Managed Cyber Essentials and Cyber Essentials Plus

Ongoing Cyber Essentials and Cyber Essentials Plus support combining annual certification, vulnerability monitoring, readiness checks and practical reporting.

Cyber Essentials is renewed annually, but the technology and working practices inside an organisation change throughout the year. New devices appear, software reaches the end of support and internet-facing services are added or replaced.

This service brings the annual certification process, vulnerability monitoring, readiness checks and renewal preparation into one managed cycle. It reduces the amount of work left until the weeks before renewal and gives your organisation or IT provider a regular view of issues that could affect the next assessment.

Managed Cyber Essentials

Managed Cyber Essentials supports the verified self-assessment and the work needed to maintain readiness between annual assessments.

Depending on the agreed service, it can include:

  • planning the annual assessment and renewal timetable
  • scope and readiness support
  • the official Cyber Essentials assessment process delivered by Be Secure Cyber as an IASME licensed Certification Body
  • recurring vulnerability monitoring for the agreed estate
  • reporting on issues such as unsupported software, missing security updates and exposed services
  • evidence and control reviews during the year
  • liaison with your IT staff or provider
  • preparation before renewal so issues are not all discovered at the end

Cyber Essentials remains a verified self-assessment. Your organisation operates the controls, completes or approves the answers and confirms that the information supplied is accurate. Where monitoring identifies a concern, we explain what it means and work with the responsible team to agree the next step.

Managed Cyber Essentials Plus

Managed Cyber Essentials Plus includes the same cycle of regular reviews, together with the additional preparation and technical assessment needed for Cyber Essentials Plus.

The service can include:

  • readiness reviews before technical testing
  • preparation of the device sample and access needed for testing
  • the annual Cyber Essentials Plus technical assessment
  • discussion of failed checks or weaknesses found
  • remediation planning and retesting where agreed
  • monitoring during the year to reduce surprises at renewal

Cyber Essentials Plus assesses the same technical controls as Cyber Essentials and adds independent technical testing. Readiness advice can help an organisation prepare, but the certification decision depends on whether the assessed environment meets the scheme requirements. A successful outcome cannot be guaranteed.

What happens during the year

The service follows an agreed cycle rather than waiting for the renewal date. Reviews can consider changes to devices, software, cloud services, remote working and internet-facing systems, along with evidence that supports the annual assessment.

Vulnerability monitoring can help identify missing updates and exposed services within the agreed coverage. It does not prove that every control is compliant or replace the organisation’s responsibility for managing its environment.

Reporting gives the business and its IT provider a shared view of the issues that could affect readiness. This is particularly useful where responsibilities are split across several suppliers or where customer and tender requirements make renewal dates important.

What remains with your organisation

Your organisation and its IT provider remain responsible for maintaining the environment, installing updates, making configuration changes and operating the controls described in the assessment.

You also need to tell Be Secure Cyber about material changes to the certification scope and provide complete, accurate assessment information. The managed service can identify and track work, but patch deployment and routine IT administration are not included unless separately agreed.

Annual certification remains unchanged

The certificate is still issued through the normal annual Cyber Essentials or Cyber Essentials Plus process. The managed service supports the work around that certification and helps maintain readiness between assessment dates; it does not create continuous certification or guarantee that every control remains compliant at every moment.

This distinction matters. Monitoring and regular reviews can reduce the amount of work left until renewal and make changes easier to manage, but they do not extend a certificate or remove the need for the annual assessment.

Who the service is for

Managed Cyber Essentials may suit organisations that:

  • renew Cyber Essentials or Cyber Essentials Plus each year
  • need certification for customers, tenders or supply chain requirements
  • rely on an external IT provider and want independent oversight of readiness
  • have changing devices, software or cloud services
  • want recurring visibility of vulnerabilities relevant to the assessed estate
  • have previously faced a rushed or difficult renewal

Organisations seeking certification for the first time can still use the existing Cyber Essentials or Cyber Essentials Plus services as defined pieces of work. The managed service is intended for those who want an ongoing relationship around annual certification and the controls that support it.

Republic of Ireland businesses with a recurring UK customer, tender or supply chain requirement can read about Cyber Essentials for Irish businesses before discussing an ongoing arrangement.

Discuss your renewal cycle

Talk to Be Secure Cyber about the systems in scope, your renewal date, the way IT responsibilities are divided and the level of support you need.

Discuss managed Cyber Essentials support