Consultant reviewing a technical gap analysis report with a client
Cyber Essentials gap analysis

Find out where you stand before you commit to a certification date.

A fixed-scope diagnostic against all five Cyber Essentials controls, run before you submit anything, so you know exactly what needs fixing and roughly how long it will take.

Controls reviewed
5
Typical turnaround
7
Gaps found, avg.
9
Illustrative figures
The challenge

Most businesses don't know which control will trip them up.

Cyber Essentials looks straightforward on paper: five control areas, a self-assessment questionnaire, a modest annual cost. In practice, businesses regularly discover during the assessment itself that a firewall rule was never tightened after an office move, that a departed contractor's laptop is still on the domain, or that a cloud admin account has no multi-factor authentication because nobody reviewed it since the account was set up two years ago.

The self-assessment questionnaire asks precise, technical questions about configuration — not intentions. It doesn't accept 'we're generally careful' as an answer, and it doesn't distinguish between a business that has genuinely reviewed its estate and one that's guessing. Answering honestly without first checking usually means either failing outright or submitting answers that won't survive scrutiny if the assessor asks for evidence.

This becomes a real business problem when certification is tied to a deadline — a tender submission, a client's supplier assurance requirement, or an insurance renewal condition. Finding out three days before the deadline that your endpoint protection isn't centrally managed, or that unsupported software is still running on a finance team laptop, leaves no time to fix it properly.

IT teams and outsourced providers are often confident their environment is compliant because it's well run day to day. Well run and Cyber Essentials compliant aren't the same thing — the scheme has specific, sometimes narrow requirements around scope boundaries, home working devices, and cloud service configuration that don't always match how a business actually operates.

Smaller organisations without a dedicated security function feel this most acutely. There's rarely anyone whose job it is to check firewall rulesets against a control checklist, and asking a generalist IT contact to self-audit against a scheme they haven't seen before produces inconsistent results.

A gap analysis exists to remove that guesswork before it costs you time or a failed assessment. It puts a second, independent set of eyes on the estate and gives you a plain answer on where you stand.

  • Configuration drift on firewalls and routers since the last review
  • Unmanaged or unsupported devices still connected to the network
  • Admin accounts and cloud services without multi-factor authentication enforced
  • Patch management gaps on software that's out of mainstream support
  • Scope boundary confusion around home working and BYOD devices
Our approach

A structured review against the five controls, not a checklist tick.

We start with a short scoping call to confirm what's in scope — devices, cloud services, sites and any bring-your-own-device arrangements — because getting the boundary wrong is one of the most common reasons assessments go badly. Scope defines the whole exercise, so we agree it in writing before any technical review begins.

From there we work through each of the five controls in turn: firewalls and internet gateways, secure configuration, user access control, malware protection, and security update management. For each one we request specific evidence — configuration exports, screenshots, account lists, patch reports — rather than relying on a verbal description of how things are set up.

Every finding is recorded against the specific requirement it relates to, scored as met, partially met or not met, and given a plain-language explanation of why. We avoid vague statements like 'improve access control' in favour of specifics: which accounts, which setting, which device.

Findings are then ranked by effort and risk, not by control order, so you can see at a glance what's a five-minute configuration change and what needs procurement or a policy decision from leadership. This is the part clients tell us they value most — a plan they can actually work through, rather than a long list with no sense of priority.

We deliver the findings in a session with your IT contact or provider, walking through each item so there's no ambiguity about what's expected. Written reports are useful for the record; a conversation is what actually gets gaps closed.

Where you want us to close the gaps ourselves, we can quote that as separate, clearly scoped remediation work. There's no obligation to use us for it — plenty of clients take the report to their existing IT provider instead, which is entirely reasonable.

  • Written scope agreement before technical review starts
  • Evidence-based scoring against each of the five controls
  • Findings ranked by effort and risk, not by checklist order
  • Walkthrough session with your team, not just a PDF
  • Optional, separately quoted remediation support
What's included

Everything in the engagement, set out up front.

A fixed-scope engagement covering the full assessment lifecycle, from scoping through to a plan you can hand to your own team.

Scope confirmation

Agreed in writing before review starts, covering devices, cloud services, sites and remote working arrangements.

Firewall & gateway review

Rule sets, default credentials and administrative access checked against scheme requirements.

Secure configuration check

Device build standards, unnecessary services and default accounts reviewed across a representative sample.

Access control review

Account provisioning, privilege levels and multi-factor authentication assessed across systems in scope.

Patch & malware protection audit

Update cadence, unsupported software and endpoint protection coverage checked against current status.

Findings walkthrough

A live session with your IT contact to talk through every finding and answer questions directly.

Deliverables

What you receive.

  • Written scope statement agreed before assessment begins
  • Control-by-control findings report with evidence references
  • Gap severity ratings and estimated remediation effort
  • Prioritised remediation roadmap with suggested sequencing
  • Plain-language summary suitable for non-technical stakeholders
  • Findings walkthrough session with your IT contact or provider
  • Reference notes on scope boundaries for the eventual submission
  • Optional quote for remediation support, if you want it
Who it suits

Built for organisations that need the work done properly.

SMEs facing a certification deadline

Businesses that need to certify against a tender, contract or insurer requirement and can't afford a failed first attempt.

Businesses with an outsourced IT provider

Where you want an independent check on your provider's configuration before relying on it for a compliance submission.

Organisations that have grown quickly

Where device counts, cloud services or remote working have expanded since the last time anyone reviewed the estate against a standard.

Anyone unsure whether they'd pass today

If nobody in the business could confidently answer 'would we pass Cyber Essentials right now', this is the way to find out.

Outcomes & benefits

What changes once the work is done.

The point of the exercise is clarity — a defensible answer on where you stand and a workable route to closing what's open.

A clear pass/fail picture

No more guessing whether the current setup would survive a real assessment.

A sequenced remediation plan

Work ordered by effort and risk, so the team isn't overwhelmed trying to fix everything at once.

Evidence for other requirements

The findings report is often useful supporting evidence for insurance renewals and supplier assurance requests too.

Fewer surprises at submission

Configuration issues surfaced and understood well before the self-assessment questionnaire is completed.

A defensible position with stakeholders

Something concrete to show a board, client or insurer who's asking what's been done to check readiness.

A realistic timeline

A grounded sense of how long remediation will actually take, rather than an optimistic guess.

Why run this separately from certification support.

We keep the gap analysis distinct from certification support and from Cyber Essentials Plus audit preparation deliberately. Bundling a diagnostic with a sales process for certification creates an obvious incentive problem — the person telling you what's wrong shouldn't also be the person who benefits from you needing more work done. A fixed-scope, standalone assessment avoids that.

It also means the report stands on its own. If you decide to run the self-assessment questionnaire yourself, hand remediation to your existing IT provider, or bring in a different consultancy for the certification stage, the findings travel with you without any dependency on continuing to work with us.

In practice, most clients who run a gap analysis with us do come back for remediation support or Plus audit preparation later, simply because it's efficient to keep continuity. That's a decision we're happy to leave until after you've seen the findings, not before.

We deliver this work across Chesterfield, Sheffield, Derby, Nottingham, Leeds, Manchester, Birmingham and London, either on site for a hands-on device sample or remotely where evidence can be shared securely — whichever suits your setup better.

Frequently asked questions

Questions we are asked most often.

What exactly does a Cyber Essentials Gap Analysis cover?

We work through all five Cyber Essentials control areas — firewalls, secure configuration, user access control, malware protection and patch management — against your actual estate: laptops, servers, cloud services and mobile devices in scope. Each control is scored as met, partially met or not met, with the specific evidence or configuration that led to that judgement, so nothing is left ambiguous.

Is this the same as the certification assessment itself?

No. This is a diagnostic step that happens before you submit anything. We don't complete or submit the self-assessment questionnaire on your behalf and we're not your certifying body. The output is a private report and remediation plan you use to close gaps at your own pace, then either self-assess or bring in support for the submission stage separately.

How long does a gap assessment take?

For most SMEs with under 100 devices, we complete the review and issue the report within five to ten working days from kick-off, depending on how quickly we get access to configuration exports and answers from your IT contact. Larger or more distributed estates, including multiple sites or a mix of managed and unmanaged devices, typically take two to three weeks.

Do you need remote access to our systems?

Usually not full access. We ask for configuration exports, screenshots or read-only views of firewall rules, endpoint protection consoles, patch management dashboards and user account lists. Where a business genuinely can't extract this themselves, we can run a short supervised session over a call, but we don't need standing administrative access to your network to complete the assessment.

What if we fail on several controls?

That's the normal outcome of a first assessment and exactly why it's worth doing before you commit to a certification date. We rank findings by how much work they take to fix and how much risk they carry if left, so you can sequence remediation sensibly rather than trying to fix everything simultaneously under time pressure.

Can you assess our supply chain or third-party IT provider's setup?

Yes, within reason. Where a managed service provider controls your firewalls or endpoints, we'll request the relevant exports from them directly or through you, and note anywhere their configuration falls outside what Cyber Essentials expects. This often surfaces gaps that neither the business nor the provider had previously flagged.

Do you provide a fixed price for this?

Yes. The gap assessment is scoped and quoted as a fixed price once we know your device count, number of sites and cloud services in scope, so there's no open-ended day-rate exposure. You'll know the cost and the delivery window before you commit to anything.

What happens to the report afterwards?

The report and remediation plan are yours to keep and use however you need — internally, with your IT provider, or as supporting evidence for a cyber insurance renewal or a client's supplier assurance request. We don't retain any ongoing rights over it, and there's no obligation to use us for the remediation work that follows.

Want a straight answer on where you stand?

Tell us roughly how many devices and sites are in scope, and we'll come back with a fixed price and a realistic delivery window. No obligation to go further afterwards.

Ask about a gap analysis