Pharoah Technology · UK Cyber Compliance CE pipeline

Cyber Essentials in 4 weeks, not 6 months.

The 54-question IASME self-assessment your future enterprise buyers demand — guided by AI, stamped by a trained QA reviewer, routed to a real Certification Body. From £29/month.

No card · 60-second check
Trained QA review on every submission
IASME-approved Certification Body certifies
PPN 09/14

Cyber Essentials is a precondition for HMG contracts. PPN 09/14 makes it mandatory for government contracts handling personal information, and enterprise buyers — NHS, Microsoft, BT — ask for certification status on every supplier portal. No certificate, no bid.

54
IASME questions across 5 control areas — every one guided
4 wks
Typical path from first login to submission-ready
~30%
Of certifications lapse — the renewal cycle is where deals die
£29/mo
Entry price — versus £500–£2,000/mo US-first platforms

Free CE readiness check

Where would you score today?

Five questions, one minute, no card. We'll tell you your Cyber Essentials readiness score, the three biggest gaps stopping certification, and what an enterprise supplier portal would conclude about you right now.

Why businesses lose Cyber Essentials contracts

The three patterns we see every week

PPN 09/14 makes Cyber Essentials a precondition for HMG contracts. Enterprise buyers (NHS, Microsoft, BT) ask for it on supplier portals. These are the three traps.

Trap 01
"They asked for CE on the portal — we don't have it"

You bid for an enterprise contract. Supplier due diligence portal asks for Cyber Essentials certificate status. You haven't got one. The procurement team marks the bid non-compliant. You lose six-figure pipeline without ever getting a meeting.

Trap 02
"We got certified once and forgot"

Cyber Essentials is an annual cycle. ~30% of certifications lapse. Without active certification, the next deal blocks at supplier due diligence. By the time you notice, you're rebuilding the assessment from scratch — and the deal has moved on.

Trap 03
"We got breached and panicked"

Security event. ICO 72-hour clock starts. Insurance claim. Customer comms. Legal. The team has no playbook. Most of the six-figure cost of a breach is reaction chaos, not the breach itself. CE prepares you operationally; cyber.law Plus pairs you with a trained QA reviewer + a regulated broker the moment something goes wrong.

What you get

Self-assess. Submit. Renew. Repeat.

The full Cyber Essentials lifecycle in one place, with a regulated assessor behind the certification step.

Assessment

AI Self-Assessment Engine

Guided 54-question IASME assessment with AI-suggested answers based on your tech stack. Save and resume. Trained QA reviewer stamps before submission.

Evidence

Evidence Collector

Integrations with Microsoft Graph, Google Workspace, Jamf and Intune. Auto-pulls MFA status, device inventory, patch level. Manual upload always available.

Policies

5-Policy Pack

Acceptable use · BYOD · incident response · supplier security · access control. Editable templates · trained QA review on Certified+.

Scanning

Vulnerability Scan (Certified+)

NCSC-approved partner scanning · CE-compliant aggregated report · remediation tasks created automatically.

Renewal

Recertification Cron

90 / 60 / 30 / 7-day alerts before expiry. Pre-fills from last year's answers. Delta questions flagged for fresh evidence.

Incident

Breach Response Pair (Plus)

Trained QA reviewer + named Supreme Capital broker on call within 24h of incident. ICO 72-hour clock managed end-to-end. Insurance routed in parallel.

Output

Your readiness, scored against the real checklist

The free check returns the same five control areas the Certification Body will assess — scored, gapped, and turned into a remediation list.

CE Readiness Report
Acme Health-Tech Ltd  ·  9 staff  ·  mixed OS
QA reviewed
61
/ 100 readiness · submission blocked
Firewalls & routers Pass
Secure configuration 2 gaps
User access control — MFA Gap — admin accounts
Malware protection Pass
Security update management Gap — 14-day patch window
CE-CHECK-061 3 fixes → submission-ready

Pricing

Three tiers. Self-serve. Cancel any time.

Subscription pays for the technology. Cyber Essentials certification fees pass through to IASME-approved Certification Bodies on Certified and Plus tiers.

Essentials
£29/mo

For self-assessment + gap monitoring

  • AI 54-question self-assessment
  • Live CE readiness score
  • 5-policy pack templates
  • Recertification cron alerts
  • Email support
Start free trial
Plus
£199/mo

For regulated industries + incident response

  • Everything in Certified
  • Cyber Essentials Plus annual assessment
  • Breach response playbook + ICO 72-hour clock
  • 24h incident response pair (trained QA reviewer + Supreme Capital broker)
  • Phishing simulation campaigns
  • Supplier security questionnaire auto-answer
Start free trial

FAQ

The questions everyone asks

Straight answers on what cyber.law is — and what it isn't.

Are you a Cyber Essentials assessor?

No. IASME is the sole UK Cyber Essentials assessment body, and certificates are issued through their network of accredited Certification Bodies. cyber.law is a technology platform that prepares your self-assessment, manages your evidence, stamps it through a trained QA reviewer, and routes the submission to one of our partner Certification Bodies. They issue the certificate.

How long does it actually take to get certified?

It depends on your starting position. If you have MFA, basic firewalls, AV and patch management already, you can be ready for submission within 1–2 weeks on cyber.law. If you're starting from scratch, 3–4 weeks of remediation is typical. Once submitted, the Certification Body usually returns a decision within 5 working days. We track the whole pipeline in your dashboard.

What's the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a self-assessment — you complete it, the Certification Body reviews and verifies. Cyber Essentials Plus is an independently assessed version — a Certification Body actively tests your controls (external + internal vulnerability scan, sample device testing). Plus is typically required by MOD and some NHS contracts. Our Plus tier includes the CE Plus assessment fee.

Will my data be safe with you?

Evidence files live in encrypted Supabase Storage, scoped by row-level security so only your team sees them. We hold a copy of your Cyber Essentials submission, your evidence, and your communications with the Certification Body. We do not share with third parties beyond the partner Certification Body you select.

I'm already on Vanta / Drata / Hicomply — should I switch?

If you're already in ISO 27001 or SOC 2 mode, those platforms are well-suited. cyber.law is built specifically for UK SMEs whose primary need is Cyber Essentials (with optional CE Plus), at SME pricing. If you also need ISO 27001, we'll be honest — go to Hicomply or ISMS.online. We don't try to be everything.

Get started

Stop losing deals at supplier due diligence.

60 seconds to find out where you stand. £29/mo to start fixing it.

Want this for your business?

Leave your details and we'll come back to you with what it does for your situation specifically — not a brochure.

£199 one-off when it opens — no card needed to join the list.