Estimated reading time: 6 minutes
Cyber Essentials is an important part of helping businesses protect themselves against common cyber threats. It gives organisations a clear set of security controls to work towards and provides reassurance that those controls are in place. For many businesses, achieving certification is an important step in improving their cyber security, but there is a common misconception that once you have passed Cyber Essentials, your organisation is secure until the certificate expires. Unfortunately, it doesn’t work like that.
Cyber Essentials certification is a point in time. Your IT environment continues to change every day, whether it’s through new devices being added, software being updated or replaced, or new vulnerabilities being discovered. This means that an organisation can pass its assessment and still find itself with security gaps further down the line.
Cyber Essentials should not be a tick box exercise
The value of Cyber Essentials is in the security controls behind the certificate, not the certificate itself. The assessment looks at areas such as firewalls, secure configuration, security updates, user access controls and malware protection. Cyber Essentials Plus goes a step further through an independent technical audit that incorporates testing of those security controls.
Both provide a useful baseline, but passing the assessment should be the beginning of good security practices rather than the end of them. A new device could be introduced without the correct security settings. An update could be missed. A piece of software could become unsupported. A user could retain access they no longer need. A new vulnerability could be discovered in a system that was secure when the assessment took place. Any of these changes can affect the security of an organisation without anything appearing obviously wrong.

This is one of the reasons Tecnica believe Cyber Essentials should be part of the way an organisation manages its IT, rather than something that is revisited shortly before the annual renewal date. Leaving everything until renewal can also create unnecessary pressure. If issues are only identified when an organisation is preparing for its assessment, there may be a limited amount of time to resolve them. Larger changes, such as replacing unsupported hardware or upgrading systems, cannot always be completed quickly. In some cases, trying to resolve everything at the last minute could even put the renewal deadline at risk.
We have seen why ongoing management matters
At Tecnica, we provide consultancy and remediation for organisations working towards Cyber Essentials and Cyber Essentials Plus, as well as ongoing IT support once certification has been achieved. This gives us a good insight into the practical challenges businesses can face when maintaining the standards required for certification.
For example, we’ve had businesses come to us for a Cyber Essentials renewal while still using Windows 10. They had previously passed Cyber Essentials while those devices were in use, but Windows 10 subsequently reached the end of support. The devices had not been proactively upgraded to Windows 11, leaving the organisation with an IT estate that no longer met the same security expectations it had when certification was achieved.
This is a good example of why Cyber Essentials needs to be considered as part of ongoing IT management. The certificate had been achieved at a particular point in time, but the technology and security requirements around it did not stand still. Keeping systems supported, applying updates and addressing changes to the IT estate needs to continue throughout the year, rather than becoming a priority again when certification is due for renewal.

We have also come across situations where organisations have made significant changes to their environment around the time of a Cyber Essentials Plus assessment, such as switching off unsupported servers while the audit was taking place. This raises an important question about whether an assessment truly reflects the environment that an organisation relies on day to day.
These examples are not about suggesting that Cyber Essentials or Cyber Essentials Plus have no value. Quite the opposite. They show why certification works best when it is supported by good IT management throughout the year. An organisation’s security is only as strong as the controls it has in place, and as the old saying goes, a chain is only as strong as its weakest link. If one part of an IT environment is overlooked, it can undermine the wider security measures that are in place.
Keeping security standards in place
This is where ongoing IT management becomes important. Organisations need to know what devices and systems they have, which software they are running, whether updates and patches are being applied, who has access to what, and whether their policies and procedures still reflect how the organisation operates.
At Tecnica, our OrcAstra Service Desk processes and tools provide ongoing visibility of a customer’s IT estate, as well as their policies and documentation. This helps us identify and track issues rather than waiting for them to become a problem at the next certification assessment. For organisations preparing for Cyber Essentials or Cyber Essentials Plus, we can also identify areas that need attention and support the remediation work required to bring the environment up to the required standard.
This approach means that Cyber Essentials becomes part of the wider management of IT and cyber security. The focus is not only on getting through an assessment, but on maintaining the controls that make the organisation more secure throughout the year.
Certification is only part of the picture
Cyber Essentials remains a valuable and recognised baseline for organisations looking to improve their cyber security. It gives businesses a clear framework and helps demonstrate that appropriate security controls are in place. However, a certificate on its own cannot protect an organisation.
The real value comes from maintaining the security standards that the certificate represents. Your certificate may be valid for a year, but your IT estate does not stand still for a year.
Cyber Essentials should therefore be more than something you prepare for once a year. It should form part of your ongoing approach to managing IT, identifying risks and keeping your organisation secure.
We Recommend:
- Cyber Essentials Certification
- Cyber Security
- Service Management (ITSM)
- The Risks of Large-Scale Cloud Providers: A Case for Tecnica Private Cloud
- Chasing AI Dreams, But at What Cost? – AI Implementation Challenges
- Smart IT Moves for Challenging Times: How SMEs Can Save Money and Reduce Emissions
- Maximising Cost Savings and ROI: Benefits of Managed IT Services for business efficiency
Contact Us
Follow us on:


