Dashboard view showing device compliance status for Cyber Essentials
Secure Chain Horizon

Cyber Essentials tracking that doesn't restart every twelve months.

Horizon keeps the Cyber Essentials question set, device and control evidence, and renewal deadlines in one place all year, so the annual certification cycle is a check rather than a rebuild from scratch.

Question set areas
5
Renewal cycle
12
Evidence owners
role
Illustrative figures
The challenge

Renewal shouldn't mean starting the evidence hunt again.

Cyber Essentials certification lasts twelve months, and for a lot of organisations the process each year looks almost identical: someone is asked to pull together evidence for the five technical controls, discovers that half of it was never saved anywhere central, and spends a week reconstructing patch reports and configuration screenshots that could have been captured as they happened.

The question set itself doesn't change dramatically year to year, but the answers can drift quietly without anyone noticing. A local administrator account gets re-enabled during a laptop rebuild. A new cloud service is adopted without MFA being switched on by default. A firewall rule opened temporarily for a project is never closed again. None of these show up unless someone is actively checking, and between certifications, nobody usually is.

Device and control evidence is particularly prone to going stale because it's often held by whoever happens to be doing IT support that week — a screenshot in an email, a spreadsheet on someone's desktop, a note in a ticketing system that gets archived and forgotten. When renewal comes round, that evidence has to be tracked down from wherever it landed, assuming it still exists at all.

Organisations moving toward Cyber Essentials Plus feel this more acutely, because a Plus auditor samples devices directly and expects the underlying control state to match what the self-assessment claimed. If evidence has only ever been gathered once a year for the base certificate, there's no way to know whether that's still an accurate picture by the time Plus sampling happens.

The result is a certification cycle that feels heavier each year than it should, run by whoever has the most patience for chasing down old files, rather than a steady process that just needs a periodic check.

  • Evidence scattered across emails, spreadsheets and support tickets
  • Control drift between certifications going unnoticed until renewal
  • No consistent record of device-level patch and MFA status
  • Plus sampling readiness unclear because evidence isn't kept current
Our approach

Track it continuously, and renewal becomes a review, not a rebuild.

Horizon holds the Cyber Essentials question set as a living record rather than an annual form. Each of the five technical control areas — firewalls and internet gateways, secure configuration, user access control, malware protection, and security update management — is tracked with its own evidence, owner and review date, so the answer to 'are we still compliant' doesn't require reconstructing anything.

Device and control evidence is logged as it's produced: patch compliance exports, MFA enforcement confirmation, firewall configuration reviews and anti-malware coverage checks are attached against the relevant control and asset, with a version history so you can see when something was last confirmed rather than assumed.

Renewal reminders are built around your actual certificate expiry date, giving whoever owns IT or information security enough advance notice to review outstanding gaps and close them before the deadline, rather than discovering issues in the final days before resubmission.

For organisations working towards or maintaining Cyber Essentials Plus, keeping the underlying evidence current in Horizon means you have a genuine, up-to-date picture of control state to check against before an independent Plus auditor samples your devices — reducing the chance of a surprise finding on the day.

Role-based access lets the people actually doing the work — internal IT, or an outsourced provider — update device and control evidence directly, while whoever holds overall accountability for certification can see current status and outstanding items without chasing anyone for an update.

  • Question set and evidence tracked continuously, not once a year
  • Device-level patch, MFA and configuration evidence held centrally
  • Renewal reminders set against your actual certificate expiry date
  • Current evidence to check before Cyber Essentials Plus sampling
What's included

Everything in the engagement, set out up front.

What's configured when Cyber Essentials tracking is set up in Horizon.

Question set structure

The five technical control areas set up as tracked items with owners, so evidence has a defined home from day one.

Device and control evidence logging

Patch reports, MFA confirmation and configuration checks recorded against the relevant device or control.

Renewal reminder scheduling

Reminders configured against your certificate expiry date, giving advance notice before the deadline.

Gap visibility

A current view of which controls have up-to-date evidence and which are due for review.

Plus readiness tracking

Evidence organised so it can be checked ahead of independent Cyber Essentials Plus sampling.

Access for internal or outsourced IT

Role-based access so whoever manages your devices day to day can update evidence directly.

Deliverables

What you receive.

  • Configured question set with owners assigned
  • Device and control evidence log
  • Renewal reminder schedule tied to your certificate date
  • Gap summary of outstanding evidence
  • MFA and patch compliance tracking view
  • Firewall and configuration review log
  • Plus readiness evidence checklist
  • Access set up for internal team or outsourced IT provider
Who it suits

Built for organisations that need the work done properly.

Certified organisations renewing annually

Businesses that already hold Cyber Essentials and want renewal to be a check rather than a repeated rebuild.

Firms working toward Cyber Essentials Plus

Organisations that need current, device-level evidence in place before independent Plus sampling takes place.

Businesses using an outsourced IT provider

Organisations where day-to-day device management sits with a third party who needs a clear place to log evidence.

First-time applicants planning ahead

Organisations setting up their evidence structure before initial submission, so future renewals inherit the same discipline.

Outcomes & benefits

What changes once the work is done.

What changes once the certification cycle runs through Horizon.

Renewal takes hours, not weeks

Evidence already logged means the annual renewal is a review of what's current, not a search-and-rebuild exercise.

Control drift caught early

Continuous tracking surfaces a lapsed patch or a disabled MFA setting before it becomes a renewal-week surprise.

Clearer readiness for Plus

Up-to-date device evidence gives a realistic view of exposure before an independent Plus auditor samples anything.

Evidence that survives a staff change

Owned and dated evidence in Horizon doesn't disappear when the person who set it up moves on.

Less reliance on one person's memory

A shared, structured record replaces the informal knowledge that used to live with whoever handled IT support.

Confidence going into resubmission

A visible, current gap summary means resubmission decisions are made from evidence, not guesswork.

Automation supports the cycle; it doesn't replace the assessment.

It's worth being clear about the boundary here. Horizon is not the IASME-accredited certification body, and it doesn't assess or issue your Cyber Essentials certificate — that's carried out by an accredited assessor against the current scheme requirements. What Horizon automates is the tracking work around that assessment: keeping the question set, evidence and renewal dates organised so the certification decision, when it's made, is based on a genuinely current picture.

That distinction protects you as much as it protects us from overstating what the platform does. A certificate obtained on stale or assumed evidence doesn't reduce your actual exposure, whatever the paperwork says. Continuous evidence tracking is worthwhile because it keeps the underlying controls honest between certifications, not because it makes the certificate itself easier to obtain on paper.

Our consultants use Horizon on Cyber Essentials engagements alongside client IT teams, working with organisations across Chesterfield, Sheffield, Derby, Nottingham, Leeds, Manchester, Birmingham and London. The tracking structure reflects patterns we've seen repeatedly in renewal cycles — evidence lost between annual submissions, control drift going unnoticed, and Plus readiness assumed rather than checked — rather than a generic feature list.

If your current renewal process relies on someone remembering where last year's evidence was saved, a short walkthrough usually makes clear whether continuous tracking in Horizon would meaningfully change that, without committing to anything before you've seen how it would work with your own device estate.

Frequently asked questions

Questions we are asked most often.

What does 'automation' mean here — does Horizon submit the questionnaire for us?

No. Horizon tracks the question set, evidence and deadlines against the current Cyber Essentials scheme requirements, and reminds owners when something needs attention or renewal is approaching. The self-assessment questionnaire is still completed and submitted by your organisation, or with our consultants, to the certification body.

Can Horizon track evidence for every device in scope?

Yes, that's one of its main uses for Cyber Essentials. Device and control evidence — patch status, firewall configuration, MFA enforcement — can be logged against each in-scope asset with owners and dates, so you have a current picture rather than reconstructing it from memory each renewal cycle.

How far ahead does Horizon remind us about renewal?

Reminders are configured against your certificate's expiry date, giving control owners advance notice to review evidence and close gaps before the twelve-month renewal deadline arrives, rather than starting the process in the final week.

Does this help with Cyber Essentials Plus as well as the base certificate?

It helps you prepare for Plus by keeping the underlying evidence current, since Plus auditors sample against the same control areas the base certificate covers. Horizon doesn't perform the Plus technical audit itself — that's carried out independently by an accredited assessor.

What happens if a control lapses between renewals?

That's the gap Horizon is designed to catch early: a device falling out of patch compliance, MFA being disabled during a system change, or a new starter added without the standard build. Tracking evidence continuously, rather than only at renewal, means these are visible to the control owner before they accumulate.

Who should own the Cyber Essentials tracking in Horizon?

Typically whoever is accountable for IT operations or information security day to day, since they're closest to patching, access control and device configuration. Role-based access lets them update evidence directly while an executive or compliance lead views overall status without managing the detail.

Can our IT provider use Horizon alongside us?

Yes, with appropriate access set up for them. Many organisations outsource day-to-day IT and want their provider updating device and patch evidence directly, while the business retains oversight and ownership of the certification decision itself.

Is this only useful for organisations already certified?

It's useful before first certification too. Setting up the question set and evidence structure in Horizon ahead of an initial submission means the first certification isn't a one-off scramble, and the same structure then carries through to every renewal after it.

Want to see your renewal cycle inside Horizon?

Ask for a walkthrough based on your current Cyber Essentials scope, and we'll show how the evidence and reminders would sit together — no obligation.

Ask for a walkthrough