Cyber Essentials Self-Certification vs Assisted, the Honest Comparison
Net Sec Group is an IASME and NCSC certification body. We run both an assisted path for buyers who want help with the work and an open submission route for buyers who want to self-certify. This article is the honest comparison. Self-certification is the right path when four conditions hold; assisted is the right path when any one of them fails. We tell you which is which because we run both, and the structural integrity of the recommendation depends on us being willing to say "do it yourself" when that is the better answer.
The article sits on the comparisons hub. For the related question of working without an internal IT team (which is its own decision separate from self-vs-assisted), see Cyber Essentials without an IT team. For the longer comparison against ISO 27001, see Cyber Essentials vs ISO 27001 cost and time.
What "self-certification" and "assisted" actually mean
The Cyber Essentials self-assessment vs assisted distinction is about who fills in the SAQ, not about what the SAQ tests. Cyber Essentials is a self-assessment scheme administered by IASME through certification bodies. Every applicant submits a Self-Assessment Questionnaire (SAQ); the certification body reviews the SAQ and either issues the certificate, asks for clarifications, or rejects on findings. There is no path that bypasses the SAQ; the question is who fills it in and assembles the evidence behind it.
Self-certification path (sometimes called DIY): the applicant fills in the SAQ themselves, assembles the evidence themselves, and submits to a certification body for assessment. The certification body reviews and decides. The applicant pays the assessment fee plus IASME's certification fee.
Assisted path (sometimes called managed or consultant-led): the applicant works with an assisting party (a certification body's assisted-path engagement, a managed service provider, or an independent consultant) who walks them through the SAQ, helps assemble evidence, and reviews the answers before submission. Buyers searching for "Cyber Essentials with help" arrive here. The assisting party is also typically the certification body in the case of Net Sec Group, which means the SAQ review and the certification decision happen with the same team that helped prepare the submission. The applicant pays the assisted-path engagement fee, which includes the certification fee.
Both paths end at the same Cyber Essentials certificate. The certificate carries the same 12-month validity, the same IASME register entry, the same standing in UK procurement contexts.
The four-condition decision rule
Self-certification is the right path when all four of these conditions hold:
- Scope is clear: one office or fully cloud-only, no ambiguity about which entities, networks, or business units are in scope.
- MFA on cloud admin is already enabled: every administrator account on every cloud service has multi-factor authentication enforced today, with evidence available.
- Internal patching cadence already meets the 14-day window: critical and high-severity patches are demonstrably applied within 14 days of vendor release for in-scope devices.
- No procurement deadline tighter than 4 weeks: the firm has time to work through the SAQ, capture evidence, submit, respond to assessor clarifications, and receive the certificate without compressing the schedule.
If all four hold, self-certification is straightforward and the lower-cost path. The work is real but tractable; the CE Self-Assessment Tool and the Cyber Essentials Checklist 2026 (Danzell) on netsecgroup.io are the references that walk through what to capture per control.
If any one of the four conditions fails, the assisted path is the better answer. Each failed condition has a specific reason:
- Scope is unclear (multiple offices, complex cloud architecture, contractor populations): scope errors cause the highest-frequency self-cert rejections and the assisted path resolves scope at the engagement start.
- MFA not yet enabled on cloud admin: enabling MFA is straightforward but capturing the evidence in the format the assessor wants takes practice; the assisted path produces evidence the assessor accepts on first read.
- Patching cadence unclear: producing the patch-management console export and demonstrating the 14-day window is the single highest-frequency self-cert failure cause; the assisted path either produces the export or surfaces the gap before submission.
- Procurement deadline under 4 weeks: time pressure compresses the back-and-forth cycle that self-certification involves; the assisted path with a 12-hour fast-track engagement hits tight tender windows that self-cert cannot.
Work-hour estimates per path
These estimates draw from our 800-plus engagement history, calibrated to a 5 to 10 person UK SME with a Microsoft 365 plus AWS or Office-only profile.
Self-certification work, internal effort: 6 to 16 hours total, distributed across 1 to 4 weeks. The wide band reflects how much of the evidence is already captured incidentally (a firm running Microsoft Intune already has half the secure-configuration evidence; a firm without an MDM has to capture per-device manually). The work is the SAQ itself (2 to 4 hours), evidence collection (3 to 8 hours), self-review and tightening (1 to 2 hours), and submission plus assessor response cycle (1 hour each correction round, typically 1 to 2 rounds).
Assisted-path work, internal effort: 2 to 5 hours total, coordinated with the assisting party. The work shrinks because the assisting party drives the SAQ, requests evidence in the right format, reviews answers before submission, and handles the back-and-forth with the certification body's reviewer. The applicant's time is in scoping calls, evidence pulls (which the applicant has unique access to), and signoff at submission.
The assisted path costs more in cash and saves time. The self-certification path costs less in cash and consumes more internal time. The break-even depends on the hourly value of the time spent. For a founder whose time is the binding constraint on the firm's growth, the assisted path is typically the rational choice even when the four conditions hold.
What the certificate looks like, both paths
Same certificate. Same IASME register entry. Same legal standing in UK procurement contexts. The path the applicant took is not visible on the certificate; an assessor reading a self-cert SAQ does not give a different decision to one reading an assisted-path SAQ if the underlying evidence is the same.
The single pre-check that prevents the most preventable self-cert failure
Across our 800-plus engagements, the highest-frequency self-cert failure cause overall is MFA gaps on cloud admin (covered in why Cyber Essentials fails on the first try). MFA gaps need real remediation, not a pre-check. The next-most-frequent failure that a 30-minute pre-check can prevent is incomplete asset list. The applicant submits a SAQ that references devices that are not on the inventory, or omits devices that the cloud admin console reveals. The assessor flags the discrepancy and the SAQ goes back for correction.
The pre-check that prevents this: before submitting, pull the device list from your MDM (or from the device list in your identity provider if no MDM), the user list from your identity provider, and the cloud-services list from finance. Reconcile the three. The asset list referenced in the SAQ should match the union of the three sources. If it does not, the gap is the failure.
This pre-check takes 30 minutes and saves the back-and-forth round that adds 1 to 2 weeks of clock time. Self-cert applicants who run it submit cleaner SAQs and pass faster.
When the assisted path is genuinely the only sensible option
Three scenarios where the assisted path is not just preferable but the only sensible option:
-
The firm has not held a Cyber Essentials certificate before AND is pursuing CE Plus directly. CE Plus is the technical assessment day on top of the SAQ. Without a CE Basic certificate from a prior cycle, the firm has not demonstrated the SAQ-level controls and is unlikely to pass the technical assessment cold. The assisted path runs CE Basic preparation and CE Plus preparation as one engagement; self-cert tries to compress the readiness work and slips on the technical day.
-
The firm has a procurement deadline under 2 weeks. The 12-hour fast-track engagement is built for this case; self-cert cannot match the schedule because the SAQ-correction back-and-forth alone runs longer than 2 weeks for a first-time applicant.
-
The firm has previously failed a CE Basic submission and the failure cause was not surface-correctable. The assisted path uses the failure analysis to drive the next attempt; self-cert risks the same failure pattern.
Common questions
Can I switch from self-cert to assisted partway through?
Yes. If you start self-cert and discover the work is harder or the deadline is tighter than expected, contact the certification body and convert to the assisted path. The work already done (asset list, MFA evidence, patching report) carries forward; the cost difference is the assisted-path engagement fee minus the self-cert assessment fee already paid.
Does the assisted path increase the chance of passing?
Yes, and the reason is structural rather than the certification body cutting you slack. The assisted path catches evidence-format issues before submission, where the self-cert path catches them after the assessor flags them. Both paths fix the same issues; the assisted path fixes them faster and cleaner.
Does the assisted path remove my obligations?
No. The applicant is responsible for the controls actually being in place; the assisting party helps capture and present the evidence. The signatory at the applicant signs the SAQ; the IASME certificate is issued to the applicant, not to the assisting party.
What does Net Sec Group's assisted path cost?
Pricing is on the pricing page. The assisted-path engagement fee is the engagement price; there are no additional fees for re-tests inside the standard engagement window.
My company has a procurement deadline next week and I have not started anything. Self-cert or assisted?
Assisted, and specifically the 12-hour fast-track engagement provided your firm meets the six preconditions described in that article. If the preconditions do not hold, the assisted path with a 48-hour standard engagement is the next-fastest option. Self-cert with a deadline next week is not realistic for a first-time applicant.
Where do we book?
Book a Cyber Essentials assessment with Net Sec Group. The booking form lets you indicate whether you want self-cert submission review or the assisted path. The assessor responds with a confirmed engagement timeline.
Reference material
- Cyber Essentials Certification Guide
- Cyber Essentials Checklist 2026 (Danzell)
- Cyber Essentials Common Failures Guide
- Cyber Essentials Basic Options
- CE Self-Assessment Tool
Where this fits on this site
This article is the self-cert versus assisted spoke under the comparisons hub. The other comparisons spoke is Cyber Essentials vs ISO 27001 cost and time. For working without an IT team, the Cyber Essentials without an IT team spoke is on the scope-decisions hub. The timelines hub indexes the three engagement-speed paths once the self-cert versus assisted decision is settled.