Cyber Essentials usually arrives as somebody else’s deadline. A client has made it a condition of the contract, an insurer wants it before renewal, or a tender will not accept a submission without it. The certification is a self-assessment questionnaire, which sounds straightforward until you reach the questions about unsupported software, admin accounts and personal devices. We put the controls right first, then take you through the assessment — and keep the certificate valid the following year rather than starting from scratch each time.
Certification, managed
Cyber Essentials passed, and still valid next year
What is included
- Pre-assessment gap review against the five controls
- Remediation of anything that would fail
- Support through the self-assessment submission
- Cyber Essentials Plus audit preparation
- Annual recertification managed
- Evidence retained between renewals
What changes
The contract stops being at risk
Certification in place before your client’s deadline, rather than after a scramble the week it is due.
Failures get found before the assessor finds them
Applications tend to come unstuck on the same few things — unsupported software, missing MFA, admin accounts used for everyday work, personal devices nobody manages. We deal with those first.
Next year is not a repeat of this year
Renewal managed and evidence retained, so recertification is a review rather than a rebuild.
Method
How we work
Assess
Document what exists, including the parts nobody wants to discuss.
Standardise
Remove the variation that causes most incidents.
Secure
Apply controls and prove they are working.
Operate
Run it day to day against agreed measures.
Improve
Review quarterly with real data, not a slide.
Then round again — reviewed quarterly
Questions
Questions we get asked about certification
What are the five controls?
Firewalls, secure configuration, user access control, malware protection and security update management. Every Cyber Essentials assessment comes back to those five. The gap review checks each one against how your systems are actually set up, rather than how they were meant to be.
What is the difference between Cyber Essentials and Cyber Essentials Plus?
The same five controls, assessed two different ways. Cyber Essentials is a self-assessment questionnaire you complete and sign off. Cyber Essentials Plus adds a hands-on technical audit, where an assessor tests a sample of your devices rather than taking the answers on trust. More client contracts and tenders now ask for Plus specifically.
Who carries out the assessment?
Base Cyber Essentials is handled in house — the gap review, the remediation and taking you through the self-assessment submission. Cyber Essentials Plus is deliberately not. The hands-on audit is carried out by an independent third-party partner, because the people who secure and maintain your systems should not be the ones who sign them off.
What happens if we would fail today?
Nothing gets submitted until we know it would pass. The gap review comes first, we remediate whatever would fail, and only then does the assessment go in. Starting from a position that would not pass today is the normal case, not the exception. This is how we guarantee you pass on the first attempt.
How long does it take?
That depends on what the gap review finds. Where the controls are broadly in place it is a matter of weeks. Where there is unsupported software to replace or devices to bring under management, that work sets the pace. You get told which of the two you are looking at after the review, not at the end. However, if you’re up against a tight deadline and need this in place sooner rather than later, we do have a fast-track service.
Does it have to be done again every year?
Yes. Certification lasts twelve months. We manage the renewal and keep the evidence between cycles, so recertification is a review rather than a rebuild.