Our Cyber Essentials certification
Our users are accident management companies, credit hire operators and law firms, working live claims with real claimant and vehicle data. Before you put that data into anyone's system you are entitled to ask what they do about security. CaseFlow Automation, which operates CreditHire Assist, holds Cyber Essentials certification covering the whole organisation.
| Organisation certified | CaseFlow Automation, 7-9 Macon Court, Crewe CW1 6EA |
|---|---|
| Scope | Whole organisation |
| Certificate number | 176bba48-8fb4-4f1a-a685-32d86b40fe3f |
| Profile version | 3.3 (Danzell) |
| Date of certification | 7 August 2026 |
| Recertification due | 7 August 2027 |
| Certification body | IT Cyber Solutions |
| Accreditation partner | IASME, the National Cyber Security Centre's delivery partner for the scheme |
Whole organisation scope matters. Some certificates cover a narrow slice of a business, a single office or one product. Ours covers everything CaseFlow Automation runs, including CreditHire Assist.
What Cyber Essentials actually covers
Cyber Essentials is a UK Government backed scheme delivered by IASME on behalf of the National Cyber Security Centre. It assesses an organisation against five technical controls.
Firewalls
Boundary and device firewalls block unapproved inbound traffic by default, with any exception documented and justified.
Secure configuration
Devices and software ship with convenient defaults rather than safe ones. This control covers removing what is not needed, changing default credentials and hardening what remains.
Security update management
Software is supported, licensed and patched. High risk and critical updates are applied within defined timescales, and unsupported software is removed.
User access control
Accounts belong to named individuals, access is granted on need, administrative privileges are separated from day to day accounts, and access is removed when someone leaves.
Malware protection
Devices are protected against malicious code through anti-malware software, application allow listing, or sandboxing.
What Cyber Essentials does not cover
We would rather be straight about the limits of this than let a badge do work it cannot do.
Cyber Essentials is a verified baseline, not an exhaustive audit. It confirms the five controls above were in place at the point of assessment. It is not Cyber Essentials Plus, which adds a hands on technical audit, and it is not ISO 27001, which certifies a whole information security management system.
The certificate itself carries this wording, and it is worth repeating rather than burying: it confirms the organisation's ICT defences were assessed as satisfactory against commodity based cyber attacks at the time of testing, and does not guarantee those defences will remain satisfactory against a cyber attack.
Security is a practice, not a certificate. The certificate is evidence that we take the practice seriously enough to be assessed on it every year.
Verifying this certificate yourself
Do not take a badge on a website as proof of anything. Anyone can put an image in a footer.
Every Cyber Essentials certificate is recorded on an independent registry. Ours is published at the link below, and the entry shows as active while the certification is current and lapses if it is not renewed.
Check our certificate on the official registry: https://registry.blockmarktech.com/certificates/176bba48-8fb4-4f1a-a685-32d86b40fe3f/active/
Supplier assurance and procurement
If you are running a supplier assurance process, we are used to it and we will not make it difficult. Alongside this certification we can provide a data processing agreement, complete a security questionnaire, and talk through where data is held and who can reach it.
For anything not answered here, ask us. A question we cannot answer straight is a question worth us fixing.