Allied ESM has been certified against the Cyber Essentials scheme, with a scope covering the whole organisation.

Certified
4 August 2026
Scope
Whole organisation
Recertification due
4 August 2027
Certification body
Shonsys Limited
Issued by
The IASME Consortium Ltd

What Cyber Essentials actually is

Cyber Essentials is a certification scheme backed by the UK Government and owned by the National Cyber Security Centre, delivered by the IASME Consortium. It verifies that an organisation has five technical controls properly in place:

  • Firewalls
  • Secure configuration
  • User access control
  • Malware protection
  • Security update management

Those five controls are not glamorous, and that is rather the point. The NCSC's position is that they defend against the overwhelming majority of common internet-based attacks — the opportunistic, automated attacks that make up most of what any organisation actually faces. Certification is a verified self-assessment, reviewed and graded by an accredited certification body, and it has to be renewed every year.

Why the scope matters more than the badge

The line worth reading on any Cyber Essentials certificate is the scope. Plenty are issued against a single department, a single office, or one isolated system — which is perfectly legitimate, but it means the controls have only been verified for that slice of the business.

Ours covers the whole organisation. Every device, every user, every system we use to deliver client work sits inside the certified boundary. For anyone assessing us as a supplier, that removes the follow-up question about what was actually in scope.

What this means if you work with us

Two practical things.

If you run supplier due diligence, the certificate answers a standard set of questions without a bespoke exercise. It can be verified independently on the IASME registry rather than taken on trust, and we will send a copy on request.

If you are in the public sector, it matters more directly. Central government contracting rules require suppliers handling certain categories of government data to hold Cyber Essentials. Allied ESM now meets that requirement in its own right, so we can be appointed for delivery work without an exception being sought.

A note on Halo

Worth being precise here, because the two are often conflated. This certification is Allied ESM's, as the delivery partner. It says nothing about the Halo platform, which holds its own independent certifications including ISO 27001:2022, Cyber Essentials Plus and SOC 2 Type 2. If you are evaluating a Halo deployment you are looking at two separate organisations with two separate security postures — and both now stand up to scrutiny.

What comes next

Cyber Essentials is a baseline, not a destination. Work towards ISO/IEC 27001 is already underway, and our information security practices are aligned to that standard while we get there. We will publish an update when it is certified rather than before.

Further reading

Our Information Security Policy → Halo for UK Public Sector → About Cyber Essentials — NCSC →
← Back to News