Cyber Essentials

Cyber Essentials Consultancy and Certification Support

We scope the assessment, close the technical gaps and prepare your answers, so the submission reflects controls that are genuinely in place.

Overview

Our Approach to Cyber Essentials

Cyber Essentials is a verified self-assessment against five technical control areas. The certificate is issued through an authorised certification body; Cloud Agile provides the consultancy, remediation and evidence work that gets you ready for it. Done properly, it also leaves you measurably more secure rather than simply certified.

What's Included

Everything You Need From Cyber Essentials

  • Scoping the assessment, including cloud services and home working
  • Gap assessment against the technical control themes
  • Technical remediation across devices, accounts and configuration
  • Policy and process improvements where the controls require them
  • Preparation of verified self-assessment responses and evidence
  • Annual renewal support and control maintenance

Getting the scope right first

Most Cyber Essentials difficulties come from scope: forgotten devices, unmanaged personal equipment, cloud services nobody listed, or an assumption that home working sits outside the assessment. We establish the boundary before any remediation starts.

  • Devices in use, including laptops, mobiles and any personal equipment
  • User accounts, administrative accounts and how they are granted
  • Cloud services and the way they are accessed and secured
  • Firewalls, routers and the network boundary, including home workers
  • Whether a whole-organisation scope is realistic or a defined subset is better

Gap assessment and remediation

We compare the environment against the technical control themes, then fix what is missing rather than simply reporting it. Where a control needs a process rather than a setting, we write the process with you.

  • Firewalls and boundary configuration
  • Secure configuration of devices and services, including default credentials
  • User access control, administrative accounts and multi-factor authentication
  • Malware protection across the device estate
  • Security update management and unsupported software
  • Supporting policies and the day-to-day processes behind them

Submission, renewal and what happens afterwards

We prepare the answers with you so the submission is accurate and defensible, and support you through any clarification the assessor raises.

Certification lapses quickly in a changing estate, so we agree how the controls will be maintained and handle the annual renewal as a planned piece of work rather than a scramble.

  • Drafting and reviewing the self-assessment responses
  • Collating the supporting evidence you need to hand
  • Liaison with the certification body during the assessment
  • Handling any queries or resubmission requirements
  • Annual renewal planning and ongoing control maintenance
Delivery

How a Project Works

  1. 1

    Scope

    Agree the assessment boundary across devices, users, cloud services and networks.

  2. 2

    Assess

    Gap-assess the environment against the technical control themes.

  3. 3

    Remediate

    Close technical gaps and put the supporting processes in place.

  4. 4

    Submit

    Prepare responses and evidence, and support you through the assessment.

  5. 5

    Maintain

    Keep controls in place and plan the annual renewal in advance.

Why It Matters

The Outcomes You'll Actually See

Scope decided deliberately

The boundary is agreed up front, which avoids the late surprises that derail submissions.

Gaps closed, not just listed

We remediate the environment rather than handing you a report and leaving the work with you.

Certification you can maintain

Controls and processes are set up so renewal is routine rather than a rebuild.

What Success Looks Like

  • An agreed, defensible assessment scope
  • Technical gaps remediated across devices, accounts and configuration
  • Prepared responses and evidence for the verified self-assessment
  • A maintenance and renewal plan that keeps the controls in place

Related services

FAQs

Frequently Asked Questions

Does Cloud Agile issue the certificate?+

No. Cyber Essentials is a verified self-assessment, and the assessment and certificate are provided through an authorised Cyber Essentials certification body. We provide the consultancy, remediation, evidence and submission support.

How long does certification take?+

It depends entirely on how much remediation is needed. A well-managed Microsoft 365 estate may need very little; an environment with unsupported software or patchy multi-factor authentication needs that work completed first.

Do home workers count?+

Yes. Home working is part of the assessment, including the devices used and how they connect. We cover it explicitly during scoping rather than leaving it as an assumption.

Should we go straight to Cyber Essentials Plus?+

Cyber Essentials is the prerequisite, so the basic certification comes first. If Plus is the end goal we prepare for that standard from the outset, which avoids doing the remediation work twice.

Ready to Elevate Your Managed IT Services?

Book a 20-minute strategy call. We'll pressure-test where technology is holding your business back, and map out how a stronger IT partnership unlocks growth.