Cyber Essentials Basic and Plus certification delivered for a professional services firm with a fragmented device estate
The challenge
A mid-size professional services firm with 320 staff across four UK offices had never undergone formal cyber certification. Their device estate had grown organically — a mix of managed laptops, BYOD mobile devices, and legacy on-premise servers — with no consistent patch management or boundary firewall policy in place. A major public sector client required Cyber Essentials Plus certification as a contractual prerequisite.
Our approach
We conducted a scoping exercise to define the certification boundary, followed by a readiness assessment against all five Cyber Essentials technical controls. We identified and remediated gaps across patch management, access control, and malware protection before submitting for Basic certification. We then conducted the Plus verification — including authenticated vulnerability scanning and hands-on technical testing of sampled devices — to achieve the higher tier.
Key findings & outcomes
- Cyber Essentials Basic certification achieved within 3 weeks of engagement start
- Cyber Essentials Plus verified on first submission — no re-test required
- 47 out-of-support software instances identified and remediated prior to assessment
- Public sector contract secured — estimated £1.8M annual revenue unlocked
3weeks
Basic to certified
47
Vulnerabilities remediated
1st
Attempt Plus pass
We'd been told CE Plus would take months and be disruptive. It wasn't. They scoped it tightly, fixed what needed fixing, and we passed first time.
