At what point did Cyber Essentials become important for your UK startup?
For UK startups selling to other businesses when did Cyber Essentials actually become something you had to think about?
Was it something you decided to get proactively or did a customer, contract or procurement process eventually ask for it?
I am particularly interested in smaller companies where there isn't a dedicated security person yet. It seems like there can be quite a gap between knowing you should have decent security practices and actually going through certification.
For anyone who's already been through it, what made you decide it was worth doing, and was the process what you expected?