Pharoah Technology · UK Cyber Compliance CE pipeline
Cyber Essentials in 4 weeks, not 6 months.
The 54-question IASME self-assessment your future enterprise buyers demand — guided by AI, stamped by a trained QA reviewer, routed to a real Certification Body. From £29/month.
Free CE readiness check
Where would you score today?
Five questions, one minute, no card. We'll tell you your Cyber Essentials readiness score, the three biggest gaps stopping certification, and what an enterprise supplier portal would conclude about you right now.
Why businesses lose Cyber Essentials contracts
The three patterns we see every week
PPN 09/14 makes Cyber Essentials a precondition for HMG contracts. Enterprise buyers (NHS, Microsoft, BT) ask for it on supplier portals. These are the three traps.
You bid for an enterprise contract. Supplier due diligence portal asks for Cyber Essentials certificate status. You haven't got one. The procurement team marks the bid non-compliant. You lose six-figure pipeline without ever getting a meeting.
Cyber Essentials is an annual cycle. ~30% of certifications lapse. Without active certification, the next deal blocks at supplier due diligence. By the time you notice, you're rebuilding the assessment from scratch — and the deal has moved on.
Security event. ICO 72-hour clock starts. Insurance claim. Customer comms. Legal. The team has no playbook. Most of the six-figure cost of a breach is reaction chaos, not the breach itself. CE prepares you operationally; cyber.law Plus pairs you with a trained QA reviewer + a regulated broker the moment something goes wrong.
What you get
Self-assess. Submit. Renew. Repeat.
The full Cyber Essentials lifecycle in one place, with a regulated assessor behind the certification step.
AI Self-Assessment Engine
Guided 54-question IASME assessment with AI-suggested answers based on your tech stack. Save and resume. Trained QA reviewer stamps before submission.
Evidence Collector
Integrations with Microsoft Graph, Google Workspace, Jamf and Intune. Auto-pulls MFA status, device inventory, patch level. Manual upload always available.
5-Policy Pack
Acceptable use · BYOD · incident response · supplier security · access control. Editable templates · trained QA review on Certified+.
Vulnerability Scan (Certified+)
NCSC-approved partner scanning · CE-compliant aggregated report · remediation tasks created automatically.
Recertification Cron
90 / 60 / 30 / 7-day alerts before expiry. Pre-fills from last year's answers. Delta questions flagged for fresh evidence.
Breach Response Pair (Plus)
Trained QA reviewer + named Supreme Capital broker on call within 24h of incident. ICO 72-hour clock managed end-to-end. Insurance routed in parallel.
Output
Your readiness, scored against the real checklist
The free check returns the same five control areas the Certification Body will assess — scored, gapped, and turned into a remediation list.
Pricing
Three tiers. Self-serve. Cancel any time.
Subscription pays for the technology. Cyber Essentials certification fees pass through to IASME-approved Certification Bodies on Certified and Plus tiers.
For self-assessment + gap monitoring
- AI 54-question self-assessment
- Live CE readiness score
- 5-policy pack templates
- Recertification cron alerts
- Email support
Includes annual IASME certification
- Everything in Essentials
- Annual Cyber Essentials certification fee included
- Vulnerability scan (annual)
- Evidence collector integrations (Microsoft / Google / Jamf / Intune)
- Trained QA review on every IASME submission
For regulated industries + incident response
- Everything in Certified
- Cyber Essentials Plus annual assessment
- Breach response playbook + ICO 72-hour clock
- 24h incident response pair (trained QA reviewer + Supreme Capital broker)
- Phishing simulation campaigns
- Supplier security questionnaire auto-answer
FAQ
The questions everyone asks
Straight answers on what cyber.law is — and what it isn't.
Are you a Cyber Essentials assessor?
No. IASME is the sole UK Cyber Essentials assessment body, and certificates are issued through their network of accredited Certification Bodies. cyber.law is a technology platform that prepares your self-assessment, manages your evidence, stamps it through a trained QA reviewer, and routes the submission to one of our partner Certification Bodies. They issue the certificate.
How long does it actually take to get certified?
It depends on your starting position. If you have MFA, basic firewalls, AV and patch management already, you can be ready for submission within 1–2 weeks on cyber.law. If you're starting from scratch, 3–4 weeks of remediation is typical. Once submitted, the Certification Body usually returns a decision within 5 working days. We track the whole pipeline in your dashboard.
What's the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is a self-assessment — you complete it, the Certification Body reviews and verifies. Cyber Essentials Plus is an independently assessed version — a Certification Body actively tests your controls (external + internal vulnerability scan, sample device testing). Plus is typically required by MOD and some NHS contracts. Our Plus tier includes the CE Plus assessment fee.
Will my data be safe with you?
Evidence files live in encrypted Supabase Storage, scoped by row-level security so only your team sees them. We hold a copy of your Cyber Essentials submission, your evidence, and your communications with the Certification Body. We do not share with third parties beyond the partner Certification Body you select.
I'm already on Vanta / Drata / Hicomply — should I switch?
If you're already in ISO 27001 or SOC 2 mode, those platforms are well-suited. cyber.law is built specifically for UK SMEs whose primary need is Cyber Essentials (with optional CE Plus), at SME pricing. If you also need ISO 27001, we'll be honest — go to Hicomply or ISMS.online. We don't try to be everything.
Get started
Stop losing deals at supplier due diligence.
60 seconds to find out where you stand. £29/mo to start fixing it.