Cyber Essentials Readiness
A structured pre-assessment against the current question set, giving you a plain pass/fail position on every requirement before you submit.
Gap analysis, remediation support and evidence management to get you certified first time — and keep you certified year after year.
Powered by Mirage AssureCyber Essentials is often a contractual requirement before it is a security decision — needed for public sector work, supply chain onboarding or cyber insurance. Failing at submission is expensive in time and credibility.
We assess you against all five control areas, tell you plainly where you fall short, help you fix it and manage the evidence through the portal so the assessment itself becomes a formality.
Pick up the whole programme or just the parts you need — readiness, remediation, evidence or the technical audit preparation.
A structured pre-assessment against the current question set, giving you a plain pass/fail position on every requirement before you submit.
A dry run of the technical audit — device sampling, malware tests and vulnerability checks — so nothing fails on assessment day.
Deciding what is in and out of scope, including cloud services, BYOD and home working, to avoid the most common cause of failure.
Verification that all internet-facing and workstation software is supported and patched within the required fourteen-day window.
Build standards, default credentials, unnecessary services and account hardening checked against the certification requirements.
Administrative account separation, joiner-mover-leaver process and multi-factor authentication coverage across cloud services.
Endpoint protection configuration, update cadence and application allow-listing reviewed against the control requirements.
Perimeter and host firewall rules assessed, with unnecessary inbound services identified and closed.
Screenshots, policies and configuration exports collected, versioned and stored in the portal ready for the assessor.
Continuous monitoring and a scheduled pre-renewal review so recertification is straightforward rather than a yearly scramble.
Everything below is delivered and tracked through the Mirage Portal.
A structured review against all five Cyber Essentials controls, with a clear pass/fail position for each requirement.
Practical, prioritised guidance on configuration, patching and policy changes — not just a list of failures.
Pre-assessment technical verification mirroring the Cyber Essentials Plus audit, so there are no surprises on the day.
Evidence collected, versioned and stored in the Mirage Portal, ready for assessment and for next year's renewal.
Support producing the supporting documentation assessors expect, aligned to how you actually operate.
Continuous monitoring keeps controls in place between annual certifications rather than drifting after sign-off.
A consistent, transparent methodology from first conversation to verified remediation.
Agree the certification boundary — organisation-wide or a defined subset — and identify in-scope devices and services.
Review current configuration and policy against each control, documenting gaps and evidence needs.
Work through the gap list with your IT team, with guidance and verification at each step.
For Plus, we run the technical checks in advance to confirm you will pass.
Submit with confidence, then monitor controls through the year ahead of renewal.
For an organisation in reasonable shape, four to six weeks from gap analysis to submission is typical. Larger remediation lists take longer.
Cyber Essentials is a verified self-assessment. Plus adds independent technical testing of a sample of your devices and services.
Yes. We frequently pick up failed submissions, identify what went wrong and get organisations through on the next attempt.
CREST-registered testing delivered through a flexible PTaaS model — designed to fit your environment, risk profile and internal teams.