Cyber Essentials + ISO 27701

Cyber Essentials compliance software, built by an auditor.

The PICMS Security Pack covers the five Cyber Essentials control areas plus ISO 27701 privacy management — designed for UK SMEs needing CE certification for tender qualification or as a stepping stone to full ISO 27001. £89/month, no separate ISO subscription required to get started.

Start 14-Day Trial Book a Demo

Five control areas, evidenced and current

Cyber Essentials is the UK government-backed scheme run by IASME — five technical control areas with a pass/fail self-assessment (CE) or independent verification (CE Plus). Most UK B2B contracts now demand CE as a baseline for any IT-handling supplier.

The CE assessment is essentially a yes/no questionnaire across five technical control areas. Each question maps to specific evidence — software inventory, firewall rules, user account list, MFA configuration screenshots, patch reports. The assessor isn't there to read your security policy; they're checking whether you can produce the evidence within minutes when asked.

Most UK SMEs come to CE on tender pressure — "we need CE certified by Q3 or we lose the contract" — and discover the evidence gathering is the hard part, not the controls themselves. PICMS is designed for that scramble. Upload your assets, point each one at the relevant control area, attach evidence (screenshots, exported reports, policy docs), and the assessment becomes a structured walk-through rather than a fire drill.

The five control areas

CE Area 1

Firewalls and routers

Boundary firewalls and internet gateways configured to deny insecure inbound traffic, with documented business justification for any open ports. Default passwords changed, admin access restricted.

CE Area 2

Secure configuration

Devices and software configured to reduce attack surface: unnecessary user accounts removed, default passwords changed, unused software uninstalled, auto-run/auto-play disabled where possible.

CE Area 3

Security update management

All software within scope kept up to date: licensed and supported, automatic updates enabled where possible, security patches applied within 14 days of release, end-of-life software removed.

CE Area 4

User access control

Account creation under formal process, separate admin and user accounts, admin privileges granted only when needed, MFA on cloud services and admin access, account removal when staff leave.

CE Area 5

Malware protection

Anti-malware tooling on all in-scope devices, automatic updates and scans, application allow-listing on servers, sandboxing for untrusted content where applicable.

Cyber Essentials Plus adds independent verification — an external assessor running their own scans and tests against your environment to verify the controls are actually configured as claimed. Most prime contractors require CE Plus rather than self-assessed CE.

Cyber Essentials evidence, structured for the assessor

5 CE Control Areas Mapped

Every CE question linked to a control area in PICMS. Evidence uploaded per question, dated, owner-attributed, reviewable by the assessor.

Asset Register

Devices, software, network gear inventoried. Each asset linked to its CE scope membership and to the control areas that apply.

User + Access Records

User account list with role, admin/standard split, MFA status, joiner-mover-leaver logs. CE Area 4 evidence in one place.

Document Control

Acceptable Use Policy, Information Security Policy, Patch Management Policy — version-controlled, approved, distribution tracked.

Incident Command Centre

Security incidents logged with chain-of-custody. CE doesn't mandate incident management but ISO 27701 does — PICMS covers both.

ISO 27701 PIMS

9 ISO 27701 PIMS clauses for privacy management — UK GDPR alignment, controller/processor records, data subject rights tracking, transfer impact assessments.

Security Awareness Training

Per-person training records with expiry tracking. Phishing test results, induction completion, refresher cycle.

Pathway to ISO 27001

CE → ISO 27001 is a common upgrade path. PICMS makes the transition incremental — your CE evidence becomes 27001 Annex A evidence without re-uploading.

What PICMS does not do

Auditor-credible vendors don't pretend software replaces engineering. PICMS does not:

  • Configure your firewalls, MFA, or patch management. Those are real engineering tasks for your IT team or MSP.
  • Issue your CE / CE Plus certificate. Only an IASME-accredited assessor does that. PICMS gets your evidence audit-ready.
  • Run vulnerability scans for you. CE Plus requires an independent external scan; you'll engage a CREST-accredited tester for that.
  • Replace your DPO under UK GDPR. ISO 27701 supports the DPO role; it doesn't replace it.

What PICMS does is give you, your team and your assessor a single source of truth — so the certification visit is a verification exercise, not a documentation hunt.

Who PICMS Cyber Essentials is built for

  • UK SMEs facing tender pressure — public sector contracts, B2B supply chain demands, cyber insurance pre-conditions all increasingly require CE / CE Plus.
  • Organisations stepping up to ISO 27001 — CE gives you the technical-controls foundation; PICMS makes the upgrade to a full ISMS incremental rather than a fresh build.
  • Privacy-conscious organisations — UK GDPR alignment via ISO 27701 PIMS is bundled in the same £89/mo subscription. No separate privacy tool needed.
  • ISO consultants managing multiple CE / 27701 clients — see PICMS Partners.

Pricing

PICMS Cyber Essentials uses the Security Starter tier:

  • Security Starter — £89/month. 5 users, Cyber Essentials and ISO 27701 included, core compliance modules (incidents, documents, training, audits). Designed as a tender-qualification entry point — most SMEs upgrade to Professional once they add ISO 27001.
  • Professional — £449/month. If you're stepping up to ISO 27001 alongside CE, Professional includes 3 ISO standards, 15 users, autonomous AI evidence agents, one industry pack.

See full pricing →

Related reading

Get CE-certified without the spreadsheet scramble.

14 days free, full feature access, no credit card surprise. Built by an IRCA Registered Principal Auditor — auditor-credible from day one.

Start Free Trial Book a Demo