Readiness assessment, accurate questionnaire answers, evidence, and the remediation behind them. From the consultant who keeps Cyber Essentials Plus maintained for a Premier League football club. Utilis prepares you for assessment; the certificate itself is issued by an IASME-licensed certification body.
Preparation, not certification. Utilis Technologies is not a certification body. Cyber Essentials and Cyber Essentials Plus certificates are issued by IASME-licensed certification bodies. We get you ready and fix what needs fixing.
A gap assessment against the five controls, read from the estate itself: firewall configuration, device management and identity settings.
The self-assessment questionnaire has to be answered accurately. We draft answers that describe what you actually do, in the terms the assessor expects.
The lists and reports that back the answers up, pulled together once and kept current.
The practical work that turns a partly-met control into a met one.
Cyber Essentials Plus adds a technical audit by the assessor. We check the same things beforehand, so there are no surprises.
Estates drift between renewals. The aim is a renewal that confirms the position instead of rebuilding it.
Cyber Essentials is asked for in tender and pre-qualification questionnaires, and by insurers. An answer that was true on assessment day and false three months later is a problem in both places.
It also sits underneath AI governance. An AI usage policy that says company data stays in approved tools means little if devices are unmanaged and administrator accounts are shared. We do both, so the answers in the Cyber Essentials questionnaire, the tender response and the AI policy agree with each other.
Readiness is one part of our wider infrastructure and security work; see the case studies for how it fits around a Premier League club and a manufacturer on public-sector frameworks. The firewall control is covered in more depth under network security and Fortinet, and a new or merged tenant under Microsoft 365 migration.
The estate is read against the five controls and the scope is agreed. You get a written gap list in priority order.
Unsupported devices, MFA gaps, BYOD, patching and administrator accounts dealt with, by us or alongside your IT team or MSP.
Answers and evidence prepared for the certification body you choose. For Cyber Essentials Plus, preparation for the technical audit and support during it.
Compliance reviewed between renewals, so the next assessment starts from a known position.
Further reading — Related guide: preparing for Cyber Essentials Plus: what actually fails.
Book a free discovery call. Bring your renewal date or the tender question that started this. You will get a straight view of where you stand against the five controls — no obligation.