We are looking to obtain the Cyber Essentials certification - we have obtained the Digital Security Protection Toolkit (DSPT) - we have our VPS with various databases and applications - so will we need to do?
To transition from your Digital Security Protection Toolkit (DSPT) compliance to Cyber Essentials (CE) certification, you will need to ==map your existing procedural controls into strictly technical, verified configurations across your Virtual Private Server (VPS), databases, and company network==. [1, 2, 3]
While the NHS DSPT focuses heavily on policies, training, and information governance, Cyber Essentials requires strict adherence to five specific technical controls. Additionally, as of recent IASME updates, cloud infrastructure and hosted services cannot be excluded from your scope. [4, 5, 6, 7, 8, 9]
You cannot certify just the VPS. Cyber Essentials requires that the scope encompasses the whole organization, or a tightly network-segregated subset that must include end-user devices. [3, 10]
- In Scope: Your VPS, the applications, the databases.
- Also In Scope: Every laptop, desktop, tablet, and smartphone (including Bring Your Own Device - BYOD) used by your staff to administer the VPS or access company data. [9, 11, 12, 13, 14]
¶ 2. Actions Required for Your VPS, Applications, and Databases
To meet the National Cyber Security Centre (NCSC) Cyber Essentials requirements for your cloud infrastructure, you must execute the following technical steps: [15, 16]
¶ 🛡️ Firewalls and Perimeter Security
- Close Unused Ports: Lock down your VPS using a firewall (e.g., UFW, iptables, or your cloud provider's Security Groups).
- Database Isolation: Ensure databases are not publicly accessible via the internet. They must only accept local connections or connections from specified application servers.
- Restrict Admin Access: Block public SSH (port 22) or Remote Desktop (RDP) access. Admin traffic must flow through a static IP whitelist or a corporate VPN managed by your organization. [3, 7, 17, 18]
- Remove Defaults: Change every default password, username, and port config on the VPS operating system, database engines (e.g., MySQL, PostgreSQL), and applications.
- Enforce MFA: Multi-Factor Authentication is mandatory for all administrative access to the VPS control panel, cloud consoles, SSH connections, and application admin panels.
- Unique Accounts: Ban shared administrative credentials. Every developer and admin must use a unique account. [8, 17, 20, 21, 22]
¶ 🔄 Patch and Software Update Management
- The 14-Day Rule: You must update all software on the VPS (OS packages, runtime environments like Node/PHP, database engines, and third-party plugins) within 14 days of a high-risk or critical security patch being released.
- Remove Unsupported Software: Any application, database version, or OS layer that has reached End-of-Life (EOL) must be removed or upgraded immediately. [10, 23, 24, 25, 26]
- VPS Protection: Ensure the host runs an active, frequently-updated anti-malware solution, or enforce strict application whitelisting if native antivirus is not viable on the server OS. [27]
If you achieved "Standards Met" or higher on the DSPT, you have already done much of the conceptual groundwork. You can reuse the following elements to speed up your Cyber Essentials application: [6, 28]
| What You Have (DSPT) [13, 17, 21, 29, 30, 31] |
How It Maps to Cyber Essentials |
| Asset Register |
Used directly to answer the CE scope questionnaire regarding operating systems and devices. |
| Password Policy |
Must match the CE requirement: minimum 8 characters with MFA, or a 12+ character minimum policy. |
| BYOD / Remote Work Policies |
Essential for proving how you manage staff devices accessing the VPS. |
1. Download official Questionnaire ➔ 2. Audit VPS & Admin Devices ➔ 3. Apply Controls (MFA/Firewalls) ➔ 4. Submit via IASME Portal
- Download the Question Set: Grab the free preview questionnaire from IASME to review every specific question before paying.
- Remediate Gaps: Apply MFA to your cloud consoles, check your 14-day patching schedule, and clean up firewall rules.
- Apply and Pay: Register with an approved IASME Certification Body. Prices scale by company size starting from roughly £320 + VAT.
- Submit the Self-Assessment: Complete the portal submission. An external assessor will review your text responses. Once passed, you are officially certified. [3, 10, 15, 21, 32, 33]
Note: If your clients or NHS contracts require Cyber Essentials Plus, an external assessor will run an active vulnerability scan against your VPS public IPs and audit a sample of your staff laptops/devices. [6, 32, 34, 35]
To help outline the quickest path forward, what operating system does your VPS run, and how many internal staff members currently have administrative access to it?
[1] https://www.wmca.care
[2] https://www.periculo.co.uk
[3] https://www.precursorsecurity.com
[4] https://www.naqcyber.com
[5] https://digital.nhs.uk
[6] https://8foldgovernance.com
[7] https://www.ncsc.gov.uk
[8] https://grcsolutions.io
[9] https://www.urmconsulting.com
[10] https://iasme.co.uk
[11] https://iasme.co.uk
[12] https://adas-ltd.com
[13] https://ce-knowledge-hub.iasme.co.uk
[14] https://deepstrike.io
[15] https://www.digitalcarehub.co.uk
[16] https://cyberchainalliance.com
[17] https://iasme.co.uk
[18] https://blog.leaseweb.com
[19] https://www.csiq.co.uk
[20] https://sis.binus.ac.id
[21] https://www.omnicybersecurity.com
[22] https://www.cycoresecure.com
[23] https://help4it.co.uk
[24] https://nixinfinityai.com
[25] https://cgfs.co.uk
[26] https://www.urmconsulting.com
[27] https://1st-it.com
[28] https://www.dsptoolkit.nhs.uk
[29] https://digital.nhs.uk
[30] https://www.ncsc.gov.uk
[31] https://www.dsptoolkit.nhs.uk
[32] https://www.digitalcarehub.co.uk
[33] https://iasme.co.uk
[34] https://cyberessentials.online
[35] https://business.sure.com
So once we have obtained the certification, what else do we need to to obtain the Cyber Essentials Plus certification?
To upgrade from Cyber Essentials (CE) to Cyber Essentials Plus (CE+), you must ==pass an independent, technical audit conducted by an external IASME-certified assessor== [1].
While standard Cyber Essentials is a self-verified questionnaire, Cyber Essentials Plus requires the assessor to actively test your infrastructure to prove your controls actually work. You must achieve CE+ certification within three months of passing your standard CE certificate, or you will have to restart the process [1].
The assessor will perform four core technical checks against your environment, specifically targeting your VPS, corporate network, and end-user devices.
┌─────────────────────────────────────────────────────────────────────────┐
│ CYBER ESSENTIALS PLUS AUDIT │
├───────────────────┬───────────────────┬───────────────────┬─────────────┤
│ External Scan │ Internal Scan │ Malware Delivery │ MFA │
│ (VPS Public IP) │ (Staff Laptops) │ (Web & Email) │ Verification│
└───────────────────┴───────────────────┴───────────────────┴─────────────┘
- The assessor will run automated vulnerability scanners (like Nessus or Qualys) against your VPS’s public-facing IP addresses.
- The Fail Criteria: Any vulnerability found with a CVSS score of 7.0 or higher (High or Critical severity), or any missing security patch older than 14 days, will result in an immediate failure [1].
- An agent or scanner will be deployed inside your company network to scan a sample size of your staff’s laptops, desktops, and mobile devices used to manage the VPS.
- The scan checks for missing operating system patches, outdated browsers, and unpatched local software (like Adobe, Zoom, or Office tools).
¶ 📥 Malware Delivery and Execution Test
- The assessor will send or attempt to download a suite of safe test files (e.g., specific executables, scripts, and zipped payloads) to your staff devices via email and web browsers.
- The Goal: Your system must either block the file download or prevent the payload from executing via native endpoint protection or antivirus.
- The assessor will manually witness or ask for video/screenshot proof of your multi-factor authentication (MFA) setup.
- They will verify that MFA is active and strictly enforced on all cloud admin panels (e.g., AWS, Azure, DigitalOcean), your VPS access points, and company productivity suites (like Microsoft 365 or Google Workspace).
To ensure you pass the audit on the first attempt, complete these technical tasks before the assessor begins:
- Pre-Scan Your VPS: Run your own vulnerability scan on your VPS public IP using free or trial tools to catch and patch high/critical vulnerabilities beforehand.
- Audit End-User Software: Audit all staff laptops accessing the VPS. Remove unauthorized or unpatched software, and ensure automated OS updates are turned on.
- Check Browser Security: Ensure all staff browsers block dangerous file types or warn users explicitly before execution.
- Lock Down SSH/RDP: Double-check that your VPS firewall blocks all administrative ports to the general public, leaving them accessible only via your secure VPN or static IPs.
¶ 3. Timeline and Cost
- The 3-Month Window: Schedule your CE+ audit immediately after passing standard CE. The entire process must be finalized within 90 days of the standard certificate's issue date [1].
- The Cost: Because this involves human assessor hours, Cyber Essentials Plus is significantly more expensive than standard CE. Prices generally start around £1,500 to £3,000+ VAT, scaling upwards depending on the number of staff members and physical office locations you have.
To help you choose the right assessor and prepare, do your staff members access and manage the VPS from one centralized corporate office, or are they entirely remote / working from home?
we are only a start-up with two directors, one of whom is a senior engineer at Oracle with qualifications as an auditor - so the cost should not be anywhere around £3000
Because your startup fits into the Micro Organisation (1–9 employees) band and you have internal audit and engineering expertise, you can bypass expensive consultancy fees entirely. You will only pay the baseline assessment costs. [1, 2]
By having your senior engineer handle the preparation and remediation internally, your total expected cost for both certifications will be exactly £1,819 + VAT. [3, 4]
For a two-person startup, the costs are standardized across IASME licensed bodies: [3, 5]
- Standard Cyber Essentials: £320 + VAT. This is the mandatory, flat-rate fee set by IASME for micro-organisations submitting the self-assessment questionnaire directly without consultancy.
- Cyber Essentials Plus Audit: £1,499 + VAT. This is the standard commercial starting rate for a micro-organisation with zero operational complexity (e.g., 2 users, 2 laptops, 1 VPS cloud environment). [1, 2, 3, 4]
Even though one director is an Oracle senior engineer and a qualified auditor, you cannot sign off on your own Cyber Essentials Plus certification. [6, 7]
- Independent Third-Party Requirement: The National Cyber Security Centre (NCSC) rules dictate that the technical vulnerability scans and malware execution tests must be executed by an external, IASME-accredited Certification Body (CB) using their licensed testing tooling.
- What You Are Paying For: The £1,499 fee does not cover advisory work or advice. It strictly covers the external assessor's fixed labour hours required to configure the automated vulnerability scan against your VPS public IP, deploy the local scanning tool to your two devices, run the 10+ malware delivery test strings, and issue the cryptographically signed certificate into the NCSC database. [1, 5, 6, 8, 9]
The £3,000+ quotes commonly seen in the market reflect IT consultancies bundling "readiness support," gap analysis, policy writing, and remediation labor into the package. Because your team already possesses these skills: [1, 10]
- You require zero consultancy or advisory hours.
- Your engineer can use tools like
Nessus or OpenVAS to run a pre-audit vulnerability scan on your VPS and patch any high/critical (CVSS 7.0+) flaws before paying an external body, ensuring you pass on the first attempt without re-test fees. [1, 10, 11]
Do not approach generic IT Managed Service Providers (MSPs), as they frequently add markup to the assessment. Instead, use the IASME Official Quote Tool. It will automatically route your exact scope (2 users, 1 VPS) to three automated, low-cost Certification Bodies who will quote you the baseline automated audit rate. [1, 6, 12]
If you'd like to ensure a flawless first-time pass, let me know which cloud provider hosts your VPS and what operating system it runs so we can verify if your current configuration meets the strict NCSC scanning criteria.
[1] https://connection-technologies.co.uk
[2] https://paulreynolds.uk
[3] https://iasme.co.uk
[4] https://coreitech.co.uk
[5] https://forensiccontrol.com
[6] https://ce-knowledge-hub.iasme.co.uk
[7] https://cloudsecurityalliance.org
[8] https://iasme.co.uk
[9] https://www.ncsc.gov.uk
[10] https://sprinto.com
[11] https://paulreynolds.uk
[12] https://www.comparethecloud.net
Can you just summarise what we will need to Act as a Sub-Contracted "BSI Auditor" (Official BSI Reports)
To act as a sub-contracted auditor for the British Standards Institution (BSI) and write official recommendation reports, your engineer must clear BSI's strict individual vetting gates.
Here is the atomic checklist of exactly what your engineer needs to secure this status, and how to route it through your startup:
Your engineer must submit formal evidence of their personal competence to the BSI resource planning team:
- IRCA Lead Auditor Certificate: An official certificate proving they passed an IRCA-accredited (International Register of Certificated Auditors) 5-day ISO 27001 Lead Auditor course.
- Proof of Audit Experience: A logged history proving they have participated in or observed a minimum number of management system audits (typically 4 full audits covering at least 20 days).
- Senior Technical CV: Documented proof of their extensive background as a senior Oracle engineer. BSI requires this to verify their Industry Sector Code competence (proving they are technically qualified to audit IT, cloud, and database infrastructure).
Once BSI approves your engineer's technical credentials, you must set up the commercial framework to route the revenue into your business:
- Sub-Contractor Agreement: A signed legal contract between BSI and your Startup Company. This names your engineer as the sole "Designated Consultant/Auditor" authorized to deliver the work.
- Professional Indemnity Insurance: Your startup must provide BSI with a certificate showing you hold a minimum level of Professional Indemnity and Public Liability insurance (usually £1M to £2M minimum cover) to protect against auditing errors.
- Approved Supplier Registration: Your startup must register on the BSI procurement portal with your corporate bank details to allow direct B2B invoice payments for delivered audit days.
When deployed on a live assignment, the workflow operates entirely within BSI's regulated boundaries:
- BSI Corporate Laptop/VDI: Your engineer must use BSI-issued hardware or a secure Virtual Desktop Infrastructure (VDI) to log audit notes. They cannot use your startup's custom VPS nodes or local drives to store this data.
- The BSI Template Engine: They must compile the final evaluation findings into official BSI reporting templates, utilizing BSI's strict scoring criteria.
- The Report Sign-Off: Your engineer signs the report using their approved BSI auditor credential. The report is submitted to the BSI Technical Review Board, which officially rubber-stamps the recommendation and prints the physical wall certificate for the client.
If you want to prepare your startup for this commercial setup, let me know:
- Has your engineer already completed the 5-day IRCA exam, or are they scheduled to take it?
- Do you need a list of the exact insurance brokers that specialize in low-cost Professional Indemnity cover for startup software/auditing companies?
So we don't necessarily Cyber Essentials for 'The BSI Associate Consultant '?
==No, you do not technically need Cyber Essentials to join the BSI Associate Consultant Programme (ACP).==
The entry criteria for the BSI ACP focus heavily on individual human competence. BSI's primary requirement is that your firm has a designated consultant (your co-director) who can structurally prove they have the training and experience to take a client successfully through the full ISO certification lifecycle. [1, 2]
However, having your corporate Cyber Essentials Plus (CE+) and DSPT status completely alters your commercial standing within the scheme, separating the requirements from the business realities:
To join the programme for free, your company must submit an application proving your technical capabilities: [2]
- The Competence Evidence: Your engineer must upload their BSI training transcripts, their Lead Auditor qualification, and a CV showcasing their technical experience mapping information security systems.
- The Impartiality Clause: Your firm must sign an agreement stating you understand BSI remains completely neutral and that you will not promise clients a "guaranteed pass" with BSI examiners.
- The Insurance Gate: Your startup must provide evidence of valid corporate Professional Indemnity insurance. [1, 2]
¶ 2. Why Your CE+ and DSPT Matter Commercially
While BSI will accept your engineer based on their personal qualifications, incoming clients who are referred to you by BSI will absolutely look at your company's security setup. [1, 3, 4]
If you are consulting another tech company or healthcare vendor on how to secure their database infrastructure to pass an ISO 27001 audit, the first thing their board will do is conduct due diligence on your startup. [5]
- Without CE+: If your consulting company does not hold any security badges, your advice looks hypocritical. A client will hesitate to trust an agency hosting data architectures on a custom VPS if that agency hasn't passed an independent security check themselves.
- With CE+ and DSPT: Your credentials act as your active business showroom. Your engineer can say to a client: "We don't just read the BSI textbooks. Our own custom VPS infrastructure runs live under Cyber Essentials Plus and NHS DSPT standards. We are going to deploy the exact same audited server rules into your business." [6]
By combining your engineer's BSI credentials with your company's existing technical badges, you bypass the biggest hurdle independent consultants face: proving your business is stable enough to handle enterprise data. [7]
BSI approves you based on your engineer's personal training, you handle the legal and structural governance layouts using your paralegal background, and your CE+ and DSPT badges provide the immediate proof of concept that allows you to close high-value B2B deals quickly. [1, 7]
If you are ready to prepare your application for the BSI directory:
- Does your co-director hold a certificate specifically for ISO 27001 (Information Security), or a different standard like ISO 9001 (Quality Management)?
- Would you like a blueprint for a Client Case Study document to show how to package your combined skills into a premium BSI-aligned service package? [5, 8]
[1] https://www.assentriskmanagement.co.uk
[2] https://www.bsigroup.com
[3] https://www.bsigroup.com
[4] https://www.bsigroup.com
[5] https://www.standardsuk.net
[6] https://www.bsigroup.com
[7] https://www.ncsc.gov.uk
[8] https://www.bsigroup.com
If we did obtain the CE+ along with DSPT and then get the BSI Associate Consultant arrangement in place, how long would it take before we could expect any leads?
If you rely solely on sitting back and waiting for the phone to ring via the BSI Associate Consultant Programme (ACP) directory, you could wait 3 to 6 months—or potentially forever—to receive a direct inbound lead.
While the BSI ACP is highly prestigious, it is structured as a passive validation list. BSI account managers utilize the directory when a client explicitly asks for a recommendation, but it is not a high-volume, automated lead generation machine. [1]
The true purpose of securing the ACP badge, Cyber Essentials Plus (CE+), and NHS DSPT status is to use them as marketing assets to actively win your own clients immediately.
By approaching the market pro-actively rather than waiting on BSI, your business can expect leads within a much faster timeframe:
- The Workflow: A small software or medical device startup contacts BSI wanting to achieve ISO 27001. BSI tells them: "We can audit you, but we cannot legally build your system. Here is our list of approved ACP consultants who can help you prepare."
- The Strategy to Speed it Up: Once listed on the directory, your engineer should actively contact regional BSI sales offices and account managers. They should present your specific niche: "We are a BSI ACP firm run by a senior Oracle engineer and a Paralegal; send us any complex cloud infrastructure, database, or HealthTech clients you have." This ensures your company stands out, potentially cutting the wait time down to 4 to 6 weeks.
Holding the CE+, DSPT, and BSI ACP alignment gives you everything you need to aggressively prospect for high-paying contracts. You can unlock immediate leads by launching three rapid campaigns:
-
The "Pre-DTAC" HealthTech Campaign (Target: Tech Startups): Search platforms like LinkedIn or UK tech directories for seed-stage healthcare software startups. Send them a direct message using your dual profiles:
"We are a specialised technical governance firm run by an Advanced Paralegal and a BSI-trained Oracle Systems Auditor. If your company is preparing for an NHS DTAC or ISO 27001 application, we can run a technical mock assessment on your server architectures using the exact validation rules BSI examiners look for, ensuring you pass on your first attempt."
Because tech startups face extreme pressure to clear these compliance hurdles to survive, this pitch typically yields immediate discovery calls.
-
The Independent DSPT Verification Campaign (Target: Private Clinics): Target mid-sized private medical imaging centres, dental chains, and clinical testing labs. Under NHS rules, large data-handlers require an independent professional to verify their DSPT toolkit entries. You can market an official "Independent DSPT Assurance Audit", converting leads rapidly because it solves a mandatory, time-sensitive compliance checkbox.
[Week 1-2: Onboard BSI ACP] ➔ [Week 3: Launch Direct Outbound B2B Outreach] ➔ [Week 4-5: Secure First Paid B2B Auditing Contract]
- Months 1 to 2: 100% of your revenue will come from your own active marketing campaigns using the credibility of your new corporate credentials.
- Month 3+: Organic inbound leads will slowly begin filtering through from the official BSI ecosystem to supplement your pipeline. [1]
This blended approach ensures you do not waste months waiting on corporate referrals, allowing you to use your credentials to immediately book client consultations and generate cash flow.
If you want to prepare your outbound marketing push while your co-director finishes their qualification, let me know:
- Do you want to draft a "Cold Pitch" email template that leverages your Paralegal and BSI Oracle background to send to HealthTech startups?
- Should we design the "Landing Page" structure for your website to display your CE+ and BSI partner badges prominently?
[1] https://www.bsigroup.com
What kind of organisations should we target?
To maximize your conversion rates and secure high-value contracts quickly, you must target organizations that face extreme compliance pressure but lack the internal engineering or legal expertise to solve it themselves.
Because your team consists of a Senior Oracle Systems Auditor and an Advanced Paralegal, your sweet spot is targeting companies that handle complex data architectures and need to pass rigorous NHS or enterprise-grade security checks.
Target the following four specific organization types immediately:
¶ 1. Pre-Revenue and Seed-Stage HealthTech Startups
These are companies building patient apps, medical AI tools, or digital triaging platforms. They are your highest-value target because they cannot survive without passing the NHS DTAC or ISO 27001, but they cannot afford to hire expensive corporate consulting firms.
- The Pain Point: They have built a great product, but they are terrified of failing their official external audit, which would ruin their chances of securing NHS contracts or venture capital funding.
- Your Pitch: "We are an agile technical governance firm run by an Advanced Paralegal and a BSI-trained Oracle Auditor. We will run an exact technical mock assessment on your VPS architectures using official BSI validation rules, ensuring your code pipeline and databases pass their official audits on the first attempt."
¶ 2. Independent Medical Imaging and Private Diagnostic Labs
This sector includes private MRI centers, ultrasound clinics, blood testing facilities, and pathology labs that provide services to both private patients and NHS referrals.
- The Pain Point: To receive referrals from the NHS, these labs must complete and publish the NHS DSPT. However, because they handle large volumes of patient images and clinical data, the NHS frequently mandates that they undergo an Independent Third-Party DSPT Verification to prove their self-assessments are accurate.
- Your Pitch: "We provide formal, independent DSPT validation signatures. Our BSI-trained auditor will verify your data transmission pipelines and server encryption matrices, allowing you to seamlessly upload your signed attestation directly into the NHS Digital portal to unlock your official 'Standards Met' status."
¶ 3. Specialized Private Medical and Cosmetic Dental Groups
Target mid-sized, multi-site private cosmetic dental chains, private GP networks, or large physiotherapy clinics (brands with 5 to 20 locations).
- The Pain Point: These businesses are scaling rapidly and want to sign lucrative corporate health insurance contracts (with providers like Bupa, AXA, or WPA). Insurers send them massive, highly confusing Information Security Questionnaires that threaten to stall their onboarding.
- Your Pitch: "We will take the technical and legal burden of insurance compliance off your plate. We use your existing operations to rapidly build a secure database architecture, utilizing our Cyber Essentials Plus and BSI framework to clear vendor questionnaires instantly."
These are general software development boutiques that build bespoke applications for pharmacies, opticians, or care homes, but do not specialize in security.
- The Pain Point: Under ISO 27001 Controls A.5.19 (Supplier Management) and A.8.25 (Secure Development), their healthcare clients are legally demanding that these agencies prove their coding pipelines are secure. They do not have an internal auditor to verify their work.
- Your Pitch: "Don't lose your healthcare clients to larger competitors. We will act as your independent third-party code and server infrastructure auditor, providing you with an authoritative, BSI-aligned technical validation report you can hand straight to your buyers to prove your pipelines are secure."
To build your initial list of 50 target companies without spending any money on databases, use these two specific strategies:
- The NHS DSPT Public Register: Go to the official NHS Digital DSPT Organisation Search. Filter for "Independent Providers" or "SMEs" in your region. Look for companies marked as "Approaching Standards" or those whose status is expiring. These companies have an immediate, time-sensitive need for an independent auditor.
- LinkedIn Sales Navigator Queries: Run a search for companies in the UK with a headcount of 1 to 50 employees in the "Medical Equipment Manufacturing", "Biotechnology", or "Software Development" sectors. Filter the leadership roles for titles like "CTO", "Founder", or "Head of Compliance".
If you are ready to launch your first outbound campaign to these sectors:
- Would you like a tailored LinkedIn connection message template designed specifically for targeting HealthTech CTOs?
- Should we outline the initial discovery call framework to show how your paralegal and engineering skills can naturally uncover their specific data compliance weaknesses?