Skip to main content
Case Study

Three Consecutive Years of Cyber Essentials Plus Certification

A world-leading research, evidence, evaluation and communications organisation operating across multiple legal entities and a sizeable technology estate.

Three consecutive years of Cyber Essentials Plus certification continuity through an annual assurance cycle that identifies gaps early, supports remediation and adapts to changing requirements.

Situation

This international research, evidence, evaluation and communications organisation works with governments, public-sector bodies and major organisations and operates across multiple legal entities.

Cyber Essentials Plus is important to its ability to demonstrate cyber assurance and support significant commercial and customer requirements. MDLabs has supported its Cyber Essentials and Cyber Essentials Plus certification programme for three consecutive years.

Challenge and complexity

Maintaining Cyber Essentials Plus year after year is different from achieving it for the first time. Technology, people, devices and cloud environments change. New vulnerabilities emerge, security controls mature and the Cyber Essentials requirements themselves evolve.

At the same time, certification continuity matters commercially. Annual certification activity therefore has to be coordinated across a complex environment and multiple stakeholder groups without turning the programme into a once-a-year tick-box exercise.

MDLabs approach

MDLabs developed a structured assurance approach around the annual certification cycle. Work starts ahead of formal assessment to understand changes in the environment and identify areas that need attention.

Across the relationship, this has included reviewing scope, coordinating with stakeholders responsible for different parts of the technology estate, reviewing asset and technical information, identifying and communicating potential gaps, supporting remediation, reviewing evidence and coordinating activity around the required renewal window before completing the Cyber Essentials and Cyber Essentials Plus assessments.

Outcome

The organisation has achieved its required Cyber Essentials Plus certification for three consecutive years within the required timescales.

Each annual engagement provides another opportunity to validate the environment, identify weaknesses, address gaps and confirm that the Cyber Essentials controls continue to be implemented appropriately. The result is a long-term assurance relationship rather than a once-a-year certification transaction.

"Thank you very much for support throughout this year's assessment; this is a brilliant result! Receiving the certificates was excellent news, but your comments mean just as much to us. We have invested a great deal of effort over the last year in strengthening not only specific controls, but also the processes, governance and evidence behind them, so it was particularly encouraging to hear your view that this was our strongest year yet. Cyber Essentials Plus has become an important milestone for us each year, not simply as a certification exercise, but as an opportunity to challenge ourselves and continue improving. Thank you also for your exceptional professionalism, pragmatism and support throughout the process. The assessment was rigorous whilst remaining collaborative, which made a real difference."

Group CISO

The client's identity remains anonymised publicly and can be disclosed to prospective customers under NDA where appropriate.