Introduction

Knowing what an organisation has in place currently (current state) and where it would like to be in the future (target state) is crucial for organisations in planning strategy and defining change. Understanding this ‘gap’ and setting a way forward is a common technique when developing strategy. A similar approach can be taken by organisations when considering Cyber Essentials:

  1. Target State: could be having technical controls in place to protect from common forms of internet-based threats and in achieving Cyber Essentials Plus certification.
  2. Current State: this could be where the organisation is currently positioned in terms of technical controls and certification status.
  3. Difference/gap: is what needs to happen in order to achieve the target state.
  4. Gap Analysis: will review the differences and define an action plan.

 

Why a Gap Analysis is Important

If a gap analysis is not carried out, there’s a risk that both the current and target states are not clearly defined. As a result, any required change/transition may not be clear. Without that clarity, organisations may risk working on the wrong things and be impacted with:

  1. Time – delays and unforeseen blockers
  2. Quality – potential inability to meet the requirements 
  3. Cost – additional time and unplanned/extra resources being required

A gap analysis helps organisations gain clarity, set priorities, and plan resources effectively for Cyber Essentials compliance.

Gap Analysis for Cyber Essentials

  • Target state: understand the requirements, determine the scope for your environment, set out how the technical controls should be applied, consider the current network architecture, devices, data and services
  • Current state: consider where organisational data / services currently resides, which devices (company and personal) and accounts access that data, whether they’re internet connected and whether technical controls are currently applied (or not)
  • Gap – focus on the differences, consider different options, set direction and define an action plan

 

Considerations and Key Notes

Recognising the need to support organisations with Cyber Essentials and Cyber Essentials Plus, NCSC has appointed Cyber Advisor’s. These are trusted professionals, qualified to provide expert advice on implementing Cyber Essentials technical controls. Their expertise includes producing a tailored gap analysis for organisations of different sizes.

IASME have key resources that can be leveraged for gap analysis support, including a Cyber Essentials readiness tool – which is aimed at providing guidance and advice for organisations. 

 

Key Notes

  • NCSC Cyber Advisors are also available and specially trained to assist with Cyber Essentials – including scoping
  • An asset list/inventory is not one of the key controls for Cyber Essentials, but is needed to form input into the process – it’s crucial to understand the devices that can access organisational data/services
  • A Cyber Essentials Readiness tool is designed to help organisations evaluate what may be required to achieve the implementation of the technical controls – an example of that is shown below:
 

A Cyber Essentials Readiness tool is designed to help organisations evaluate what may be required to achieve the implementation of the technical controls - an example of that is shown:

 

Example Scenario

To bid for contracts, organisations ABC is required to hold Cyber Essentials Plus. Cyber security has not been a top priority. Growing threats like data breaches and ransomware drive the need for certification. There’s recognition that achieving Cyber Essentials will reduce risk, boost trust, include free cyber liability insurance and can lead to Organisation ABC bidding for new contracts.

  • Organisations ABC reads the Cyber Essentials Requirements for IT Infrastructure to gain an understanding of the scheme and what needs to be in place
  • The organisation goes through the IASME readiness tool to see how close they are to achieving the required target state
  • A decision is made to receive support to help clarify scope, create an action plan and implement the required controls – a Cyber Advisor is contacted for support
  • The organisation quickly determines where to focus resources and works with the Cyber Advisor to implement the technical controls across the whole organisation
  • Cyber Essentials Plus certification is quickly achieved through the support of an IASME Certification Body
  • The organisation reduces risk, is able to bid for new contracts, receives free cyber liability insurance and has enhanced trust from customers and suppliers

 

Tips and Recommendations

  • Having a clear plan can reduce impacts on time, quality, and cost
  • Support is available from trusted sources such as NCSC Assured Service Providers and NCSC Assured Cyber Advisors
  • Documenting an asset or inventory list helps track devices accessing organisational data, understand risks, and support decision-making
  • Using the IASME readiness tool supports gap analysis and highlights the importance of Cyber Essentials requirements

 

How We Help

At RB Consultancy Ltd, we support organisations to improve cyber security and to meet Cyber Essentials and Cyber Essentials Plus requirements. As NCSC assured service providers and IASME certification body:

  • We explain the importance of Cyber Essentials, can define a gap analysis and action plan
  • We can explain why the Cyber Essentials questions are being asked and how they intend to protect organisations
  • We support organisations to achieve Cyber Essentials and Cyber Essentials Plus
  • We assess and issue organisations with certifications

 

Conclusion

Having a gap analysis for Cyber Essentials and Cyber Essentials Plus helps clarify where to focus and apply key resources. Without a gap analysis, organisations face delays, unexpected issues, and no clear plan. Ensuring Cyber Essentials compliance reduces risk and boosts trust. It also enables contract bids, includes free cyber liability insurance, and enhances security. If you need any assistance with Cyber Essentials / Cyber Essentials Plus certification, please contact us for support.

 

Written by Remo Belisari, Managing Director of RB Consultancy Ltd, an experienced cyber security professional cyber advisor. Remo holds certifications relating to CISSP, ISSAP, ISO 27001, Cyber Essentials, IASME Cyber Assurance, and has many years experience in IT and cyber security. Remo has a history of supporting organisations from all over the world – including a Fortune 500 in USA and over 100 organisations across the UK. The views expressed in this blog are those of the author and do not necessarily reflect the views of RB Consultancy Ltd, its clients, partners, or affiliated organisations. The content is intended for general information only and should not be taken as legal advice.

Cyber Essentials: Gap Analysis

Other articles you might find useful.

Cyber Security Consultancy: Incident Response

Cyber Security Consultancy: Incident Response

Incident response planning is the difference between a contained breach and a business-ending disaster. Using the 2014 Sony Pictures attack as a case study, we explain what incident response is, why it matters, and how to strengthen cyber resilience.

Read More »
Benefits of Cyber Essentials Plus

Benefits of Cyber Essentials Plus

Cyber Essentials Plus certification goes beyond basic compliance by providing a technical security audit that actively tests your defences against real-world threats. Through hands-on vulnerability

Read More »
Cyber Security Consultancy: Change Management

Cyber Security Consultancy: Change Management

Cyber Security Consultancy: Change Management A single change can bring multiple organisations to a standstill – the July 2024 CrowdStrike incident proved this, causing widespread outages across airlines, hospitals, and banks without any threat actors involved. Effective IT change management and business continuity planning require thorough testing, risk assessment, and rollback procedures before changes go […]

Read More »
Cyber Security Consultancy: Physical and Environmental Protection

Cyber Security Consultancy: Physical and Environmental Protection

Cyber Security Consultancy: Physical and Environmental Protection Cyber resilience goes beyond firewalls and passwords, physical security controls and environmental risk management are equally critical to protecting your organisation. Storm Dennis showed how flooding can destroy server rooms, backups, and operations in hours, highlighting why business continuity planning must account for real-world threats like fire, flood, […]

Read More »
Cyber Security Risk Management: Supply Chain Security & Building Resilience

Cyber Security Risk Management: Supply Chain Security & Building Resilience

Cyber Security Risk Management: Protecting Against Supply Chain Security Risks Effective cyber security risk management is not about eliminating every threat – it’s about understanding what could go wrong and putting appropriate measures in place to protect what matters most. The 2020 SolarWinds attack exposed critical supply chain security risks, with thousands of organisations compromised […]

Read More »
The Top 10 Benefits of Cyber Essentials

The Top 10 Benefits of Cyber Essentials

  Introduction Cyber Essentials is a UK government-backed annual certification scheme that helps organisations protect against common cyber threats. It provides a clear framework for securing devices, networks, and data. By implementing five key technical controls – relating to firewalls, secure configuration, security updates, access control, and malware protection – organisations can significantly reduce cyber […]

Read More »
Get started today

Ready to get certified and
reduce your cyber risk?

Book a free 30-minute discovery call with Remo. No sales pitch, no pressure — just a straightforward conversation about what you need and whether we are the right fit to help.

About RB Consultancy Ltd

Remo Belisari

Founder & Managing Director, RB Consultancy Ltd

Remo Belisari is a Chartered Cyber Security Professional with over a decade of experience advising organisations from start-ups to multinationals across the UK, Europe, Asia and the USA.

Through RB Consultancy Ltd he delivers high-quality, cost-effective and practical cyber security services that support compliance, strengthen resilience and enable business growth.

Remo holds the most respected certifications in the field and is personally involved in every client engagement, ensuring clear and valuable outcomes.

Personal Qualifications

Company Accreditations

Remo Belisari, founder of RB Consultancy
NCSC Assured Cyber Advisor (Cyber Essentials) Cyber Essentials Assessor Cyber Essentials Plus Assessor IASME Cyber Assurance Assessor Vulnerability Assessment Plus (VA+) Certified Defence Cyber Certification - Level 0 Assessor Defence Cyber Certification - Level 1 Assessor
RB Consultancy shield logo blue

RB Consultancy Ltd

Pioneer House, Pioneer Business Park,
North Road, Ellesmere Port, Cheshire,
CH65 1AD

NCSC Assured Service Provider
IASME Certification Body
Chartered (ChCSP) · CISSP · ISSAP