Get certified. Win contracts.
Fix your insurer's requirements.
Fixed-price Cyber Essentials and CE+ certification for businesses across East Yorkshire and the East Riding. Published prices, a named lead engineer throughout, and a team based in the area rather than a distant call centre. Serving Hull, Beverley and the wider East Riding.
Cyber Essentials, and why Yorkshire businesses are pursuing it
Cyber Essentials is a UK Government-backed scheme covering five technical controls. Across East Yorkshire it is increasingly asked for by insurers, public-sector buyers and the Humber energy supply chain.
Government contracts
Mandatory for any public sector contract involving sensitive personal data or certain technical products and services. Without it, you cannot bid.
Cyber insurance
Many underwriters now require CE as a condition of cover, or offer meaningful premium reductions for certified businesses. Getting certified before your renewal can offset the cost.
Supply-chain due diligence
Solicitors, accountants, dental and healthcare practices, and motor trade businesses are increasingly required to show CE certification by NHS commissioners, insurer panels, and larger clients in their supply chains.
GDPR and data protection
Certification provides documented evidence of active technical steps to protect personal data, directly relevant if the ICO investigates following a breach or incident.
Practical risk reduction
The five controls address the attack vectors behind the majority of commodity cyber incidents hitting UK SMBs. DSIT's Cyber Security Breaches Survey 2025/2026 found 43% of UK businesses experienced a breach or attack in the past year.
Current scheme version: Danzell (Requirements for IT Infrastructure v3.3). This became mandatory for applications registered after 26 April 2026. Key changes include MFA now required for all cloud services, stricter auto-fail marking, and updated device management requirements. All Wolds Cyber engagements are assessed against the current Danzell v3.3 requirements.
Cyber Essentials in East Yorkshire, priced as a subscription
A certificate proves the day you were assessed. Danzell v3.3 (mandatory for applications registered after 26 April 2026) auto-fails on missing MFA on a cloud service, and on falling more than 14 days behind on a critical patch. Those obligations run every day of the year, so certification is included in a subscription that watches the controls all year, and we do not sell bare certification. All prices ex-VAT.
Wolds Certify
The default route to a Cyber Essentials certificate. Continuous vulnerability monitoring, patch management, awareness training and £25k cyber insurance, with CE preparation and submission support included. One-off year 1 setup fee of £395, or £795 if full CE readiness work is needed.
Wolds Assure
Everything in Certify plus Cyber Essentials Plus preparation and submission support, and the GDPR privacy toolbox. CE+ delivered remotely as standard; on-site verification adds £395. One-off year 1 setup fee of £695, or £1,295 if full CE and CE+ readiness work is needed.
Pricing by organisation size
Wolds Watch is the monitoring-only tier for organisations that want the controls under active watch without pursuing a certificate. Wolds Certify includes CE. Wolds Assure includes CE and CE+.
| Tier | 1 to 9 users | 10 to 19 users | 20 to 49 users | 50 to 99 users | 100 to 249 users |
|---|---|---|---|---|---|
| Wolds Watch | £400/yr | £523/yr | £892/yr | £1,251/yr | £1,855/yr |
| Wolds Certify | £1,280/yr | £1,675/yr | £2,856/yr | £4,006/yr | £5,937/yr |
| Wolds Assure | £3,200/yr | £3,835/yr | £4,954/yr | £6,504/yr | £9,649/yr |
All prices ex-VAT. VAT added at 20% where applicable. One-off year 1 setup fees: Watch none, Certify £395 (or £795 with full CE readiness), Assure £695 (or £1,295 with full CE and CE+ readiness). Full detail on the Wolds Compliance page →
What every CE and CE+ engagement includes
No hidden extras. No separate charge for readiness work. Every item below is part of the fixed price.
Gap assessment
Methodology-driven review of your current posture against all five Cyber Essentials control areas. You receive a clear list of what passes, what fails, and what needs remediation before formal submission.
Remediation guidance
Plain-English remediation steps for every gap identified. You, or your existing IT provider, work through the list. We are available for questions throughout and provide policy templates for each control area.
Policy templates
Documented policies covering each of the five control areas, tailored to your organisation size. Required for evidence purposes and useful long-term for onboarding and audits.
Evidence preparation
We prepare the full evidence pack for submission, mapping your controls to the questionnaire requirements. No ambiguity about what the certifying body needs to see.
Submission and one resubmission
We handle submission to the IASME-accredited certification body. If a failed point requires resubmission, one resubmission is included in the price, no additional charge.
30-day post-cert retest window
After certification is issued, a 30-day window allows retesting of any borderline controls at no extra charge. Useful when a remediation was applied during the final stages of the process.
Named lead engineer throughout
One person, from first call to certificate. Not an account manager who hands off to a junior analyst. You know who is doing the work, and so do we.
Annual renewal reminder
Your CE certificate is valid for 12 months. We send a renewal reminder before expiry so you do not inadvertently lapse, particularly important if certification is required for an insurance renewal or contract.
Why readiness work before submission matters. The most expensive mistake is submitting for Cyber Essentials before you know whether you will pass. A failed first assessment costs the assessment fee and the remediation time and a retake fee. Starting with a gap assessment, which is included in every CE and CE+ engagement price, removes that risk entirely.
The five Cyber Essentials control areas
All five must be met to achieve certification. Each addresses a distinct category of attack vector. The Danzell v3.3 requirements (mandatory for applications registered after 26 April 2026) introduced stricter requirements across several of these areas.
Firewalls
All internet-connected devices must be protected by a correctly configured firewall with unnecessary ports and services closed. Applies to both boundary firewalls and software firewalls on individual devices. One of the most commonly failed controls on initial assessment.
Secure configuration
Devices and software must be configured securely from the outset: default passwords changed, unnecessary accounts removed, auto-run features disabled, admin access restricted. Frequently failed by organisations that have never formally reviewed their baseline configuration.
Access control
User accounts managed properly, admin access limited to those who need it, accounts for leavers removed promptly, and multi-factor authentication now required for all cloud services under the Danzell v3.3 requirements. This MFA change is a significant auto-fail under the current scheme.
Malware protection
Devices protected against malware, antivirus, application allow-listing, or sandboxing as appropriate. Requirements differ by device type, operating system, and usage context. The gap assessment works through each category to confirm which controls apply.
Patch management
Operating systems and software kept current. High-risk vulnerabilities patched within 14 days. Software that is end-of-life and no longer receiving security updates must be removed from scope or isolated, it cannot be included in the certified estate.
How Cyber Essentials certification works, end to end
From first call to certificate in hand. Timescale depends primarily on how many gaps need remediation and how quickly they can be addressed.
Free 15-minute call
We establish your organisation size, current posture, and the right certification level. You receive a confirmed engagement price and scope before any work starts. No commitment required.
Gap assessment
We assess your current configuration against all five control areas and produce a plain-English gap list. Nothing is submitted to the certifying body at this stage, you see exactly what needs work first.
Remediation
You or your IT team works through the gap list. We provide policy templates and are available for technical questions. For CE+, we recheck controls once remediations are applied before proceeding to submission.
Evidence preparation
We build the evidence pack, mapping your controls to the questionnaire requirements. This is where the paperwork gets done, accurately and completely, to avoid back-and-forth with the certifying body.
Submission and certification
We handle submission to our IASME-accredited certification body. Basic CE is typically certified within a few working days of submission. CE+ involves hands-on verification by the certifying body and takes longer.
Certificate issued
You receive your Cyber Essentials certificate, valid for 12 months. The 30-day retest window opens. We send a renewal reminder before the next annual cycle to keep you continuously certified.
Provable. Fixed price. Plain English.
Most providers either charge separately for readiness and certification, or price by "call us for a quote". Neither is useful if you are trying to budget or compare. These are the reasons Yorkshire SMBs choose Wolds Cyber for CE work.
Published prices, all-in
Wolds Certify from £1,280 per year, Wolds Assure from £3,200, both with certification included. Wolds Watch from £400 for monitoring only. Published banded prices, no discovery-call-required pricing, no readiness charge on top.
A certificate you own, provably working
You get a certificate and report you own outright, issued through an IASME-accredited certification body and defensible to insurers, regulators, and clients doing due diligence. And if you go on to managed security with us, you do not have to take our word for it: you see your posture and get a plain-English report every month.
Named lead engineer, no handoff
One person throughout. The engineer you brief is the engineer who does the work and handles the submission. No account managers, no junior analysts, no "I'll need to check with the team."
One resubmission included
If a control fails on first submission and requires resubmission, that is included in the price. The most expensive outcome is paying twice because a minor gap was missed, the readiness work and included resubmission protect against that.
Plain-English delivery
Gap reports, remediation steps, and policy templates written for someone running a business, not for a technical audience. You should be able to hand the gap list to your IT provider or office manager without needing a translator.
Yorkshire-based
Based in East Yorkshire, covering York, Hull, Harrogate, Scarborough, Beverley, and the wider East Riding and North Yorkshire area. Available for on-site if needed. No outsourced delivery.
Cyber Essentials across East Yorkshire and the East Riding
We are based in East Yorkshire, so this is home turf. Pick the page nearest you, or call us about anywhere in the East Riding.
Cyber Essentials Hull
CE and CE+ for Hull and the Humber energy, ports and digital supply chain.
Cyber Essentials York
CE and CE+ for York and the surrounding area, with the full price table.
We also serve Beverley, Driffield, Pocklington, Market Weighton, Goole, Bridlington and the surrounding East Riding towns. For the whole county see Cyber Essentials Yorkshire, or read the full Cyber Essentials guide.
Which businesses pursue Cyber Essentials
CE certification is increasingly requested across professional and regulated sectors. The following business types are most commonly required to demonstrate certification, by clients, insurers, or commissioners.
If your organisation is not on this list but you handle personal data, hold sensitive client information, or have a contract that asks for evidence of cyber security controls, the initial call will confirm whether certification is relevant for you.
Frequently asked questions
How much does Cyber Essentials cost in East Yorkshire?
We do not sell bare certification. Cyber Essentials sits inside Wolds Certify (from £1,280 per year for 1 to 9 users) and Cyber Essentials Plus inside Wolds Assure (from £3,200). Wolds Watch, monitoring only, starts at £400. Larger organisations pay the banded rate. All prices ex-VAT.
Which East Yorkshire towns do you cover?
We work across the East Riding, including Hull, Beverley, Driffield, Pocklington, Market Weighton, Goole and Bridlington. We are based in East Yorkshire, so most engagements run remote-first with no travel premium, and on-site visits where needed carry a £395 surcharge.
Do I need Cyber Essentials for my East Yorkshire business?
It is mandatory for government contracts involving sensitive personal data. Beyond that, it is increasingly required by cyber insurers as a condition of cover and by larger clients, particularly in legal, healthcare, and public sector supply chains, as part of their vendor due diligence process.
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Basic Cyber Essentials is a self-assessment questionnaire, independently verified by a certifying body. Cyber Essentials Plus involves hands-on technical testing by an assessor who verifies that your controls work in practice, not just on paper. CE+ carries significantly more weight with insurers and clients requiring supply-chain assurance. Both cover the same five control areas. CE sits inside Wolds Certify; CE+ sits inside Wolds Assure.
Does Cyber Essentials cover the MFA requirements introduced in April 2026?
Yes. The current Danzell (v3.3) scheme, mandatory for applications registered after 26 April 2026, requires MFA for all cloud services, not just remote access. This is a stricter requirement than the previous scheme version and is an auto-fail if not met. All Wolds Cyber engagements assess against the current Danzell requirements. If you were assessed under an older version, your renewal will need to meet the updated controls.
How long does Cyber Essentials certification take?
The initial call and gap assessment typically takes one to two days. Remediation time depends on how many gaps are identified and how quickly they can be addressed, some organisations are ready to submit within days, others take a few weeks. Once the evidence pack is submitted, basic CE is typically certified within a few working days. CE+ involves hands-on verification and takes longer end-to-end. The most expensive mistake is submitting before gaps are closed, the readiness assessment prevents that.
Can I just buy a Cyber Essentials certificate on its own?
Not from us. Wolds Certify includes CE, and Wolds Assure includes CE and CE+, alongside continuous monitoring, patch management, awareness training and £25k cyber insurance. See the Wolds Compliance page for full detail. We stopped selling bare certification because Danzell v3.3 auto-fails on missing MFA or a critical patch that is more than 14 days out of date, and those are things a point-in-time certificate cannot evidence.
Our IT company says they can do CE certification. Why use Wolds Cyber?
You get a fixed published price, a named security specialist for the whole engagement, and a certificate and report you own outright, issued through an IASME-accredited certification body and suitable for sharing with your insurer, a regulator, or a client doing due diligence. You can keep your existing IT provider for day-to-day support. And if you want security handled beyond a one-off certificate, we run it and show you it is working: a plain-English posture report every month, so your controls are provable, not just promised.
Ready to get Cyber Essentials certified?
The first step is a free 15-minute call. We confirm your organisation size, the right price band, and what the process involves, before any work starts. No commitment, no obligation.
Not sure where you stand? Take our free Cyber Essentials self-check first.