Govern & Assure

Cyber Essentials Assessments

Cyber Essentials assessments covering scoping, readiness, remediation, certification, and Cyber Essentials Plus technical testing.

  • Clear assessment scope
  • Readiness before assessment
  • Practical requirement interpretation
  • Remediation support
  • Cyber Essentials Plus

Cyber Essentials is straightforward by design, but getting through the assessment still depends on having the scope, technical controls, and responses right.

We take you through the full process, from confirming what is in scope and reviewing your current position through to assessment, remediation, and certification. Where Cyber Essentials Plus is required, we also manage the additional technical testing needed to demonstrate that the same five control areas are working in practice.

The aim is to keep the process clear and practical. We explain what each requirement means for your environment, identify anything that needs attention, and help you resolve issues rather than leaving you to work through assessment feedback on your own.

If you are not ready to certify yet, that is not a blocker. Readiness and remediation work can be built into the engagement so you move towards certification with a clear view of what needs to change.

Get a quote for Cyber Essentials Assessments

Tell us your scope and objectives, and we’ll come back with a clear, fixed proposal, usually the same working day.

Get a Quoteor call +44 (0) 203 393 7795
  • CREST-accredited
  • UK-based specialists
  • Crown Commercial Service supplier

How it works

  1. 01

    Confirm scope

    We establish the systems, users, and services included in the assessment and make sure the boundary is clear.

  2. 02

    Review readiness

    We work through the Cyber Essentials requirements with you and identify anything that needs clarification or remediation.

  3. 03

    Complete the assessment

    We take you through the Cyber Essentials assessment and deal with any points that need further information or correction.

  4. 04

    Resolve issues

    If something does not meet the requirement, we explain the gap, clarify what needs to change, and support you through the remediation process.

  5. 05

    Complete certification

    Once the requirements have been met, we complete the certification process. Where Cyber Essentials Plus is in scope, the additional technical testing forms part of that journey.

Cyber Essentials or Cyber Essentials Plus?

Both routes are based on the same five technical control areas. The difference is the level of assurance.

Cyber Essentials assesses how those controls are implemented across your organisation through the scheme assessment.

Cyber Essentials Plus builds on the same requirements with additional technical testing of the in-scope environment, providing greater assurance that the controls are working in practice.

Which route is right depends on why you are pursuing certification. Some organisations need Cyber Essentials to satisfy a customer, tender, or supply-chain requirement. Others choose Cyber Essentials Plus because they want the additional technical assurance or because it is specifically required.

We help you understand which route applies and what needs to happen to get there.

What you get

Clear assessment scope

We establish what is included in the assessment so the boundary is understood before detailed work begins.

Readiness before assessment

We review your position against the Cyber Essentials requirements and identify anything that needs attention before certification.

Practical requirement interpretation

We explain how the requirements apply to your environment and help remove ambiguity around the assessment questions.

Remediation support

Where something does not meet the requirement, we explain the issue and help you work through the corrective action.

Cyber Essentials Plus

Where you need the higher-assurance route, we manage the additional technical testing across the in-scope environment.

Support through to certification

We keep the process moving from initial scope through assessment, remediation, and completion.

Frequently asked questions

Straight answers to what prospective clients ask us most.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Both cover the same five technical control areas. Cyber Essentials assesses your implementation through the scheme assessment. Cyber Essentials Plus adds technical testing of the in-scope environment, providing a higher level of assurance.

Do we need to be fully ready before we start?

No. If you are unsure whether everything is in place, we combine readiness and remediation with the assessment process. We identify the gaps, explain what needs to change, and help you move towards certification rather than expecting everything to be perfect on day one.

What happens if something does not meet the requirement?

We explain why it does not meet the requirement and what needs to change.

Where the issue can be remediated, we work with you to resolve it and move the assessment forward.

What does Cyber Essentials Plus involve?

Cyber Essentials Plus adds technical testing across a representative sample of the in-scope environment to verify that the Cyber Essentials controls are operating effectively. We help prepare the environment, coordinate the testing, and work through any findings that arise.

How do we know what is in scope?

We establish the assessment boundary with you at the start, looking at the systems, users, and services relevant to the certification. Getting the scope clear early helps avoid confusion later in the assessment.

What happens after certification?

Cyber Essentials certification is not a substitute for maintaining the underlying controls. Systems, users, and services change, so the controls need to stay current. We help you understand what needs to be maintained ahead of renewal and where further improvement may be worthwhile.

Ready to talk about cyber essentials assessments?

Get a fixed-scope quote, usually the same working day.