Managed cyber security

Cyber Essentials Readiness

Practical preparation for Cyber Essentials and Cyber Essentials Plus.

What is Cyber Essentials Readiness?

Cyber Essentials readiness support helps a business define the assessment scope, understand the current requirements, close technical gaps and prepare accurate evidence. 39Security provides preparation and remediation support; certification is awarded independently by an authorised Certification Body and its assessment fee is separate unless explicitly included.

Who is this service for?

UK businesses seeking Cyber Essentials or preparing for Cyber Essentials Plus because of customer contracts, public-sector supply chains, insurance, governance or a desire to establish a practical technical baseline.

What problem does it solve?

Applications can fail when the scope is unclear, unsupported devices remain in use, cloud services are omitted, administrator access is weak or questionnaire answers do not match the real environment. Last-minute remediation also increases disruption and cost.

What is included?

  • Scope, asset and cloud-service review
  • Assessment against the current five technical controls
  • Prioritised gap and remediation plan
  • Firewall and secure-configuration guidance
  • Security-update and unsupported-software review
  • User-access and MFA review
  • Malware-protection evidence support
  • Questionnaire quality review and assessment preparation

What is not included?

  • Issuing the certificate
  • Independent Certification Body fees unless stated
  • Guarantee of passing an independent assessment
  • Remediation of every legacy system within the base review fee
  • Legal interpretation of customer contracts

How implementation works

We begin with a scope workshop covering users, devices, servers, cloud services, remote access and internet boundaries. Evidence is gathered, gaps are recorded and remediation is assigned. When controls are ready, questionnaire answers are reviewed for accuracy and consistency before submission to the chosen Certification Body.

Supported platforms and products

The assessment scope may include Windows, macOS, mobile devices, servers, network equipment, Microsoft 365, cloud services and remote working. The exact Cyber Essentials requirements and grace periods in force at the assessment date are used.

How quickly are alerts investigated?

Readiness is a project rather than an alert-monitoring service. Security issues discovered during the review are prioritised and urgent exposure is escalated. Ongoing monitoring can be added through managed security plans.

Who responds?

39Security explains the requirement, recommends proportionate changes, carries out agreed configuration work and coordinates evidence with the client and existing IT provider. The Certification Body makes the independent assessment decision.

What evidence and reporting will you receive?

The customer receives a gap record, remediation tracker, scope notes and supporting evidence references. Cyber Essentials Plus preparation can include technical sampling readiness and pre-assessment checks.

Cyber Essentials, insurance and Microsoft 365

Cyber Essentials addresses five technical control areas. It can support insurer and supplier expectations but does not replace wider risk management, incident response, backup, data protection or ISO/IEC 27001 where those are required.

What does it cost?

Readiness, managed preparation, Plus preparation and annual renewal packages are shown excluding VAT. The independent assessment and certification charge is separate unless the proposal states otherwise.

How is the service governed?

Before activation, the proposal should identify the covered users, devices, locations and platforms, together with the service window, escalation contacts and change responsibilities. During operation, material exceptions are recorded rather than hidden, and recommendations are separated into urgent actions, planned improvements and optional projects. This gives managers a practical view of risk, cost and ownership.

Service reviews should test whether coverage still matches the business. New starters, leavers, acquisitions, cloud applications, office moves and supplier changes can all create gaps. 39Security therefore treats onboarding, reporting and periodic review as part of the control, not as administration around the edge of the product.

What should good delivery look like?

A buyer should be able to identify what is protected, who is watching it, what happens when something goes wrong and which evidence will be available afterwards. The provider should explain limitations honestly, avoid vague promises and document any dependency on Microsoft licensing, internet connectivity, third-party suppliers or customer action. Clear boundaries make response faster and reduce disputes during an incident.

Questions to ask before selecting a provider

  • Which systems, users and locations are included in the quoted scope?
  • Who reviews alerts, during which hours, and what happens when the named contact is unavailable?
  • What evidence will we receive for clients, insurers, auditors or board reporting?
  • Which actions are included in the monthly fee and which require separate project approval?
  • How are service quality, response times, exclusions and exit arrangements documented?

Frequently asked questions

Can 39Security award Cyber Essentials certification?

No. 39Security provides readiness, remediation and evidence support. The certification decision is made by an authorised independent Certification Body through the official scheme.

What are the five Cyber Essentials controls?

The scheme covers firewalls, secure configuration, security update management, user access control and malware protection. The organisation must apply the current requirements across the declared scope.

Is the certification fee included?

The website package price covers the stated 39Security consultancy and technical preparation. The independent Certification Body assessment fee is separate unless a written proposal explicitly includes it.

How often must Cyber Essentials be renewed?

Certification is time-limited and is normally renewed annually. Ongoing control reviews reduce the risk of discovering unsupported systems, account issues or evidence gaps just before renewal.