A Cyber Essentials gap analysis is the single most useful piece of preparation any UK organisation can do before it applies for certification — and the step most businesses skip, then fail the assessment because of it. It is a structured, honest audit of your live estate against the five NCSC technical controls, run before the clock starts, so you find your own weaknesses on your own terms rather than paying an assessor to find them for you. Get it right and a first-time pass becomes routine. Get it wrong — or skip it entirely — and you join the roughly one-in-three applicants who fail their first attempt on avoidable, well-understood issues.
This step-by-step guide walks a UK business through the whole journey: how to scope the assessment boundary, how to test each of the five controls, how to build a remediation plan that prioritises the fixes that actually block certification, what the common failure points look like in the real world, and roughly what remediation work costs. It is written for the person who has been handed the job of “getting us Cyber Essentials” and needs a practical, ordered method rather than a marketing brochure. Everything below is anchored to the current NCSC Cyber Essentials scheme (the “Montpellier” question set administered by IASME) and to what Cyber Essentials Plus auditors genuinely look at when they turn up with a laptop and a set of test devices.
What a Cyber Essentials gap analysis actually is
A Cyber Essentials gap analysis is a control-by-control comparison of your organisation’s current technical reality against the requirements the scheme sets out. Cyber Essentials is a UK government-backed certification, owned by the NCSC and delivered through IASME as the sole accreditation body and its network of certification bodies. It defines five technical controls that, implemented properly, are estimated by the NCSC to protect against around 80% of common, untargeted internet-borne attacks. The gap analysis is simply the exercise of asking, for every one of those controls, “where do we stand today, and what would an assessor mark us down for?”
The five controls are firewalls, secure configuration, user access control, malware protection and security update management (patch management). Each has specific, testable sub-requirements — not vague aspirations. The self-assessment question set makes you attest to each one in writing, and for Cyber Essentials Plus an independent auditor then verifies your answers by actually testing a sample of your devices. A gap analysis maps your estate against every requirement, records the evidence, and produces a prioritised list of remediations. It is the difference between hoping you pass and knowing you will.
It matters commercially, not just technically. Cyber Essentials is mandatory for many central government contracts that involve handling certain sensitive information, it is increasingly demanded in private-sector supply chains, and it is a common condition of cyber insurance. A failed or delayed certification can put a bid at risk. Doing the gap analysis first de-risks the timeline: you find out in week one whether you are two days or two months away from ready.
Run your gap analysis against the whole question set, not a summary of it. Download the current IASME self-assessment question document and treat every question as a checklist row. Assessors mark against the exact wording — “we’re basically fine” is not an answer that survives contact with the Montpellier question set.
Cyber Essentials gap analysis by the numbers
Before diving into method, it helps to size the exercise. The figures below are drawn from published scheme data, IASME certification-body reporting and the pattern of engagements a typical UK managed IT provider sees across its client base. They frame why a structured gap analysis pays for itself many times over.
The headline to take from these numbers is that scope and time pressure, not exotic vulnerabilities, are what catch people out. Once you pass the self-assessment for Cyber Essentials Plus you have a fixed window to complete the hands-on audit, and everything in that window is easier if your remediation work was already done. A gap analysis front-loads the effort into the calm period before you commit to a certification date.
Where UK applicants lose marks — the failure hotspots
Not all controls fail equally. When you aggregate the reasons UK businesses get sent back to fix things, a clear pattern emerges: a small number of issues account for the large majority of failures. The chart below shows the relative frequency of the problems that most often surface during cyber essentials vulnerability testing and self-assessment review. Use it to decide where to point your gap analysis effort first.
Two themes dominate. First, cyber essentials patch management and unsupported software: anything that no longer receives security updates from its vendor — an old Windows build, an unpatched router firmware, a mobile handset past its update window — is an automatic fail if it sits inside scope. Second, identity: multi-factor authentication on cloud and administrative accounts is now a firm requirement, and inconsistent MFA is one of the fastest ways to be marked non-compliant. Your gap analysis should interrogate these two areas hardest.
Cyber Essentials remediation cost breakdown
The certification fee itself is modest — it is the cyber essentials remediation work uncovered by the gap analysis that carries the real budget. The table below sets out indicative UK costs for the common remediation lines. These are illustrative planning ranges for a typical small-to-medium organisation; your figures depend on estate size, how much you do in-house and whether you engage a partner. Treat them as a way to build a realistic budget, not as fixed quotes.
| Item | Typical UK range (ex VAT) | Notes |
|---|---|---|
| Cyber Essentials (self-assessment) certificate | £320 – £500 | IASME fee banded by organisation size; single annual certificate |
| Cyber Essentials Plus audit | £1,400 – £3,500+ | Hands-on assessor testing; priced on device sample size and estate complexity |
| Gap analysis & readiness review | £750 – £2,500 | One-off; the exercise this guide describes, done with a partner |
| MFA rollout across cloud & admin accounts | £0 – £2,000 | Often free in existing Microsoft 365 licences; cost is configuration time |
| Replacing end-of-life devices / OS | £450 – £900 per device | The single biggest variable; depends on how much kit is out of support |
| Patch / update management tooling & setup | £2 – £6 per device / month | RMM or Intune-based automated patching; ongoing, not one-off |
| Firewall / router reconfiguration or replacement | £0 – £1,200 | Often just configuration; hardware only if the device is unsupported |
The pattern nearly always holds: the certificate is cheap, the audit is moderate, and the cost that swings the total is hardware replacement for end-of-life devices. That is exactly why the gap analysis is worth doing early — discovering three out-of-support laptops in week one lets you budget and phase the spend, rather than being ambushed by it days before an audit. Where MFA and patch automation are concerned, much of the capability is already paid for inside a standard Microsoft 365 Business Premium licence; the cost is time to configure it correctly, not new software.
Gap analysis in-house versus with a partner
Should you run the gap analysis yourself or bring in a specialist? Both are legitimate. A capable internal IT lead with time and the question set in front of them can do a thorough job. The trade-off is objectivity, speed and knowing what an assessor actually scrutinises. The comparison below lays out the two routes honestly so you can choose based on your estate and appetite.
Self-run gap analysis
Internal IT lead, using the IASME question set
Partner-led gap analysis
Managed IT / certification specialist
The honest rule of thumb: if this is your first certification, if you are going straight for Cyber Essentials Plus, or if your estate mixes Windows, macOS, mobile and bring-your-own devices, a partner-led gap analysis usually pays for itself by turning a likely resubmission into a first-time pass. If you have a small, homogeneous, well-managed estate and confident in-house IT, a self-run analysis against the full question set is entirely realistic. Either way, the method that follows is the same.
Readiness scoring — where most UK businesses sit today
When you begin a gap analysis it is useful to know, roughly, how ready the average organisation is against each control so you can benchmark yourself. The score grid below groups the five controls into where UK SMEs typically start strong, where they are middling, and where they most often fall short. Use it to sanity-check your own findings — if you are strong exactly where most are weak, look twice, because assessors do.
The lesson from the grid is that the controls people assume are the hard part — firewalls, antivirus — are usually fine, because modern operating systems and routers ship with sensible defaults. The genuine risk sits in the disciplines that require ongoing operational effort: patching on a timetable, retiring old kit, and enforcing identity controls uniformly. Weight your gap analysis accordingly.
The gap analysis to certification timeline
A well-run programme is predictable. The timeline below shows what a realistic path from a standing start to a passed Cyber Essentials Plus audit looks like for a typical UK SME. Fast movers with a clean estate compress this; organisations with hardware to replace stretch the remediation phase. The sequence, though, is stable.
The critical dependency is the 14-day rule: once you pass the self-assessment, the Cyber Essentials Plus audit must be booked and completed within fourteen days. Do not submit the self-assessment until your remediation is genuinely finished and verified, or you risk running that clock while you are still fixing things.
Cyber Essentials benchmarks and control maturity
To make your gap analysis quantitative rather than a gut feel, it helps to score each control area as a maturity percentage. The benchmarks below reflect the average starting position of UK SMEs across each requirement before remediation — a rough picture of the estate an assessor most often meets. Rate your own organisation against the same rows and the gaps become visible immediately.
Average UK SME control maturity before remediation
The shape of this profile — strong on firewalls and antivirus, weak on patching, unsupported software and identity — is remarkably consistent across UK organisations. If your self-assessment scores you highly on the bottom four rows, be sceptical and verify with evidence, because those are precisely the rows a Cyber Essentials Plus auditor will test hands-on.
How far the average estate is from ready
Rolling those control scores into a single readiness figure gives you a headline number to track through remediation. The donut below shows the typical overall readiness of a UK SME at the start of a gap analysis — before any fixes. The goal of the whole exercise is to move this number to 100% and keep it there through annual recertification.
A little over half ready is the norm, and it is not a bad place to start — it means the perimeter and endpoint basics are usually in place and the work is concentrated in a handful of well-understood disciplines. The gap analysis turns that abstract 54% into a concrete list of named fixes, each with an owner. That is what converts “we’re about halfway” into a booked, passable audit date.
The Cyber Essentials gap analysis checklist — the 12 essentials
This is the working checklist. Run through it in order; each item maps to one or more of the five controls and to a question in the IASME set. Record evidence for every point — a screenshot, a policy line, a configuration export — because evidence is what turns a self-assessment from an assertion into a defensible submission and what a Cyber Essentials Plus auditor will ask to see.
- Define and document the scope. Decide whether you are certifying the whole organisation or a defined sub-set, and list every device, server, cloud service and user inside the boundary. A vague scope is a fail waiting to happen.
- Build a complete asset inventory. Every desktop, laptop, server, mobile phone, tablet and network device in scope, with its operating system and version. You cannot patch or retire what you have not listed.
- Confirm no unsupported software remains in scope. Check every OS and key application is still receiving vendor security updates. Anything end-of-life must be removed, replaced or segregated out of scope before you apply.
- Enforce a 14-day patch window. Ensure high and critical security updates are applied within 14 days of release across operating systems, browsers, and internet-facing applications — the core of cyber essentials patch management.
- Turn on automatic updates where possible. Automate OS and application updates so the 14-day window is met by default rather than by someone remembering.
- Change every default password. Firewalls, routers, servers, admin consoles and any device shipped with a default credential must have it changed to a strong, unique password.
- Harden secure configuration. Disable or remove unused accounts, services and software; this is the heart of cyber essentials secure configuration and one auditors probe directly.
- Enforce MFA everywhere it applies. Multi-factor authentication on all cloud services and all administrative access. Inconsistency here is one of the most common failure points.
- Apply least privilege on accounts. Separate administrative accounts from everyday user accounts; grant admin rights only where genuinely needed and review them.
- Verify malware protection. Confirm anti-malware is active and updating on every in-scope endpoint, or that application allow-listing is in place where that approach is used.
- Confirm boundary firewalls and personal firewalls. A correctly configured firewall between your network and the internet, and host firewalls enabled on devices that leave the office.
- Run an internal vulnerability scan. An authenticated scan across in-scope devices surfaces missing patches and weak configuration before an assessor’s cyber essentials vulnerability testing does — do this last, after remediation, as a dress rehearsal.
Turn this list into your gap analysis tracker: one row per item, columns for current state, gap, severity (blocking / non-blocking), owner, target date and evidence link. A shared spreadsheet is entirely sufficient — the discipline of filling every cell is what delivers the pass, not the tool.
Your Cyber Essentials readiness benchmark
Once you have worked the checklist and logged your gaps, score yourself. The gauge below represents a suggested go / no-go threshold: below it, you have blocking issues that would fail an assessment and should not yet submit; at or above it, you are in first-time-pass territory. Re-run the score after each remediation sprint to watch the needle move.
Why 85 rather than 100 as the submit threshold? Because a small number of non-blocking, cosmetic items — a policy document still in draft, a nice-to-have configuration tweak — can be finished in parallel without jeopardising the pass. What the gauge should never hide is a single blocking issue: one piece of unsupported software or one cloud service without MFA drops you to a hard no-go regardless of the overall score. Blocking gaps are pass / fail, not points on a dial.
Common Cyber Essentials mistakes to avoid
Most failures are self-inflicted and predictable. These are the mistakes that send UK applicants back for a resubmission most often — each one is entirely avoidable if your gap analysis looks for it deliberately.
- Drawing the scope too wide, then failing on a forgotten device. Certifying “everything” sounds rigorous but pulls a dusty server or an unmanaged laptop into scope. Scope deliberately, include what genuinely accesses your data, and account for every device you include.
- Ignoring mobile phones and tablets. Any device that accesses organisational email or data is in scope and must meet the update and access requirements. Handsets past their update window are a frequent, overlooked fail.
- Treating BYOD as out of sight, out of scope. Personal devices used for work are in scope. If you cannot enforce the controls on them, restrict what they can access rather than hoping the question does not come up.
- Assuming default MFA is enough. MFA that is available but not enforced, or enforced on some cloud services and not others, fails. It must be on for all users on all cloud and admin access.
- Missing the 14-day patch window on third-party apps. Businesses patch Windows but forget browsers, PDF readers and line-of-business apps. The window applies to all internet-facing software, not just the operating system.
- Leaving unsupported software live “just until we upgrade”. Out-of-support software in scope is an automatic fail with no partial credit. Retire, replace or segregate it before you submit — there is no negotiating this one.
- Submitting the self-assessment before remediation is verified. This starts the 14-day CE Plus clock while you are still fixing things. Finish and re-test first, submit second.
- Doing it once and forgetting it. Certification is annual and the discipline is continuous. Estates that let patching and MFA drift after the certificate arrives face a far harder recertification twelve months later.
The two mistakes that cause the most damage are unsupported software and inconsistent MFA, because both are hard fails rather than points deductions. If your gap analysis finds either, treat it as blocking and do not book an audit date until it is genuinely resolved and evidenced.
Real-world example — a Manchester consultancy’s gap analysis
Consider a typical 38-person management consultancy in Manchester bidding for public-sector framework work that required Cyber Essentials. They assumed they were “basically compliant” — modern laptops, Microsoft 365, a decent firewall. The gap analysis told a more useful story. It found two laptops still running an out-of-support operating system, MFA enabled for the finance team but never enforced for everyone else, three former contractors whose accounts were still active, and a line-of-business PDF tool two major versions behind on security updates. None of these were exotic; all four were hard blockers.
Because they found the gaps before applying, the sequence was calm: the two laptops were replaced on a planned budget line, MFA was enforced tenant-wide over a weekend using licensing they already owned, the stale accounts were disabled the same afternoon, and automated patching was switched on so the 14-day window was met by default. Four weeks after the gap analysis they passed the self-assessment first time and cleared the Cyber Essentials Plus audit inside the window — without a single resubmission.
“We thought the gap analysis would just confirm we were fine. Instead it found four things that would have failed us, and it found them while we still had time to fix them properly. That distinction — finding your own gaps before an assessor does — is the whole point.”
The takeaway is not that this organisation was unusually careless; it was unusually typical. The controls it failed on were exactly the ones the benchmarks predict. What made the difference was doing the analysis early enough that every fix was a planned action rather than an emergency.
Cyber Essentials gap analysis at a glance
The reference table below summarises the key facts from this guide in one place — a quick recap to keep beside your tracker as you work.
| Fact | Detail |
|---|---|
| Scheme owner | NCSC, delivered through IASME as sole accreditation body |
| Current question set | “Montpellier” self-assessment question set |
| Number of technical controls | Five — all must be met in full |
| The five controls | Firewalls, secure configuration, user access control, malware protection, security update management |
| Patch window for high/critical updates | 14 days from vendor release |
| CE Plus audit window | Within 14 days of passing the self-assessment |
| Certificate validity | 12 months, then recertify |
| Self-assessment fee | ~£320–£500 depending on organisation size |
| CE Plus audit fee | ~£1,400–£3,500+ depending on estate |
| Most common failure | Unsupported software in scope |
| Second most common failure | Missing / inconsistent MFA |
| Biggest budget variable | Replacing end-of-life devices |
| Single most valuable prep step | A structured gap analysis before applying |
| MFA & patching cost | Often included in existing Microsoft 365 licensing |
How Cloudswitched delivers Cyber Essentials certification
Cloudswitched runs Cyber Essentials gap analysis and remediation for UK businesses as a managed engagement: we scope the boundary with you, audit your estate against the full IASME question set, produce a prioritised remediation tracker, carry out the fixes — MFA enforcement, patch automation, secure configuration, device replacement planning — and support you through both the self-assessment and the Cyber Essentials Plus audit. We work to what assessors actually test, so the gap analysis reflects reality rather than a checklist read in isolation.
Get expert help with your Cyber Essentials gap analysis
From first gap analysis to a passed Cyber Essentials Plus audit, we handle the scoping, remediation and evidence so your certification is a predictable outcome, not a scramble.
Cyber Essentials CertificationFrequently Asked Questions
What is a Cyber Essentials gap analysis?
A Cyber Essentials gap analysis is a structured audit of your organisation’s current technical setup against the five NCSC controls that the certification requires — firewalls, secure configuration, user access control, malware protection and patch management. You compare your live estate to each requirement, record where you fall short, and produce a prioritised list of remediations. Done before you apply, it lets you find and fix your own weaknesses on your own timeline rather than failing an assessment and paying to resubmit.
How long does a Cyber Essentials gap analysis take?
For a typical UK SME the analysis itself takes one to two weeks, covering scoping, asset inventory and control-by-control testing. Remediation then usually runs two to four weeks depending on what is found — MFA and configuration fixes are quick, while replacing end-of-life hardware can extend the timeline. A clean, well-managed estate can be analysed and remediated in under a month; one with significant unsupported software will take longer because devices must be replaced.
What are the five Cyber Essentials controls?
The five technical controls are firewalls (a correctly configured boundary between your network and the internet), secure configuration (removing defaults and unused services), user access control (least privilege and MFA), malware protection (active anti-malware or application allow-listing), and security update management (applying high and critical patches within 14 days and running no unsupported software). Every applicant must meet all five in full — there is no partial certification.
What is the most common reason UK businesses fail Cyber Essentials?
Unsupported, end-of-life software still in scope is the single most common failure, followed closely by missing or inconsistent multi-factor authentication on cloud services. Both are hard fails rather than points deductions, which is why they matter so much. A good gap analysis targets these two areas hardest, because catching them early — before you submit — is the difference between a first-time pass and a resubmission.
How does Cyber Essentials patch management work?
Cyber Essentials patch management requires that high and critical security updates are applied within 14 days of the vendor releasing them, across operating systems, browsers and internet-facing applications, and that no unsupported software remains in scope. The practical route is to enable automatic updates where possible and use patch management tooling — such as Microsoft Intune or an RMM platform — so the window is met by default rather than relying on someone remembering to check.
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is a verified self-assessment: you attest to meeting the five controls and a certification body reviews your answers. Cyber Essentials Plus adds an independent, hands-on audit where an assessor tests a sample of your devices — checking patch levels, malware protection, configuration and MFA in person. Plus must be completed within 14 days of passing the self-assessment, so your remediation needs to be genuinely finished and verified before you submit.
What is cyber essentials vulnerability testing?
For Cyber Essentials Plus, the assessor carries out vulnerability testing on a sample of your in-scope devices — typically an authenticated scan that looks for missing patches, unsupported software and insecure configuration, plus checks that malware protection and MFA are working. You can and should run your own internal authenticated scan during your gap analysis as a dress rehearsal, so you surface and fix these issues before the assessor’s test rather than during it.
How much does Cyber Essentials remediation cost?
The certificate itself is modest — roughly £320 to £500 for the self-assessment and £1,400 to £3,500 or more for the Plus audit. The variable cost is remediation. MFA and patch automation are often free within existing Microsoft 365 licensing, so the cost is configuration time. The figure that swings a budget is replacing end-of-life devices, typically £450 to £900 each. A gap analysis done early lets you budget and phase this spend rather than being caught out.
Do mobile phones and personal devices count for Cyber Essentials?
Yes. Any device that accesses organisational data or services — including mobile phones, tablets and personal bring-your-own devices — is in scope and must meet the relevant controls, including being on a supported, updated operating system with a screen lock and access controls. Overlooking mobiles and BYOD is a frequent cause of failure. If you cannot enforce the controls on a personal device, restrict what organisational data it can access instead.
What is cyber essentials secure configuration in practice?
Secure configuration means removing everything that increases risk without adding value: changing all default passwords, disabling or deleting unused user accounts and services, removing software you do not need, and turning off features that are not required. In practice it is a hardening pass across every in-scope device and cloud service. Assessors probe it directly, so your gap analysis should document the configuration state of a representative sample of devices with evidence.
How often do I need to renew Cyber Essentials?
Cyber Essentials certification is valid for twelve months, after which you recertify. The controls, though, are continuous disciplines — patching, MFA enforcement and asset management do not pause between certificates. Organisations that keep those controls live find recertification straightforward; those that let them drift face effectively a fresh remediation programme a year later. Treating the annual certificate as a checkpoint on ongoing hygiene, rather than a one-off project, is the sustainable approach.
Can I do the gap analysis myself or do I need a partner?
You can absolutely run it yourself if you have capable in-house IT, time, and you work against the full IASME question set rather than a summary. A partner-led gap analysis adds objectivity and knowledge of what assessors actually test, which typically pays for itself for first-time applicants, for those going straight to Cyber Essentials Plus, or for mixed estates spanning Windows, macOS and mobile. For a small, homogeneous, well-run estate, a self-run analysis is entirely realistic.
Related reading
Continue building your security and compliance posture with these related guides from the Cloudswitched blog.
- Phishing-Resistant MFA and Passkeys: The 2026 UK Business Guide
- IT Support SLA & Response Times: The UK Business Benchmark Guide for 2026
- IT Due Diligence for UK Business Acquisitions — The vCIO Checklist
- Microsoft 365 Copilot Cost & ROI: A 2026 UK SME Buying Guide
- Onsite IT Support in London, Manchester, Birmingham & Beyond
Ready to pass Cyber Essentials first time?
Cloudswitched runs the gap analysis, does the remediation and takes you through the assessment — so certification is a booked, predictable outcome for your UK business.
Cyber Essentials Certification