Home How it works Resources About Contact Get in touch

How it works

Cyber Essentials Readiness

We assess your security posture against the five Cyber Essentials controls, give you a clear readiness verdict, and hand you a plan your IT provider can deliver. We advise; we don’t certify (that’s IASME) and we don’t do the remediation ourselves.

The engagement lifecycle

Scoping call

30 minutes, free. We learn your size, stack, and deadline, then send a fixed-price proposal.

Kick-off

You complete a short questionnaire and gather evidence. We confirm on-site or remote assessment.

Assessment day

We walk firewalls, identity, malware, patching, and BYOD with you — verifying what we can see.

Report & handover

Written report in about five working days, plus a walkthrough call. Then your IT provider takes the plan.

Products and pricing

Get in touch and we’ll confirm the right tier on a scoping call. Complex estates are quoted as price on application.

Readiness Assessment

For businesses that want direction, not delivery.

SizePrice
Small£500 fixed
Standard£900 fixed
ComplexPOA
  • One-day assessment (on-site or remote)
  • Written readiness report with verdict and gaps
  • High-level remediation plan
  • Generic policy templates available free from Resources
Get in touch

Readiness Retainer

Keep-you-compliant support between annual re-certifications. Not sold as a first purchase — for clients who have already completed a Readiness engagement with us.

SizePrice
Smallfrom £200 / month
Standard£350 / month
ComplexPOA
  • Triggers: new staff, devices, software, supplier questionnaires
  • Monthly light-touch check-in and on-demand advisory
  • Annual re-readiness review ahead of re-certification
  • Audit / insurer / RFP support
Get in touch

Submission support (£250): optional add-on. We sit with you on submission day, review answers before you send, and help with assessor clarifications.

What the report contains

Typically 15–25 pages for a standard engagement.

  • Executive summary with verdict and top findings
  • Agreed scope statement
  • Per-control assessment (firewalls, secure configuration, access control, malware, patching) plus BYOD where relevant
  • Verified vs asserted evidence flags
  • Remediation schedule with owner, effort, cost range, and priority
  • Clear next steps

What we don’t do

We don’t certify — that’s IASME’s role. We don’t deliver remediation — your IT provider does, or one from a small number of Oxfordshire IT firms we can introduce you to. We’re not an NCSC Assured Service Provider — we’re working towards that qualification, but the readiness work is a separate, self-standing service.

Frequently asked questions

Many IT providers offer Cyber Essentials as an add-on to their own managed service. That can create a conflict — they're assessing work they also deliver. We're independent of your delivery provider, so the assessment stays honest. The report is written so your existing IT firm (or one we introduce) can quote and deliver from it.

From first scoping call to our report is typically 2–3 weeks. Time to actual Cyber Essentials certification depends on remediations and IASME's assessment queue. Some clients submit within days of the report; others need weeks or months of remediation first.

We track our accuracy. If our readiness assessment was materially wrong, we'll help re-run at a discounted fee. The engagement letter sets out the professional-opinion basis: we prepare you; IASME certifies independently; your submitted answers remain your responsibility.

Yes. Travel may add cost for on-site work; remote assessment works well for most standard estates.

Generic templates are free to download from Resources. The Readiness + Policy Pack tier includes the tailored version — customised to your organisation, adopted, and signed off.

Not currently. We refer to a small number of trusted Oxfordshire IT providers, or you can hand the report to your existing provider. Retainer clients get ongoing readiness support from us directly — still advisory, not hands-on IT delivery.

Yes for the Policy Pack tier and above — same engagement plus additional prep for the technical audit.

Optional. We sit with you on the day you submit to IASME, review your answers before you click send, and help handle any clarifications the assessor comes back with. Recommended for first-time applicants.

No problem — previous feedback is useful input for the assessment.

Yes, and this is arguably the best reason. Cyber Essentials covers the controls that stop the most common cyber-attacks on small businesses. Done without an external deadline hanging over you, it's a much better experience than done under contract pressure — you get to make sensible calls about timing, tools, and cost, instead of scrambling.

We're putting Trinito through Cyber Essentials Plus ourselves — the same certification we help you prepare for. We track outcomes. Named-client testimonials will appear here with permission as we complete engagements.

Fixed-fee engagement letter with the price agreed at the scoping call. 50% on booking, 50% on report delivery. Get in touch and we'll take it from there.

Ready to talk?

Get in touch

Free 30-minute scoping call. We handle enquiries manually and reply within one working day.

Get in touch

Browse resources

Free policy templates and plain-English guides before you commit.

Resources