// 01 — Two Levels of Assurance
Choose the certification route that matches your risk and customer requirements
Both certifications assess the same five technical control areas. The difference is how those controls are verified: Cyber Essentials uses a verified self-assessment, while Cyber Essentials Plus adds an independent technical assessment of the organisation’s environment.
LEVEL // VERIFIED SELF-ASSESSMENT
Cyber Essentials
A clear baseline for protecting your organisation against common internet-based attacks and demonstrating that core cyber hygiene controls are in place.
- Scope definition and eligibility review.
- Gap analysis against the assessment questions.
- Control remediation and configuration guidance.
- Answer and evidence preparation support.
- Submission readiness review before certification.
LEVEL // INDEPENDENT TECHNICAL ASSESSMENT
Cyber Essentials Plus
Higher assurance through independent technical testing that verifies the Cyber Essentials controls are implemented and operating effectively across the agreed scope.
- Cyber Essentials Plus scope and asset preparation.
- Technical gap analysis before the assessment.
- External exposure and vulnerability readiness checks.
- Endpoint, cloud, access, and patching evidence preparation.
- Remediation support through assessment readiness.
// 02 — The Five Controls
Strengthen the controls that stop common attacks
Our readiness work focuses on practical implementation. We help your team understand what is in scope, identify where current controls fall short, and make the changes required to support accurate answers and a successful technical assessment.
CONTROL 01
Firewalls
Review internet gateways, host firewalls, cloud security rules, exposed services, and administrative access so only necessary and authorised traffic is permitted.
CONTROL 02
Secure Configuration
Remove or disable unnecessary accounts, software, services, and insecure defaults across devices, operating systems, applications, and cloud platforms.
CONTROL 03
User Access Control
Apply least privilege, control administrative accounts, strengthen authentication, and ensure access is approved, reviewed, and removed when no longer needed.
CONTROL 04
Malware Protection
Confirm appropriate malware defences, application controls, platform protections, and user restrictions are deployed across in-scope devices and services.
CONTROL 05
Security Updates
Establish supported software inventories and reliable patching processes so critical and high-risk vulnerabilities are addressed within required timescales.
// 03 — Readiness Services
Hands-on support from first gap to assessment day
As an IASME-authorised Certification Body, Primelo Cyber assesses and issues Cyber Essentials directly. We also work alongside technical and operational teams to remediate gaps and prepare for the separate Cyber Essentials Plus technical assessment.
SERVICE 01
Scope & Gap Analysis
Define the organisation, devices, networks, cloud services, and users in scope, then assess current controls against the certification requirements.
SERVICE 02
Remediation Support
Prioritised technical guidance to resolve configuration, access, software support, patching, firewall, endpoint, and cloud-control gaps.
SERVICE 03
Assessment & Certification
We review the Cyber Essentials submission as your IASME-authorised Certification Body and issue the certificate directly when the requirements are met.
SERVICE 04
Plus Readiness Testing
Prepare for Cyber Essentials Plus with technical checks that mirror likely assessment focus areas and identify weaknesses before the independent assessor does.
Cyber Essentials Plus Readiness
- Confirm that the Cyber Essentials scope accurately reflects your live environment.
- Prepare representative devices, users, locations, cloud services, and technical evidence for assessment.
- Review external exposure, endpoint protections, patching status, access controls, and secure configuration.
- Identify and remediate technical issues before independent testing begins.
- Support your team through assessment queries and any permitted remediation window.
// 04 — Delivery Path
A clear route to certification readiness
The programme is sized around your environment and target certification. Each stage produces clear actions and evidence so there is no ambiguity about what is ready, what remains outstanding, and who owns the next step.
PHASE 01
Discover
Confirm the target level, business drivers, certification deadline, technical scope, and key control owners.
PHASE 02
Assess
Review the five control areas and document gaps against the requirements for Cyber Essentials or Plus.
PHASE 03
Remediate
Implement the priority changes with practical support for internal teams and technology partners.
PHASE 04
Validate
Recheck controls, answers, evidence, and technical readiness before independent certification activity.
- Direct Cyber Essentials assessment and certification from an IASME-authorised Certification Body.
- Clear separation between our Cyber Essentials certification role and CE+ readiness-only support.
- Fixed-scope remediation plans aligned to your certification deadline and available resources.
- Reusable control evidence that can support supplier assurance, tenders, and wider security programmes.
Organisations seeking broader governance and risk assurance can continue from Cyber Essentials into our Cyber Assurance certification service. Where customers or compliance programmes require technical validation of specific systems, our penetration testing service delivered by CREST and OSCP certified testers can provide deeper security testing.
Start Your Readiness Assessment