Cyber Essentials is the certification most UK public-sector buyers and many larger private ones require of a supplier that touches their data. Its self-assessment is a set of facts about your IT: devices, sign-in, updates, malware protection, access. Rowpa holds those facts as a security profile you fill in once, and reads them back the way the scheme asks, area by area, ready to copy in.
Rowpa does not certify. Certification is through an IASME-licensed body; Rowpa gets you there with the answers in hand.
Rowpa is not a certification body and this is not the assessment. What it does is smaller and useful: the thirty-odd items the scheme cares about (MFA on email and cloud services, automatic updates within 14 days, no unsupported software, admin accounts separate, device encryption and locking, malware protection, firewalls) are the same items every supplier security questionnaire asks, so you answer them once in your security profile. The Cyber Essentials page then shows your answer beside each area, marks the ones where you said something the scheme would not accept, says which items you have not answered, and lists the inventory Rowpa does not hold: your device list with operating systems, every cloud service you use, how many people work remotely.
Since the 2026 question set, cloud services are in scope and passwordless sign-in counts. The mapping is versioned so a reissue of the questions is a data change, not a rebuild.
Free. The security profile and the Cyber Essentials reading are part of your record on every plan.
Every questionnaire, your pack, and the Cyber Essentials portal read from the same profile.
Build your security profile free