Prepare for Cyber Essentials and Cyber Essentials Plus
Use PurpleWASP to define scope, complete the Cyber Essentials questionnaire and five technical-control workspaces, resolve readiness gaps, and prepare the evidence and testing workflow for Cyber Essentials Plus.
What PurpleWASP supports
PurpleWASP provides a connected Cyber Essentials readiness workspace and a separate Cyber Essentials Plus technical-assurance workflow. The Cyber Essentials side combines scope, the Danzell questionnaire, the five technical areas, remediation, management declaration and submission review. Cyber Essentials Plus adds preflight, sampling, technical tests, findings, an outcome view, an assessor evidence pack and certificate/renewal records.
| Area | PurpleWASP capability |
|---|---|
| Scope | Define the assessment boundary before questionnaire/readiness work is treated as authoritative. |
| Questionnaire | Complete the Danzell question set with conditional questions and progress tracking. |
| Technical areas | Work through Firewalls, Secure Configuration, Security Update Management, User Access Control and Malware Protection. |
| Readiness | Review evaluated gaps, human-review items, remediation and the internal readiness score/driver model. |
| Submission preparation | Record management declaration, perform submission review and retain certificate/renewal history where applicable. |
| Cyber Essentials Plus | Run technical preflight, sampling, testing, findings/remediation, outcome review and evidence-pack preparation. |
1. Confirm the assessment scope
Start from the Cyber Essentials dashboard and open Scope. Define the organisation, systems and assessment boundary that the questionnaire will describe. Complete scope before relying on downstream readiness results.
2. Complete the Danzell questionnaire
Use the questionnaire workspace to answer the complete assessment set. Conditional questions count only when they apply, and the workspace separates unanswered items, evaluated gaps and responses that require human review.
- Answer from the organisation's real technical configuration rather than the desired future state.
- Use supporting notes where an answer needs explanation.
- Review automatic-fail gaps immediately instead of waiting for the final submission review.
- Use the section cards to move between the questionnaire and the detailed technical workspaces.
3. Work through the five technical areas
PurpleWASP provides dedicated workspaces for the five Cyber Essentials technical areas:
- Firewalls — review boundary and host firewall arrangements.
- Secure Configuration — track secure build/configuration requirements.
- Security Update Management — review supported software and update/patch practices.
- User Access Control — review accounts, privileges and access governance.
- Malware Protection — record the malware-protection approach in the assessed environment.
Where organisation Controls or evidence already exist in Control Management, reuse those records rather than creating duplicate assurance artefacts only for Cyber Essentials.
4. Resolve readiness gaps and remediation
The Readiness Review brings together questionnaire completion, evaluated gaps and responses that require human judgement. The Remediation workspace gives the assessment team a consolidated place to work outstanding items before declaration.
- Resolve unanswered applicable questions.
- Address automatic-fail/evaluated gaps.
- Complete the human-review queue for narrative or gateway responses that cannot safely be reduced to a simple Yes/No rule.
- Follow unresolved technical issues back to the owning system, Control or evidence record.
5. Prepare declaration and submission review
When readiness blockers have been resolved, use the Management Declaration and Submission Review workspaces to perform the organisation-side confirmation before submission to the appropriate certification process. Certificate and renewal records can then be retained in PurpleWASP for lifecycle visibility.
6. Run the Cyber Essentials Plus technical-assurance workflow
Cyber Essentials Plus is managed as a distinct technical-assurance workflow rather than as another questionnaire page.
- Preflight — confirm the prerequisite assessment state and readiness for technical verification.
- Sampling — establish the systems/devices/accounts or other technical sample that will be tested.
- Technical Testing — record tests and results against the Plus work programme.
- Findings & Remediation — track technical failures through remediation.
- Outcome — consolidate the technical-assurance position.
- Assessor Evidence Pack — prepare the traceable evidence package used to support the external assessment.
- Plus Certificate — retain certificate/renewal information after the authoritative external decision.
Readiness score and Drivers / Improve Score
The Cyber Essentials and Cyber Essentials Plus dashboards include PurpleWASP internal readiness scores. Use View Drivers to understand the components contributing to the score and Improve Score to see the highest-impact outstanding work.
Certification boundary
PurpleWASP organises the assessment, readiness, technical-assurance and evidence work. It does not make the independent Cyber Essentials or Cyber Essentials Plus certification decision.
- A high internal readiness score is not a certificate.
- Completing the questionnaire is not the same as certification.
- For Plus, PurpleWASP records and packages technical-assurance work; the authorised external assessment remains authoritative.
First-time implementation handbook
Download the customer-facing implementation handbook for first-time guidance. Technical platform documentation is available only through authorised internal channels.
Download the Cyber Essentials first-time implementation handbook
Common problems
Readiness is blocked even though the questionnaire looks complete
Open Readiness Review and check evaluated gaps and the human-review queue. A completed answer count does not mean every response is satisfactory.
The Plus workflow is not ready to start
Review Plus Preflight and the underlying Cyber Essentials assessment state. Confirm the prerequisite scope and assessment records are complete before creating the technical sample.
The dashboard score did not improve
Open View Drivers and inspect the specific incomplete driver. Update the authoritative questionnaire, remediation, technical-test, evidence or finding record and then refresh the dashboard.