Cyber Security

Cyber Essentials for Sussex SMEs: Renewals & Insurers

Cyber Essentials for Sussex SMEs: what renewals, insurers and supplier questionnaires actually require. Book a Security Triage Call to get started.

Cyber Security

Cyber Essentials for Sussex SMEs: Renewals & Insurers

Cyber Essentials for Sussex SMEs: what renewals, insurers and supplier questionnaires actually require. Book a Security Triage Call to get started.

Published:

If you run a small business in Sussex and you've been asked for a Cyber Essentials certificate — by an insurer at renewal, a large customer in a tender, or a supplier questionnaire — you're not alone. The government-backed scheme has become one of the most common baseline checks that 10–25 seat owner-managers encounter, and it appears at the most inconvenient moments.

This article covers what a Cyber Essentials renewal actually requires of a typical Microsoft 365 estate, which five technical controls the questionnaire tests, what evidence insurers and suppliers expect to see, and how your support arrangement should differ from a one-off audit.

What Cyber Essentials Actually Tests: The Five Controls

Cyber Essentials is not a general security assessment. It tests five specific technical controls, and the self-assessment questionnaire asks around 48 questions grouped under those five areas:

  1. Firewalls — Are internet gateways configured to block unauthorised access?

  2. Secure configuration — Are devices and services built to a standard, not left on defaults?

  3. User access control — Are permissions controlled, MFA enforced, and admin accounts separated?

  4. Malware protection — Is endpoint protection active, standardised and monitored across all in-scope devices?

  5. Patch management — Are operating systems and applications kept up to date, with unsupported software removed?

That is the full scope. The scheme does not assess backups, incident response plans, monitoring, or anything beyond these five controls. Knowing that boundary is important — it means you can prepare without trying to pre-solve every security problem your business faces.

For a Sussex SME running Microsoft 365 as its primary platform, the practical question is whether those five controls are consistently true across your environment, not whether you have perfect security. Our Cyber Essentials evidence checklist for Microsoft 365 breaks down exactly what evidence to gather for each control area.

What a CE Renewal Actually Requires of a 10–25 Seat M365 Estate

Renewal is not a rubber stamp. IASME requires you to complete the current questionnaire in full, regardless of whether you certified last year. You enter all the information again because the scheme treats every certification as an annual review of your cyber security.

Here is what that means in practice for a typical Sussex business with 10–25 users on Microsoft 365:

Scope definition — what has changed since last year?

Between certifications, your estate may have grown. A new hire with a company laptop. A second office location. A cloud service you started using. Any of these can expand what is in scope, and the questionnaire requires you to list every device, user account, server and cloud service that processes or stores organisational data.

Pull a copy of last year's submitted questionnaire and your current asset inventory. Identify anything new that needs adding to scope before you start answering.

The five controls — evidence, not belief

The self-assessment requires written answers against each question, plus supporting evidence. For a Microsoft 365 estate, that typically means:

  • Screenshots or exports from your management tools showing MFA coverage, device compliance status and patch configurations.

  • A documented process for joiner/mover/leaver account management.

  • Evidence that your firewall or internet gateway is configured to block unnecessary inbound access.

  • A list of malware protection tools with confirmation they are active on every in-scope endpoint.

If you have already aligned your Microsoft 365 environment to Cyber Essentials controls, you will find much of this evidence already exists. Our guide on aligning Microsoft 365 with CE controls walks through the governance decisions that make this evidence real rather than one-off.

IASME assessment fees

IASME publishes tiered fees for Cyber Essentials self-assessment. For a small business (10–49 employees), the fee is £440 + VAT. Micro businesses (0–9 employees) pay £320 + VAT. Medium organisations (50–249 employees) pay £500 + VAT. These fees go to IASME for the assessment process; they do not include any consultancy or support services.

What Insurers and Supplier Questionnaires Actually Expect

Cyber Essentials certification does not automatically guarantee you cyber insurance cover, nor does any insurer treat it as a blanket waiver of their questionnaire. What it does do is three things: it opens access to coverage, it earns premium reductions with many UK domestic insurers, and it strengthens your claims position by providing independent verification that your baseline controls are in place.

Insurer expectations at renewal

If you renewed a cyber-insurance policy in the last year, you will have noticed the questionnaire. It used to be a handful of questions about backups and antivirus. It is now a comprehensive security audit that takes a competent IT team several days to answer properly.

The controls that underwriters now check fall into five areas: multi-factor authentication (MFA), endpoint detection and response (EDR), tested immutable backups, incident response plan, and Cyber Essentials certification.

The practical approach is to start 90 days before your insurance renewal date. Run an honest control review against the broker's questionnaire and your current policy wording. Close gaps that will affect either premium or coverage, prioritising MFA, backups and EDR. Document what you have with screenshots, policy excerpts, training completion reports and backup test results.

Cyber Essentials certifies five technical controls. It does not assess backups, incident response plans, or monitoring. Those are the three controls that underwriters weight most heavily for ransomware risk. Holding a certificate shows baseline hygiene; it does not answer the insurer's full questionnaire.

Supplier questionnaires and tender requirements

Supplier security questionnaires from larger customers — particularly in government, finance, professional services and public-sector supply chains — increasingly require Cyber Essentials as a minimum standard. The UK Government Procurement Notice 09/23 specifies that Cyber Essentials is required in many cases for suppliers to government departments, and the Ministry of Defence requires it across all supply chain partners handling defence information.

When a supplier questionnaire arrives, the most useful approach is to treat it as an externally validated checklist. Cross-reference the questionnaire against your current CE scope statement and your five-control evidence pack. Where gaps exist, Cyber Essentials certification is the fastest path to closing them. If you need context on what a typical self-assessment questionnaire looks like, our guide on the Cyber Essentials self-assessment questionnaire walks through the structure and what to expect.

How Support Should Differ From a One-Off Audit

A one-off audit tells you what would fail today. A proper support arrangement should ensure it does not fail tomorrow, next quarter, or at your next renewal date. The Cyber Essentials hub covers both the certification process and the ongoing governance that keeps your controls in place year after year.

The distinction matters because Cyber Essentials certification is valid for 12 months, and the controls must remain in place throughout that period. Drift is the most common reason SMEs find themselves unprepared at renewal time — settings that were correct six months ago have changed, new devices have been added without the same controls, or unsupported software has crept into scope.

A managed support partner should provide:

  • Baseline enforcement — Devices built to a standard, not configured individually. MFA enforced across all users, not just admin accounts. Patching applied within defined windows, not 'when someone notices'.

  • Evidence readiness — A living evidence pack: device inventories, MFA coverage reports, admin role lists, patch status dashboards, malware protection confirmations. Not something you assemble the week before renewal.

  • Renewal management — Diarising your certification date, pulling last year's answers, checking for scope changes, and resubmitting before the certificate lapses.

  • Ownership clarity — Named owners for each control area, documented decision rights, and exception handling with time-bound remediation.

This is not a certification service — it is a practical operational assessment aligned with the principles of Cyber Essentials, ensuring your baseline holds year after year.

CE vs CE+: Which One Do You Actually Need?

Cyber Essentials (self-assessment) and Cyber Essentials Plus differ in their level of assurance, not in the controls they assess. Both test the same five technical controls. CE Plus adds a hands-on technical audit where an independent assessor verifies that your controls are correctly implemented in practice — including vulnerability scans and a representative sample of device testing.

Most Sussex SMEs need standard Cyber Essentials self-assessment. CE Plus is typically required when a specific customer contract, government tender, or regulator mandates the higher assurance level. If you are unsure which your insurer or supplier requires, check the wording of their questionnaire — if it asks for a technical audit or independent verification, that is CE Plus.

For Kent-based SMEs looking for CE support and renewal guidance, we cover that separately on our Microsoft 365 for Kent SMEs page — this article focuses specifically on the Sussex context.

What Happens Between Submission and Certificate?

Once you submit your completed questionnaire through the IASME portal:

  1. An independent Assessor reviews your answers within approximately 3 working days.

  2. If any answers are considered non-compliant, you receive feedback and have 2 working days to address the issues, update your answers, and resubmit.

  3. The Assessor remarks the updated assessment within a further 3 working days.

  4. If you pass, your certificate is issued immediately and is valid for 12 months from the date of issue.

  5. If you still fail after the resubmission window, you will need to reapply and pay the assessment fee again.

The total timeline, assuming your answers are solid on first submission, is typically 5–10 working days from submission to certificate.

Frequently Asked Questions

Do we need Cyber Essentials or Cyber Essentials Plus?

Standard Cyber Essentials (self-assessment) is what most Sussex SMEs need. It covers the five technical controls and satisfies the majority of insurer questionnaires and supplier requirements. Cyber Essentials Plus adds an independent technical audit — a hands-on verification of your controls by an external assessor. You only need CE Plus if a specific customer contract, government tender, or regulator explicitly requires the higher assurance level. If you are unsure which your insurer or supplier requires, check the wording of their questionnaire: if it mentions independent verification or a technical audit, that is CE Plus.

How far ahead of renewal should we start?

Start at least 90 days before your insurance renewal date if the certificate affects your premium or coverage. For a standard CE renewal, 4–6 weeks is usually sufficient — enough time to review scope changes, gather evidence, complete the questionnaire, and allow for the assessor's review window. If you are also closing gaps that affect your insurance terms (MFA, EDR, backup testing), the 90-day window gives you time to deploy and verify those controls before the renewal meeting.

Will our Microsoft 365 setup pass as-is?

It depends on how your M365 estate has been managed. A properly configured Microsoft 365 environment can satisfy most of the five CE controls: MFA enforced for all users, devices enrolled in Intune with compliance policies, Microsoft Defender active on endpoints, automated patching through Intune update rings, and spam filtering configured. The common failure points are shared admin accounts, unmanaged devices, unsupported software on some endpoints, and MFA not enforced for standard users. If you have already aligned your environment to CE controls, you will likely need only evidence gathering rather than technical remediation.

What happens between submission and certificate?

After you submit the questionnaire through IASME, an independent Assessor reviews your answers within approximately 3 working days. If any answers are non-compliant, you receive feedback and have 2 working days to address the issues and resubmit. The Assessor remarks the updated assessment within a further 3 working days. If you pass, your certificate is issued immediately and valid for 12 months. If you still fail after the resubmission window, you need to reapply and pay again.

Next Steps

If you are a Sussex owner-manager facing a Cyber Essentials renewal, an insurer questionnaire, or a supplier form demanding baseline certification, the most practical first step is understanding exactly where your current estate stands against the five controls — and who is responsible for keeping them in place after certification.

Book a Security Triage Call to get a clear picture of your gaps and a structured path to closing them.

More resources

Keep reading

Browse the latest practical guides across Managed IT, Cyber Security, Modern Workplace, and Backup

More resources

Keep reading

Browse the latest practical guides across Managed IT, Cyber Security, Modern Workplace, and Backup

More resources

Keep reading

Browse the latest practical guides across Managed IT, Cyber Security, Modern Workplace, and Backup

For 10-15 seat

Owner-managed SMEs in Sussex & Kent

Who want clarity, stability, and a proper security baseline — start with the free Security Triage Call.

For 10-15 seat

Owner-managed SMEs in Sussex & Kent

Who want clarity, stability, and a proper security baseline — start with the free Security Triage Call.

For 10-15 seat

Owner-managed SMEs in Sussex & Kent

Who want clarity, stability, and a proper security baseline — start with the free Security Triage Call.