Cyber Essentials usually arrives as somebody else’s deadline. A client has made it a condition of the contract, an insurer wants it before renewal, or a tender will not accept a submission without it. The certification is a self-assessment questionnaire, which sounds straightforward until you reach the questions about unsupported software, admin accounts and personal devices. We put the controls right first, then take you through the assessment — and keep the certificate valid the following year rather than starting from scratch each time.
Certification, managed
Cyber Essentials passed, and still valid next year
What is included
- Pre-assessment gap review against the five controls
- Remediation of anything that would fail
- Support through the self-assessment submission
- Cyber Essentials Plus audit preparation
- Annual recertification managed
- Evidence retained between renewals
What changes
The contract stops being at risk
Certification in place before your client’s deadline, rather than after a scramble the week it is due.
Failures get found before the assessor finds them
Applications tend to come unstuck on the same few things — unsupported software, missing MFA, admin accounts used for everyday work, personal devices nobody manages. We deal with those first.
Next year is not a repeat of this year
Renewal managed and evidence retained, so recertification is a review rather than a rebuild.
Method
How Commstec works
Assess
Document what exists, including the parts nobody wants to discuss.
Standardise
Remove the variation that causes most incidents.
Secure
Apply controls and prove they are working.
Operate
Run it day to day against agreed measures.
Improve
Review quarterly with real data, not a slide.