For a complex organisation, Cyber Essentials preparation should begin before anyone starts filling in the assessment. The most useful first step is usually a structured gap assessment that establishes scope, tests current practice against the requirements and turns uncertainty into a practical remediation plan.
Cyber Essentials is built around five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. The current NCSC Requirements for IT Infrastructure are version 3.3, effective from 27 April 2026.
Start with scope, not the questionnaire
Many problems in Cyber Essentials projects begin with an incomplete view of what the organisation is actually certifying. Large and distributed organisations may have multiple legal entities, cloud platforms, shared services, remote workers, suppliers and different technology teams. A gap assessment should make those dependencies visible before the formal assessment starts.
The objective is not simply to create an asset list. It is to understand which people, devices, software, cloud services and networks support the proposed certification boundary, who controls them and where responsibility is shared.
What should a Cyber Essentials gap assessment examine?
A useful review should look at both the technical position and the evidence needed to explain it. That normally includes:
- the proposed organisational and technical scope
- firewall and boundary protection arrangements
- secure configuration standards and unnecessary services
- supported operating systems, applications and firmware
- security update management and remediation timescales
- user and administrator access controls
- multi-factor authentication for cloud services where required
- malware protection arrangements
- ownership of controls, exceptions and supporting evidence
This distinction matters. A control may be operating correctly but poorly documented, or an organisation may have strong policies that are not implemented consistently across the declared scope. A good gap assessment separates control gaps, evidence gaps and technical gaps rather than treating them as the same problem.
Prioritise remediation before setting the assessment date
Once gaps are visible, the organisation can sequence remediation sensibly. Unsupported software, update-management failures, unclear scope and inconsistent privileged access usually need earlier attention than documentation tidy-up.
For larger estates, remediation also needs ownership. Each issue should have an accountable team, a target date, dependencies and evidence showing when the fix has been completed. This prevents Cyber Essentials becoming a last-minute exercise driven by a certification deadline.
Why current scheme knowledge matters
The scheme changes over time. The April 2026 requirements introduced version 3.3 and IASME also strengthened the marking approach around critical practices including multi-factor authentication and timely security updates. Preparing against an old question set or relying on a previous year's interpretation can create avoidable problems.
An experienced Cyber Essentials assessor can help an organisation understand how the current requirements apply to its environment and where questions of scope or shared responsibility need to be resolved. The formal certification decision remains based on the organisation's declared scope and assessment evidence.
What should the output look like?
The most useful deliverable is not a long report of observations. It is a working roadmap that management and technical teams can use. We typically expect it to include:
- a clear proposed certification boundary and assumptions
- a prioritised register of control, evidence and technical gaps
- recommended remediation actions
- owners, dependencies and sequencing
- issues that need assessor clarification before formal submission
- a readiness view showing what must be completed before assessment
Use the gap assessment to improve security, not just pass
Cyber Essentials works best when the preparation process improves the underlying environment. The goal should be consistent technical controls across the declared scope, with evidence that reflects how the organisation actually operates.
For complex organisations, that makes the gap assessment more than a pre-certification checklist. It becomes the bridge between the scheme requirements, the technology estate and a remediation programme that can be owned and measured.
