80%
fewer cyber-insurance claims — NCSC reporting based on 2022 insurer data found 80% fewer claims among organisations with Cyber Essentials than organisations holding the same policy without certification.
Protect your organisation against common cyber threats, meet customer and supply-chain requirements, and demonstrate your commitment to cyber security through the UK Government-backed Cyber Essentials scheme.
Ultralink supports healthcare and pharmaceutical organisations from Cyber Essentials readiness assessment and remediation through to Cyber Essentials or Cyber Essentials Plus certification.
80%
fewer cyber-insurance claims — NCSC reporting based on 2022 insurer data found 80% fewer claims among organisations with Cyber Essentials than organisations holding the same policy without certification.
82%
trust the technical controls — 82% of surveyed scheme users were confident that Cyber Essentials technical controls provide protection against common cyber threats.
61%
prefer certified suppliers — 61% of Cyber Essentials users said they were more likely to choose suppliers with Cyber Essentials certification.
Source: UK Government Cyber Essentials Impact Evaluation
Cyber Essentials and Cyber Essentials Plus assess the same five technical control areas. The main difference is how the implementation of those controls is verified.
| Comparison point | Cyber Essentials | Cyber Essentials Plus |
|---|---|---|
| Assessment method | Verified self-assessment | Independent technical testing |
| Controls covered | Five technical control areas | The same five control areas |
| Level of assurance | Assessor reviews your declared implementation | Technical tests verify implementation |
| Suitable for | Baseline cyber-security assurance | Contracts or buyers requiring greater assurance |
| Validity | 12 months | 12 months |
| Pricing | Tiered according to organisation size | Based on the size and complexity of the technical environment |
Cyber Essentials may be sufficient when you need to demonstrate that essential protections are in place. Cyber Essentials Plus may be more appropriate when a contract, customer, tender or internal risk requirement calls for independently tested controls. Ultralink can review your requirements, proposed certification scope and technical environment before recommending the appropriate route.
A Cyber Essentials readiness assessment identifies issues that could lead to delays, additional work or an unsuccessful assessment. We review your proposed scope and current security arrangements across the five Cyber Essentials technical control areas.
We check how internet-connected devices and networks are protected, including firewall configuration, administrative access and exposure to external services.
We review devices, operating systems, applications and cloud services for unnecessary accounts, insecure settings, default credentials and avoidable functionality.
We assess whether in-scope operating systems, applications, firmware and network devices remain supported and receive required security updates within the scheme’s timescales.
We examine how user and administrator access is granted, protected and removed, including account privileges, password controls and multi-factor authentication.
We review the controls used to prevent malicious software from running, including endpoint protection, application controls and restrictions on untrusted applications.
The review is focused on Cyber Essentials requirements. Wider security improvements can be identified separately without confusing them with the actions required for certification.
Under the requirements applying to assessment accounts created after 27 April 2026, multi-factor authentication must be used for access to cloud services wherever the service provides it. Missing required MFA and failures involving important security-update requirements can result in an unsuccessful assessment.
Ultralink identifies these issues before application so your team knows what must be addressed and what can be treated as a wider security recommendation.
We discuss why you need certification, your deadline and whether Cyber Essentials or Cyber Essentials Plus is likely to be appropriate.
We identify the users, devices, networks, cloud services and locations that may form part of the assessment.
Our team reviews your current controls against the applicable Cyber Essentials requirements and identifies potential blockers.
Your internal team, existing IT provider or Ultralink addresses the agreed technical gaps before application.
We help organise the required information and prepare your organisation for submission or Cyber Essentials Plus testing.
A successful assessment depends on whether the required controls are working across your actual environment—not simply whether each question has been answered.
Readiness support based on current Cyber Essentials requirements
Experience across healthcare, pharmaceutical and MedTech environments
Practical Microsoft 365, cloud and cyber-security capability
Clear separation between mandatory and recommended actions
Remediation support where technical changes are required
Collaboration with your internal team or existing IT provider
Guidance from initial scoping through to assessment preparation
Our focus is to give your organisation a clear and manageable route towards certification.
The cost of becoming certified depends on more than the official assessment fee. Your total requirement may include readiness assessment, remediation and the formal certification process.
Following an initial discussion, Ultralink can provide a scoped quotation for the readiness and remediation support you require.
The cost of the official assessment or Cyber Essentials Plus audit is determined separately by the authorised Certification Body.
Timescales depend on your current controls, certification scope, availability of technical information and the amount of remediation required.
An organisation with a well-managed environment may be able to prepare relatively quickly. Where unsupported systems, missing MFA, unresolved updates or multiple IT providers are involved, additional time may be required.
If certification is connected to a tender, contract or renewal deadline, contact us as early as possible so we can assess whether the required timescale is realistic.
Whether you are applying for the first time, renewing your certificate or preparing for Cyber Essentials Plus, Ultralink can help you establish the right starting point. We will help you confirm the certification level and scope, identify potential blockers and understand the likely remediation, cost and delivery requirements.
A Cyber Essentials readiness assessment reviews your proposed certification scope and current technical controls before you formally apply. It identifies potential blockers and provides recommended remediation actions.
Ultralink provides Cyber Essentials readiness assessment, remediation and application support. The formal assessment and certificate must be provided by an authorised Cyber Essentials Certification Body.
Cyber Essentials uses a verified self-assessment. Cyber Essentials Plus includes independent technical testing of your systems and requires Cyber Essentials to be completed first. The right level may depend on your customer, tender, contract or internal security requirements.
Yes. We can review identified concerns, help resolve technical gaps and support your team in preparing accurate information. Available options may depend on the stage and deadline of your existing assessment.
Cyber Essentials may be required or valued within certain NHS, public-sector and healthcare supply chains. However, the precise requirement depends on the relevant contract or procurement framework. It does not automatically replace the NHS DSP Toolkit, UK GDPR obligations or other required security standards.
You do not need to proceed directly to formal assessment. We can prioritise the gaps, help complete the necessary remediation and recommend applying once the relevant controls and evidence are in place.
Cyber Essentials and Cyber Essentials Plus certifications are valid for 12 months. Organisations must renew annually to maintain valid certification.
Confirm the certification level and scope, identify potential blockers and understand the likely remediation, cost and delivery requirements.