Advanced IT Services · Transforming ICT capabilities for schools · 24/7 support across the UK

Cyber Essentials for Schools

Cyber Essentials is the fastest way for a school to prove — to governors, to the DfE, to insurers and to parents — that the basics of cyber security are done properly. We help schools and trusts across the UK achieve Cyber Essentials and Cyber Essentials Plus as part of our managed IT support, not as an extra project bolted on top. Our engineers already run your network, your devices and your updates, so most of the evidence the assessor needs is work we’re doing for you anyway.

Certification support is included with our service, not sold on top — and your ongoing compliance is tracked in AIT Horizon so it never quietly lapses.

Smiling pupil

Trusted by schools nationwide

249schools supported
20multi-academy trusts
75-strongteam
Est. 2000

What is Cyber Essentials — and what is Cyber Essentials Plus?

Cyber Essentials is a UK Government-backed certification scheme, run by the National Cyber Security Centre (NCSC), that certifies your school has five fundamental technical controls in place. It comes in two levels:

Cyber Essentials (CE) is a verified self-assessment. Your school answers a structured questionnaire about how its IT is configured, a senior leader signs it off, and a licensed assessor reviews the answers. Certification lasts twelve months.

Cyber Essentials Plus (CE+) covers the same five controls, but an independent assessor tests them hands-on — auditing a sample of your devices, running vulnerability scans and checking that what the questionnaire says is actually true on the ground. CE+ carries significantly more weight with insurers, auditors and trust boards, and it’s the level we recommend for multi-academy trusts and larger secondaries.

For most schools the honest barrier isn’t the assessment itself — it’s knowing whether your estate would pass, and fixing the gaps without disrupting teaching. That’s the part we do for you.

The five technical controls

Firewalls

every internet connection protected by a correctly configured boundary firewall, with no unnecessary services exposed.

Secure configuration

devices and software set up safely: default passwords gone, unused software removed, auto-run disabled.

User access control

staff and pupils have only the access they need; admin accounts are separated, controlled and protected with multi-factor authentication.

Malware protection

every in-scope device protected by supported anti-malware, application allow-listing or sandboxing.

Security update management

operating systems and applications licensed, supported and patched, with high-risk updates applied within 14 days.

Why schools are getting certified now

The DfE expects it.

The DfE’s digital and cyber security standards for schools map almost one-to-one onto the five Cyber Essentials controls. Certification is the cleanest way to evidence that you meet them.

Insurance and the RPA.

The DfE Risk Protection Arrangement's cyber cover conditions — offline backups, multi-factor authentication, cyber awareness training — sit squarely inside CE territory. Commercial cyber insurers increasingly ask for the certificate outright.

Funding and procurement.

A growing number of grants, contracts and framework bids ask whether your school or trust holds Cyber Essentials. Some now require it.

Schools are targets.

Education is one of the most-attacked sectors in the UK. The five controls are specifically chosen because they stop the commodity attacks — phishing-delivered malware, exploited unpatched systems, hijacked admin accounts — that account for the vast majority of school incidents.

Governors need assurance.

A current certificate is a plain-English answer to the question every board now asks: “are we on top of cyber security?”

How we get your school certified

1

Gap analysis

We assess your school or trust against all five controls: every internet connection, server, staff and curriculum device, cloud service and admin account in scope. You get a plain-English report showing exactly what passes today and what doesn't.

2

Remediation

Our engineers fix the gaps as part of your support service — tightening firewall rules, retiring unsupported operating systems, rolling out MFA, separating admin accounts, bringing patching into policy. We schedule disruptive work for evenings, weekends and holidays, exactly as we do for every other install.

3

Assessment

For CE, we prepare the self-assessment answers with you and support your senior leader through sign-off. For CE+, we get the estate audit-ready, then support the independent assessor's on-site and remote testing until you pass.

4

Certification and beyond

Your certificate lands, valid for twelve months — and the work that earned it becomes standing policy, tracked in AIT Horizon, so renewal is a formality rather than a scramble.

Because certification is assessed by an independent, licensed body, no provider can honestly guarantee a pass — what we guarantee is that we’ll keep fixing and re-testing with you until you get there.

AIT Horizon

Certification that doesn’t lapse — tracked in AIT Horizon

Most schools that achieve Cyber Essentials drift out of compliance within months — a new unsupported laptop here, a shared admin password there — and only find out at renewal. Our clients don’t, because their posture lives in AIT Horizon, the leadership platform included with our service, not sold on top.

  • RAG compliance tracker. Each of the five controls is broken into checkpoints with a red/amber/green status, so your Executive view shows at a glance that, say, 4 of 5 controls are green and security update management is amber because 12 devices (illustrative) are awaiting a patch window. Trust leaders see the same picture per school in the Schools view.
  • Policies. The access-control, patching and password policies your certification depends on are held in Horizon — versioned, dated and ready to hand to an assessor or auditor on request.
  • Strategy roadmap. Renewal isn’t a surprise: your CE anniversary, CE+ audit windows and any planned scope changes sit on the Horizon strategy roadmap alongside the rest of your IT plan.
  • IT Finance. Cyber Essentials fails schools most often on unsupported hardware and operating systems. Horizon’s IT Finance module ties your hardware refresh and software licensing schedules into 5-year projections — so replacing those ageing devices before they cost you your certificate is a budgeted line, not an emergency. A school can see, for example, that refreshing 30 out-of-support laptops (illustrative) falls in year two of its plan, costed and approved long before renewal.

Existing clients sign in through the Customer Portal to see their compliance position today.

Illustrative demo data

Cyber Essentials vs Cyber Essentials Plus

Cyber EssentialsCyber Essentials Plus
AssessmentVerified self-assessment questionnaireIndependent hands-on audit and vulnerability scans
Best forPrimaries and smaller schools starting outMATs, secondaries and independents needing strong assurance
Typical timescale with AITN4–8 weeks from gap analysis (illustrative)8–12 weeks from gap analysis (illustrative)
Validity12 months12 months (requires CE first)
Weight with insurers, auditors and bidsGoodStrongest

Not sure which level fits? Call 0115 9170 197 and we’ll advise honestly — plenty of schools should start with CE and step up to CE+ the following year.

Frequently asked questions

No — there's no blanket legal requirement. But the DfE's cyber security standards expect schools to have the same controls in place, the RPA's cyber cover conditions overlap heavily with them, and a growing number of funding streams, frameworks and insurers ask for the certificate. Practically, most schools now need to do the work either way — certification simply gives you the recognised proof.

The controls are identical; the checking isn't. CE is a verified self-assessment — you declare how your IT is set up and an assessor reviews the answers. CE+ has an independent assessor test it in practice: auditing sample devices, scanning for vulnerabilities and confirming your malware protection and patching actually work. CE+ costs more and takes longer, but it's materially stronger evidence, which is why trusts and larger schools tend to hold it.

It depends entirely on where you start. A school already on our managed service, with patching, MFA and access control in good order, can often go from gap analysis to a CE certificate in a matter of weeks; CE+ adds the independent audit on top. A school with an ageing estate and shared admin accounts should plan a term. The gap analysis is what tells you honestly — that's why we start there, free of charge, before anyone commits to a timescale. (All timescales illustrative — your readiness call will give you a real one.)

It shouldn't, and with us it doesn't. Most remediation — firewall changes, patching policy, MFA rollout — happens behind the scenes, and anything with classroom impact is scheduled for twilight sessions, weekends or holidays, the same way we handle every install across the 249 schools we support. Staff typically notice one change: signing in becomes slightly more deliberate, and considerably safer.

The certification fee itself is set by the scheme's delivery body and banded by organisation size — for a single school it's typically a few hundred pounds a year, with CE+ audit fees on top. The bigger variable is remediation: replacing unsupported devices or restructuring accounts costs whatever it costs. For our supported schools, the engineering work is part of the service — and Horizon's IT Finance module puts the hardware side into your 5-year budget so it's planned, not painful. Call 0115 9170 197 for a straight answer on your school's likely total.

Ready to get certified?

Whether you’re starting from scratch or renewing under pressure, a free readiness call will tell you exactly where your school stands against the five controls — and what it would take to close the gap.

Or call the team on 0115 9170 197.

Supporting 249 schools and 20 trusts across the UK since 2000.