Skip to main content
Home/ Preparation guide
Preparation guide

How should an enterprise prepare for Cyber Essentials Plus?

Begin by making scope, ownership and readiness visible to everyone involved.

1. Agree the certification objective.

Write down the business reason for certification: a customer requirement, procurement milestone or assurance programme. Identify the legal entities and operations you want the certificate to cover. Ask your assessor to review the proposed boundary before you commit to a date.

2. Build a usable view of the estate.

Bring together current information about endpoints, operating systems, locations, cloud services, networks and identity platforms. Record who owns each part of the estate and which teams or suppliers can provide evidence.

Flag shared services, unsupported technology, remote-working arrangements and exceptions for early discussion. A useful estate view shows dependencies and uncertainty, not just a device count.

3. Coordinate readiness and remediation.

Assign an accountable internal lead and named technical owners. Separate issues that need investigation from issues with an agreed remediation plan. Track progress so assessment scheduling is based on readiness rather than a hoped-for completion date.

Prepare the whole declared scope. A small set of well-configured devices is not a substitute for consistent implementation.

4. Prepare for technical assessment.

Cyber Essentials Plus includes independent technical testing. Your assessor will explain the applicable process, required access and evidence. Use the current NCSC documentation and agree practical arrangements in advance.

Current NCSC scheme resources ↗

Your first-conversation checklist.

  • Organisation size and legal entity structure
  • Current Cyber Essentials position
  • Proposed scope and high-level estate summary
  • Target timeframe and commercial driver
  • Known gaps, dependencies and internal owners
Explore Enterprise Cyber Essentials Plus →
Readiness in practice

When the gaps are substantial, readiness creates the route to certification.

For one multinational energy organisation, the right starting point was not the Cyber Essentials Plus assessment. A comprehensive gap assessment showed where investment, technical change and operational improvement were needed first.

The findings helped the organisation build an internal business case and the resulting programme ran for approximately 12 months before the organisation was ready for formal assessment.

Read the full transformation case study →

What changed during the programme

Investment: independent findings supported the case for remediation budget.

Operations: vulnerability management moved towards Business as Usual rather than certification-time preparation.

Lifecycle: asset lifecycle management was strengthened so unsupported technology could be identified and managed earlier.

Outcome: the organisation successfully achieved Cyber Essentials Plus with a more sustainable foundation for maintaining the controls.

Discuss your assurance requirements

Tell us about your organisation, scope and target timeframe. Start with a conversation with an experienced assessor.

Discuss your requirements →