Penetration Testing
Manual testing for websites, applications, APIs, networks and technical environments where deeper assurance is required.
View ServiceDigital Safety CIC supports UK organisations that need Cyber Essentials, Cyber Essentials Plus or IASME Cyber Assurance guidance. Choose the right certification route, understand the requirements and get practical support before you submit or proceed to assessment.
Choose your service and organisation size to see the total price.
Optional support is available for Cyber Essentials customers who would like preparation help or guided completion support before certification.
Secure online payment


Secure checkout opens via Stripe.
Prices exclude VAT. VAT will be added at checkout where applicable.
Support for UK organisations preparing for Cyber Essentials, Cyber Essentials Plus or IASME Cyber Assurance.
Digital Safety CIC helps organisations understand the right certification route, prepare the required information and move through the next steps with clear guidance. Support can include readiness review, practical preparation, guided completion help and advice on what needs to be addressed before submission or assessment. Certification outcomes depend on the relevant scheme requirements and the formal assessment process.
Guidance for organisations completing the self-assessment certification route.
Support for organisations preparing for technical verification of Cyber Essentials controls.
Practical guidance for organisations considering IASME Cyber Assurance Level 1 or Level 2.
Digital Safety CIC supports UK organisations choosing between Cyber Essentials, Cyber Essentials Plus and IASME Cyber Assurance. These routes help organisations understand their cyber security position, evidence key controls and prepare for supplier or client assurance requirements.
A practical certification route for organisations that need to check and evidence core cyber security controls against the Cyber Essentials requirements.
A higher-assurance route for organisations that already hold Cyber Essentials and need technical verification of key controls.
A broader assurance route for organisations that need to consider governance, policies, documentation and cyber security controls.
A more detailed assurance route for organisations that need stronger evidence, governance review and a scoped approach before proceeding.
A practical certification route for UK organisations that need to evidence core cyber security controls.
Cyber Essentials helps organisations check whether essential cyber security controls have been considered and put in place. It is often used for supplier assurance, tender requirements, client confidence and internal risk management.
Digital Safety CIC supports organisations by helping them understand the requirements, prepare their responses and identify practical gaps before submission.
This route is suitable for organisations that need a clear starting point for cyber assurance without moving straight to a technical assessment.
Remote certification support and assessment guidance for smaller organisations.

Remote certification support and assessment guidance for growing organisations.

Remote certification support and assessment guidance for established organisations.

Remote certification support and assessment guidance for larger organisations with wider requirements.

Additional preparation and guided completion options are available for organisations that need extra help before certification.
A preparation session covering readiness, Cyber Essentials requirements, common gaps and practical next steps before submission.

Guided completion support using practical guidance to help organisations prepare responses and supporting information.

Technical assessment support for UK organisations that already hold Cyber Essentials and need stronger assurance that key controls work in practice.
Cyber Essentials Plus is the next step after Cyber Essentials when clients, suppliers, insurers or procurement teams need additional technical assurance.
Digital Safety CIC supports organisations by helping them understand the assessment requirements, prepare devices and users, and identify practical readiness gaps before testing.
This route is suitable for organisations that need technical verification of Cyber Essentials controls rather than self-assessment alone.
Cyber Essentials Plus assessment route for smaller organisations that are ready for technical verification.

Cyber Essentials Plus assessment route for growing organisations that need additional technical assurance.

Cyber Essentials Plus assessment route for established organisations with a wider technical environment.

Cyber Essentials Plus assessment route for larger organisations where scope and readiness need careful coordination.

Preparation support is available for organisations that need help improving readiness before Cyber Essentials Plus testing.
Scoped preparation support covering areas such as endpoint readiness, patching, firewall checks, malware protection and secure configuration.
Practical guidance for preparing Windows, macOS or Linux devices before Cyber Essentials Plus testing.
A targeted readiness review covering devices, users, patching, malware protection, firewalls, unsupported software and common failure points.
Before Cyber Essentials Plus proceeds, DS-CIC should confirm your Cyber Essentials certificate status, organisation size, assessment scope, device availability and any preparation support required.
If the organisation is not ready for technical testing, preparation support may be recommended before assessment is booked.
Cyber Essentials Plus requires your organisation to hold a valid Cyber Essentials certificate with at least 30 days remaining at the time of assessment.
A broader assurance route for UK organisations that need to evidence cyber governance, policies, controls and supporting documentation.
IASME Cyber Assurance Level 1 helps organisations evidence how cyber security is managed across governance, policies, procedures, controls and supporting information.
Digital Safety CIC supports organisations by helping them understand the requirements, review readiness and prepare the information needed before submission.
This route is suitable for organisations that need wider cyber assurance than Cyber Essentials alone, especially where clients, suppliers or internal governance teams expect more documented evidence.
IASME Cyber Assurance Level 1 route for smaller organisations preparing governance, control and documentation evidence.

IASME Cyber Assurance Level 1 route for growing organisations preparing governance, control and documentation evidence.

IASME Cyber Assurance Level 1 route for established organisations with wider policy, process and evidence requirements.

IASME Cyber Assurance Level 1 route for larger organisations where readiness and documentation may need more coordination.

Preparation support is available for organisations that need help understanding the IASME Level 1 questions, reviewing existing policies and preparing submission information.
Remote support to help organisations understand the IASME Level 1 questions, review existing policies and processes, organise answers and identify gaps before submission.
Guided completion support with structured prompts to help organisations prepare submission wording and understand what supporting information may be required.
Before IASME Cyber Assurance Level 1 proceeds, DS-CIC should confirm your Cyber Essentials certificate status, organisation size, readiness position and whether additional preparation support is needed.
If key information, policies or supporting evidence are not ready, preparation support may be recommended before submission.
IASME Cyber Assurance Level 1 requires your organisation to hold a valid Cyber Essentials certificate with at least 30 days remaining at the time of assessment.
A stronger audited assurance route for UK organisations that need deeper evidence, governance review and technical control validation.
IASME Cyber Assurance Level 2 is designed for organisations that need a more detailed assurance process than Level 1, including audit requirements, evidence review and validation of how cyber security controls are managed.
It can support supplier assurance, contract requirements, governance expectations and stronger customer confidence where a scoped audit route is appropriate.
Digital Safety CIC supports organisations by helping them understand the requirements, prepare evidence, identify readiness gaps and decide what needs to be addressed before the audited assessment route proceeds.
A scoped audited route involving review of cyber security processes, procedures, records, technical controls and supporting evidence.
Preparation support covering policies, procedures, records, technical controls and evidence readiness before the audited assessment route.
Support to organise audit evidence, including policies, risk records, asset information, access controls, backup records, incident response evidence, supplier records and governance artefacts.
DS-CIC should confirm certificate status, organisation size, audit scope, readiness position, evidence availability and whether preparation support is needed before a Level 2 quote is issued.
This prevents organisations from booking an audited route before key information, controls or evidence are ready for review.

Harvey leads Digital Safety CIC’s cyber security services, bringing extensive experience across both the public and private sectors, including roles as Lead Security Architect at Dyson and leadership positions within public sector security and digital forensics.
He specialises in cyber security architecture, risk management, and compliance, with a strong track record of delivering practical, standards-aligned security solutions across complex environments.
Supporting Harvey is a wider team of specialist practitioners, providing deep expertise across:
A clear route from choosing the right certification option through to preparation, assessment and next steps.
Digital Safety CIC keeps the certification process practical and clear. Whether you purchase a fixed-price option or request a quote for scoped support, DS-CIC will confirm your organisation details, selected route and readiness requirements before the next stage begins.
Select Cyber Essentials, Cyber Essentials Plus, IASME Cyber Assurance Level 1 or a quote-led IASME Cyber Assurance Level 2 route.
Fixed-price services can be purchased online. Scoped, technical, readiness or audit-led services are quoted individually after reviewing your requirements.
After payment or enquiry, Digital Safety CIC will contact you to confirm your organisation details, selected route and support requirements.
DS-CIC helps you understand requirements, identify practical gaps, prepare information and organise evidence for your chosen route.
Your selected route proceeds in line with the relevant scheme requirements, with DS-CIC confirming what is needed before assessment, submission or quotation.
Send an enquiry and Digital Safety CIC will help identify the appropriate certification route, preparation support and next steps.
Common questions about Cyber Essentials, Cyber Essentials Plus and IASME Cyber Assurance support from Digital Safety CIC.
These FAQs explain the main certification routes, prerequisites, pricing notes and next steps for UK organisations considering IASME Cyber Essentials support.
Cyber Essentials is a UK cyber security certification route that helps organisations check and evidence core technical controls. It is often used as a first step for supplier assurance, tender requirements and baseline cyber risk management.
Cyber Essentials has no prerequisite certification requirement.
Cyber Essentials Plus is the next step after Cyber Essentials. It gives stronger assurance because technical verification is involved, rather than relying only on self-assessment answers.
A valid Cyber Essentials certificate is required and should have at least 30 days remaining at the time of assessment.
IASME Cyber Assurance Level 1 helps organisations evidence cyber governance, security controls, policies, procedures and supporting documentation.
A valid Cyber Essentials certificate is required and should have at least 30 days remaining at the time of assessment.
IASME Cyber Assurance Level 2 is a stronger audited assurance route for organisations that need deeper evidence, governance review and technical control validation.
It requires both a valid Cyber Essentials certificate and a valid IASME Cyber Assurance Level 1 certificate, each with at least 30 days remaining at the time of assessment.
Cyber Essentials is usually the starting point for organisations that need baseline certification. Cyber Essentials Plus is suitable where technical verification is needed. IASME Cyber Assurance Level 1 and Level 2 are more suitable where wider governance, documentation or supplier assurance requirements apply.
If you are unsure, Digital Safety CIC can review your requirements and help identify the most appropriate route before you proceed.
Cyber Essentials has no prerequisite certification requirement.
Cyber Essentials Plus and IASME Cyber Assurance Level 1 require a valid Cyber Essentials certificate. IASME Cyber Assurance Level 2 requires both a valid Cyber Essentials certificate and a valid IASME Cyber Assurance Level 1 certificate.
Yes. Additional Cyber Essentials preparation support and remote guided completion support can be selected if your organisation needs extra help before certification.
These support options are intended to help organisations understand the requirements, prepare responses and identify practical gaps before submission.
No. The listed prices exclude VAT. VAT will be added at checkout where applicable.
Services marked as quote required are scoped individually before work begins.
Digital Safety CIC will contact you to confirm your organisation details, selected service, certificate status where relevant, support requirements and next steps.
For quote-led services, DS-CIC will review the scope before confirming pricing and recommended next steps.
Yes. Charities, CICs, schools and other UK organisations can use the enquiry form to ask about the most suitable certification route and support options.
Yes. If you are unsure which route is right for your organisation, use the enquiry form or call Digital Safety CIC on 0800 048 7322 before purchasing.
Choose a fixed-price certification route or request guidance if your organisation needs help selecting the right Cyber Essentials or IASME Cyber Assurance option.
Optional support is available for Cyber Essentials customers who would like preparation or guided completion help before certification.
Secure online payment


Secure checkout opens via Stripe.
Prices exclude VAT. VAT will be added at checkout where applicable.
This service requires your organisation to hold a valid Cyber Essentials certificate with at least 30 days remaining at the time of assessment.
Send an enquiry and the DS-CIC team will contact you to discuss scope, timing and next steps.
If you are unsure what type of testing you need, contact DS-CIC directly and we will help you define the right scope.
Digital Safety CIC can also support wider cyber security, data protection and website improvement work where your organisation needs practical help beyond certification.
Manual testing for websites, applications, APIs, networks and technical environments where deeper assurance is required.
View ServiceIdentify website weaknesses, exposed risks and common vulnerabilities before they become business issues.
View ServicePractical support with privacy, data protection governance, policies and compliance requirements linked to digital services.
View ServiceSecure website design, hosting, SSL, backups, malware scanning and ongoing website support.
View Service