Our process
Cyber Essentials: doing it yourself vs using an advisor
Self-assessment is a genuinely viable route for a lot of small businesses, not just a budget option. If your setup is simple (one office or fully cloud-based, standard laptops and phones, a small number of well-understood SaaS tools) and someone on your team is comfortable reading the question set carefully, there's no real reason you can't do this yourself.
Where an advisor tends to earn their fee is scoping ambiguity, not the questions themselves. Remote and hybrid teams, personal devices used for work, contractors with their own laptops, multiple legal entities sharing infrastructure: these are the setups where it's genuinely easy to scope something wrong, either leaving a real gap in or pulling in more of your business than the certification actually needs to cover.
Where an advisor tends to earn their fee is scoping ambiguity, not the questions themselves.
The other place advisors save time is the specific failure points that catch people out even when they've read the question set properly: MFA that's enabled for the main login but not for the free tools the team also uses, a patch that technically got applied but outside the 14-day window for critical updates, or an admin account that never got separated from someone's everyday login. Knowing to check these before submitting is the difference between a clean pass and a resubmission.
Worth knowing
A quick way to tell which camp you're in: run the free 5-minute check. If it comes back clean, you're probably fine to self-assess. If it flags scoping questions you're not sure how to answer, a free 30-minute call will usually resolve them faster than working through it alone.