2-sec is listed by the National Cyber Security Centre as assured to provide Cyber Advisor services (opens in a new tab), the NCSC standard for firms advising small and medium-sized organisations on the Cyber Essentials technical controls. The scheme is delivered by IASME as the NCSC's official delivery partner. 2-sec already certifies organisations to Cyber Essentials and Cyber Essentials Plus (opens in a new tab) as an IASME and CREST certification body.

What the NCSC Cyber Advisor Scheme Assures

The scheme assures two separate things, and most announcements about it blur them together.

A Cyber Advisor is an individual. IASME defines one as “a trusted cyber security expert (opens in a new tab), assured by the National Cyber Security Centre (NCSC), to help small and medium sized organisations implement the Cyber Essentials technical controls.” An Assured Service Provider is a company. The NCSC is explicit that the two are linked: “All Cyber Advisors must work for a company which has met the NCSC's standards and been accepted as an Assured Service Provider (opens in a new tab).”

So there is no such thing as a freelance Cyber Advisor. The individual passes an independent assessment; the firm behind them passes a separate one.

Designation Held by What the scheme says it means
Cyber Advisor An individual A cyber security expert assured by the NCSC to help small and medium-sized organisations implement the Cyber Essentials technical controls
Assured Service Provider A company A firm that has met the NCSC's quality and security standards and employs assured Cyber Advisors
Cyber Essentials Certification Body A company A firm licensed to assess and certify organisations against Cyber Essentials — a separate role from advising

2-sec sits on the company side of that table. The NCSC's own listing describes it as “an NCSC-approved Cyber Advisor company (opens in a new tab) providing cyber security guidance, and practical support to small and medium-sized organisations in the UK.”

The scheme is aimed at organisations IASME describes as a “small or medium-sized business (fewer than 250 employees)”, and it covers the five technical controls that Cyber Essentials is built on. It is worth being precise about the word too. The NCSC's own terms are assured and NCSC-approved. Not accredited. Accreditation is a different thing in a different system, and this scheme does not confer it.

Why the NCSC Cyber Advisor Scheme Exists

The gap the scheme addresses is not awareness of Cyber Essentials. It is implementation.

Most organisations that come to us already know they need the certificate, usually because a customer or an insurer has asked for it. What they do not have is anyone who can look at the estate they actually run and say which of the five controls it currently fails and what to do about it on a budget. That is a different job from assessing them, and until this scheme existed there was no way to tell a firm that could do it from a firm that said it could.

Can One Firm Both Advise You and Certify You?

Yes, and IASME says so directly. The scheme permits it.

IASME's guidance states that organisations seeking certification “will need to apply through a Cyber Essentials Certification Body”, and that “many Cyber Advisors work closely with a Certification Body or indeed, hold both roles themselves.” 2-sec now holds both. That is the practical value of this: advice and assessment under one roof, with no handover in the middle where the context gets lost.

It is also the obvious question to ask us, and you should ask it. A firm that advises you on the controls and then assesses whether you met them is marking its own homework unless it has a stated position on how those two engagements are kept apart.

What This Means If You Are Preparing for Cyber Essentials

Nothing changes about the standard itself. What changes is who you can check.

The NCSC and IASME both publish directories of assured providers, which means you no longer have to take a supplier's word for it. Check the NCSC's own listing for 2-sec (opens in a new tab), or search the IASME Cyber Advisor directory (opens in a new tab), before you engage anyone — us included. If a firm claims the designation and is not listed, that is worth a question.

If you are working through the controls now and want a second pair of eyes on scope before you commit to an assessment date, do get in touch (opens in a new tab). That conversation is usually short and it is free.

The certificate has never been the point. Passing it without changing anything is the failure mode the scheme was built to close.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top