Choosing the Right Cyber Essentials Certification Provider
An objective buyer's guide to picking a Cyber Essentials provider in the UK – 10 criteria that decide whether you pass first time, on time and on budget.
Last reviewed: July 2026 · Written by Harpal Bilan, IASME-licensed Cyber Essentials & Cyber Assurance assessor at NixInfinity-AI.
10 objective criteria to judge any provider
Most "best provider" lists are pay-to-play. Use these 10 criteria to judge any Cyber Essentials provider – ourselves included. Each one has a measurable answer.
IASME-licensed Certification Body
Not a reseller. A CB reviews and issues certificates directly – no handoff to a third party, no timeline blackout.
Named UK assessor
You know who is reviewing your submission and can speak to them. Not an offshore call-centre queue.
Pre-submission check included
The assessor reviews your answers before you formally submit, so avoidable failures never get logged against your account.
Structured remediation guidance
Written, prioritised guidance when a control is not yet in place – not a generic pass/fail email.
Clear retest arrangements
You know in advance what happens if a technical test fails on CE+ – rescope, retest window, and any additional cost.
Realistic turnaround
Standard 5–10 working days; genuine fast-track for tender deadlines without cutting corners on evidence review.
CE+ testing arrangements
Remote vs on-site testing options, vulnerability scanning covered, sampling method explained in writing.
Transparent pricing
IASME-aligned tier price stated up front. No surprise add-ons for pre-check, retests or scoping calls.
Communication and support
A named point of contact, agreed response times, and support that survives your assessor being on leave.
What happens if you fail
A written policy for unsuccessful assessments: no repeat IASME fee inside the current cycle, structured resubmission.
Certification Body vs reseller: the difference
IASME licenses a fixed number of Certification Bodies in the UK. Only those bodies can review submissions and issue certificates. Everyone else who sells "Cyber Essentials" is a reseller – they take your money, fill out paperwork on your behalf, and forward the submission to a Certification Body. That handoff typically adds 3–5 working days to your timeline, removes the named-assessor relationship, and makes pre-check harder because the reseller cannot see the assessor's review.
Verify any provider on the official IASME directory before you buy.
How NixInfinity-AI meets each criterion
Applying the same 10 criteria to ourselves, honestly:
- IASME-licensed Certification Body: yes – verifiable on the IASME directory. We review and issue certificates directly.
- Named UK assessor: Harpal Bilan or Emma Wharram – both IASME-licensed Cyber Essentials and Cyber Assurance assessors. See the team.
- Pre-submission check: included on every engagement at no extra cost.
- Structured remediation guidance: written, prioritised, control-by-control – not a pass/fail email.
- Retest arrangements: stated in the engagement letter before you commit.
- Realistic turnaround: 5–10 working days standard; genuine 24-hour fast-track for tender deadlines – see fast certification.
- CE+ testing: remote testing by default, on-site available; sampling method and vulnerability-scanning approach documented up front. See Cyber Essentials Plus.
- Transparent pricing: IASME-aligned £320 + VAT with no add-ons for pre-check or scoping – see pricing.
- Communication and support: named point of contact with a stated response SLA; cover during leave.
- If you don't pass first time: no repeat IASME fee inside the current cycle; structured resubmission plan.
We are a small, focused Certification Body – ideal for SMEs and mid-market organisations, tender deadlines, renewals and sector-specific work (IFAs, law firms, schools, G-Cloud suppliers). Less ideal for very large enterprises already running an in-house ISO 27001 programme who want a Big-Four audit relationship.
