Pebble IT Achieves Cyber Essentials Plus Certification: Strengthening security for our customers
Updated: Aug 2

Updated August 2026: this post was first published in March when we announced our certification. We've refreshed it now that the 2026 Cyber Essentials requirement changes are in force, because the questions clients ask us have changed with them.
We're proud to say Pebble IT is Cyber Essentials Plus accredited, the highest level of certification in the UK government-backed Cyber Essentials scheme.
Protecting our customers, our colleagues and the data we're trusted with has always been central to how we work. Achieving CE+ means those controls haven't just been implemented, they've been independently tested and verified by an external assessor. For a Managed Service Provider, that distinction matters: we hold the keys to our clients' systems, so our own security should be held to a higher standard than anyone's.
What is Cyber Essentials?
Cyber Essentials is a UK government-backed certification designed to protect organisations from the most common online threats. The National Cyber Security Centre (NCSC) recommends it as the minimum security baseline for every organisation.
The scheme is built around five technical controls proven to stop the majority of commodity cyber attacks:
Firewalls and internet gateways
Secure configuration
User access control
Malware protection
Patch management
These cover the weaknesses criminals most commonly exploit. Most attacks aren't sophisticated; they're the digital equivalent of trying the front door to see if it's unlocked.
What makes Cyber Essentials Plus different?
Cyber Essentials, the basic certification, is a self-assessment. Cyber Essentials Plus goes much further. CE+ involves hands-on technical testing by an independent auditor, including vulnerability scanning, device configuration checks, testing of security controls in real-world scenarios, and proof that policies are actually being enforced.
In short: CE says you follow best practice. CE+ proves it.
We've written a full comparison of the two, including which one your business actually needs, in our guide to Cyber Essentials vs Cyber Essentials Plus.
The 2026 changes are now in force
When we first published this post, the tightened Cyber Essentials requirements were on the horizon. They're now live, and they've made the scheme more rigorous and more meaningful. Businesses renewing their certification this year are finding questions that didn't exist last time, and evidence requirements that catch out anyone who treated CE as a box-ticking exercise.
That's a good thing. A certification worth having should be hard to blag. But it does mean preparation matters more than it used to, which is exactly where we come in: we take clients through Cyber Essentials readiness, remediation and submission, and having passed the toughest version of the audit ourselves, we know precisely what assessors look for.
Why this matters in Hertfordshire, Essex and London
The demand we're seeing locally isn't driven by enthusiasm for certificates. It's driven by three practical pressures. Public sector and council supply chains increasingly require Cyber Essentials before a supplier can even bid, which affects a lot of businesses across Hertfordshire and Essex working with local authorities and government frameworks. Larger London clients are pushing certification requirements down their supply chains, so firms that have never been asked before are suddenly being asked. And insurers are treating CE as evidence of basic competence at renewal time, with some pricing accordingly.
If any of those apply to you, certification stops being optional and starts being a commercial requirement with a deadline attached.
What this means for our customers
Our Cyber Essentials Plus certification gives customers confidence that we operate to a government-approved standard, validated independently rather than self-declared. It means secure configuration, patching, access control and endpoint protection aren't things we recommend and skip ourselves. And it means when we guide you through your own CE or CE+ certification, we're leading from experience, not from a checklist.
Security threats evolve quickly. CE+ isn't a badge for the website footer; it's proof of an ongoing commitment, re-tested every year.
How can we help you?
Whether you need Cyber Essentials certification support, a stronger cyber security setup, or managed IT support that has security built in rather than bolted on, we'd be happy to have a friendly chat. Reach out at hello@PebbleIT.co.uk or contact us on the website.




Comments