Cyber Essentials service provider — who should certify your business?
Choose a Cyber Essentials service provider that is a listed certification body on the NCSC scheme; the certification checks five core technical controls and the certificate is valid for 12 months, so expect annual reaccreditation. See NCSC’s Cyber Essentials guidance.
Assessment rejected due to missing configuration evidence — gather and timestamp the exact artefacts the assessor asks for
Problem: assessors commonly reject submissions because the screenshots or logs supplied are vague, out of date or lack context. That usually happens when IT teams send single screenshots without showing the wider configuration or proof that a change was applied across the estate. Diagnosis: the auditor needs repeatable, verifiable proof — not a summary sentence in an email.
Recommended next step: collect the precise artefacts the assessor requests and provide them in a consistent format. At minimum you should supply:
- Timestamped configuration exports (firewall rules, router ACLs, MDM console snapshots).
- Patch management reports showing successful installs and device counts.
- Access-control lists or identity provider screenshots that show role mappings.
When you submit, add a short manifest that maps each artefact to the relevant Cyber Essentials control. If your team cannot produce these artefacts within a week, tell the assessor and agree a short remediation window — being transparent prevents unexpected rejection and extra fees.
Vulnerability scan failed because endpoints were unpatched — impose an accelerated patch and reporting cadence
Problem: external scans or the provider’s internal tests flag multiple vulnerable endpoints that should have been patched under normal maintenance. Diagnosis: common causes are shadow IT, inconsistent update policies, or machines excluded from management tools.
Recommended next step: run an emergency patch cycle focused on high-risk CVEs, then demonstrate the result. Practical steps include:
- Prioritise patches for internet-facing assets and known critical CVEs.
- Use your patch management tool to produce a report showing device counts pre- and post-deployment.
- Temporarily isolate unmanaged devices and either enrol them in your MDM or document compensating controls.
Demand a short retest window from the provider after remediation — most providers will retest failed items within 7–14 days if you can show evidence of fixes. If your internal team lacks capacity, hire short-term external help to avoid repeating the same failure on the next attempt.
Provider supplies paperwork only, not technical fixes — require a remediation SLA or change provider
Problem: some suppliers deliver template answers and a self-assessment tick-box service rather than fixing the underlying security issues. Diagnosis: you’ll notice the assessor spends most time on documentation and offers little hands-on remediation or configuration work.
Recommended next step: insist on a binding remediation Service Level Agreement (SLA) that defines what the provider will fix, within what timescale, and how they will prove the fixes. The SLA should include:
- Scope of technical work (e.g., firewall rules, MFA enablement, patch deployment).
- Maximum remediation times (for instance, critical fixes within 5 working days).
- Deliverables that prove the work (screenshots, console exports, retest evidence).
If the provider refuses to commit, replace them. Look for suppliers who combine accreditation support with hands-on IT capability and clear pricing for remedial work. To compare options, review provider services and accreditations on our Cyber Essentials service page before you sign.
Related reading
- our cyber essentials guide
- Cyber Essentials vs ISO 27001: which is right for your UK SME?
- Cyber Essentials support — outsourced certification help and technical fixes
- Cyber Essentials IT Support: A Practical Guide for UK SMEs
- Cyber Essentials Certification for Financial Services
FAQ
Can Cyber Essentials certification expire and how long does it last?
Certificates are valid for 12 months; you must complete a fresh assessment annually to remain certified and demonstrate continued compliance.
What proof does an assessor expect to accept a patching claim?
Assessors typically accept central patch-management reports showing device counts and timestamps, plus vendor logs for critical updates; provide both summary and raw exports where possible.
Is it acceptable to use a small local IT company as the service provider?
Yes, provided they are a listed certification body or work with one, can produce the required artefacts, and are willing to perform or arrange technical remediation within agreed SLAs.







