11th August 2026
TwentyFour Becomes an Official Cyber Essentials & Cyber Essentials Plus Certification Body
TwentyFour IT Services is proud to announce that we are now an official Cyber Essentials and Cyber Essentials Plus Certification Body.
Licensed and Assured by IASME, the National Cyber Security Centre’s official delivery partner for the Cyber Essentials scheme, TwentyFour can now officially assess businesses and issue Cyber Essentials and Cyber Essentials Plus certifications directly.
Alignment with the Cyber Essentials certification scheme is something that sits at the heart of everything we do here at TwentyFour. Our core Cyber Security offering ensures that every client has the tools and processes in place to achieve Cyber Essentials should they choose to.
Until now, we have been able to support businesses throughout the UK to achieve Cyber Essentials and Cyber Essentials Plus, supporting them to put the tools and processes in place, supporting them with documentation and audit requirements, however we have worked with external third parties for the certification process. However, we did not want to just be the “Joe Bloggs down the street who can help you achieve Cyber Essentials”, our commitment is to be able to support businesses throughout the entire process.
This important milestone means businesses can access practical cyber security guidance, technical preparation, assessment and certification, end to end through one trusted technology partner.
Over the past 12 months, we have seen a significant shift in the industry where more businesses are being asked to provide assurance of their cyber security practices as part of tender processes.
What does becoming a Cyber Essentials Certification Body mean?
Cyber Essentials Certification Bodies are specially trained cyber security companies licensed and assured by IASME to assess businesses against the requirements of the Cyber Essentials scheme.
Cyber Essentials Plus Assessors must also hold the additional qualifications required to complete the technical audit stage of the certification process
Becoming a Certification Body enables TwentyFour to support businesses throughout the entire certification process, from understanding the scope and identifying technical gaps to completing the assessment and issuing certification.
This strengthens our ability to provide businesses with a clear, structured and practical route towards better cyber security, enabling them to demonstrate to their clients and partners that they take their cyber and data security processes seriously.
What is Cyber Essentials?
Cyber Essentials is a UK Government-backed cyber security certification scheme developed by the National Cyber Security Centre.
It is recommended by the NCSC as the minimum cyber security standard for businesses of every size and is designed to protect businesses from the most common internet-based cyber threats.
Cyber Essentials focuses on five essential technical controls:
- Firewalls
- Secure configuration
- Security update management
- User access control
- Malware protection
Together, these controls help businesses reduce common weaknesses such as unsupported software, missing security updates, excessive administrative access, insecure devices and insufficient protection from malware and ransomware.
Cyber Essentials is completed through a verified self-led or supported questionnaire with an authorised Cyber Essentials Assessor. An authorised senior representative from the business must confirm that the information supplied is accurate and that the required controls are in place.
Once all requirements have been met, the business receives a Cyber Essentials certificate that is valid for 12 months.
What is Cyber Essentials Plus?
Cyber Essentials Plus (the highest level of certification available through the Cyber Essentials scheme) covers the same five technical controls as Cyber Essentials but provides a greater level of assurance through independent technical testing and auditing.
Rather than relying solely on the verified self-assessment, a qualified Cyber Essentials Plus Assessor tests a representative sample of the business’s devices and systems. This can include vulnerability scans, security update checks, malware protection testing, multi-factor authentication checks and verification that the controls described within the assessment have been implemented correctly.
Cyber Essentials Plus can be particularly valuable for businesses that handle sensitive information, work within regulated industries, work with government bodies, or need to demonstrate a higher level of cyber assurance to customers and supply chain partners.
Why should businesses achieve Cyber Essentials certification?
Cyber Essentials does more than provide a logo for your website and tick a box for your business insurance. It gives your business a recognised security baseline and demonstrates to clients, stakeholder and prospective customers that fundamental cyber security controls are being managed properly.
The UK Government’s Cyber Security Breaches Survey 2025/26 found that 43% of UK businesses had identified a cyber security breach or attack during the previous 12 months.
Government data also states that businesses with Cyber Essentials are 92% less likely to make a claim on their cyber insurance than businesses without the certification. During the 12 months between April 2025 and March 2026, 59,090 Cyber Essentials and Cyber Essentials Plus certificates were awarded.
Certification can also help businesses:
- Build confidence with customers and stakeholders.
- Demonstrate a clear commitment to cyber security.
- Meet requirements within customer and supplier contracts.
- Access opportunities where Cyber Essentials is required as part of a tender.
- Improve visibility over devices, software, users and security responsibilities.
- Provide a stronger foundation for wider compliance frameworks and cyber security strategies.
Cyber Essentials is increasingly being used by businesses to assess security throughout their supply chains, giving customers greater confidence that suppliers have implemented appropriate baseline protections, and is commonly being asked for as part of tender processes.
How can TwentyFour help your business achieve Cyber Essentials?
Our in-depth assessment of cyber security tools and process can highlight gaps that were not previously visible by internal teams or third-party providers.
Unsupported software, inconsistent patching, unmanaged devices, excessive permissions, lack of account security controls and unclear cloud security responsibilities can all affect a business’s ability to achieve certification.
TwentyFour can help you understand the assessment scope, review your existing environment and identify any areas that need to be addressed.
Our team can then provide practical support to implement the necessary security and process improvements throughout your business. Depending on your environment, this could include updating or replacing unsupported systems, strengthening user access controls, enabling multi-factor authentication, improving endpoint protection, reviewing firewall configurations, formalising security update management and more.
Once your business is ready, our qualified Assessors can complete the relevant Cyber Essentials or Cyber Essentials Plus assessment and guide you through the formal certification and audit process.
This provides a clearer journey towards certification, supported by people who already understand how technology, security and compliance need to work together because we do it ourselves.
Maintaining Cyber Essentials through Compliance Management
Achieving certification should not be treated as a tick box exercise.
Technology environments change throughout the year. People join, people leave, devices are replaced, software reaches the end of support, cloud services are introduced and new vulnerabilities are discovered. Without ongoing management, a business can gradually move away from the controls it had in place when they achieved certification and come renewal or audit, they may no longer be compliant.
Compliance with Cyber Essentials must be constantly reviewed to ensure you stay compliant come recertification. This is especially important as the current assessment requirements also reinforces that businesses are responsible for maintaining compliance with the Cyber Essentials controls throughout the certification period.
TwentyFour’s Compliance Management service helps businesses manage this as an ongoing process rather than a last-minute renewal project.
Through regular reviews, technology management, patch management, security reporting, policy guidance, active security monitoring and strategic support, we can help ensure the controls remain active and effective throughout the year.
This can include maintaining an accurate asset register, monitoring software support dates, reviewing administrative access, managing security updates, checking multi-factor authentication, gathering evidence and preparing for annual recertification.
By combining certification with ongoing Compliance Management, businesses can remain better protected, better prepared and ready to demonstrate their security posture when customers, insurers or supply chain partners ask for evidence.
A more straightforward route to cyber security certification
Becoming an official IASME Accredited Cyber Essentials and Cyber Essentials Plus Certification Body is an important next step for TwentyFour. Allowing us to provide a more complete compliance journey, helping businesses understand what is required, strengthen their cyber security, achieve recognised certification and maintain the necessary controls throughout the year.
Whether your business is working towards its first Cyber Essentials certificate, preparing for Cyber Essentials Plus or approaching its annual renewal, TwentyFour can ensure you gain and maintain certification with confidence.
Reach out today to the TwentyFour team to discuss how your business could benefit from becoming Cyber Essentials and/or Cyber Essentials Plus certified.
Enquire HereRecent Insights



