Cyber Essentials for startups. From $2,000.

The certificate many United Kingdom (UK) public-sector contracts require to bid. A Cyber Essentials certificate is issued by an independent IASME licensed certification body, never by us. We build the program, the policies and the evidence behind it.

Made in the USA · Featured at Startup Grind

From $2,000
Platform onboarding
Certificate
a Cyber Essentials certificate
Scoped on a call
How you start
Independent
Issued by an independent IASME licensed certification body

What you get for Cyber Essentials.

The same platform every framework runs on, pointed at this one: your answers, your evidence, your documents.

Five control themes, scopedFirewalls, secure configuration, access control, malware protection and patching, each mapped to the devices and cloud services inside your boundary.
Self-assessment answers draftedThe questionnaire answers the certification body reviews, drafted from your intake with the device list, software versions and patch dates it expects.
Plus readiness packFor Cyber Essentials Plus, a pre-check of the sampled devices and an external scan rehearsal so the assessor's hands-on testing holds no surprises.

How Cyber Essentials runs here.

Four steps, in this order, with the handoff at the end.

  1. Step 1

    Inventory your devices in an afternoon

    The intake asks about laptops, phones, cloud services, admin accounts and update settings. Founders usually finish it in one sitting.

  2. Step 2

    Gap analysis against the five themes

    A deterministic analysis scores every device and service against the five themes and lists the fixes, usually patching, MFA and removing shared admin accounts.

  3. Step 3

    Fix, document and build the binder

    Configuration policies are drafted from your answers, you apply the fixes, and the evidence lands in one binder alongside the drafted self-assessment.

  4. Step 4

    Certify with a licensed body

    An IASME licensed certification body, arranged through partner firms, reviews your self-assessment. For Plus, its assessor also tests a sample of devices hands-on.

What Cyber Essentials costs.

Published where it can be published, and arranged with the firm that signs it where it cannot.

$2,000 one time for platform onboarding.

That is the intake, the gap analysis, your policies, the evidence binder and the handoff package.

A Cyber Essentials certificate is arranged with an independent IASME licensed certification body and quoted before it begins.

Cyber Essentials is certified only by an IASME licensed certification body, and the certificate must be renewed annually. Plus requires hands-on testing by the body's assessor. Polara Labs prepares you and is not a certification body.

Polara Labs is not a certification body. Certification audits are performed by independent accredited certification bodies.

Cyber Essentials questions.

What buyers ask, and what the work actually involves.

Platform onboarding starts at $2,000 and covers the gap analysis, policies, drafted self-assessment and evidence binder. The certification body's fee, and the assessor's testing for Plus, are arranged through partner firms and priced separately.
Basic is a verified self-assessment. Plus adds hands-on testing by the assessor: a vulnerability scan, device sampling and checks that malware protection works. Many UK central government contracts and any handling sensitive data require Plus.
Only if you sell into the UK public sector or to UK enterprises that pass the requirement down to suppliers. It is inexpensive relative to ISO 27001 and often clears a UK procurement gate on its own.
A certification body licensed by IASME, the scheme's delivery partner for the UK National Cyber Security Centre. Polara Labs prepares you; the body certifies you.

Unblock the deal.

Tell us where you are with Cyber Essentials and we will tell you what is left.

polara labs

Polara Labs builds both sides of the audit: the readiness platform startups use to earn a SOC 2 report, an ISO 27001 certificate or whatever their buyers ask for, and the practice OS audit firms use to run the examination. Every price is published on the page it belongs to.

© 2026 Polara Labs Inc. All rights reserved.Contact: founder@polaralabs.com

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms in our network; the audit opinion is theirs alone and is not regulated by Polara Labs. We generate custom policies, evidence checklists, and remediation guidance. You remain responsible for implementing controls and owning audit outcomes. Replace placeholders with your actual controls and have final documents reviewed by qualified professionals before your audit.