Cyber Essentials buyer guide

Managed Cyber Essentials support, DIY preparation or assessment-only?

Compare managed Cyber Essentials readiness support, self-led preparation and assessment-only routes, including evidence, remediation and internal effort.

Compare the approaches

Three ways to get Cyber Essentials.
Which works best for your team?

Each route can be appropriate. The useful comparison is what it is designed to prove, the work your team must own and what happens after something is found.

01
GUIDED ROUTE

Managed readiness support

A specialist reviews scope, controls and evidence, then helps turn gaps into a prioritised plan before formal assessment.

Best when
Teams that want confidence, structure and practical support.
Watch for
Readiness support is separate from the independent certification decision.
02
INTERNAL ROUTE

Self-led preparation

Your team interprets the requirements, confirms scope, checks the five controls and assembles the submission evidence.

Best when
Organisations with confident internal ownership and current evidence.
Watch for
Ambiguous scope or weak evidence can create rework close to submission.
03
CERTIFICATION ROUTE

Assessment-only

An authorised certification body assesses the submission, or conducts the independent technical audit required for Plus.

Best when
Teams already confident they are ready to be assessed.
Watch for
The assessor tests or verifies; they are not a substitute for a readiness programme.

Questions before procurement

Four questions that narrow the choice.

Answer these before comparing suppliers or prices. They expose where ownership, evidence and expectations are still unclear.

Speak to us
  1. 01

    Do we know exactly which organisation, devices, users and cloud services are in scope?

    If the boundary is uncertain, resolve it before treating the questionnaire as an administrative exercise.

  2. 02

    Can we evidence all five controls, not simply state that tools exist?

    Evidence should reflect the agreed scope and current configuration rather than policy intent alone.

  3. 03

    Is a customer, tender or insurer asking for Plus rather than the verified self-assessment?

    The same five controls apply, but Plus adds independent technical testing and needs deeper preparation.

  4. 04

    Who owns remediation if a gap is found?

    A named internal owner and realistic deadline are more important than rushing to submit.

Side-by-side view

Compare what changes in practice.

The descriptions are category-level guidance, not claims about every provider. Confirm the precise scope, people, technology, evidence and exclusions before appointing anyone.

Decision factorManaged readiness supportSelf-led preparationAssessment-only
Primary purposePrepare the organisation and evidencePrepare internallyComplete formal assessment
Scope definitionGuided and challengedOwned internallyAssessed as submitted
Five-control reviewStructured readiness reviewInternal reviewVerification against scheme requirements
Evidence supportOrganised and checked before submissionCollected internallyEvidence considered as part of assessment
Gap prioritisationClear remediation planInternal judgementFailed or queried requirements may need correction
Remediation guidanceIncluded to the agreed scopeProvided internallyUsually outside the core assessment
Internal effortModerate and guidedHighestLow only if already prepared
Best timingBefore submission or Plus auditWhen controls and evidence are matureWhen readiness is already established

Our suggestion

Choose self-led preparation when your team already understands the Cyber Essentials scope, controls and evidence. Choose assessment-only when you are confident the controls are operating and mainly need formal certification. Choose managed readiness support when you need help defining scope, finding gaps, organising evidence and reaching submission with fewer avoidable delays.

Where Pentesys fits

Feel like you need some help?

Pentesys helps establish the scope, review the five controls, check the available evidence and prioritise remediation. Formal assessment and certification remain with an authorised certification body, so customers can see exactly which role Pentesys is performing.

  • 01Defined readiness review
  • 02Questionnaire and evidence check
  • 03Prioritised remediation actions
  • 04Plus technical pre-assessment where required

FAQ

Common Questions

Can we complete Cyber Essentials without a readiness provider?

Yes. Organisations can prepare internally and apply through an authorised certification body. Readiness support is useful when scope, evidence, control interpretation or remediation ownership is uncertain.

Does managed readiness guarantee certification?

No provider should guarantee an independent certification outcome. Managed readiness reduces avoidable uncertainty and rework, while the authorised certification body retains the assessment decision.

Is Cyber Essentials Plus a penetration test?

No. Cyber Essentials Plus is an independent technical audit of the five scheme controls. A penetration test examines a broader agreed technical scope for exploitable weaknesses and attack paths.

Trusted experience

Supporting recognised organisations.

Royal Ballet and Opera logo
Royal Ballet and Opera
Rightmove logo
Rightmove
Fortis logo
Fortis
Orange logo
Orange
Small Luxury Hotels of the World logo
Small Luxury Hotels of the World
AI Incumbency logo
AI Incumbency
Pentesys has continuously performed admirably during our collaboration, giving us faith in their knowledge. They delivered work that above our expectations by approaching each project with a deep understanding of our specifications. Their team demonstrated a remarkable degree of proficiency by effectively pinpointing weaknesses and offering practical suggestions to reduce possible hazards.
MDFortis Cyber Security Limited
Unlike previous pentests that produced generic outputs, this engagement gave us clear, prioritised actions with real-world attack scenarios. The platform visibility into assets, vulnerabilities and remediation progress has helped us mature our security posture significantly. The team were professional, responsive, and genuinely cared about improving our security rather than just ticking a box.
Head of ITHealthcare Technology Company
The red team and external attack surface management work highlighted blind spots we didn't know existed. What stood out was the strategic guidance alongside the technical delivery – helping us shape a longer-term security roadmap rather than a one-off engagement. This felt like a partnership, not just a transactional assessment.
CISOSaaS Provider
Pentesys has continuously produced excellent work. Their group demonstrated extraordinary technical proficiency by spotting crucial flaws and offering clever fixes that greatly strengthened our security stance. Their meticulous approach and attention to detail ensured that every facet of the project was covered in full.
IT Security SpecialistRightmove PLC
We engaged Pentesys and the team for a complex penetration test and adversary simulation. The quality of the technical findings, realism of the attack paths, and clarity of reporting were outstanding. The recommendations were practical and mapped clearly to business risk, which made board-level conversations much easier. We've since built Pentesys into our ongoing security assurance programme.
CTOUK Financial Services Provider

Assurance that joins up

Recognised expertise, built around your environment.

Pentesys combines independent assurance, qualified testers and practical integration with the systems your teams already use.

The next useful step

Choose the smallest scope that answers the question.

Tell us what you need to prove, what has already been tested and what your stakeholders expect. We’ll recommend a proportionate route.

Plan your readiness review