Start looking into Cyber Essentials and three names turn up: the NCSC, IASME, and whichever certification body is trying to sell you a certificate. It is rarely explained who does what, which makes it hard to know whether you are buying the real thing or somebody's own scheme.
The structure is simple once someone lays it out.
The three layers
The NCSC owns the scheme. The National Cyber Security Centre is part of GCHQ. It defines the five controls and what "passing" means. It does not certify anybody, and you cannot buy anything from it.
IASME delivers it. The IASME Consortium is the NCSC's Cyber Essentials Partner — the sole organisation appointed to run the scheme on the NCSC's behalf. IASME sets the assessment fees, maintains the questionnaire, and licenses the companies that carry out assessments.
Certification bodies do the assessing. These are independent companies licensed by IASME. They review your submission, decide whether you pass, and issue the certificate. This is who you actually buy from.
So the chain is: NCSC defines it → IASME runs it → a certification body certifies you.
What this means in practice
Every licensed certification body issues the same certificate. There is no premium version. A certificate from a small assessor and one from a large consultancy are identical, carry the same government backing, and are equally valid to whoever asked you for it.
That is worth internalising, because prices vary widely for something that does not vary at all.
So what are you choosing between?
If the certificate is the same, the choice is about service. Four things genuinely differ:
- Resubmission policy. The big one. If your submission fails, does the body let you correct and resubmit within a window, or do you pay again? This is where a cheap certificate quietly becomes an expensive one.
- Turnaround. Some review in a day or two, others in a fortnight. Matters if a contract deadline prompted this.
- How much help you get. Some hand you the questionnaire and wait. Others will tell you when an answer looks wrong before it becomes a failure.
- Whether they can do Plus. Not every body is licensed for Cyber Essentials Plus. If Plus is likely later, using one body for both saves repeating the exercise.
How to check a body is genuinely licensed
Anyone can claim to "help with Cyber Essentials". Only licensed bodies can certify.
- Check they appear on IASME's own list of certification bodies. If they are not on it, they cannot issue the certificate — at best they are a consultant who will subcontract it.
- Be wary of anything described as "Cyber Essentials equivalent" or an in-house scheme. It is not the same and will not satisfy a contract asking for Cyber Essentials.
- Ask directly: "Are you an IASME-licensed certification body, and can you certify us yourselves?" A straight answer is easy for a real one.
About the insurance
A valid Cyber Essentials certificate includes £25,000 of cyber liability cover arranged through IASME, subject to eligibility — broadly a UK-registered organisation under £20m turnover with the whole organisation in scope.
Two things people get wrong. It comes with the certificate regardless of which body issued it, so it is not a reason to pay more. And scoping matters: certify only part of your organisation and you may lose eligibility. If the cover is relevant to you, confirm it before narrowing scope to make the questionnaire easier.
The short version
- NCSC — owns the standard. You buy nothing from them.
- IASME — runs the scheme, sets assessment fees, licenses assessors.
- Certification body — assesses you and issues the certificate. Your actual supplier.
- The certificate is identical whoever issues it. Choose on resubmission policy, turnaround, and support.
Where we fit
We are not a certification body, and we would tell you if we were pretending otherwise. What we do is the part that makes certification straightforward: running the controls the questionnaire asks about, continuously, so the answers are true when you submit them.
Telebyte Shield covers patching inside the 14-day window, device encryption, MFA, threat protection and a compliance dashboard from £25 per user per month, with Cyber Essentials certification available as an add-on on the Compliance+ tier — arranged through a licensed body, with the controls already in place.
If you are working out who to certify with, tell us what you have been asked for and we will point you straight, including when that means going direct to a certification body without us.
Related reading: what Cyber Essentials costs in 2026 and the 2026 checklist.
Scheme structure and the IASME-arranged cyber liability cover are described as published at the time of writing. Confirm eligibility and current terms with your certification body.