UK Cyber Security Baseline

Cyber Essentials Certification & Cyber Essentials Plus Readiness

Primelo Cyber is an IASME-authorised Certification Body that assesses and issues Cyber Essentials directly. We also provide remediation and readiness support for the separate Cyber Essentials Plus technical assessment.

Choose the certification route that matches your risk and customer requirements

Both certifications assess the same five technical control areas. The difference is how those controls are verified: Cyber Essentials uses a verified self-assessment, while Cyber Essentials Plus adds an independent technical assessment of the organisation’s environment.

LEVEL // VERIFIED SELF-ASSESSMENT

Cyber Essentials

A clear baseline for protecting your organisation against common internet-based attacks and demonstrating that core cyber hygiene controls are in place.

  • Scope definition and eligibility review.
  • Gap analysis against the assessment questions.
  • Control remediation and configuration guidance.
  • Answer and evidence preparation support.
  • Submission readiness review before certification.
LEVEL // INDEPENDENT TECHNICAL ASSESSMENT

Cyber Essentials Plus

Higher assurance through independent technical testing that verifies the Cyber Essentials controls are implemented and operating effectively across the agreed scope.

  • Cyber Essentials Plus scope and asset preparation.
  • Technical gap analysis before the assessment.
  • External exposure and vulnerability readiness checks.
  • Endpoint, cloud, access, and patching evidence preparation.
  • Remediation support through assessment readiness.

Strengthen the controls that stop common attacks

Our readiness work focuses on practical implementation. We help your team understand what is in scope, identify where current controls fall short, and make the changes required to support accurate answers and a successful technical assessment.

CONTROL 01

Firewalls

Review internet gateways, host firewalls, cloud security rules, exposed services, and administrative access so only necessary and authorised traffic is permitted.

CONTROL 02

Secure Configuration

Remove or disable unnecessary accounts, software, services, and insecure defaults across devices, operating systems, applications, and cloud platforms.

CONTROL 03

User Access Control

Apply least privilege, control administrative accounts, strengthen authentication, and ensure access is approved, reviewed, and removed when no longer needed.

CONTROL 04

Malware Protection

Confirm appropriate malware defences, application controls, platform protections, and user restrictions are deployed across in-scope devices and services.

CONTROL 05

Security Updates

Establish supported software inventories and reliable patching processes so critical and high-risk vulnerabilities are addressed within required timescales.

Hands-on support from first gap to assessment day

As an IASME-authorised Certification Body, Primelo Cyber assesses and issues Cyber Essentials directly. We also work alongside technical and operational teams to remediate gaps and prepare for the separate Cyber Essentials Plus technical assessment.

SERVICE 01

Scope & Gap Analysis

Define the organisation, devices, networks, cloud services, and users in scope, then assess current controls against the certification requirements.

SERVICE 02

Remediation Support

Prioritised technical guidance to resolve configuration, access, software support, patching, firewall, endpoint, and cloud-control gaps.

SERVICE 03

Assessment & Certification

We review the Cyber Essentials submission as your IASME-authorised Certification Body and issue the certificate directly when the requirements are met.

SERVICE 04

Plus Readiness Testing

Prepare for Cyber Essentials Plus with technical checks that mirror likely assessment focus areas and identify weaknesses before the independent assessor does.

Cyber Essentials Plus Readiness

  • Confirm that the Cyber Essentials scope accurately reflects your live environment.
  • Prepare representative devices, users, locations, cloud services, and technical evidence for assessment.
  • Review external exposure, endpoint protections, patching status, access controls, and secure configuration.
  • Identify and remediate technical issues before independent testing begins.
  • Support your team through assessment queries and any permitted remediation window.

A clear route to certification readiness

The programme is sized around your environment and target certification. Each stage produces clear actions and evidence so there is no ambiguity about what is ready, what remains outstanding, and who owns the next step.

PHASE 01

Discover

Confirm the target level, business drivers, certification deadline, technical scope, and key control owners.

PHASE 02

Assess

Review the five control areas and document gaps against the requirements for Cyber Essentials or Plus.

PHASE 03

Remediate

Implement the priority changes with practical support for internal teams and technology partners.

PHASE 04

Validate

Recheck controls, answers, evidence, and technical readiness before independent certification activity.

Organisations seeking broader governance and risk assurance can continue from Cyber Essentials into our Cyber Assurance certification service. Where customers or compliance programmes require technical validation of specific systems, our penetration testing service delivered by CREST and OSCP certified testers can provide deeper security testing.

Start Your Readiness Assessment