Cyber Essentials Plus Pre-Assessment Gap Analysis

A full Cyber Essentials Plus-style assessment before your live certification

With the April 2026 changes increasing the jeopardy of Cyber Essentials Plus, going straight into the live assessment without prior verification may carry significantly more risk than in previous years.

Our Cyber Essentials Plus Pre-Verification service follows the same technical process as a formal CE+ assessment, but without the certification outcome or IASME certification fee. In practical terms, this means we carry out the same style of device sampling, vulnerability scanning and control verification that would take place during the live assessment, allowing any issues to be identified and addressed in advance.

For many organisations, this provides a much clearer view of likely certification readiness and helps avoid issues only coming to light during assessment week, when the commercial and contractual implications of failure may be much greater.

What the Cyber Essentials Plus Pre-Assessment Gap Analysis includes

The process mirrors a standard Cyber Essentials Plus verification as closely as possible.

This includes technical verification of the five Cyber Essentials controls across the agreed scope, including vulnerability scanning, patching compliance, malware protection, MFA and secure configuration checks.

Where relevant, we also review the scope of cloud services, remote devices and any areas where infrastructure or working practices may have changed since the previous certification cycle.

The objective is to assess whether the environment is likely to meet the standard on the day of the formal CE+ verification.

Following the assessment, we provide a clear remediation report setting out any issues identified, the likely impact on certification, and the steps required to bring the environment into line with the standard.

Why organisations are using this ahead of renewal

The 2026 changes place greater emphasis on patching compliance, MFA and consistent control across the whole in-scope environment.

As a result, many organisations are looking for greater assurance before entering the live assessment process.

This service is particularly valuable where:

  • The device estate has grown or changed
  • Hybrid and remote working devices are in scope
  • MFA has recently been rolled out
  • Cloud services now form a larger part of the estate
  • Patching is managed across multiple teams or third parties

By identifying issues in advance, your internal IT team has the opportunity to remediate in a controlled way, rather than under the pressure of a live certification timeline.

Cyber Essentials Services

Testimonials

"The Securious team have been excellent – their expertise is second-to-none and they’ve really helped us focus on the right areas to improve our cyber security and protect our organisation."

“It’s very important to us to make sure that our organisation is protected from cyber threats and Securious has been instrumental in us achieving this."

“I can only give 10’s across the board. Not just in this instance but I’ve worked with various people at Securious… and the quality of service, responsiveness and the support you give where required is always superb.”

"This is probably the best summary report I’ve seen."

"It’s 10 out of 10 on all counts, the service has been excellent."

“We appreciate your support! Securious has been fantastic to work with”

Get in touch to get started now

Because the assessor effort and technical verification process are broadly the same as a live Cyber Essentials Plus assessment, the cost is typically aligned to the CE+ verification fee, less the IASME certification costs: £1,500 + VAT.

Securious UK team - tailored cyber security audits