Bluewater.Cyber Essentials
0800 088 4711

Cyber Essentials · IASME certified assessor

Cyber Essentials, done properly — without the paperwork.

One structured intake, one call, one submission. Answer the questions below and you will see straight away where you stand against all five controls — before you spend anything.

  • Live readiness score against the five technical controls
  • Every gap comes with the fix, in plain English
  • Save and come back — nothing is ever lost
  • Fixed fee from £950 plus the IASME fee

Start your assessment

No account, no payment, no commitment.

We send a save-and-resume link here. No password to remember.

Takes about 20 minutes. Already started? Resume where you left off.

What we will ask

Eight steps, about twenty minutes.

  1. Step 1

    Contact & organisation

    Who you are, and which legal entity is being certified.

  2. Step 2

    Scope & target level

    What you are certifying, and why.

  3. Step 3

    Sites, networks & remote workers

    Every location that connects to your systems.

  4. Step 4

    Devices

    Every laptop, desktop, tablet and phone that touches business data.

  5. Step 5

    Servers & network equipment

    Servers, firewalls, switches, access points, NAS and anything else on the network.

  6. Step 6

    Cloud services

    Every SaaS account that holds business data or logs people in.

  7. Step 7

    Users & administrators

    Everyone with an account, and what level of access they hold.

  8. Step 8

    Security controls

    The five Cyber Essentials control areas, in plain English.

Fixed fees

You will know the number before we start.

Cyber Essentials

from £950

Self-assessment prepared, reviewed and submitted for you.

Cyber Essentials Plus

from £2,000

Everything above, plus the hands-on technical audit.

Annual renewal

60–70% of fee

Your data is already on file, so recertification is quick.

The IASME certification fee (£320–£500 + VAT depending on your size) is paid to IASME and passed through at cost.

Common questions

The things that trip people up.

Do personal phones count?

If a personal phone receives company email or accesses company data, it is in scope. It does not need to be company-owned, but it does need to be up to date and PIN-protected.

What about people working from home?

Home workers are in scope. Their home router is not assessed, but their device is - so it needs a host firewall, current updates and malware protection.

We use a lot of cloud services. Is that a problem?

No, but every one of them is in scope. The requirement is multi-factor authentication, always for administrators and for standard users wherever the service supports it.

We still have some Windows 10 machines.

Unsupported software in scope is an automatic fail. You can upgrade, replace, or remove those machines from scope with genuine network segregation. Flag it in the assessment and we will work out the cheapest route.

What if we do not know an answer?

Choose Not sure. It is a genuinely useful answer - it tells us exactly what to check, and it is far better than a guess that fails assessment later.

Start your assessmentOr call 0800 088 4711