What we check

The externally-visible basics a buyer’s security questionnaire — or a Cyber Essentials assessor — looks at first.

Encryption & TLS

HTTPS, a valid SSL certificate and a modern TLS version — the first thing any questionnaire asks about.

Security headers

HSTS, CSP, X-Frame-Options and friends — the browser protections assessors expect to see set.

Information disclosure

Whether your server leaks its software and versions — a common questionnaire flag and a patch-hygiene signal.

Privacy policy

If you collect any personal data — even a contact form — UK GDPR expects a privacy policy that’s easy to find.

Cookie consent

Using analytics or tracking? UK cookie law (PECR, the Privacy and Electronic Communications Regulations) expects a consent mechanism before non-essential cookies load.

Contact & accessibility

A way to reach you (and, for limited companies, registered details), plus an accessibility statement.

This is a compliance indicator to help you spot gaps — it is not legal advice or a certification, and passing it is not a guarantee of compliance. It covers the technical, website-visible basics, not the policy, training and governance parts of a questionnaire.

Coming soon

Need Cyber Essentials or questionnaire help?

We fix and host the technical side today. Assisted Cyber Essentials readiness and supplier-questionnaire support are on the way — leave your email and we’ll tell you the moment they’re live.

No spam — one email when it launches. We never share your address.

Compliance questions

Is this a Cyber Essentials certification?

No. It's a free, plain-English readiness check of the technical basics a buyer's security questionnaire or a Cyber Essentials assessor looks at on your website. We're not a certification body — but we can fix the technical issues it finds, and an assisted readiness service is on the way.

Does the law force my small business to do this?

Usually the driver isn't the law — it's your customers. Supplier security questionnaires, and buyers asking for Cyber Essentials as a condition of a contract, are what push most small businesses to act. This check shows how your website measures up on the technical basics they look at.

What does the free scan actually check?

The externally-visible technical signals — HTTPS and TLS, security headers, version disclosure and cookie security — plus website basics like a privacy policy, cookie consent, contact details and an accessibility statement. It can't see the governance, policy and staff-training parts of a questionnaire — those sit with you.

Can you get me Cyber Essentials certified?

Not yet — we're building an assisted service for that. Today we fix and host the technical side, which is where most website-related questionnaire failures actually are (out-of-support software and unpatched systems are automatic Cyber Essentials fails). Join the waitlist to hear when the full service launches.

How is this different from the security scan?

The security scan is the deep technical audit — 24 checks with a downloadable report. The compliance check reframes the buyer-facing basics (what a customer's questionnaire or an assessor looks at) and adds website-basics checks like privacy policy and cookie consent. You can run both free.