Skip to content
Pentesys
Compliance

CyberEssentialsandCyberEssentialsPlus,withouttheguesswork

Gap analysis, remediation support and evidence management to get you certified first time — and keep you certified year after year.

Mirage AssurePowered by Mirage Assure

Cyber Essentials is often a contractual requirement before it is a security decision — needed for public sector work, supply chain onboarding or cyber insurance. Failing at submission is expensive in time and credibility.

We assess you against all five control areas, tell you plainly where you fall short, help you fix it and manage the evidence through the portal so the assessment itself becomes a formality.

How we support you

Support at every stage of certification

Pick up the whole programme or just the parts you need — readiness, remediation, evidence or the technical audit preparation.

Cyber Essentials Readiness

A structured pre-assessment against the current question set, giving you a plain pass/fail position on every requirement before you submit.

Cyber Essentials Plus Preparation

A dry run of the technical audit — device sampling, malware tests and vulnerability checks — so nothing fails on assessment day.

Scope Definition Workshop

Deciding what is in and out of scope, including cloud services, BYOD and home working, to avoid the most common cause of failure.

Patch & Vulnerability Review

Verification that all internet-facing and workstation software is supported and patched within the required fourteen-day window.

Secure Configuration Review

Build standards, default credentials, unnecessary services and account hardening checked against the certification requirements.

Access Control & MFA Review

Administrative account separation, joiner-mover-leaver process and multi-factor authentication coverage across cloud services.

Malware Protection Assessment

Endpoint protection configuration, update cadence and application allow-listing reviewed against the control requirements.

Firewall & Boundary Review

Perimeter and host firewall rules assessed, with unnecessary inbound services identified and closed.

Evidence Pack Production

Screenshots, policies and configuration exports collected, versioned and stored in the portal ready for the assessor.

Annual Renewal Management

Continuous monitoring and a scheduled pre-renewal review so recertification is straightforward rather than a yearly scramble.

Capabilities

What's included in Cyber Essentials

Everything below is delivered and tracked through the Mirage Portal.

Gap analysis

A structured review against all five Cyber Essentials controls, with a clear pass/fail position for each requirement.

Remediation support

Practical, prioritised guidance on configuration, patching and policy changes — not just a list of failures.

Plus readiness

Pre-assessment technical verification mirroring the Cyber Essentials Plus audit, so there are no surprises on the day.

Evidence management

Evidence collected, versioned and stored in the Mirage Portal, ready for assessment and for next year's renewal.

Policy and documentation

Support producing the supporting documentation assessors expect, aligned to how you actually operate.

Ongoing assurance

Continuous monitoring keeps controls in place between annual certifications rather than drifting after sign-off.

Coverage

Scope and depth

The five controls

  • Firewalls and internet gateways
  • Secure configuration
  • User access control
  • Malware protection
  • Security update management
  • Scope definition and boundary agreement

Beyond certification

  • Cyber Essentials Plus technical verification
  • Supply chain and tender evidence packs
  • Insurance questionnaire support
  • Alignment with ISO 27001 and NIS2 groundwork
  • Annual renewal planning
  • Continuous control monitoring
How it works

Our delivery process

A consistent, transparent methodology from first conversation to verified remediation.

  1. 01

    Scope

    Agree the certification boundary — organisation-wide or a defined subset — and identify in-scope devices and services.

  2. 02

    Assess

    Review current configuration and policy against each control, documenting gaps and evidence needs.

  3. 03

    Remediate

    Work through the gap list with your IT team, with guidance and verification at each step.

  4. 04

    Verify

    For Plus, we run the technical checks in advance to confirm you will pass.

  5. 05

    Certify and maintain

    Submit with confidence, then monitor controls through the year ahead of renewal.

What you receive

  • Gap analysis report with per-control pass/fail status
  • Prioritised remediation plan with owners and effort estimates
  • Evidence pack stored and versioned in the portal
  • Pre-assessment verification results for Cyber Essentials Plus
  • Renewal calendar and ongoing control monitoring

Business outcomes

  • First-time certification without wasted submissions
  • Contract and tender requirements unblocked
  • Better insurance and supply chain positioning
  • A baseline that genuinely reduces common attack paths
FAQs

Common questions

How long does certification take?

For an organisation in reasonable shape, four to six weeks from gap analysis to submission is typical. Larger remediation lists take longer.

What is the difference between Cyber Essentials and Plus?

Cyber Essentials is a verified self-assessment. Plus adds independent technical testing of a sample of your devices and services.

Can you help if we have already failed an assessment?

Yes. We frequently pick up failed submissions, identify what went wrong and get organisations through on the next attempt.

Save time and book a call with us

Enterprise-grade penetration testing, built around your business

CREST-registered testing delivered through a flexible PTaaS model — designed to fit your environment, risk profile and internal teams.