Compare

Cyber Essentials: do it yourself or use software?

An honest comparison. The DIY route is real and we won't pretend otherwise — here's what it actually takes, and where Kept earns its keep.

The DIY route, honestly

Cyber Essentials is a self-assessment. If your business is small, your accounts are individual, your devices are supported and multi-factor authentication is on everywhere, you can complete it without any software at all. What you're signing up for is the preparation around the questionnaire:

  • Scoping: listing every cloud service and device yourself, from memory and card statements
  • Policies: finding templates online, adapting them, and keeping versions straight
  • Controls: manually checking updates, accounts and multi-factor authentication on each service
  • Evidence: screenshots and notes in folders, rebuilt from scratch at renewal
  • Renewal: relying on your own calendar to notice the certificate expiring

Budget a few days of someone's time, and the same again every twelve months at renewal.

The Kept route

  • A free scan reads your connected cloud services and builds the register for you
  • The policies assessors ask for are drafted in the app, ready to adapt
  • Gaps across the five controls are flagged in one checklist
  • Dated evidence is logged as you go, so renewal starts from a current file
  • Automatic reminders at 90, 60, 30, 14, 7 and 1 day before expiry

Kept costs from £29 a month with a 14-day free trial and no card required. If your time is worth more than about an hour a month, the maths usually settles the question.

When DIY genuinely wins

If you enjoy this kind of admin, your setup is simple, and you're confident you'll remember renewal — do it yourself and spend the money elsewhere. Our free policy templates and readiness score are free whether or not you ever subscribe. If you start the DIY route and stall, Kept will still be here.

Common questions

Can I do Cyber Essentials myself without any tools?
Yes. The assessment is a self-assessment questionnaire, and a competent IT-literate person in a straightforward business can complete it alone. The parts that take time are writing the policies from scratch, keeping a record of your cloud services and devices, and remembering to gather fresh evidence when renewal comes round.
How long does the DIY route take?
For a small business with tidy accounts and supported devices, expect a few days spread over a few weeks: scoping your services, writing or adapting policies, checking the five controls, and answering the questionnaire. Most of the time is preparation, not the questionnaire itself.
Where do DIY attempts usually fail?
The common reasons submissions come back are missing cloud services in the scope, shared accounts instead of individual ones, unsupported software still installed, and multi-factor authentication not enforced everywhere it is offered. A failed submission means paying for and repeating the assessment.
What does Kept do that I can't do myself?
Nothing you fundamentally couldn't do by hand — it does the tedious parts for you. Kept scans your cloud services, drafts the policies assessors ask for, keeps a dated evidence register all year, and reminds you well before renewal. Most customers buy back the preparation days, not the knowledge.

Try both routes free

Run the free scan, download the templates, and see the full workspace before spending a penny.