Cyber Essentials & Cyber Resilience Act Readiness for Swadlincote & Burton upon Trent Businesses

More customers, suppliers, insurers, and tenders are asking the same question: can you prove your cyber security is up to scratch? Cyber Essentials is fast becoming the answer businesses are expected to have — and a new wave of regulation, from the UK’s Cyber Security and Resilience Bill to the EU Cyber Resilience Act, means “prove it” is only going to get more formal from here.CADS IT is based in Woodville, right on the doorstep of Swadlincote and a short drive from Burton upon Trent, and we offer two ways to get ahead of this instead of scrambling when a customer or a new law asks the question first: a guided, in-person or remote walkthrough of the Cyber Essentials questionnaire, and a readiness review against the cyber resilience rules coming down the track. Both are paid, expert-led services — not a form you’re left to fill in alone, and not a call centre reading from a script three counties away.

Cyber Essentials Review & Certification Support

What Cyber Essentials Is?

Cyber Essentials is the UK government-backed cyber security certification, run by IASME on behalf of the National Cyber Security Centre (NCSC). It checks five basic technical controls that stop the most common cyber attacks: firewalls, secure configuration, security update management, user access control, and malware protection.There are two levels:Cyber Essentials — a self-assessment questionnaire, verified by an independent assessorCyber Essentials Plus — the same five controls, checked with hands-on independent technical testing, for higher assuranceIncreasingly, businesses need one or both to win contracts (especially public sector and supply chain work), satisfy a customer’s due diligence, or qualify for cheaper cyber insurance. Organisations with turnover under £20 million also get complimentary cyber liability insurance included when they achieve full-organisation Cyber Essentials certification — a benefit a lot of businesses don’t realise they’re leaving on the table.

How Our Cyber Essentials Review Works

  • Initial scoping call — we confirm which parts of your IT estate are in scope, including any home or hybrid workers, cloud services, and BYOD devices
  • Guided questionnaire walkthrough — we sit with you (remotely or on-site) and go through every question, explaining what’s being asked and what evidence you need
  • Gap check before submission — we flag anything likely to fail against the current published standard before you submit, not afterSubmission support — you submit through IASME (or your chosen certification body) with confidence, and we’re on hand if the assessor comes back with questions
We can also help implement any fixes the questionnaire uncovers — patching, MFA rollout, device management — as separate, quoted work.Our Cyber Essentials Review service: from £450 + VAT, depending on the size and complexity of your IT setup.This is separate from the official certification fee, which is paid directly to your certification body and is priced by organisation size: currently £320+VAT (micro, 0–9 employees) up to £600+VAT (large, 250+ employees), correct as of 2026 — Cyber Essentials Plus is quoted individually based on your network. We’ll confirm exact current pricing with you before you commit to anything.

Cyber Resilience Act & Cyber Security and Resilience Bill — Readiness Review

What's Changing?
Two pieces of regulation are reshaping what “good enough” cyber security looks like for businesses that supply software, hardware, or digital services:The EU Cyber Resilience Act (CRA) applies to anyone manufacturing or supplying “products with digital elements” — software and connected hardware — into the EU market, from apps to smart devices. Reporting obligations for actively exploited vulnerabilities begin 11 September 2026, with the full set of cybersecurity requirements becoming mandatory from 11 December 2027. There are lighter-touch provisions for micro, small, and medium-sized businesses, but the direction of travel is the same for everyone: security has to be designed in and maintained, not bolted on.The UK Cyber Security and Resilience Bill is expected to expand the UK’s existing NIS Regulations, widening cyber security duties to more digital services, managed service providers, and the wider supply chains that support essential and important UK organisations. It’s still progressing through Parliament, so exact scope and dates are still firming up — but the direction is the same as the EU rules, and it’s worth planning for now rather than waiting for it to land.Even if neither applies to you directly today, if you sell into a regulated supply chain — or supply IT, software, or hardware to a business that does — expect customers to start asking you to demonstrate resilience well before the deadlines above hit.

What Our Readiness Review Covers

Review of your current cyber security controls against the direction of both the CRA and the UK BillAssessment of your software/hardware supply chain and third-party dependencies, where relevantVulnerability handling and incident-reporting readiness — can you actually detect and report a problem within the expected timeframes?A prioritised, plain-English action plan — what to fix now, what to plan for, and what to simply keep an eye onA written report you can show to customers, insurers, or your own board as evidence you’re taking this seriouslyOur Cyber Resilience Readiness Review: from £450.00 + VAT, scoped to the size of your business and whether products/software are involved.

Local to Swadlincote & Burton upon Trent

Cyber Essentials and cyber resilience reviews are often sold by national call centres who’ve never set foot in your building. We’re based in Woodville — a few minutes from Swadlincote town centre and around 15 minutes from Burton upon Trent — so where it helps, we do this face to face:On-site scoping and evidence-gathering for the Cyber Essentials questionnaire, rather than a phone call trying to talk you through your own firewall settings

    In-person Cyber Essentials Plus testing across Swadlincote, Burton upon Trent, Ashby-de-la-Zouch, and the wider South Derbyshire and East Staffordshire area
  • A face-to-face readiness review workshop for the Cyber Resilience Act/Bill assessment, useful if you want your team or board involved directly rather than reading a report cold<

Local knowledge of the businesses we’re already working with in Swadlincote, Burton, and the surrounding manufacturing, logistics, and retail sectors — many of whom are already being asked about cyber security by their own customers and supply chains

Why Get This Sorted Now

Contracts and tenders increasingly require it — Cyber Essentials is now a standard pre-qualification requirement for public sector and much private-sector supply chain workCyber Resilience Act reporting starts September 2026 — if you supply software or connected products into the EU, that deadline is closeCheaper insurance, fewer headaches — certified businesses often see better cyber insurance terms, and Cyber Essentials includes free cover for smaller organisationsBeing early is an advantage — get ahead of the Cyber Security and Resilience Bill before it’s a scramble, and before every customer is asking the same question at

Why Choose CADS IT

We do the IT work behind the certificate, too — patching, access control, malware protection, and secure configuration are all things we can fix directly, not just tell you aboutPlain English, no jargon — you’ll understand exactly what’s being asked and whyLocal and easy to reach — based in Woodville, on the doorstep of Swadlincote and minutes from Burton upon Trent, supporting businesses across the East Midlands for over 20 yearsOne relationship covers it — if a gap review uncovers a wider IT, network, or Sage-integrated systems issue, we can see the whole picture rather than just ticking a compliance box

Cyber Essentials is a self-assessment questionnaire verified by an independent assessor. Cyber Essentials Plus covers the same five controls but adds hands-on technical testing of your systems, giving customers and insurers a higher level of assurance.

The official certification fee is paid to your certification body and is set by organisation size — currently from £320+VAT for micro businesses up to £600+VAT for large organisations (Cyber Essentials Plus is quoted individually). Our review and walkthrough service is a separate, additional fee — we’ll always confirm both costs upfront before you commit.

If you bid for public sector contracts, supply larger businesses, handle customer data, or want better cyber insurance terms, it’s increasingly expected rather than optional. If you’re not sure whether it applies to you, that’s exactly what the initial scoping call is for.

It’s an EU regulation covering products with digital elements — software and connected hardware — sold into the EU. Reporting duties start September 2026, with full requirements from December 2027. It mainly affects manufacturers and suppliers of digital products, but businesses further down a regulated supply chain are increasingly asked to show similar readiness.

The UK Cyber Security and Resilience Bill is expected to widen existing cyber security duties (currently under the NIS Regulations) to more digital services and supply chains. It’s still going through Parliament, so we track its progress and build our readiness reviews around the latest published direction rather than guessing ahead of it.

Yes — patching, multi-factor authentication, device management, network segmentation, and secure configuration are all things we can implement directly, quoted separately once we know what’s needed.

A Cyber Essentials questionnaire walkthrough is typically wrapped up within a couple of weeks, depending on how quickly any gaps can be closed. A Cyber Resilience Readiness Review is usually a few days from scoping call to written report.

Swadlincote and Burton upon Trent are two of our closest and most regularly served areas — we’re based in Woodville, right between the two. We can visit in person for on-site scoping or Cyber Essentials Plus testing, or handle the whole process remotely if that’s easier for you.  We  have custoemrs in Birmingham, Tamworth,  Leicester, Coalville, Burton and Derby

Accordion ContentFor the certification itself, no — Cyber Essentials is standardised by IASME/NCSC regardless of who guides you through it. Where local helps is speed, being able to visit in person if you get stuck, and understanding the kinds of IT setups common among small to medium local business rather than working from a generic national script.