Managed Cyber Essentials support, DIY preparation or assessment-only?
Compare managed Cyber Essentials readiness support, self-led preparation and assessment-only routes, including evidence, remediation and internal effort.
DECISION VIEW · FOUNDATION
Three routes. One clear decision.
Compare the approaches
Three ways to get Cyber Essentials. Which works best for your team?
Each route can be appropriate. The useful comparison is what it is designed to prove, the work your team must own and what happens after something is found.
01
GUIDED ROUTE
Managed readiness support
A specialist reviews scope, controls and evidence, then helps turn gaps into a prioritised plan before formal assessment.
Best when
Teams that want confidence, structure and practical support.
Watch for
Readiness support is separate from the independent certification decision.
02
INTERNAL ROUTE
Self-led preparation
Your team interprets the requirements, confirms scope, checks the five controls and assembles the submission evidence.
Best when
Organisations with confident internal ownership and current evidence.
Watch for
Ambiguous scope or weak evidence can create rework close to submission.
03
CERTIFICATION ROUTE
Assessment-only
An authorised certification body assesses the submission, or conducts the independent technical audit required for Plus.
Best when
Teams already confident they are ready to be assessed.
Watch for
The assessor tests or verifies; they are not a substitute for a readiness programme.
Questions before procurement
Four questions that narrow the choice.
Answer these before comparing suppliers or prices. They expose where ownership, evidence and expectations are still unclear.
Do we know exactly which organisation, devices, users and cloud services are in scope?
If the boundary is uncertain, resolve it before treating the questionnaire as an administrative exercise.
02
Can we evidence all five controls, not simply state that tools exist?
Evidence should reflect the agreed scope and current configuration rather than policy intent alone.
03
Is a customer, tender or insurer asking for Plus rather than the verified self-assessment?
The same five controls apply, but Plus adds independent technical testing and needs deeper preparation.
04
Who owns remediation if a gap is found?
A named internal owner and realistic deadline are more important than rushing to submit.
Side-by-side view
Compare what changes in practice.
The descriptions are category-level guidance, not claims about every provider. Confirm the precise scope, people, technology, evidence and exclusions before appointing anyone.
Decision factor
Managed readiness support
Self-led preparation
Assessment-only
Primary purpose
Prepare the organisation and evidence
Prepare internally
Complete formal assessment
Scope definition
Guided and challenged
Owned internally
Assessed as submitted
Five-control review
Structured readiness review
Internal review
Verification against scheme requirements
Evidence support
Organised and checked before submission
Collected internally
Evidence considered as part of assessment
Gap prioritisation
Clear remediation plan
Internal judgement
Failed or queried requirements may need correction
Remediation guidance
Included to the agreed scope
Provided internally
Usually outside the core assessment
Internal effort
Moderate and guided
Highest
Low only if already prepared
Best timing
Before submission or Plus audit
When controls and evidence are mature
When readiness is already established
Our suggestion
Choose self-led preparation when your team already understands the Cyber Essentials scope, controls and evidence. Choose assessment-only when you are confident the controls are operating and mainly need formal certification. Choose managed readiness support when you need help defining scope, finding gaps, organising evidence and reaching submission with fewer avoidable delays.
Where Pentesys fits
Feel like you need some help?
Pentesys helps establish the scope, review the five controls, check the available evidence and prioritise remediation. Formal assessment and certification remain with an authorised certification body, so customers can see exactly which role Pentesys is performing.
Can we complete Cyber Essentials without a readiness provider?+
Yes. Organisations can prepare internally and apply through an authorised certification body. Readiness support is useful when scope, evidence, control interpretation or remediation ownership is uncertain.
Does managed readiness guarantee certification?+
No provider should guarantee an independent certification outcome. Managed readiness reduces avoidable uncertainty and rework, while the authorised certification body retains the assessment decision.
Is Cyber Essentials Plus a penetration test?+
No. Cyber Essentials Plus is an independent technical audit of the five scheme controls. A penetration test examines a broader agreed technical scope for exploitable weaknesses and attack paths.
Trusted experience
Supporting recognised organisations.
Royal Ballet and Opera
BigBear.ai
Rightmove
Fortis
Gumtree
Orange
Small Luxury Hotels of the World
AI Incumbency
Royal Ballet and Opera
BigBear.ai
Rightmove
Fortis
Gumtree
Orange
Small Luxury Hotels of the World
AI Incumbency
“
Pentesys has continuously performed admirably during our collaboration, giving us faith in their knowledge. They delivered work that above our expectations by approaching each project with a deep understanding of our specifications. Their team demonstrated a remarkable degree of proficiency by effectively pinpointing weaknesses and offering practical suggestions to reduce possible hazards.
MD·Fortis Cyber Security Limited01“
Unlike previous pentests that produced generic outputs, this engagement gave us clear, prioritised actions with real-world attack scenarios. The platform visibility into assets, vulnerabilities and remediation progress has helped us mature our security posture significantly. The team were professional, responsive, and genuinely cared about improving our security rather than just ticking a box.
Head of IT·Healthcare Technology Company02“
The red team and external attack surface management work highlighted blind spots we didn't know existed. What stood out was the strategic guidance alongside the technical delivery – helping us shape a longer-term security roadmap rather than a one-off engagement. This felt like a partnership, not just a transactional assessment.
CISO·SaaS Provider03“
Pentesys has continuously produced excellent work. Their group demonstrated extraordinary technical proficiency by spotting crucial flaws and offering clever fixes that greatly strengthened our security stance. Their meticulous approach and attention to detail ensured that every facet of the project was covered in full.
IT Security Specialist·Rightmove PLC04“
We engaged Pentesys and the team for a complex penetration test and adversary simulation. The quality of the technical findings, realism of the attack paths, and clarity of reporting were outstanding. The recommendations were practical and mapped clearly to business risk, which made board-level conversations much easier. We've since built Pentesys into our ongoing security assurance programme.
CTO·UK Financial Services Provider05
Assurance that joins up
Recognised expertise, built around your environment.
Pentesys combines independent assurance, qualified testers and practical integration with the systems your teams already use.
INDEPENDENTLY VERIFIEDCREST member companyPenetration Testing · EMEA