Answer about 15 plain-English questions about your business and how you run your IT — a few more if you put Cloud, OT or AI Security in scope. You’ll see straight away whether certification is expected of you, how you score against the areas CSA actually assesses, what to fix first, and how much CSA funding you may qualify for. Nothing is sent anywhere — the result appears on this page.
Your overall score is every point you earned across the pillars in scope, divided by the points available. Each pillar is also scored on its own, so you can see where the work actually sits.
Book a free 30-minute consultation and we’ll walk through your result, confirm your funding entitlement, and give you a fixed timeline and price to the mark. No obligation, no jargon.
No — and it’s important to be clear about that. This is a free readiness indicator we built to help you understand where you stand before you commit to anything. The official Cyber Essentials assessment is a formal self-assessment certified by a CSA-appointed certification body, and it requires documented evidence for every requirement. Think of this page as the honest conversation before that process starts.
It’s a good directional indicator, based on your own answers about the nine core domains CSA assesses, plus the extra questions for any Cloud, OT or AI pillar you put in scope. A formal gap assessment goes considerably deeper, because an assessor works from evidence rather than self-reported answers — which is why businesses that score well here can still find gaps. Treat the score as a starting point, not a verdict.
Nothing leaves your browser. The assessment is calculated entirely on your own device, we don’t ask for an email address, and no answers are stored or sent to us. If you want us to see your result, use the “Email me this result” link — that opens your own mail app with a summary you can review and send.
Because certification runs on evidence. If you can’t confirm today whether MFA is enforced everywhere or whether a backup has ever been restore-tested, an assessor won’t be able to either. “Not sure” is treated as a gap until it’s verified and documented — and verifying it is usually quick.
From CSA’s published funding bands, using your endpoint count and the number of pillars you want in scope. Funding applies to the first successful Cyber Essentials certification per organisation, for SMEs and non-profits incorporated in Singapore, and is deducted directly from your certification fee. It runs until 6 February 2028. Figures are subject to CSA’s terms and eligibility — we confirm your exact entitlement before you commit to anything.
Not really. A low score means the basics aren’t in place yet, which is a very ordinary starting point for a growing SME — and it’s the same work that cuts your day-to-day risk, certification aside. None of the assessed areas requires exotic technology. It requires someone to work through them in order, which is exactly what we do.
OT stands for operational technology — the computers and controllers that run physical equipment, rather than the IT that handles information. Your IT is email, files, laptops and databases. Your OT is the controller inside a production line, a chiller or cold room, a lift, a conveyor, a CNC machine, or a building management, CCTV and door-access system.
In practice it applies to manufacturers, food and beverage producers, logistics and warehousing, marine and offshore, facilities managers and utilities. If you run a typical office business — an agency, a law firm, an accountancy, a consultancy, a software company — you have no OT, and you should leave that pillar unticked.
CSA assesses it separately for good reason. When IT fails you lose data or time; when OT fails, something physical stops or becomes unsafe. OT also tends to run older software that cannot simply be patched or rebooted while the line is running, and it is often reached remotely by the equipment vendor — a route into the business most owners have never thought about. It used to sit isolated from the internet, and increasingly it does not, which is why it became a pillar in 2025.
Possibly. Cyber Trust is the risk-based mark for larger and more digitalised organisations, with broader requirements. If your answers suggest it, we’ll flag it in your result. Most organisations still start with Cyber Essentials, and there’s no harm in doing so — but we’ll tell you honestly which one fits.
Want the full picture first? Read our guide to CSA Cyber Essentials — what it is, the nine domains, funding and how certification works.
Skip the questionnaire and speak to someone who does this every week. We’ll tell you in one call whether you need the mark, what it takes, and what it costs after funding.