Skip to main content
    NixInfinity-AI
    Provider Buyer's Guide

    Choosing the Right Cyber Essentials Certification Provider

    An objective buyer's guide to picking a Cyber Essentials provider in the UK – 10 criteria that decide whether you pass first time, on time and on budget.

    Last reviewed: July 2026 · Written by Harpal Bilan, IASME-licensed Cyber Essentials & Cyber Assurance assessor at NixInfinity-AI.

    10 objective criteria to judge any provider

    Most "best provider" lists are pay-to-play. Use these 10 criteria to judge any Cyber Essentials provider – ourselves included. Each one has a measurable answer.

    IASME-licensed Certification Body

    Not a reseller. A CB reviews and issues certificates directly – no handoff to a third party, no timeline blackout.

    Named UK assessor

    You know who is reviewing your submission and can speak to them. Not an offshore call-centre queue.

    Pre-submission check included

    The assessor reviews your answers before you formally submit, so avoidable failures never get logged against your account.

    Structured remediation guidance

    Written, prioritised guidance when a control is not yet in place – not a generic pass/fail email.

    Clear retest arrangements

    You know in advance what happens if a technical test fails on CE+ – rescope, retest window, and any additional cost.

    Realistic turnaround

    Standard 5–10 working days; genuine fast-track for tender deadlines without cutting corners on evidence review.

    CE+ testing arrangements

    Remote vs on-site testing options, vulnerability scanning covered, sampling method explained in writing.

    Transparent pricing

    IASME-aligned tier price stated up front. No surprise add-ons for pre-check, retests or scoping calls.

    Communication and support

    A named point of contact, agreed response times, and support that survives your assessor being on leave.

    What happens if you fail

    A written policy for unsuccessful assessments: no repeat IASME fee inside the current cycle, structured resubmission.

    Certification Body vs reseller: the difference

    IASME licenses a fixed number of Certification Bodies in the UK. Only those bodies can review submissions and issue certificates. Everyone else who sells "Cyber Essentials" is a reseller – they take your money, fill out paperwork on your behalf, and forward the submission to a Certification Body. That handoff typically adds 3–5 working days to your timeline, removes the named-assessor relationship, and makes pre-check harder because the reseller cannot see the assessor's review.

    Verify any provider on the official IASME directory before you buy.

    How NixInfinity-AI meets each criterion

    Applying the same 10 criteria to ourselves, honestly:

    • IASME-licensed Certification Body: yes – verifiable on the IASME directory. We review and issue certificates directly.
    • Named UK assessor: Harpal Bilan or Emma Wharram – both IASME-licensed Cyber Essentials and Cyber Assurance assessors. See the team.
    • Pre-submission check: included on every engagement at no extra cost.
    • Structured remediation guidance: written, prioritised, control-by-control – not a pass/fail email.
    • Retest arrangements: stated in the engagement letter before you commit.
    • Realistic turnaround: 5–10 working days standard; genuine 24-hour fast-track for tender deadlines – see fast certification.
    • CE+ testing: remote testing by default, on-site available; sampling method and vulnerability-scanning approach documented up front. See Cyber Essentials Plus.
    • Transparent pricing: IASME-aligned £320 + VAT with no add-ons for pre-check or scoping – see pricing.
    • Communication and support: named point of contact with a stated response SLA; cover during leave.
    • If you don't pass first time: no repeat IASME fee inside the current cycle; structured resubmission plan.

    We are a small, focused Certification Body – ideal for SMEs and mid-market organisations, tender deadlines, renewals and sector-specific work (IFAs, law firms, schools, G-Cloud suppliers). Less ideal for very large enterprises already running an in-house ISO 27001 programme who want a Big-Four audit relationship.

    Compare us to your shortlist

    Book a 30-minute call. We will tell you honestly whether we are right for your situation – or recommend who is.

    Frequently Asked Questions

    Related Cyber Essentials Guides