A tender names Cyber Essentials
The opportunity is attractive, but certification has appeared as a pass-or-fail supplier requirement rather than an optional extra.
A customer, insurer or tender has asked a question that “we have antivirus” cannot answer. Before you rush into a certificate or another security product, establish what evidence they need, what is in scope and which recognised standard will actually satisfy the request.
The request is rarely just about technology. Someone needs a consistent, defensible answer before they accept risk, award work or renew cover.
The opportunity is attractive, but certification has appeared as a pass-or-fail supplier requirement rather than an optional extra.
Questions about devices, access, updates and cloud services expose how difficult it is to turn everyday IT into reliable evidence.
The renewal asks who has administrator access, how accounts are protected and whether important controls are actually enforced.
Your customer needs confidence that a weakness in a smaller supplier will not become a route into its information or systems.
Leaders want a simple way to see whether the basics are owned, measured and maintained—not another collection of product names.
Renewal reveals whether the controls became normal business practice or were treated as a one-off project for last year’s badge.
Start with the business requirement. The right evidence becomes much clearer once the request, scope and present position are understood.
A questionnaire is not the security work. It reveals whether the work has clear ownership and evidence behind it.
Ask whether they require Cyber Essentials, Cyber Essentials Plus, answers to their own questionnaire or evidence of particular controls—and confirm the deadline.
Map the people, devices, networks and cloud services involved. Cyber Essentials normally covers the whole organisation or a clearly defined and separately managed subset agreed with the Certification Body.
Identify who owns each control, where the information comes from and which gaps need resolving before anybody signs or submits an assessment.
Cyber Essentials is the Government-recommended minimum cyber security standard and covers five technical controls. It is often the most useful recognised baseline, but the buyer may be asking for a different level or type of evidence.
Sources: NCSC Cyber Essentials overview and the current technical requirements.
| What they need | What it should demonstrate | Sensible route |
|---|---|---|
| Basic reassurance | Important controls are known, owned and documented | Focused security review with a clear improvement plan |
| Recognised baseline | Five core technical controls meet an independently assessed standard | Cyber Essentials verified self-assessment |
| Higher assurance | The same five controls have also been tested in practice | Cyber Essentials Plus independent technical testing |
| Ongoing cloud evidence | Microsoft 365 protections are monitored and maintained | A documented Microsoft 365 security standard |
The useful outcome is not a folder of screenshots. It is a small set of controls, owners and records that stay current between requests.
Know which devices, software, users, administrators and cloud services are in scope before trying to describe how they are protected.
Prioritise secure configuration, updates, access control, malware protection and internet boundaries before polishing policies.
Give one person responsibility for keeping answers, supporting records and renewal dates current rather than rebuilding them under deadline pressure.
Each route solves a different part of the evidence problem. Begin with the requirement that is actually blocking the decision in front of you.
Define the likely scope, prepare the environment, close practical gaps and approach independent assessment with confidence.
Plan your certification → Improve everyday resilienceBring devices, accounts, email and data under one maintained security approach instead of responding questionnaire by questionnaire.
Explore managed security → Evidence the cloud standardAround 170 CIS-aligned checks, continuously monitored and improved for managed clients.
See the security standard →You can clarify the requirement and current gaps before committing to a certification project or a larger technology change.
No certification can prove that an organisation is immune from every incident. Cyber Essentials provides independently assessed evidence that five important technical controls are in place to reduce exposure to common internet-based attacks. It is a recognised baseline, not a claim of perfect security.
Confirm the exact requirement, deadline and scope before purchasing an assessment. Then review the current environment against the Cyber Essentials questions and technical requirements, close the gaps and submit when the answers can be supported by evidence.
No. Certification is independently assessed through an IASME-licensed Certification Body. West View IT can help define the likely scope, prepare the environment, resolve practical gaps and support the assessment without pretending to mark its own work.
Both levels cover the same five technical controls. Cyber Essentials combines a self-assessment with independent verification, while Cyber Essentials Plus adds hands-on technical testing by an independent assessor for greater assurance.
Yes. We can carry out a focused readiness review and work with your existing provider to gather evidence or close agreed gaps. If the exercise exposes a wider ownership problem, we will explain that clearly rather than using certification as a pretext for an unnecessary change.
Owen Williams · Managing Director
Book a relaxed 30-minute call with Owen. Bring the questionnaire, tender wording or insurer request and we will help you identify the proof, scope and sensible next step.
01449 798119 · enquiries@westviewit.co.uk