Case Study
Case Study: Cyber Essentials for a 5-Day Tender Deadline
Published 30 April 2026
The brief
A B2B SaaS company bidding on an NHS Digital framework lot. The PQQ required Cyber Essentials (not Plus) plus a Data Security and Protection Toolkit reference. The timeline was 5 working days.
The starting position
- 35 staff – mix of full-time and contractors
- Microsoft 365, Azure DevOps, AWS production environment
- 4 contractor laptops on Windows 10 (out of mainstream support)
- MFA enforced on admins only – not on all users
- Legacy SMTP authentication still permitted
- BYOD policy informal – no MDM
What we did across 5 days
- Day 1 – Readiness call. Identified the four blockers above. Agreed a fix plan with the client's IT lead.
- Day 2 – Contractor laptops upgraded to Windows 11. MFA Conditional Access policy extended to all users with a 24-hour enrolment window.
- Day 3 – Legacy SMTP, IMAP and POP disabled at tenant level. BYOD policy formalised in writing. Intune compliance policy applied to mobile devices.
- Day 4 – SAQ completed in a 3-hour working session. Pre-submission review. Submitted to IASME at 4pm. Certificate issued by us at 6pm.
- Day 5 – Bid submitted with the certificate number embedded in the PQQ.
The outcome
- Certificate issued day 4
- Bid submitted day 5, awarded day 7
- Contract value £450k over 24 months
- Cost: £510 + VAT (10–49 staff tier, all-inclusive)
- Now on a renewal retainer with CE Plus planned for year 2
Why this worked
A clear plan on day 1 and a single technical contact who could action changes the same day. As the IASME-licensed Certification Body, we issued the certificate ourselves immediately after review – no third-party queue.
