Cyber Essentialsi can unlock contracts, strengthen supplier confidence and reduce common cyber risks. Foundation shows you what needs attention, gives your team clear remediation actions and prepares the evidence for a smoother assessment.
CTRL-05LIVE EVIDENCE
CONTROL STATUSPriority action identified
Readiness gap found
Why readiness matters
We walk you through the maze of Cyber Essentials questions, technical controls and evidence requirements.
Certification can feel like a maze of questions, technical controls and evidence. The costly part is discovering gaps after submission—when a tender, customer deadline or insurance renewal is already waiting. Pentesys turns the requirements into a practical plan. We agree the scope, assess your current position, explain gaps in plain English and support remediation before you enter the formal certification process.
01Understand your likely pass position before submission
02Unblock tenders, supply-chain onboarding and customer requirements
03Give IT teams a prioritised remediation plan, not another questionnaire
04Keep evidence organised for assessment and annual renewal
Choose the level of assurance
Five control areas to meet.Two levels of assessment depth.Is Essentials or Plus right for you?
Both certifications establish a recognised baseline for firewalls, secure configuration, management of security updates, controls on user access and protection against malware to help prevent common cyber attacks.
The right route depends on the evidence your customers, tenders, insurers or leadership team expect.
CYBER ESSENTIALS
Verified self-assessment
Your organisation answers questions about the five controls across an agreed scope. The answers are reviewed through an authorised certification body.
Certification route
A practical recognised baseline
Useful for customer and supply-chain assurance
A common requirement in eligible government contracting
Best when you need a clear baseline and recognised evidence.Start today →
CYBER ESSENTIALS PLUS
Independent technical audit
Plus covers the same five controls and adds hands-on technical verification by an independent qualified assessor.
Certification route
Technical testing of a representative sample
Greater confidence that controls work in practice
Stronger assurance for higher-trust relationships
Best when stakeholders need independently tested assurance.Start today →
The scheme logos identify the two certification routes; they do not indicate that Pentesys awards either certification. Pentesys provides readiness and preparation support, while certification is completed through an authorised certification body. Cyber Essentials Plus is a structured technical audit of the scheme controls, not a substitute for a broader, objective-led penetration test.
The five Cyber Essentials controls
What does Cyber Essentials actually assess?
Cyber Essentials and Cyber Essentials Plus assess the same five technical controls. Plus adds independent testing to verify that those controls are working in practice.
01
Firewalls
Protect internet-connected devices and services by allowing only necessary, authorised network traffic.
02
Secure configuration
Remove unnecessary accounts, software and settings, and replace insecure defaults before systems are used.
03
Security update management
Keep operating systems, applications and firmware supported and apply high-risk or critical fixes within the required timescale.
04
User access control
Give people only the access they need, protect privileged accounts and use multi-factor authentication where required.
05
Malware protection
Prevent untrusted or malicious code from running through approved applications, anti-malware controls or application allow-listing.
2026 preparation priorities
Four common ways to fail an assessment.
A strong application will often fail if these four criteria are not met. Pentesys Foundation helps you avoid this outcome.
01Define scope precisely
Identify the legal entities, devices, networks and cloud services included, and document any justified exclusions clearly.
02Apply MFA consistently
Multi-factor authentication is mandatory for cloud services where it is available under the current requirements.
03Meet update timescales
High-risk and critical security updates must be installed within the required 14-day window across the full scope.
04Maintain the baseline
Keep control ownership clear, protections operating and assessment evidence current after certification.
How Pentesys works
A clear route from uncertainty to assessment-ready.
01
Scope
Agree which people, devices, networks and cloud services the certification will cover.
02
Assess
Review your current controls and identify evidence or configuration gaps.
03
Act
Give your technical team clear, prioritised remediation actions.
04
Prepare
Organise the evidence and, for Plus, rehearse the technical checks before assessment.
Annual cycleMaintain · review · renew12 months
→↓←↑
What you receive
Pentesys provides readiness guidance, remediation planning and evidence support. Formal Cyber Essentials certification is completed through an authorised certification body.
✓Cyber Essentials Plus pre-check findings where required
✓Renewal plan to reduce next year's scramble
Choose the right level of support
Prepare with the right evidence.
Cyber Essentials and Cyber Essentials Plus use the same five control themes, but the preparation and evidence required are different. Choose the route that matches your internal capacity and the level of independent proof your stakeholders expect.
Capability
Pentesys Foundation Ready
Self-led Cyber Essentials
Pentesys Foundation Plus-ready
Target outcome
Assessment-ready Cyber Essentials submission
Cyber Essentials submission
Prepared estate and evidence for an independent Plus audit
Control scope review
Included
Completed by your team
Included in greater technical depth
Questionnaire support
Guided review and evidence check
Completed by your team
Aligned to the five controls and audit preparation
Technical pre-assessment
Configuration and evidence review
Not included
Included
Device and control sampling
Not normally required
Not included
Included
Gap prioritisation
Prioritised action plan
Managed internally
Technical evidence-gap report
Remediation support
One remediation review
Managed internally
Remediation workshop
Formal certification or audit
Completed by an authorised certification body
Completed by an authorised certification body
Completed independently by an authorised certification body
Best suited to
Teams wanting a clear, supported route to Cyber Essentials
Teams with confident internal ownership and evidence
Not sure which level of proof you need?Tell us what is driving the requirement. We’ll help separate readiness support from the independent certification decision.
Pentesys holds Cyber Essentials certification. That matters because the guidance we give is grounded in the same practical controls and evidence process our customers work through.
Cyber Essentials is a government-backed scheme. Pentesys supports readiness and remediation planning; formal certification is awarded through an authorised certification body.
Pentesys is Cyber Essentials certifiedCertified 12 August 2026 · Whole organisation · Recertification due 12 August 2027View our current certificate ↗
Common questions
Cyber Essentials, without the ambiguity.
What is the difference between Cyber Essentials and Cyber Essentials Plus?+
Cyber Essentials is a verified self-assessment against five technical controls. Cyber Essentials Plus covers the same controls but adds an independent technical audit to verify that they are working in practice.
Does Pentesys award the Cyber Essentials certificate?+
No. Pentesys provides readiness reviews, remediation planning and evidence support. Formal assessment and certification are completed through an authorised Cyber Essentials certification body.
What does Cyber Essentials cover?+
The scheme focuses on firewalls, secure configuration, security update management, user access control and malware protection across the organisation’s agreed scope.
How long does Cyber Essentials certification last?+
Cyber Essentials and Cyber Essentials Plus certificates are valid for 12 months. Organisations need to recertify annually and maintain the controls throughout the certification period.
Can Pentesys help if we are not ready to submit?+
Yes. Foundation is designed to identify scope, control, configuration and evidence gaps before formal submission, then turn them into a prioritised remediation plan.
Explore the subject
Related guidance
Start with the basics, understand the risk and choose the right next action.
Pentesys has continuously performed admirably during our collaboration, giving us faith in their knowledge. They delivered work that above our expectations by approaching each project with a deep understanding of our specifications. Their team demonstrated a remarkable degree of proficiency by effectively pinpointing weaknesses and offering practical suggestions to reduce possible hazards.
MD·Fortis Cyber Security Limited01“
Unlike previous pentests that produced generic outputs, this engagement gave us clear, prioritised actions with real-world attack scenarios. The platform visibility into assets, vulnerabilities and remediation progress has helped us mature our security posture significantly. The team were professional, responsive, and genuinely cared about improving our security rather than just ticking a box.
Head of IT·Healthcare Technology Company02“
The red team and external attack surface management work highlighted blind spots we didn't know existed. What stood out was the strategic guidance alongside the technical delivery – helping us shape a longer-term security roadmap rather than a one-off engagement. This felt like a partnership, not just a transactional assessment.
CISO·SaaS Provider03“
Pentesys has continuously produced excellent work. Their group demonstrated extraordinary technical proficiency by spotting crucial flaws and offering clever fixes that greatly strengthened our security stance. Their meticulous approach and attention to detail ensured that every facet of the project was covered in full.
IT Security Specialist·Rightmove PLC04“
We engaged Pentesys and the team for a complex penetration test and adversary simulation. The quality of the technical findings, realism of the attack paths, and clarity of reporting were outstanding. The recommendations were practical and mapped clearly to business risk, which made board-level conversations much easier. We've since built Pentesys into our ongoing security assurance programme.
CTO·UK Financial Services Provider05
Assurance that joins up
Recognised expertise, built around your environment.
Pentesys combines independent assurance, qualified testers and practical integration with the systems your teams already use.
INDEPENDENTLY VERIFIEDCREST member companyPenetration Testing · EMEA
Tell us what you need to understand, test or prove. We'll recommend the smallest useful next step and prepare the right specialist for the conversation.