Back to Blog
Business & Strategy
3 min read

Why We Got Cyber Essentials Certified Before Our First Client

ST
STACK46 Team
Engineering · 28 Aug 2026
Why We Got Cyber Essentials Certified Before Our First Client

Most agencies your size don't bother. Here's why we did it anyway.

Cyber Essentials is a UK Government-backed certification scheme, assessed independently through IASME, that verifies a business has real baseline cyber security controls in place — not a policy document nobody reads, but checked configuration: firewalls, access control, malware protection, patch management, secure configuration across every device and system that touches client work.

Most software agencies at our stage skip it. It costs time and money for a business with no external clients yet to justify, and nobody's asking to see it — yet.

We got certified anyway, because of what we actually do: write and run code that will eventually hold client data, client credentials, and client infrastructure access. If we're asking a client to trust us with any of that, "trust us" isn't good enough. A certificate assessed by a third party, that we could lose if we stopped meeting the bar, is a real commitment — not a marketing claim.

What it actually covers

Cyber Essentials assesses five technical control areas: firewalls and internet gateways, secure configuration, user access control, malware protection, and security update (patch) management. It's not a paperwork exercise — IASME's assessors check the actual state of the systems, not a policy binder.

What this means practically

Every engagement Stack46 takes on runs on infrastructure that's already been independently checked against a government-recognised baseline. That's true whether you're our first external client or our fiftieth. It's also why we can say, plainly, that data handling and security aren't things we're promising to figure out once we scale — they're things we already had assessed before we needed to.

The honest caveat

Cyber Essentials verifies baseline controls, not a guarantee against every possible incident — no certification does that. What it does verify is that we didn't skip the fundamentals to move faster. That's the bar we hold for every build, client or our own.

Frequently asked

What is Cyber Essentials?+

Cyber Essentials is a UK Government-backed certification scheme, independently assessed through IASME, that verifies a business has real baseline cyber security controls in place — checked configuration, not a policy document nobody reads.

What does Cyber Essentials actually check?+

Five technical control areas: firewalls and internet gateways, secure configuration, user access control, malware protection, and security update (patch) management. IASME's assessors check the actual state of the systems, not a policy binder.

Why did Stack46 get certified before having any external clients?+

Because Stack46's work involves writing and running code that will eventually hold client data, credentials, and infrastructure access — and an independently assessed certification, one that can be lost by not meeting the bar, is a stronger commitment than simply saying "trust us."

Does Cyber Essentials guarantee against every security incident?+

No. It verifies baseline controls, not a guarantee against every possible incident — no certification does that. It confirms the fundamentals weren't skipped to move faster.

Build with STACK46

Ready to put these ideas into practice? Let's talk about your project.

Get Started