top of page
Frequently Asked Questions
Any questions about our company or Cyber Essentials?
You've come to the right place!
FAQ
IASME Cyber Assurance is a UK cyber security and governance standard, formerly known as IASME Governance. It assesses technical, organisational, user and management controls, and is available at two levels: Level 1, a verified self-assessment, and Level 2, an independent audit.
No. Cyber Assurance is a UK-developed, risk-based standard certified through IASME, designed to be an affordable and accessible alternative to ISO 27001. ISO 27001 is the international standard, awarded by an international certification body. Cyber Assurance Level 2 covers comparable ground and is often accepted where ISO 27001 would once have been required.
Yes. You need a valid Cyber Essentials certificate in place throughout your Cyber Assurance certification. Cyber Essentials covers the core technical controls, and Cyber Assurance builds the wider governance and resilience controls on top. If you are not certified yet, we can take you through both.
Level 1 is a verified self-assessment: you answer a set of questions that an independent assessor then reviews. Level 2 is a full independent audit, where an assessor interviews staff, reviews evidence and confirms your controls work in practice. You must hold Level 1 before moving to Level 2.
Certification runs on an annual cycle, so you renew to stay certified and current with the standard. We will give you plenty of notice ahead of renewal so there is no gap in your certification.
The cost depends on the level you need and the size and scope of your organisation. Get in touch and we will give you a clear quote with no surprises.
It suits small and medium organisations that want to show customers, partners and supply chains that they take information security and resilience seriously, without the cost and complexity of a full ISO 27001 programme.
Yes. Cyber Assurance Level 2 is a strong foundation for ISO 27001, and we can prepare you for it and work with our partners to take you through to certification.
ISO 27001 is the international standard for an Information Security Management System (ISMS). Its current version is ISO/IEC 27001:2022. It provides a risk-based framework for protecting the confidentiality, integrity and availability of information, backed by a set of controls in Annex A.
ISO 27001 is the international standard, awarded by an accredited international certification body. IASME Cyber Assurance is UK-developed and certified through IASME, and is designed as a more affordable, right-sized route for small and medium organisations. Cyber Assurance Level 2 is a strong stepping stone towards ISO 27001.
Regola certifies Cyber Essentials and Cyber Assurance directly as an IASME certification body. For ISO 27001, we prepare you for the audit and work with our trusted partners, who carry out the certification itself.
It depends on your needs. Many small and medium organisations find IASME Cyber Assurance more proportionate and cost-effective. ISO 27001 tends to be worth it when a customer, contract or framework specifically requires it, or when you operate internationally.
ISO/IEC 27001:2022 is the current version. It replaced the 2013 version, and the transition period for organisations moving from the older version closed at the end of October 2025.
Cyber Essentials starts from £320+VAT for micro organisations, with pricing increasing for larger businesses based on the IASME tier structure. Regola can give you a clear quote once we understand the size and scope of your business.
For a well-prepared business, the questionnaire itself can be completed in a few days, with assessment typically returned within a few working days of submission. If corrections are needed, total time depends on how quickly the business can address feedback. Most clients are certified within two to four weeks of starting.
Yes. Cyber Essentials was specifically designed to be accessible to small and medium-sized businesses. It covers the protections most attacks rely on getting past, and for many SMEs it's also a requirement for public sector tenders, supplier onboarding, or cyber insurance.
Cyber Essentials is a self-assessment, reviewed and certified by a licensed Certification Body. Cyber Essentials Plus adds a hands-on technical audit of your systems using NCSC-approved tools, verifying that the controls you've declared are actually in place. CE+ is required for some contracts and gives stronger assurance.
No. We're based in Torquay and work with businesses across Devon and the South West face to face, but we also support clients across the UK remotely. The IASME portal and assessment process work the same way wherever you're based.
Certification is valid for 12 months. After that you'll need to renew to stay listed in the IASME directory, keep your blockmark badge active, and maintain your cyber liability insurance cover.
If your assessment is referred back, you will receive comprehensive feedback and access to help from a real person. You then have a 48-hour period to make corrections and pass at no additional charge. If you do not implement the necessary changes fairly promptly, you will fail Cyber Essentials and be required to purchase a new assessment.
Standard Cyber Essentials is a verified self-assessment: you answer questions about your security controls, a qualified assessor reviews them, and a certificate is issued if you meet the requirements.
Cyber Essentials Plus adds an independent technical audit. An assessor uses NCSC-approved tools to verify that the controls you declared are actually working on your live systems. The technical requirements are the same; the level of assurance is higher.
Yes. You must hold a valid Cyber Essentials certificate before the CE+ audit can begin. The CE+ assessment must be completed within three months of that certificate being issued. If your CE certificate has expired or is more than three months old, you will need to renew it before proceeding with CE+.
In practice, yes. You can prepare for both simultaneously, and some organisations run the questionnaire and the CE+ audit back to back in quick succession. The CE questionnaire must be submitted and approved before the technical audit begins, but with good preparation these can follow on closely.
For a well-prepared organisation that already holds basic Cyber Essentials, the Cyber Essentials Plus pathway typically takes six to eight weeks. If there are significant issues to remediate following the audit, it can take longer.
The audit covers servers, desktop computers, laptops, thin clients, tablets and mobile phones. To make sure a full sample is taken, each type of operating system is required to be tested. The scope must match your Cyber Essentials certificate.
If the audit finds issues, you receive detailed feedback and have an opportunity to remediate. For update management failures in particular, the assessor will retest not just the original failing devices but an additional random sample. A second failure on retest will result in the CE+ not being awarded.
Yes. The audit can be conducted entirely remotely using screen sharing and remote scanning tools, or in person if you prefer. Regola can accommodate both for clients across Devon, the South West, and the wider UK.
It depends on what you need it for. If you are tendering for government contracts that specify CE+, or if clients in regulated sectors are asking for independently verified security assurance, then yes, it is essential.
If you mainly need Cyber Essentials for supplier onboarding or general credibility, the standard certification may be sufficient. We are happy to help you work out which level is right for your situation.
Contact Regola with a brief overview of your network (number of devices, operating systems, whether the audit would be remote or on-site) and we will come back to you with a clear, itemised quote. There is no obligation.
The primary difference is in the level of testing your company undergoes.
Cyber Essentials: This is a self-assessment questionnaire that is verified by a qualified professional (like us). It shows you have the right processes in place.
Cyber Essentials Plus: This includes the self-assessment, but also involves an independent external and internal vulnerability scan of your systems by a certifying body. It proves that your security controls are actually working in practice.
The cyber threat landscape changes daily. Cyber Essentials ensures you aren't relying on "luck" to keep you safe. It provides a formal, audited framework that drastically reduces your vulnerability to automated attacks, which constantly scans the internet for weak spots.
Absolutely. In fact, it is often small businesses that are targeted by cyber criminals because they typically lack the necessary defences. Don't let this be you!
Of course! This is where we provide the most value. Our entire service is designed to be an easy experience for companies without dedicated IT staff. We translate the technical jargon into plain English, guide you through the questionnaire, and help you implement the fixes. You don't need to be a tech expert; you just need to know how your business runs.
Yes. If you fail the assessment, you will be provided feedback and be allowed to make corrections over a 48 hour period, in which you can pass the assessment without any additional charge.
However, if you fail to implement the necessary changes during this time, you will fail and have to purchase a new assessment.
No. A Cyber Essentials Certificate is valid for 12 months, before it must be renewed.
The timeline varies depending on your readiness. For a business that is well-prepared and cyber aware, or even has dedicated staff, the process from initial guidance to receiving your certificate can be as quick as 1-2 weeks.
For those starting from scratch, we recommend allowing 1-3 months to work through the guidance, implement necessary changes, and complete the assessment without feeling rushed.
No. The requirement is that you have a malware protection solution that is "appropriate and effective." This could be the built-in solution like Microsoft Defender (which is perfectly acceptable when properly configured), or any other commercial solution.
IASME is the National Cyber Security Centre's (NCSC) partner responsible for managing the Cyber Essentials scheme. They oversee all Certification Bodies like Regola. Our association with IASME means we have been vetted and approved by the governing body of the scheme, ensuring our assessments are conducted to the highest standard.
Yes, though indirectly. While Cyber Essentials is not a GDPR compliance scheme, it directly supports it. The five technical controls you need to implement for Cyber Essentials are fundamental to keeping personal data secure.
If you ever faced an ICO investigation, being able to demonstrate you have these controls in place (via certification) would be a very strong point in your favour.
Yes, this is a significant benefit of becoming certified. With this certification, free cyber insurance is provided for up to £25000, for organisations with under £20 million turnover.
The certification assessment is designed to be very affordable for small to medium businesses. The price varies depending on the size of the company, with the micro-business assessment being £320 plus VAT.
Absolutely! Many of your clients (especially if they are other businesses), will see your Cyber Essentials Certification as proof that you can be trusted with their data, and that your company is resilient.
Many businesses are increasingly hesitant to partner with companies that do not appear to have strong security controls in place.
Yes. There is a 24 hour incident response helpline operated by experts, provided by IASME. This is included with Cyber Essentials for free.
Yes. While we are based in Devon, we offer our support to businesses across the UK.
Get Started Today
Protect your business and gain a competitive edge over market rivals with a Cyber Security certification. Why wait?
bottom of page
