliberately, because that choice quietly settles whether the cover applies at all. Treat the £25,000 as a floor rather than a safety net: worth having and not the whole answer for most firms.

05

Five Controls, One of Them Awkward

Cyber Essentials asks about five things: firewalls, secure configuration, user access control, malware protection and patching. Four of them live inside your Microsoft 365 tenant, which is what our assessment measures directly. The fifth is the firewall at your edge. That is the one that most often needs real work, because it is hardware and configuration rather than a setting somebody can toggle.

We configure firewalls from small UTM appliances through to next-generation platforms, so that control does not have to become somebody else's problem halfway through your application.

Pile of old keys and padlocks
Person at a desk working through a printed document
06

We Have Sat on Your Side of the Audit

Cyber Essentials Plus adds a hands-on technical assessment by an external auditor. That is where readiness gets tested rather than described. We have acted as the technical lead through that process: producing the evidence the assessor asks for, walking them through how things are configured and fixing what the testing turns up while it is still in the room.

Knowing what gets asked is most of the preparation. Certification itself is issued by an IASME-accredited body rather than by us. Our job is getting you to the point where the assessment is uneventful.

Assessed with tools, not just checklists

We assess your Microsoft 365 environment with our own tooling, mapped to Cyber Essentials controls, so readiness is measured rather than guessed. The same assessments cover the technical requirements of the Data Security and Protection Toolkit (DSPT) for care providers.

Cyber Essentials & Cyber Essentials Plus

Core Assessment Criteria

Secure Configuration

Malware Protection

Rigorous Evaluation

Penetration Testing

Audited Security Controls

Firewall Protection

User Access Control

Patch Management