Cyber Essentials readiness,
without the guesswork.
Cyber Essential Check scans your perimeter, maps every gap to the exact CE v3.3 control, and gives your team a fix-and-verify workflow — so you walk into assessment prepared, not hoping.
Readiness score
72%
Auto-fails
2 open
- TLS 1.3 on primary MXPass
- DMARC policy: rejectPass
- HSTS max-age below 6 monthsWarn
- MFA not enforced — control A5.1Fail
- Windows 10 detected — EOL Oct 2025Fail
5
CE v3.3 controls covered
20+
Auto-fail rules
<60s
Time to first scan
UK
Chester-based team
How it works
From domain to evidence pack in three steps.
01
Enter your domain
No agents, no installs. We probe DNS, mail, TLS and web posture from the public internet — the same view an assessor sees.
02
Map to CE v3.3
Every finding is tied to the exact IASME control wording, severity, and the auto-fail rules assessors reject on first.
03
Fix, rescan, export
Tick off remediation, run a rescan to verify, and export a branded evidence pack in PDF and CSV for your assessor.
What it checks
The five controls, plus every auto-fail.
Coverage matches the CE v3.3 (Danzell) requirements published by IASME — the same framework your assessor will grade you against.
Public perimeter scan
DMARC, DKIM, SPF, TLS, HSTS, MTA-STS, DNSSEC, exposed remote admin and sensitive paths.
Cloud connectors
Microsoft 365, Google Workspace, Xero/QuickBooks. MFA coverage, admin sprawl, patch lag.
Auto-fail detection
MFA gaps, EOL Windows 10, critical patches over 14 days — flagged before an assessor sees them.
v3.3-mapped findings
Every gap references the exact IASME control wording, evidence needed, and remediation steps.
Evidence pack export
PDF and CSV outputs formatted for IASME assessors. Screenshot templates included.
Progress tracker
Tick off remediation, rescan to verify, and keep an audit trail of what was fixed and when.
The auto-fails
Most Cyber Essentials failures come from the same six issues.
We check these before anything else — so within minutes you know whether you'd pass today, and exactly what to fix if you wouldn't.
Run the auto-fail checkMFA not enforced
Any admin or user-facing service missing MFA is an instant fail.
Critical patches > 14 days
OS, browsers and public-facing software must be patched within 14 days of a high/critical CVE.
End-of-life software
Windows 10 post-Oct 2025, unsupported OS or browsers in scope — automatic fail.
Shared admin accounts
Named admin identities and separation of privilege are non-negotiable.
Unencrypted portable devices
Any laptop or phone in scope without full-disk encryption fails outright.
Default router / firewall credentials
Anything left on the vendor default password fails on day one.
Pricing
Transparent British pricing.
Start free. Upgrade when you're ready for evidence exports and cloud connectors.
Micro
PopularUp to 10 staff
£29/mo
- Unlimited scans
- 1 cloud connector
- PDF gap report
- Remediation plan
Small
11–50 staff
£59/mo
- Everything in Micro
- Unlimited connectors
- Full evidence pack
- Renewal reminders
FAQ
Common questions from UK SMEs.
Ready in minutes. Certified with confidence.
Free public domain scan. No card required. Upgrade only when you need evidence exports.
Start your free scanReadiness guidance only — not an IASME/NCSC-approved certification body. Final sign-off requires an IASME-approved assessor.