Pre-audit technical verification
We run the same checks an auditor will run — malware tests, patch status, secure config, access control and firewall review — before audit day.
Technical audit preparation, pre-assessment verification and evidence management so your Cyber Essentials Plus audit is a formality.
Cyber Essentials Plus adds independent technical testing to the self-assessed Cyber Essentials questionnaire. Many organisations fail because they assume the self-assessment is enough, or because a sample of devices fails on audit day.
We prepare you thoroughly: technical checks against the same five controls, sampled device testing, vulnerability scans and a complete evidence pack. By the time the auditor arrives, every control has been verified and documented in the Mirage Portal.
Everything below is delivered and tracked through the Mirage Portal.
We run the same checks an auditor will run — malware tests, patch status, secure config, access control and firewall review — before audit day.
A representative sample of workstations, servers and mobile devices is tested to surface issues that could cause a fail.
Internet-facing and internal systems are checked for unsupported software and unpatched vulnerabilities within the required windows.
Screenshots, exports and policy documents are collected, versioned and stored ready for the auditor.
Any gaps are fixed with clear guidance, then re-verified before the audit.
We support the audit itself, answer technical questions and provide additional evidence if the auditor asks for it.
Priced by organisation size. Credits are rounded up to the nearest whole credit at £125 each, and prices exclude UK VAT.
| Organisation size | Credits | Cost |
|---|---|---|
| Micro (0-9 Employees) | 12 | £1,500 |
| Small (10-49 Employees) | 21 | £2,625 |
| Medium (50-249 Employees) | 23 | £2,875 |
| Large (250+ Employees) | 34 | £4,250 |
A consistent, transparent methodology from first conversation to verified remediation.
We confirm the certification boundary and select representative devices for testing.
Technical checks mirror the audit process across all five control areas.
Gaps are fixed and re-tested so nothing fails on the day.
The evidence pack is completed and stored in the portal for auditor review.
We support the audit and confirm certification, then schedule renewal activity.
Yes. Cyber Essentials Plus requires the self-assessment questionnaire to be completed and verified before the technical audit.
The auditor samples a representative set. We test a similar sample in advance so issues are found early.
We work with you to remediate and re-test before the audit, so you go into certification with confidence.
CREST-registered testing delivered through a flexible PTaaS model — designed to fit your environment, risk profile and internal teams.