BrightCert Is Live: Cyber Essentials Readiness for UK SMEs
I have launched BrightCert, a Cyber Essentials readiness platform for UK SMEs.
The idea is simple: before a small business spends money on consultancy or applies for certification, it should be able to answer one practical question clearly:
How ready are we, and what do we need to fix first?
BrightCert helps answer that through a guided assessment, readiness scoring, gap analysis, and a report that can be shared with the people who need to act on it.
Why I built it
Cyber Essentials is important for UK businesses, especially SMEs bidding for contracts, working with larger customers, or trying to show that they take cyber security seriously.
But the preparation process can feel more confusing than it needs to be. Many teams do not have a dedicated security person. The language can feel technical. The five control areas are clear in principle, but translating them into practical business actions is where people get stuck.
BrightCert is designed for that gap.
It does not replace official certification. It does not issue the certificate. Official certification is handled by IASME-licensed Certification Bodies.
BrightCert helps businesses prepare before they reach that point.
What BrightCert does
BrightCert guides a business through a plain-English readiness assessment covering the five Cyber Essentials control areas:
- boundary firewalls and internet gateways
- secure configuration
- user access control
- malware protection
- security update management
The product then turns the answers into:
- an overall readiness score
- control-area scores
- plain-English gap findings
- priority fixes
- a downloadable PDF report
- preparation notes for next steps
The goal is not to overwhelm people with security jargon. The goal is to give business owners, operations managers, and IT providers a structured view of where they stand.
The launch offer
BrightCert is currently taking on the first 10 founding customers.
The full report is available at £99 instead of £199 for those first customers. In exchange, I am asking for honest feedback: what was clear, what was confusing, what helped, and what needs to be improved.
That feedback matters because this product should be shaped around real SME workflows, not assumptions made from the outside.
Who it is for
BrightCert is useful if your business:
- is bidding for a contract that asks for Cyber Essentials
- has been asked about security by a customer, insurer, or partner
- wants to understand its security gaps before applying
- needs a clear action list for an IT provider or internal team
- does not know whether it is ready and wants a straight answer
For many SMEs, the first problem is not fixing every control immediately. The first problem is understanding what matters most.
What this means for my work
BrightCert sits naturally alongside the rest of my work at Cognumi.
Cognumi is about secure AI-managed operations for service businesses. BrightCert applies that same thinking to a narrower, high-value security workflow: helping UK SMEs prepare for Cyber Essentials with clearer guidance and more actionable reporting.
My background is in cybersecurity research, and I have been building AI agents and automation systems around UK compliance workflows. BrightCert is the product expression of that work: focused, practical, and built for a real business problem.
The standard I want BrightCert to meet
BrightCert should be clear about what it does and what it does not do.
It helps businesses assess readiness, find gaps, and prepare. It does not guarantee a pass. It does not replace an official Certification Body. It does not pretend that every organisation has the same risk profile or technical setup.
The job is to make the preparation process easier to understand and easier to act on.
That is the product I wanted to exist for UK SMEs, so I built it.
You can try it at brightcert.co.uk.