HackRisk and Cyber Essentials: do you need both?
Cyber Essentials shows you met the UK government's baseline on the day your certificate was issued, and HackRisk Core keeps watching what attackers can see of your business for the rest of the year.
Cyber Essentials is the minimum standard of cyber security the UK Government recommends for organisations of all sizes. It checks five technical controls through a verified self-assessment, and Cyber Essentials Plus adds an independent technical audit. Certificates expire after 12 months. The scheme describes itself as a 'point in time' assessment, where that point is the date the certificate is issued.
HackRisk scans what attackers can see of your business, including your external assets, known vulnerabilities and credentials exposed on the dark web. It gives you a HackRisk Score. HackRisk Core adds continuous monitoring with instant email alerts. It is not a certification and does not replace the Cyber Essentials assessment.
For most organisations the answer is both. The certificate proves the baseline and opens doors to contracts, and monitoring helps you hold that baseline between renewals. Our Cyber Essentials Readiness tier puts certification and monitoring on one plan.
Why this question comes up
The question usually comes up in one of two ways. A customer, insurer or tender asks for Cyber Essentials, and someone asks whether a monitoring subscription is now redundant. Or you already monitor your attack surface and wonder what a certificate adds. The scheme's own rules help answer both.
Contracts ask for the certificate. IASME, the NCSC's delivery partner, says Cyber Essentials is required in a large number of central government contracts and an increasing number of local government contracts, and for Ministry of Defence suppliers across the supply chain that handles defence information. No monitoring tool, HackRisk included, can stand in for that.
The requirements changed in April 2026. Under version 3.3 of the requirements and the 'Danzell' question set, used for purchases from 27 April 2026, failing to use multi-factor authentication on cloud services where it is available is an automatic fail. So is failing to install high-risk or critical security updates within 14 days of release.
The declaration now covers the whole year. The board-level declaration signed as part of the self-assessment now includes a statement acknowledging your responsibility to maintain compliance with all Cyber Essentials controls throughout the certification period. The certificate is issued on one date, and the commitment runs for 12 months.
Plus testing is a sample. The Cyber Essentials Plus audit includes an internal and external vulnerability scan and tests a random sample of systems, typically around 10 per cent, before the Assessor decides whether more testing is needed.
The certificate answers one question: did you meet the baseline when you were assessed? Monitoring answers another: what can an attacker see of you today?
HackRisk in brief
HackRisk is a cyber risk monitoring platform for UK SMEs, built and run by the security experts at CyberLab. It scans your business from the outside, the way an attacker sees it, and turns everything it finds into one score: your credit score for cyber security.
Behind the score sits continuous monitoring of your external attack surface, dark web monitoring for stolen staff credentials, vulnerability scanning and supply chain checks. The results arrive as a report your board can actually read, with the fixes ranked by what needs attention first. Pricing is published: £49.99 a month for the Core plan on a 12-month commitment (£59.99 a month rolling), with a Cyber Essentials Readiness tier from £77 a month.
It starts with a free report. Enter your domain and you get a board-ready assessment within 24 hours, plus 30 days of full portal access, without handing over card details or sitting through a sales call.
HackRisk and Cyber Essentials at a glance
| HackRisk | Cyber Essentials | |
|---|---|---|
| What it is | External attack surface monitoring with a risk score and plain-English reports; continuous in HackRisk Core | A certification scheme developed by the NCSC and delivered by IASME |
| Timing | Continuous monitoring with instant email alerts (HackRisk Core) | A 'point in time' assessment, where the point is the date the certificate is issued. Certificates expire after 12 months |
| What it looks at | Your external exposure: external asset map, external vulnerability scanning and dark web credential monitoring. Core also includes an internal vulnerability scan of 5 endpoints | Five technical controls (firewalls, secure configuration, security update management, user access control, malware protection) across the scope you agree with your Certification Body |
| How it is checked | Automated scanning | Cyber Essentials: verified self-assessment confirmed by a senior person and marked by an Assessor. Plus: the same, with an independent technical audit |
| Vulnerability scanning | Included; repeated as part of continuous monitoring in HackRisk Core | Cyber Essentials Plus includes an internal and external vulnerability scan as part of its technical audit |
| What you get | HackRisk Score, regular and on-demand reports, prioritised resolution advice | A certificate and digital badge, listed in the public certificate search |
| Recognised in contracts | No; it is evidence of ongoing security work, not a certification | Yes; required in many central government contracts and for MoD suppliers handling defence information |
| Cost | Free report; Core £49.99/month on a 12-month commitment or £59.99/month rolling; Cyber Essentials Readiness from £77/month on a 12-month term | Cyber Essentials £320 to £600 + VAT by organisation size; Plus quoted individually (checked October 2026) |
| Insurance | Up to 10% cyber insurance discount | Free Cyber Liability Insurance arranged by IASME for UK organisations under £20m turnover that certify their whole organisation |
| Supply chain | Supplier invitations, supplier questionnaires and certification sharing, free | The NCSC calls on large organisations to improve adoption of Cyber Essentials in their supply chains |
| Who provides it | HackRisk, a trading name of Cyberlab Security Limited | Delivered by IASME, the NCSC's official delivery partner |
How they fit together
A certificate is a snapshot by design
IASME calls Cyber Essentials a 'point in time' assessment and, from April 2026, states that the point in time is the date the certificate is issued. The certificate then stands for 12 months, and the signed declaration commits you to keeping every control in place for that whole period.
HackRisk Core monitors continuously and sends instant email alerts. That is why the two sit well together.
Inside and outside views
Cyber Essentials covers five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. Cloud services must be in scope. A scope that doesn't include end-user devices isn't acceptable.
HackRisk looks from the outside, the way an attacker does. It shows exposed services, known vulnerabilities on internet-facing systems and leaked credentials. It cannot confirm whether your admin accounts are separated or every laptop runs anti-malware.
Where they help each other
On security update management, the scheme requires high-risk and critical updates within 14 days of release, and missing that is an automatic fail. HackRisk's vulnerability scanning flags known vulnerabilities on the systems it scans, which gives you an early prompt when something on your perimeter has fallen behind.
On credentials, Cyber Essentials requires multi-factor authentication on cloud services. HackRisk's dark web scanning tells you when your organisation's credentials appear in leaked data. Monitoring does not prove compliance, but it tells you where to look.
Plus testing and continuous scanning are different jobs
The Cyber Essentials Plus audit is a hands-on technical check: an internal and external vulnerability scan, then testing of a random sample of user devices, internet gateways and internet-facing servers. Since April 2026, failing the update test means a retest that also covers a new random sample.
HackRisk does not perform that audit and is not a substitute for it. HackRisk Core monitors continuously, which includes the time between audits.
When Cyber Essentials alone is enough
Cyber Essentials on its own can be the right call. It may be enough if:
- You need the certificate for a tender or a customer, and your IT provider already monitors your external exposure and applies updates promptly.
- Your internet footprint is small and rarely changes, and someone is clearly responsible for keeping it that way between renewals.
- Budget is tight. Self-led certification starts at £320 + VAT for organisations with 0 to 9 employees. The free Readiness Tool, the downloadable question set and the free 30-minute consultation with an NCSC-assured Cyber Advisor for eligible SMEs can all help you prepare.
- You want a one-off outside view before you apply, which the free HackRisk Report gives you without a subscription.
If you go it alone, download the Danzell question set early, check MFA on every cloud service and confirm your patching meets the 14-day rule before you submit. Both are automatic fails.
When you also want HackRisk
You will probably want HackRisk alongside your certificate if:
- You run internet-facing services such as websites, customer portals, remote access or cloud applications, where new exposure can appear between renewals.
- You want instant email alerts, which HackRisk Core includes, rather than finding out at your next assessment or after an incident.
- You are preparing for Cyber Essentials Plus and want to find external vulnerabilities before the Assessor's scan does.
- You want to show customers and insurers ongoing evidence, a HackRisk Score and regular reports, alongside an annual certificate.
- You check your own suppliers' security and want questionnaires and certification sharing in one place, through supply chain security.
See an example report to judge whether the output is useful to you, or get your own free report in 24 hours.
Doing both
The simplest way to do both is the Cyber Essentials Readiness tier, from £77 a month on a 12-month term. It includes everything in HackRisk Core, a dedicated account manager and security consultant sessions, plus help getting Cyber Essentials or Cyber Essentials Plus certified. That spreads the cost of certification across the year. A CE+ pre-assessment consultation is available as an add-on, price on request.
One sensible order is to start with the free HackRisk Report, fix what it finds on your perimeter, then work through the question set and certify. Keep monitoring running after the certificate is issued, and use the findings at renewal, when you enter all your answers again. If you would rather talk it through, contact us.
Frequently asked questions
If I have Cyber Essentials, do I still need HackRisk?
Cyber Essentials is a point-in-time assessment, and the declaration you sign commits you to maintaining every control throughout the 12-month certification period. HackRisk Core monitors your external exposure continuously and sends instant email alerts.
If I use HackRisk, do I still need Cyber Essentials?
If a contract, customer or insurer asks for it, yes. HackRisk is not a certification and cannot replace the Cyber Essentials assessment. Cyber Essentials is required in a large number of central government contracts and for Ministry of Defence suppliers handling defence information. It also checks controls an external scan cannot see, such as user access control and malware protection on your devices.
How much does Cyber Essentials cost?
IASME prices the self-assessment by organisation size: £320 + VAT for 0 to 9 employees, £440 + VAT for 10 to 49, £500 + VAT for 50 to 249 and £600 + VAT for 250 or more (checked October 2026). Cyber Essentials Plus is quoted individually, based on the size and complexity of your network. HackRisk's Cyber Essentials Readiness tier, which includes certification, starts at £77 a month on a 12-month term.
How long does a Cyber Essentials certificate last?
Cyber Essentials and Cyber Essentials Plus certificates expire after 12 months. IASME emails a reminder roughly a month before you need to recertify, and you enter all the information again each time, which works as an annual review.
What changed in Cyber Essentials in April 2026?
Version 3.3 of the requirements took effect on 27 April 2026, with a new question set called Danzell. Not using MFA on cloud services where it is available is now an automatic fail, as is not installing high-risk or critical security updates within 14 days of release. The requirements document makes clear that cloud services must be in scope. The 'point in time' is defined as the date the certificate is issued, and the signed declaration now covers ongoing compliance throughout the certification period. Applications started before 27 April 2026 can continue under version 3.2.
What does Cyber Essentials Plus include?
Cyber Essentials Plus includes a technical audit with an internal and external vulnerability scan and testing of a random sample of systems.
Can HackRisk certify me for Cyber Essentials?
The Cyber Essentials Readiness tier includes help getting Cyber Essentials or Cyber Essentials Plus certified. The HackRisk monitoring is separate from the assessment. Certification follows the scheme's process, marked by a qualified Assessor.
Is the free Cyber Essentials insurance the same as the HackRisk insurance discount?
No. UK organisations with a turnover under £20m that certify their whole organisation are entitled to free Cyber Liability Insurance arranged by IASME. HackRisk plans separately include up to 10% off cyber insurance. They are different benefits from different providers.
See your score before you decide anything
The quickest way to compare is to see what HackRisk finds about your own business: your HackRisk Score and a board-ready breakdown of what attackers can see, within 24 hours.
No card details, no sales call. Plans from £49.99 a month on a 12-month commitment, if you decide to keep monitoring.
Information about Cyber Essentials on this page was checked against ncsc.gov.uk and iasme.co.uk on 6 October 2026. If you spot something out of date, tell us and we’ll correct it.