Cyber Essentials Companies in the UK: Providers and Support Guide
AC
Acumon Chartered Accountants·12 min read
Preparing for Cyber Essentials is not simply a matter of installing antivirus software or changing a few technical settings. For growing companies, corporate groups and regulated organisations, it often forms part of a wider review of cyber risk, operational controls, financial compliance and corporate security.
The UK has a broad mix of Cyber Essentials providers, from specialist cybersecurity consultancies to managed IT firms and wider compliance practices. Some focus mainly on certification, while others deal with technical remediation, risk reviews, staff awareness and longer-term security planning.
This guide highlights a selection of companies providing Cyber Essentials services in the UK. It is not a ranking. The aim is to give organisations practical context on how different providers work, what they cover and the type of support available before, during and after certification.
Acumon
Acumon is a UK firm of chartered accountants and registered auditors providing Cyber Essentials services to companies, charities, and international corporate groups.
The firm works with organisations ranging from growing owner-managed businesses and charities through to larger corporate groups and regulated entities. Cyber Essentials engagements are delivered through a structured approach focused on reviewing technical controls, identifying security gaps, and preparing organisations for certification.
Acumon supports organisations working towards Cyber Essentials and Cyber Essentials Plus certification. The Cyber Essentials scheme focuses on five technical control areas: firewalls, secure configuration, security update management, user access control, and malware protection. Cyber Essentials Plus includes additional technical verification of the controls implemented across the organisation.
For growing businesses, corporate groups, and regulated organisations, Cyber Essentials preparation extends beyond antivirus software or isolated IT settings. It forms part of a wider review of technology risk, financial compliance, operational resilience, internal controls, and corporate security. This broader approach helps ensure that cybersecurity responsibilities are aligned with governance structures, reporting processes, regulatory obligations, and the organisation’s overall risk framework.
In addition to its UK audit registration, Acumon also holds audit licences in several international financial centres, including the Cayman Islands, British Virgin Islands (BVI), Jersey, and Isle of Man. This experience enables the firm to support international corporate groups where entities, systems, and operational teams are located across multiple jurisdictions.
Acumon works with finance teams, IT teams, and boards to support Cyber Essentials certification while also helping organisations strengthen cybersecurity processes, governance arrangements, financial compliance, corporate security, and internal controls as they grow.
Cyber Essentials Capabilities:
Acumon provides Cyber Essentials services across a wide range of organisational structures and sectors.
These include:
UK limited companies and corporate groups
Public Interest Entities (PIEs) and regulated organisations
UK subsidiaries of international groups
charities and not-for-profit organisations
owner-managed businesses preparing for Cyber Essentials certification
offshore holding companies and investment vehicles
Cyber Essentials engagements are led by senior professionals with direct involvement throughout the engagement.
Regulatory Licences and Registrations:
Acumon holds several audit registrations that enable it to support organisations operating across multiple jurisdictions.
These include:
UK statutory audit registration
Public Interest Entity (PIE) audit licence
Jersey audit licence
Isle of Man audit licence
Cayman Islands audit licence
British Virgin Islands audit licence
These registrations support the firm’s work with groups that include entities in both the UK and key international financial centres.
Core Services:
In addition to Cyber Essentials support, Acumon provides a range of services that support cybersecurity, technology risk, and governance.
These include:
Cyber Essentials readiness reviews
Cyber Essentials certification support
Cyber Essentials Plus preparation
cybersecurity gap assessments
IT controls and technology risk reviews
internal audit and governance reviews
risk management and compliance support
Cyber Essentials work is delivered alongside discussions with management and boards regarding cybersecurity processes, technology controls, and governance frameworks.
Many organisations first encounter Cyber Essentials requirements when they begin working with public sector bodies, regulated clients, larger corporate customers, or supply chain partners that require recognised cybersecurity certification.
Acumon works with businesses that are:
approaching their first statutory audit
preparing for external investment
expanding into international markets
operating within corporate group structures
Early engagement with a Cyber Essentials adviser helps ensure that systems, devices, user accounts, software updates, and security documentation are aligned with certification requirements and integrated into the organisation’s wider risk, financial compliance, and corporate governance framework.
Address: 1-2 Craven Road, Ealing, London, W5 2UA, UK
RSM UK
RSM UK is an audit, tax and consulting firm with a cyber risk practice within its wider risk and governance work. They examine how cyber threats affect strategy, business transformation and operational delivery, rather than treating security as an issue owned only by the IT department. Their work involves boards, senior executives and operational leaders with different responsibilities for managing risk.
Their cyber resilience services place particular weight on governance, accountability and continuity during an incident. They work with leadership teams to clarify oversight responsibilities, shape board-level discussions and review how security decisions are made across the organisation. This work sits alongside their broader consulting services in risk, governance, investigations and business transformation.
PwC UK is a professional services firm working across audit, consulting, deals, risk and tax. They deal with public, private and third-sector organisations, bringing together technology, regulatory and sector knowledge for projects involving business change, compliance and risk. Their cyber security work forms part of a wider technology practice rather than operating separately from broader organisational priorities.
They approach technology work through both value creation and protection. This means looking at security alongside transformation, cost management, regulation and trust. Their teams work with organisations ranging from growing private businesses to public bodies and multinational groups, adapting the scope of each engagement to the systems, risks and governance structures involved.
Key Highlights:
Multidisciplinary professional services firm
Dedicated technology and cyber security capabilities
Work across public, private and third sectors
Combined technology and risk expertise
Regulatory and compliance knowledge
Access to broader audit and consulting teams
Services:
Cyber security services
Technology consulting
Risk consulting
Digital transformation
Regulatory compliance
Audit and assurance
Deals advisory
Tax services
Contact Information:
Website: www.pwc.co.uk
Phone: +44 (0)14 1355 4000
Address: 120 Bothwell Street, Glasgow, G2 7JS
Instagram: www.instagram.com/pwc_uk
Facebook: www.facebook.com/PwCUK
LinkedIn: www.linkedin.com/company/pwc-uk
S&W
S&W is an accountancy and advisory firm with a digital team specialising in cyber security. They combine technical, regulatory and business knowledge across strategy, protection, detection, response and recovery. Their consultants work across networks, applications and cloud environments, while remaining independent of individual technology vendors.
Their assignments range from individual technical reviews to complete security programmes. They assess existing controls, develop cyber strategies, design security architecture and deal with regulatory requirements across different industries. They also work with organisations during transactions, internal change, security incidents and periods of rapid growth, when systems and responsibilities often need closer review.
Key Highlights:
Independent cyber security advice
Partner-led delivery
Technical and regulatory expertise
Vendor-agnostic approach
Strategy, assurance and recovery capabilities
Experience with organisational and system change
Services:
Cyber strategy and transformation
Security architecture and engineering
Cyber governance, risk and compliance
Technical assurance
Security certification support
Identity and access management
Incident response
Resilience and recovery
Network, application and cloud security
Contact Information:
Website: www.swgroup.com
Phone: +44 117 233 2200
Address: 45 Gresham Street, London EC2V 7BG
Twitter: x.com/S_W_Group
LinkedIn: www.linkedin.com/company/swgroupuk
BDO UK
BDO UK is an accountancy and business advisory firm providing audit, tax, deals, consulting, risk and outsourcing services. They mainly work with entrepreneurial and growing organisations, covering businesses at different points in their development. Their advisory teams bring financial, operational and technical work together when clients are dealing with business change or more complex risk requirements.
Cyber security and data protection sit within BDO Digital, alongside their wider consulting and risk capabilities. Their work is informed by the organisation's operating model, regulatory duties and use of technology rather than security being considered in isolation. They also draw on audit, governance and outsourcing expertise where cyber controls affect reporting, accountability or third-party arrangements.
Key Highlights:
Accountancy and business advisory firm
Cyber security and data protection practice
Focus on growing and entrepreneurial organisations
Combined digital and risk capabilities
Wider audit and governance expertise
UK and Ireland office network
Services:
Cyber security services
Data protection services
Digital consulting
Risk consulting
Governance advisory
Audit and assurance
Outsourcing
Tax and deals services
Contact Information:
Website: www.bdo.co.uk
Phone: 0161 817 7500
Address: Eden Building, Irwell Street, Salford, Manchester, M3 5EN, United Kingdom
LinkedIn: www.linkedin.com/company/bdo-llp
Instagram: www.instagram.com/bdo_uk
Grant Thornton UK
Grant Thornton UK is an audit, tax and advisory firm working with organisations facing growth, regulation and operational complexity. Their advisory model places senior professionals directly into client work, with technology used to handle routine analysis while advisers focus on judgement, decisions and practical recommendations.
Cyber is one of the firm's core consulting areas, alongside financial services advisory, forensics, government work, restructuring and deals. Their cyber teams work within this broader advisory structure, drawing on knowledge from risk, regulation and business operations. This gives clients access to specialists beyond the immediate security engagement when wider organisational issues need attention.
Fig Group is a UK compliance and cybersecurity business providing certification, assessment and governance services. They operate as an IASME-licensed certification body for Cyber Essentials, Cyber Essentials Plus and Defence Cyber Certification at Levels 0 and 1. Their certification process uses published pricing, defined scopes and direct access to assessors, with a six-working-hour turnaround guarantee for compliant Cyber Essentials submissions.
Alongside certification, they run a governance platform that brings controls, evidence, risk registers, supplier assurance, incidents, policies and reporting into one system. They work with corporate teams, managed service providers and organisations in sectors including accountancy, financial services, education, healthcare and defence. Their platform also connects with external systems and maps evidence across multiple compliance frameworks.
Key Highlights:
IASME-licensed certification body
Cyber Essentials and Cyber Essentials Plus assessments
Defence Cyber Certification at Levels 0 and 1
Public pricing and defined assessment scopes
Governance platform for compliance, risk and evidence
Address: 167-169 Great Portland Street, London, W1W 5PF
URM Consulting Services
URM Consulting Services is an information security and risk consultancy that is now part of Cooper Parry. They work across cyber security, data protection, business continuity and risk management, combining consultancy with technical testing, auditing, training and their Abriska risk management software. Their consultants include cyber essentials assessors, penetration testers, data protection specialists and ISO implementation and audit practitioners.
They are licensed by IASME to assess organisations for cyber essentials and cyber essentials plus. Their work covers preparation, remediation and formal certification, with technical testing available for networks, infrastructure, web applications, mobile applications and cloud environments. They also carry out internal audits, supplier audits and PCI DSS assessments, while helping organisations manage related standards such as ISO 27001, ISO 22301, SOC 2 and NIST.
Key Highlights:
IASME-licensed certification body
Cyber essentials and cyber essentials plus assessors
Address: Davidson House 1st Floor, The Forbury, Reading RG1 3EU
Facebook: www.facebook.com/URMConsulting
Twitter: x.com/URMconsulting
LinkedIn: www.linkedin.com/company/urm-consulting
Instagram: www.instagram.com/urmconsulting
ITWiser
ITWiser is a Yorkshire-based managed IT provider working with small businesses and larger organisations. They operate as a managed service provider, value-added reseller and IT solutions provider, looking after servers, networks and everyday technology requirements. Their delivery model is largely proactive, with remote monitoring used to identify technical problems before they disrupt normal work.
They also maintain in-house expertise across IT and network security and operate as a cyber essentials certification body. Their advice is not tied to individual vendors or sales targets, so they assess the wider market when recommending systems and security measures. Their managed services are adjusted around the size, infrastructure and practical needs of each client.
Address: 34 Bradford Chamber, Business Park, New Lane, Bradford BD4 8BX
ITPS
ITPS is a UK technology company delivering managed services, cyber security, cloud infrastructure, communications and data services. They work with public, private and not-for-profit organisations, handling both ongoing IT operations and complex technology projects. Their teams design and manage systems that give authorised users access to business data while maintaining security, availability and continuity.
Their cyber security practice includes cyber essentials services alongside wider protection, resilience and recovery work. They also provide cloud, network and data centre services, giving their security teams direct visibility of the infrastructure being assessed. Their work spans sectors such as healthcare, education, charities, housing, manufacturing, legal services and financial services.
Key Highlights:
UK technology and managed services provider
Dedicated cyber security practice
Experience across public and private sectors
Cloud and infrastructure expertise
ISO 9001, ISO 20000-1 and ISO 27001 certified
Security and operational services delivered together
Address: Unit 5, Angel Park, Drum Industrial Estate, Chester-le-Street, County Durham, DH2 1AQ
LinkedIn: www.linkedin.com/company/itps
Conclusion
Choosing a Cyber Essentials provider depends on how much work needs to happen before the assessment. Some organisations are already close to meeting the required controls and mainly need certification. Others need a deeper review of systems, access, policies, staff practices and technical weaknesses before they are ready to proceed.
For growing companies, corporate groups and regulated entities, preparing for Cyber Essentials is not simply about configuring antivirus software. It often sits within a wider review of cyber risk, financial compliance, internal controls and corporate security. This guide helps organisations compare different providers by looking at how they work, what they assess and how much practical support they offer throughout the process.
AC
Written by the Acumon team
Acumon is an ICAEW-registered firm of chartered accountants and registered auditors
based in London, with offices in Pitstone, Aylesbury and Bournemouth. Need advice on
anything covered here? Talk to us.
An internal audit function must be assessed by a qualified, independent assessor at least once every five years. That requirement is Standard 8.4 of the Global Internal Audit Standards, which…
An internal audit function must be assessed by a qualified, independent assessor at least once every five years. That requirement is Standard 8.4 of the Global Internal Audit Standards, which…
An internal audit function must be assessed by a qualified, independent assessor at least once every five years. That requirement is Standard 8.4 of the Global Internal Audit Standards, which…
Read article
Get in Touch
Ready for Accountants Who Move Your Business Forward?
Tell us what you need. Within one business day, a qualified accountant will be in touch to talk it through and give you a clear, fixed-fee quote — no obligation.
We use essential cookies to run this site, plus Google Analytics and Google Ads to
understand how visitors use it and measure our advertising — only with your consent. See our
Privacy Policy.