Frequently Asked Questions
Find answers to common questions about our Managed Cyber Essentials service and discover how Knowall IT can guide your business to certification, strengthen your cyber security, and ensure full compliance with minimal disruption to your operations.
What is Cyber Essentials and why does my business need it?
Cyber Essentials is a UK Government-backed certification scheme that proves your organisation meets a baseline of cyber security best practice. It protects against up to 80% of the most common cyber attacks, helps you win public sector and government contracts, and can reduce your cyber insurance premiums. It's also a strong signal to clients and partners that you take security seriously.
What's the difference between Cyber Essentials Basic and Cyber Essentials Plus?
Both certifications cover the same five technical controls. The difference is how they're verified. Cyber Essentials Basic is self-assessed — you answer a questionnaire confirming your controls are in place. Cyber Essentials Plus goes further, with an independent technical audit including vulnerability scanning on your devices and external IPs. Plus provides a higher level of assurance and is increasingly required by larger organisations and supply chains.
Do all businesses get free cyber insurance with Cyber Essentials?
Not all businesses qualify. To be eligible for the free £25,000 cyber liability insurance that comes with Cyber Essentials Basic certification, your organisation must meet all of the following criteria: your entire organisation must be certified (not just part of it), you must be domiciled in the UK or Crown Dependencies, your annual turnover must be under £20 million, and you must opt in to the insurance during the certification process. Businesses with a turnover above £20m are not eligible for the automatic insurance cover. Please note the policy also carries a £1,000 excess and does not cover money stolen via electronic means or cyber fraud. If you already have a cyber insurance policy in force, you should be aware that you cannot claim on two policies simultaneously.
Does Cyber Essentials Plus also include the free cyber insurance?
No — the free £25,000 cyber liability insurance is only included with Cyber Essentials Basic certification. It does not come with CE Plus. However, CE Plus certification can help you save up to 10% on your existing specialist cyber insurance premiums, and demonstrates a higher level of independently verified security to insurers.
How long does the certification process take with Knowall IT?
For Cyber Essentials Basic, most businesses are certified within 24 hours once any remedial work is complete. Cyber Essentials Plus typically takes a little longer due to the independent audit and vulnerability scanning process, but our team handles all liaison with the assessors and keeps things moving as quickly as possible. We'll give you a clear timeline from the outset so there are no surprises.
What if we fail the first assessment attempt?
With our managed service, we do extensive prep work before submission to make sure you pass first time. If you do need to resubmit, one free retry is included. A second failure would require re-purchasing the certification. Our pre-assessment checks, gap remediation and evidence gathering are specifically designed to eliminate this risk — it's why we offer an Assured Pass option for CE Plus.
Will Knowall IT carry out the technical fixes, or do we need our own IT team?
We can handle everything. Our team can implement firewall changes, patch management, AV deployment and all other remediation tasks in-house — you don't need your own IT team or a separate supplier. If you do have existing IT staff or a provider, we're equally happy to work alongside them.
Is Cyber Essentials required to bid for government contracts?
Yes — Cyber Essentials certification is mandatory for all UK central government contracts that involve handling personal data or providing certain technical products and services. Many local authorities, NHS trusts and large private sector organisations also now require it from suppliers. If you're looking to win public sector work, getting certified is increasingly non-negotiable.
How often does Cyber Essentials need to be renewed?
Certification is valid for 12 months from the date of issue. Knowall IT offers an annual renewal service and ongoing monitoring to keep you compliant year after year — so your certification never lapses and your free cyber insurance (if eligible) stays in force.
Can charities and non-profits get Cyber Essentials certified?
Yes — Cyber Essentials is open to all UK organisations including charities, schools, universities and local authorities, not just businesses. Eligible charities and non-profits with a turnover under £20m can also qualify for the free £25,000 cyber liability insurance that comes with certification.