PPCS guides UK accounting firms through Cyber Essentials and Cyber Essentials Plus — start to finish, no jargon, fixed-price. Show clients, insurers and prospects that your firm takes security as seriously as they do.
Both certifications sit under the same NCSC scheme. The difference is how the evidence is verified — and the level of assurance you can show your clients.
A structured self-assessment reviewed by a certification body. The essential first step for any firm handling client financial data.
Everything in Cyber Essentials, plus a hands-on technical audit by an external assessor. The level of assurance clients and insurers increasingly ask for.
Cyber Essentials focuses on baseline technical controls the NCSC has identified as the most effective defences against everyday cyber threats.
Boundary firewalls and internet gateways on every device.
Devices set up securely from the start — no default passwords.
Right people, right access. MFA on everything client-facing.
Effective antivirus and endpoint protection on all endpoints.
Software and operating systems kept fully up to date.
Two levels of the same scheme. Choose based on the assurance your clients — and your insurer — need to see.
| Cyber Essentials | Cyber Essentials Plus | |
|---|---|---|
| Type of assessment | Self-assessment questionnaire | Independent hands-on technical audit |
| Verification | Reviewed by a certification body | Tested by a qualified external assessor |
| Testing scope | Based on your firm's declarations | Internal & external vulnerability testing |
| Assurance level | Baseline confidence | Higher, independently verified assurance |
| Investment | £995 (PPCS-supported) | £2,495 (PPCS-supported) |
| Typical timeline | 1–3 days, self-paced | 5–10 days including assessor testing |
| Best suited for | Firms starting their compliance journey | Firms needing verified, defensible security |
| Validity | 12 months | 12 months |
Certification isn't paperwork. For UK accounting practices it opens doors, protects fees, and satisfies the questions your clients now ask.
Insurers, larger clients and public-sector buyers routinely ask for CE evidence. Certification answers the question before it's asked.
The five controls are the ones the NCSC has proven stop the majority of everyday threats — phishing follow-ups, credential theft, ransomware entry.
Cyber Essentials is mandatory for many central and local government contracts — and increasingly for large private-sector procurement.
Technical controls that back up your data protection promises — the evidence the ICO expects to see behind your privacy policies.
Some professional indemnity insurers already ask about certification. Firms with CE frequently see better questionnaires — and sometimes better premiums.
The controls you put in place for CE become the technical baseline underneath ISO 27001 and your AI Governance work. Nothing wasted.
Our process is designed around fee-earning teams. You get expert-led support, not a template dumped in your inbox.
A short conversation to understand your firm, tech stack (Xero, Sage, QuickBooks, Microsoft 365) and where you are today.
We map your setup against the five CE controls and produce a clear, prioritised gap analysis — with a fixed remediation plan.
We help you close the gaps — MFA rollout, patching, endpoint protection, secure configuration — practical fixes, not theory.
We handle the certification body paperwork end-to-end. You review and sign off — we do the rest.
For CE Plus we coordinate the independent assessor testing, sit alongside your team, and fix anything that comes up.
You receive your certificate, IASME registration and marketing assets — then we set a reminder for renewal 10 months later.
Fixed-price. Practitioner-led. Delivered around your team's calendar. Book a short call and we'll tell you exactly where you stand and what it will take.
CE gives you technical baseline. Two other things typically follow — and PPCS delivers them as one joined-up programme.
CE covers the technical side. ISO 27001 wraps policy, risk management, business continuity and audit-ready evidence around it — the standard larger clients ask for.
Explore ISO 27001 →Once your data is safe, the next question is how your firm uses AI. AIGAS is the sector-specific AI governance framework built for accountants — free tier through to independent assessment.
Explore AIGAS →Cyber Essentials has a reputation problem. Most of the reasons firms delay certification don't survive the first conversation.
"It's only for large organisations."
The scheme was designed by the NCSC specifically for SMEs — including sole practitioners and small accounting firms.
"It's too technical for us to handle."
We translate every question into plain English and handle the technical work. You review, sign off, and get certified.
"We don't handle sensitive data anyway."
Every accounting practice holds tax records, bank details, payroll data and HMRC credentials. That's exactly what attackers target.
"It's just a paperwork exercise."
Certification requires genuine security improvements — MFA, patching, endpoint protection. Real controls, not just a badge.
The questions we hear most often from accounting firms considering certification.
For a well-prepared firm using cloud accounting and Microsoft 365, Cyber Essentials typically takes 1–3 days from assessment to certificate. CE Plus adds a 5–10 day window for the independent audit.
Yes — Cyber Essentials Plus builds directly on the CE questionnaire. In practice we often deliver both back-to-back so there's no wasted work between the two.
It's not a legal requirement, but it's mandatory for many public-sector contracts and increasingly expected by larger clients, PI insurers and mid-market prospects.
Yes — the scheme explicitly covers cloud services under your control (Xero, Sage, QuickBooks, Microsoft 365, Google Workspace). The way your firm accesses and secures them is part of the assessment.
PPCS's process is built around a pre-submission readiness check, so you don't submit until we're confident you'll pass. If anything does come up, remediation support is included in the fixed price.
Both certifications are valid for 12 months. Renewal is usually more efficient than the first cycle because your controls are already in place — PPCS's renewal fees reflect that (£495 for CE, £995 for CE Plus).
You can apply to a certification body direct — but you'll need to run the readiness assessment, remediation and paperwork yourself. PPCS delivers all of that on a fixed price, so certification becomes a project you sign off, not one you have to manage.
Tell us a little about your firm and where you are on Cyber Essentials. We'll come back with a clear, honest view of the right next step — no obligation.
Prefer to browse first? See transparent pricing →
