Define the real scope
Map corporate devices, remote working, BYOD, servers, routers, Microsoft 365 and other cloud services before deciding what the assessment covers.
Business IT, cloud and network specialists
Readiness, remediation and assessment support
HAD-IT helps organisations define the certification scope, close technical gaps across the five controls, gather accurate evidence and prepare for assessment with a licensed Certification Body.
Scope. Secure. Evidence.
More than completing a questionnaire
Cyber Essentials is the government-recommended minimum cyber-security standard for organisations of all sizes. It concentrates on five technical controls: firewalls, secure configuration, security update management, user access control and malware protection.
Cyber Essentials combines a verified self-assessment with independent review. Cyber Essentials Plus uses the same protections but adds more rigorous independent technical testing. HAD-IT can prepare and improve the environment; the formal assessment and certification decision remain with a licensed Certification Body.
How HAD-IT supports the journey
Good preparation improves everyday security as well as the likelihood of a smoother assessment.
Map corporate devices, remote working, BYOD, servers, routers, Microsoft 365 and other cloud services before deciding what the assessment covers.
Prioritise unsupported software, missing updates, weak administrator practices, absent MFA, unsuitable firewall rules and inconsistent endpoint protection.
Create inventories, configuration records and factual answers that responsible leaders can review before the assessment is submitted.
Check readiness across the agreed scope, resolve avoidable failures and coordinate practical access and timing with the independent assessor.
Choose the appropriate assurance level
We clarify what your customer, tender or internal security objective requires before planning the work.
Prepare for the verified self-assessment by understanding the questions, implementing every applicable requirement and presenting accurate answers.
Build on Cyber Essentials with readiness for independent hands-on technical testing across a representative sample of the agreed environment.
Confirm the required level, scope wording and deadline before technical work begins or a tender response makes an unsupported claim.
Recheck people, devices, software, cloud services and suppliers so previous answers are not copied into an environment that has changed.
From uncertainty to assessment readiness
We identify the organisation boundary, devices, software, cloud services, remote users, administrators and existing security controls.
Gaps are prioritised and corrected, with inventories, settings, ownership and evidence recorded as changes are completed.
We help review the submission or Plus readiness and work alongside the chosen licensed Certification Body while keeping responsibilities clear.
Questions, answered
The scheme is reviewed regularly, so we confirm the applicable question set, scope and technical requirements against current official guidance before work begins.
Both levels use the same five technical controls. Cyber Essentials is based on a verified self-assessment and independent review; Cyber Essentials Plus adds more rigorous independent technical testing to confirm that the controls are implemented.
HAD-IT provides preparation, remediation, evidence and coordination support. The assessment and certificate must be delivered by a Certification Body licensed through the official scheme. We keep that independent decision separate from our technical work.
Yes. Current requirements bring cloud services that host organisational data or services into scope. Responsibility is shared with the provider, but the applicant must still configure its accounts, access and available security controls correctly.
The current NCSC Requirements for IT Infrastructure are version 3.3 for assessment accounts created from 27 April 2026. Because the scheme is reviewed regularly, we confirm the current version and marking approach when your work starts.
No provider should guarantee an independent assessment result before the scope and environment are examined. We identify and remediate gaps, prepare evidence and make remaining risks clear, while the Certification Body retains the assessment decision.
Start before the assessment clock is running
One group. More expertise.
From secure systems and dependable infrastructure to the wider services your organisation needs, HAD-GROUP connects the right expertise around your business.