Cyber Essentials readiness

We have been through Cyber Essentials ourselves. We help you prepare for yours.

SoftExponent Ltd holds Cyber Essentials certification at whole-organisation scope. That first-hand experience shapes how we help UK organisations prepare: understanding what the scheme actually asks for, identifying the gaps that count, and getting the evidence in order before assessment begins.

Cyber Essentials certified Whole-organisation scope Senior-led Independently verifiable
Where preparation stalls

Cyber Essentials is designed to be achievable. Getting the scope, controls and evidence in order is where organisations can lose time.

Most delays are not technical. They come from unclear scope, evidence that was never recorded, and questionnaire wording that is easy to misread or answer inconsistently.

01

Deciding what the assessment covers

Scope decides everything that follows. Whole-organisation certification means every user, device and internet-facing service in scope has to meet the requirements. A narrower scope is allowed and can be appropriate, but it needs to be defined precisely rather than assumed.

02

Knowing what is actually in scope

Laptops are the easy part. Personally owned phones used for work, home routers, contractor devices, cloud services and systems running unsupported operating systems can all affect scope. What needs to be included — and what does not — has to be understood before the assessment begins.

03

Producing evidence after the fact

The controls are often in better shape than the paperwork. Settings may already be in place but never documented, and reconstructing the evidence under time pressure takes longer than recording it as you go.

04

Configuration that drifted quietly

Default accounts, services enabled during a migration and never turned off, unused administrator logins from a previous supplier. None of this is unusual. It simply accumulates until someone goes looking for it.

05

Access that grew with the business

Shared logins, administrator rights granted for convenience, leavers who still have a mailbox, and multi-factor authentication applied to some services but not others. Access tends to accumulate rather than be designed.

06

Keeping software current, everywhere

Operating systems are usually managed. Browsers, plugins, firmware, mobile devices and the one server nobody wants to restart are where update management tends to slip — and where assessment answers become harder to stand behind.

The requirements

The five controls, in plain terms.

Cyber Essentials is built around five technical controls. Each is straightforward to describe, but the detail matters when it is applied across a real working environment. Here is what each one means day to day for a smaller UK organisation.

01

Firewalls

Every device that connects to the internet needs a controlled boundary between it and the outside world. For most organisations, that means the firewall in the office router or internet connection, supported by the software firewall built into each laptop when people are working elsewhere.

In practice, the detail is in the defaults and the exceptions. Has the router’s administrative password been changed from the one it shipped with? Can its management interface be reached from the internet? If a port has been opened for a legitimate business reason, is there a record of why it was needed, who approved it, and whether it still needs to remain open?

02

Secure configuration

Devices and services often arrive configured for convenience rather than security. This control is about removing what is not needed and changing settings that should never have been left at their defaults, so the environment is deliberately configured rather than accidentally configured.

Day to day, that means removing software and user accounts that are no longer needed, disabling features left behind after a project, requiring a password or PIN before a device unlocks, and making sure devices lock after a period of inactivity. Auto-run from removable media is another common setting worth checking.

03

User access control

People should have the access their role needs and no more, and accounts with administrative privileges should be separate from those used for everyday work such as email and web browsing. As organisations grow, access can accumulate quietly unless someone is responsible for reviewing it.

In practice, that means knowing how accounts are approved and created, removing access promptly when someone leaves, keeping administrator rights out of everyday use, avoiding shared logins, and enforcing multi-factor authentication where required. Cloud services and remote access need the same attention.

04

Malware protection

Devices need protection against malicious software, and the right approach can differ by platform. For many devices that means anti-malware software that keeps itself up to date. Other approaches restrict devices to approved applications, while some platforms use protections built into the operating system and its application store.

What matters is that the protection covers every in-scope device, is enabled and kept current. That includes mobile devices where applicable. The important part is being able to show that protection is in place and maintained, rather than simply assuming it is.

05

Security update management

Software needs to remain supported by its vendor and kept up to date. Where a device or application has reached end of life and no longer receives security updates, the organisation needs a clear plan to replace it, isolate it appropriately or otherwise remove the risk it creates.

In practice, critical and high-risk security updates need to be applied promptly across operating systems, browsers, plugins, firmware and mobile devices. Just as importantly, someone should be able to explain how updates are deployed, monitored and checked rather than simply assumed to be happening. Unsupported servers and ageing mobile devices are common places for this control to become difficult.

How we help

Preparation that removes surprises, rather than one that ticks boxes.

Our role is to get you to the point where the answers are true, the evidence is there, and nothing in the questionnaire relies on guesswork.

We prepare you for the assessment. We do not mark it. That separation is deliberate. It keeps our role clear and the assessment independent.

We start by understanding how your organisation actually works, because scope follows the business rather than the other way around. From there, we work through each control, record what is already in place, and identify anything that needs attention before assessment.

You get a prioritised view rather than a list. Some issues need to be addressed before submission; others may be sensible improvements without being immediate assessment priorities. Knowing the difference helps keep the preparation focused.

Where the next step requires an accredited assessor or specialist certification input, we can help coordinate that handover while keeping the assessment independent.

GR

Readiness and gap review

A structured review of all five control areas against your current environment, with scope agreed before anything else.

PR

Remediation priorities

What needs to change before submission, what can follow afterwards, and what is already in good order.

EV

Evidence preparation

Turning settings and working practices into clear evidence that remains useful during assessment and after certification.

QW

Questionnaire walkthrough

Working through the questions with you so the wording is clear and the answers reflect what is genuinely in place.

RP

Practical remediation planning

A plan that fits how your organisation operates, sequenced so the work can be carried out realistically rather than left as a list of recommendations.

SS

Support up to submission

Senior input available as you work through the remaining items, so questions can be resolved without slowing progress.

Our own certification

Why our own certification matters.

Our advice is informed by first-hand experience of the same scheme we help clients prepare for. Our own certification is current, covers the whole organisation and can be independently verified.

01

Assessed, not asserted

SoftExponent Ltd completed the Cyber Essentials assessment with an independent assessor. We answered the same questions and produced the same kind of evidence we will ask you for.

02

Whole-organisation scope

Our certification covers the whole organisation. That gives us first-hand experience of applying the Cyber Essentials requirements across the breadth of our own working environment.

03

Independently verifiable

You do not have to take our word for it. Our certification appears in the public certificate search, and you can check it before you speak to us. Verify our certification →

Common questions

Questions organisations ask before they start.

If your question is not covered here, ask us directly. We would rather clarify it before you commit time to preparation.

Cyber Essentials is a UK government-backed scheme built around five technical controls that help organisations protect themselves against common internet-based attacks. Certification involves completing a self-assessment questionnaire that is reviewed by a licensed Certification Body. It is often requested by clients, insurers and public sector buyers.

Firewalls, secure configuration, user access control, malware protection and security update management. We explain each one in plain terms further up this page, including what it means in practice for a smaller organisation.

No. SoftExponent prepares organisations for Cyber Essentials but does not issue certificates and is not a Cyber Essentials Certification Body. Certification remains independent, and where an accredited assessor or specialist certification input is required, we can help coordinate the next step.

We agree the scope first, review your environment against the five controls and identify what needs attention before assessment. From there, we prioritise remediation, help prepare the evidence and work through the questionnaire with you so the answers reflect what is genuinely in place.

It depends on your environment, but you should expect to show what devices and users are in scope, how accounts are created and removed, where multi-factor authentication is enforced, how devices are configured, what malware protection is in place, and how security updates are managed. Capturing that evidence as you go is much easier than reconstructing it later.

There is no useful one-size-fits-all answer. The timeline depends on your scope, the state of the environment and how much remediation is needed. An organisation with managed devices, enforced multi-factor authentication and a clear inventory may need relatively little preparation; unmanaged devices, unsupported software or access that has not been reviewed can take longer to resolve. We give you a realistic view once we understand the starting point.

Cyber Essentials uses a self-assessment questionnaire reviewed by a Certification Body. Cyber Essentials Plus covers the same five technical controls but adds independent hands-on technical verification. We can help organisations prepare, but we do not carry out the Cyber Essentials Plus technical assessment itself.

How to start

Two sensible starting points.

Know you need Cyber Essentials? Start with readiness support. Not sure where your wider security stands? Start with a Security Posture Review.