Build the baseline. Prove it works.

Get Cyber Essentials Ready

Foundation · Get Cyber Essentials Ready

Cyber Essentials can unlock contracts, strengthen supplier confidence and reduce common cyber risks. Foundation shows you what needs attention, gives your team clear remediation actions and prepares the evidence for a smoother assessment.

Why readiness matters

We walk you through the maze of Cyber Essentials questions, technical controls and evidence requirements.

Certification can feel like a maze of questions, technical controls and evidence. The costly part is discovering gaps after submission—when a tender, customer deadline or insurance renewal is already waiting. Pentesys turns the requirements into a practical plan. We agree the scope, assess your current position, explain gaps in plain English and support remediation before you enter the formal certification process.

  • 01Understand your likely pass position before submission
  • 02Unblock tenders, supply-chain onboarding and customer requirements
  • 03Give IT teams a prioritised remediation plan, not another questionnaire
  • 04Keep evidence organised for assessment and annual renewal

Choose the level of assurance

Five control areas to meet.Two levels of assessment depth.Is Essentials or Plus right for you?

Both certifications establish a recognised baseline for firewalls, secure configuration, management of security updates, controls on user access and protection against malware to help prevent common cyber attacks.

The right route depends on the evidence your customers, tenders, insurers or leadership team expect.

CYBER ESSENTIALS

Verified self-assessment

Your organisation answers questions about the five controls across an agreed scope. The answers are reviewed through an authorised certification body.

  • A practical recognised baseline
  • Useful for customer and supply-chain assurance
  • A common requirement in eligible government contracting
Best when you need a clear baseline and recognised evidence.Start today
CYBER ESSENTIALS PLUS

Independent technical audit

Plus covers the same five controls and adds hands-on technical verification by an independent qualified assessor.

  • Technical testing of a representative sample
  • Greater confidence that controls work in practice
  • Stronger assurance for higher-trust relationships
Best when stakeholders need independently tested assurance.Start today

The scheme logos identify the two certification routes; they do not indicate that Pentesys awards either certification. Pentesys provides readiness and preparation support, while certification is completed through an authorised certification body. Cyber Essentials Plus is a structured technical audit of the scheme controls, not a substitute for a broader, objective-led penetration test.

The five Cyber Essentials controls

What does Cyber Essentials actually assess?

Cyber Essentials and Cyber Essentials Plus assess the same five technical controls. Plus adds independent testing to verify that those controls are working in practice.

01

Firewalls

Protect internet-connected devices and services by allowing only necessary, authorised network traffic.

02

Secure configuration

Remove unnecessary accounts, software and settings, and replace insecure defaults before systems are used.

03

Security update management

Keep operating systems, applications and firmware supported and apply high-risk or critical fixes within the required timescale.

04

User access control

Give people only the access they need, protect privileged accounts and use multi-factor authentication where required.

05

Malware protection

Prevent untrusted or malicious code from running through approved applications, anti-malware controls or application allow-listing.

2026 preparation priorities

Four common ways to fail an assessment.

A strong application will often fail if these four criteria are not met. Pentesys Foundation helps you avoid this outcome.

01Define scope precisely

Identify the legal entities, devices, networks and cloud services included, and document any justified exclusions clearly.

02Apply MFA consistently

Multi-factor authentication is mandatory for cloud services where it is available under the current requirements.

03Meet update timescales

High-risk and critical security updates must be installed within the required 14-day window across the full scope.

04Maintain the baseline

Keep control ownership clear, protections operating and assessment evidence current after certification.

How Pentesys works

A clear route from uncertainty to assessment-ready.

01

Scope

Agree which people, devices, networks and cloud services the certification will cover.

02

Assess

Review your current controls and identify evidence or configuration gaps.

03

Act

Give your technical team clear, prioritised remediation actions.

04

Prepare

Organise the evidence and, for Plus, rehearse the technical checks before assessment.

Annual cycleMaintain · review · renew12 months

What you receive

Pentesys provides readiness guidance, remediation planning and evidence support. Formal Cyber Essentials certification is completed through an authorised certification body.

Ready to get started

Choose the right level of support

Prepare with the right evidence.

Cyber Essentials and Cyber Essentials Plus use the same five control themes, but the preparation and evidence required are different. Choose the route that matches your internal capacity and the level of independent proof your stakeholders expect.

CapabilityPentesys Foundation ReadySelf-led Cyber EssentialsPentesys Foundation Plus-ready
Target outcomeAssessment-ready Cyber Essentials submissionCyber Essentials submissionPrepared estate and evidence for an independent Plus audit
Control scope reviewIncludedCompleted by your teamIncluded in greater technical depth
Questionnaire supportGuided review and evidence checkCompleted by your teamAligned to the five controls and audit preparation
Technical pre-assessmentConfiguration and evidence reviewNot includedIncluded
Device and control samplingNot normally requiredNot includedIncluded
Gap prioritisationPrioritised action planManaged internallyTechnical evidence-gap report
Remediation supportOne remediation reviewManaged internallyRemediation workshop
Formal certification or auditCompleted by an authorised certification bodyCompleted by an authorised certification bodyCompleted independently by an authorised certification body
Best suited toTeams wanting a clear, supported route to Cyber EssentialsTeams with confident internal ownership and evidenceOrganisations needing stronger independently tested assurance

Not sure which level of proof you need?Tell us what is driving the requirement. We’ll help separate readiness support from the independent certification decision.

Discuss the right Foundation route

A proportionate starting point

Start with the support your team needs.

Published prices use a defined starting scope. We confirm any third-party certification-body fees separately before work begins.

ONE-OFF READINESS

Foundation – Cyber Essentials Ready

£795

All you need to be in great shape for your Cyber Essentials assessment.

  • Readiness review
  • Questionnaire and evidence check
  • Prioritised action plan
  • One remediation review
PLUS PREPARATION

Foundation – Cyber Essentials Plus Ready

from £2,495

We help you prepare the technical foundation and evidence for the more rigorous Cyber Essentials Plus audit.

  • Technical pre-assessment
  • Device and control sampling
  • Evidence-gap report
  • Remediation workshop

Certified in our own business

We apply the Cyber Essentials baseline ourselves.

Pentesys holds Cyber Essentials certification. That matters because the guidance we give is grounded in the same practical controls and evidence process our customers work through.

Cyber Essentials is a government-backed scheme. Pentesys supports readiness and remediation planning; formal certification is awarded through an authorised certification body.

Common questions

Cyber Essentials, without the ambiguity.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a verified self-assessment against five technical controls. Cyber Essentials Plus covers the same controls but adds an independent technical audit to verify that they are working in practice.

Does Pentesys award the Cyber Essentials certificate?

No. Pentesys provides readiness reviews, remediation planning and evidence support. Formal assessment and certification are completed through an authorised Cyber Essentials certification body.

What does Cyber Essentials cover?

The scheme focuses on firewalls, secure configuration, security update management, user access control and malware protection across the organisation’s agreed scope.

How long does Cyber Essentials certification last?

Cyber Essentials and Cyber Essentials Plus certificates are valid for 12 months. Organisations need to recertify annually and maintain the controls throughout the certification period.

Can Pentesys help if we are not ready to submit?

Yes. Foundation is designed to identify scope, control, configuration and evidence gaps before formal submission, then turn them into a prioritised remediation plan.

Trusted experience

Supporting recognised organisations.

Royal Ballet and Opera logo
Royal Ballet and Opera
Rightmove logo
Rightmove
Fortis logo
Fortis
Orange logo
Orange
Small Luxury Hotels of the World logo
Small Luxury Hotels of the World
AI Incumbency logo
AI Incumbency
Pentesys has continuously performed admirably during our collaboration, giving us faith in their knowledge. They delivered work that above our expectations by approaching each project with a deep understanding of our specifications. Their team demonstrated a remarkable degree of proficiency by effectively pinpointing weaknesses and offering practical suggestions to reduce possible hazards.
MDFortis Cyber Security Limited
Unlike previous pentests that produced generic outputs, this engagement gave us clear, prioritised actions with real-world attack scenarios. The platform visibility into assets, vulnerabilities and remediation progress has helped us mature our security posture significantly. The team were professional, responsive, and genuinely cared about improving our security rather than just ticking a box.
Head of ITHealthcare Technology Company
The red team and external attack surface management work highlighted blind spots we didn't know existed. What stood out was the strategic guidance alongside the technical delivery – helping us shape a longer-term security roadmap rather than a one-off engagement. This felt like a partnership, not just a transactional assessment.
CISOSaaS Provider
Pentesys has continuously produced excellent work. Their group demonstrated extraordinary technical proficiency by spotting crucial flaws and offering clever fixes that greatly strengthened our security stance. Their meticulous approach and attention to detail ensured that every facet of the project was covered in full.
IT Security SpecialistRightmove PLC
We engaged Pentesys and the team for a complex penetration test and adversary simulation. The quality of the technical findings, realism of the attack paths, and clarity of reporting were outstanding. The recommendations were practical and mapped clearly to business risk, which made board-level conversations much easier. We've since built Pentesys into our ongoing security assurance programme.
CTOUK Financial Services Provider

Assurance that joins up

Recognised expertise, built around your environment.

Pentesys combines independent assurance, qualified testers and practical integration with the systems your teams already use.

Ready to apply this to your environment?

Turn readiness into an owned route to assessment.

Tell us what you need to understand, test or prove. We'll recommend the smallest useful next step and prepare the right specialist for the conversation.

Speak to us