Readiness, remediation and assessment support

Prepare properly for Cyber Essentials and Cyber Essentials Plus.

HAD-IT helps organisations define the certification scope, close technical gaps across the five controls, gather accurate evidence and prepare for assessment with a licensed Certification Body.

Government-backedA recognised baseline against common cyber threats
Two certification levelsVerified assessment or independent technical testing
Practical supportScope, remediation, evidence and readiness

More than completing a questionnaire

Begin with the systems, services and people that are actually in scope.

Cyber Essentials is the government-recommended minimum cyber-security standard for organisations of all sizes. It concentrates on five technical controls: firewalls, secure configuration, security update management, user access control and malware protection.

Cyber Essentials combines a verified self-assessment with independent review. Cyber Essentials Plus uses the same protections but adds more rigorous independent technical testing. HAD-IT can prepare and improve the environment; the formal assessment and certification decision remain with a licensed Certification Body.

How HAD-IT supports the journey

Turn the requirements into controlled, supportable changes.

Good preparation improves everyday security as well as the likelihood of a smoother assessment.

01

Define the real scope

Map corporate devices, remote working, BYOD, servers, routers, Microsoft 365 and other cloud services before deciding what the assessment covers.

02

Close technical gaps

Prioritise unsupported software, missing updates, weak administrator practices, absent MFA, unsuitable firewall rules and inconsistent endpoint protection.

03

Build accurate evidence

Create inventories, configuration records and factual answers that responsible leaders can review before the assessment is submitted.

04

Prepare for Plus testing

Check readiness across the agreed scope, resolve avoidable failures and coordinate practical access and timing with the independent assessor.

Choose the appropriate assurance level

The same controls, with different ways of demonstrating them.

We clarify what your customer, tender or internal security objective requires before planning the work.

Cyber Essentials

Prepare for the verified self-assessment by understanding the questions, implementing every applicable requirement and presenting accurate answers.

Cyber Essentials Plus

Build on Cyber Essentials with readiness for independent hands-on technical testing across a representative sample of the agreed environment.

Contract and supply-chain requirements

Confirm the required level, scope wording and deadline before technical work begins or a tender response makes an unsupported claim.

Renewal and continuous improvement

Recheck people, devices, software, cloud services and suppliers so previous answers are not copied into an environment that has changed.

From uncertainty to assessment readiness

A practical route to Cyber Essentials certification.

STEP 01

Discover & scope

We identify the organisation boundary, devices, software, cloud services, remote users, administrators and existing security controls.

STEP 02

Remediate & document

Gaps are prioritised and corrected, with inventories, settings, ownership and evidence recorded as changes are completed.

STEP 03

Prepare & coordinate

We help review the submission or Plus readiness and work alongside the chosen licensed Certification Body while keeping responsibilities clear.

Questions, answered

What organisations usually ask us.

The scheme is reviewed regularly, so we confirm the applicable question set, scope and technical requirements against current official guidance before work begins.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Both levels use the same five technical controls. Cyber Essentials is based on a verified self-assessment and independent review; Cyber Essentials Plus adds more rigorous independent technical testing to confirm that the controls are implemented.

Can HAD-IT issue the Cyber Essentials certificate?

HAD-IT provides preparation, remediation, evidence and coordination support. The assessment and certificate must be delivered by a Certification Body licensed through the official scheme. We keep that independent decision separate from our technical work.

Do Microsoft 365 and other cloud services count?

Yes. Current requirements bring cloud services that host organisational data or services into scope. Responsibility is shared with the provider, but the applicant must still configure its accounts, access and available security controls correctly.

Which version of the requirements applies?

The current NCSC Requirements for IT Infrastructure are version 3.3 for assessment accounts created from 27 April 2026. Because the scheme is reviewed regularly, we confirm the current version and marking approach when your work starts.

Can you guarantee that we will pass?

No provider should guarantee an independent assessment result before the scope and environment are examined. We identify and remediate gaps, prepare evidence and make remaining risks clear, while the Certification Body retains the assessment decision.

Start before the assessment clock is running

Let’s find the gaps and build a credible route to certification.

Discuss Cyber Essentials

One group. More expertise.

Four specialist teams. One joined-up view.

From secure systems and dependable infrastructure to the wider services your organisation needs, HAD-GROUP connects the right expertise around your business.