- Azure Cloud
How to Use Azure Policy for Governance and Compliance
7 Nov, 2025
Gap analysis, remediation and hands-on preparation to get your Cyber Essentials certificate first time, without the jargon.
We check your current setup against all five Cyber Essentials controls before you submit anything, so surprises don't appear mid-application.
Where your systems fall short, we fix them -- patching, secure configuration and access control -- not just tell you what's wrong.
We prepare your self-assessment questionnaire so it reflects your actual environment accurately, giving you the best chance of passing first time.
Cloudswitched provides cyber essentials certification uk support for SMEs -- gap analysis, remediation and a cyber essentials preparation service that gets your self-assessment questionnaire submitted accurately first time. NCSC cyber essentials is the UK government-backed scheme that verifies your business has basic technical controls in place against the most common cyber attacks, and an iasme certification body issues the certificate on the National Cyber Security Centre's behalf once your assessment is reviewed and approved. Whether you need cyber essentials for small business to satisfy a client's supply chain requirement, cyber essentials for government contracts, or simply want a clear, affordable way to demonstrate basic security hygiene, we handle the technical preparation so the application itself is straightforward. Many businesses come to us after attempting the self-assessment questionnaire alone and finding the technical wording harder to interpret than expected, or after a previous submission was rejected and they're not sure why. We start every engagement with a proper gap analysis rather than guessing at what an assessor will ask.
Cyber Essentials certification is built around five technical controls: firewalls, secure configuration, user access control, malware protection and patch management. Together, the NCSC estimates these controls protect against the vast majority of common, unsophisticated cyber attacks that target small businesses -- not nation-state hacking, but the everyday phishing, malware and unpatched-software attacks that cause the most actual damage.
A working cyber essentials checklist covers your firewall configuration, how devices are configured out of the box, who has admin rights on which systems, what anti-malware or EDR protection is installed, and how quickly security patches get applied across your estate. We walk through each item with you before the self-assessment questionnaire is submitted.
Cyber essentials patch management requirements are stricter than most businesses expect: critical and high-risk patches generally need applying within 14 days of release, across every device and piece of software in scope, including firmware. This is often the single biggest gap we find during a gap analysis.
Cyber essentials secure configuration means removing unnecessary software and accounts, disabling auto-run features, setting proper password policies, and turning off default settings that ship insecure out of the box -- unglamorous work that's frequently skipped when systems are first set up.
Once your gap analysis and remediation are complete, your self-assessment questionnaire is submitted to an accredited certification body for review. IASME oversees the scheme and accredits these certification bodies on behalf of the NCSC, so the certificate you receive carries genuine, recognised weight with clients and contract holders.
We assess your firewalls, device configuration, access control, malware protection and patch management against the current cyber essentials requirements before you touch the application.
Where gaps exist, our team fixes them directly -- tightening configuration, sorting out admin access, and getting patch management on a proper 14-day cycle.
We help complete the self-assessment questionnaire accurately, reflecting your real environment, ready for review by an accredited certification body.
Certification lasts 12 months. We help keep patch management, configuration and access control on track in between, so renewal is a formality rather than a re-run of the original project.
Here's how to get cyber essentials certified with our support, from first review to certificate.
We review your current setup against all five controls and flag exactly what needs fixing before you apply.
We fix the gaps directly -- configuration, access control, patching and malware protection -- so you're genuinely ready.
We help you complete the cyber essentials self-assessment questionnaire accurately, ready for submission to a certification body.
Once approved, you receive your cyber essentials certificate and badge, valid for 12 months, ready to display and share with clients.
We don't just fill in the self-assessment questionnaire for you -- we fix the underlying gaps first, so the cyber essentials accreditation reflects a genuinely secure environment, not just paperwork.
Our managed IT plans already include the EDR endpoint protection, 24/7 monitoring and cloud backup that map directly onto several Cyber Essentials controls, so clients on our IT support packages often start from a stronger position and need less remediation before applying.
We explain every requirement in plain English -- what it means, why it matters, and what changes practically for your team -- rather than handing you an NCSC document and wishing you luck.
If your assessment has been rejected before, we identify exactly why and fix it, rather than resubmitting the same gaps.
You get a dedicated point of contact throughout, from gap analysis to the certificate landing in your inbox.
And because our team handles both the technical remediation and the application itself, nothing gets lost in a handover between a security consultant and whoever is filling in the paperwork.

The most frequent issue is patch management -- devices and software not updated within the required 14-day window for critical patches, often because there's no formal process tracking it. Close behind are unnecessary local admin rights held by everyday user accounts, firewalls left on factory default settings, weak or shared passwords, and out-of-support software still running somewhere on the network. None of these are difficult to fix once identified, but they're rarely visible until someone actually goes looking.
Two levels of the same NCSC scheme, verified differently.
You complete a self-assessment questionnaire, verified by an accredited certification body. It's faster and more affordable, and suitable for most SME supply chain requirements.
Adds an external technical audit of your systems, verifying the controls are actually in place rather than self-reported -- often required for higher-value government or supply chain contracts.
We fix the security first, then help with the paperwork. Here's what sets us apart.
We check every control against your real environment before submitting anything, avoiding rejected applications and wasted fees.
We fix the gaps ourselves -- configuration, patching, access control -- rather than just producing a report and leaving you to it.
You get one person who understands your environment throughout, not a different consultant at each stage.
Our IT support plans include EDR endpoint protection, 24/7 monitoring and cloud backup -- directly relevant to several Cyber Essentials controls.
We explain what each requirement means in practice for your team, not just quote the NCSC's technical wording back at you.
If a previous application was turned down, we find out exactly why and fix the actual issue rather than resubmitting blind, saving a second round of certification body fees.
We help keep patch management and configuration on track between renewals, not just in the run-up to your application.
Where the self-assessment level isn't enough, we prepare your environment for the externally audited Plus standard too.
Your cyber essentials preparation service quote is scoped to your current environment, with no surprise fees mid-process.
From a five-person consultancy to a multi-site trades business, cyber essentials uk certification is designed to be achievable for organisations without a dedicated IT security team. Whether you're in London, Manchester or anywhere else in the UK, our cyber essentials certification manchester and nationwide clients get the same remote-first gap analysis and remediation process, because the five technical controls don't change from postcode to postcode. What does change is the environment we're assessing -- a five-person consultancy, a multi-site trades business and a supplier bidding for a public sector contract each present different gaps, even against the same checklist.
Cloudswitched is based in the City of London and delivers cyber essentials certification uk wide on a remote-first basis. Gap analysis and remediation work is largely done remotely -- reviewing configuration, patch status and access control over a secure connection -- with on-site coverage in London where hardware genuinely needs hands.
How we work: A structured gap analysis, a clear remediation plan, and a guided self-assessment submission mean you always know where you stand in the process.
Who we help: Consultancies, trades businesses, suppliers to larger organisations and government contractors all come to us for the same reason -- an affordable, straightforward path to a genuine cyber essentials accreditation.
Getting started: Every engagement begins with a free initial review against the five controls, so you know exactly what needs fixing before committing to a remediation and application timeline.
Coverage
Cyber Essentials gap analysis, remediation and application support delivered remotely to SMEs across the UK.
iasme certification
IASME is the organisation appointed by the NCSC to manage the Cyber Essentials scheme, accrediting the certification bodies that review and issue certificates on its behalf.
cyber essentials gap analysis
A gap analysis reviews your current firewalls, configuration, access control, malware protection and patch management against the certification requirements before you apply.
Got questions about Cyber Essentials certification? We've answered the most common ones below. If you need more detail, get in touch.
You (or a preparation service like ours) complete a self-assessment questionnaire covering five technical controls, which is then reviewed by an accredited certification body. We handle the gap analysis, remediation and application support so the questionnaire reflects a genuinely compliant environment rather than an aspirational one.
Standard Cyber Essentials is self-assessed and suits most SME supply chain requirements. Cyber Essentials Plus adds an external technical audit and is often required for higher-value government or enterprise contracts. We can advise which applies to your situation.
Once any gaps are remediated, the self-assessment questionnaire itself is usually reviewed within a few working days. The remediation stage varies -- from a few days for minor configuration fixes to a few weeks if patch management or access control needs a proper overhaul.
You'll need a properly configured firewall, secure device configuration, controlled user access with no unnecessary admin rights, up-to-date malware protection, and a patch management process that applies critical updates within 14 days.
Many public sector contracts and tenders require cyber essentials for government contracts as a minimum standard, particularly where the work involves handling sensitive data. We can confirm what a specific tender requires and prepare you accordingly.
We review the specific reason for rejection, fix the underlying issue, and resubmit -- rather than guessing at what might be wrong. This is a common situation for businesses applying without proper preparation, and it's usually fixable without starting the whole process again from scratch.
Certification is valid for 12 months, after which you need to reassess and renew. We can help keep your controls maintained between renewals so the process isn't a scramble each year.
Yes -- beyond satisfying client and contract requirements, working through the certification process closes real security gaps that put small businesses at risk from everyday phishing and malware attacks, and the badge is a genuine, recognisable trust signal for customers, and it often opens doors to supply chain opportunities that specifically require it.
Limited time offer — valid until 31/05/2026
We believe that communication is key to any successful partnership. Submit your details and one of our friendly team members will be in touch with you shortly.
Submit your details and one of our friendly team members will be in touch with you shortly
Powered by industry-leading technologies including SolarWinds, Cloudflare, BitDefender, AWS, Microsoft Azure, and Cisco Meraki to deliver secure, scalable, and reliable IT solutions.