Compliance guide

Prepare for Cyber Essentials and Cyber Essentials Plus

Use PurpleWASP to define scope, complete the Cyber Essentials questionnaire and five technical-control workspaces, resolve readiness gaps, and prepare the evidence and testing workflow for Cyber Essentials Plus.

Compliance Manager, Security Manager, IT Manager or authorised contributor Assessment and renewal cycle Updated 18 September 2026

What PurpleWASP supports

PurpleWASP provides a connected Cyber Essentials readiness workspace and a separate Cyber Essentials Plus technical-assurance workflow. The Cyber Essentials side combines scope, the Danzell questionnaire, the five technical areas, remediation, management declaration and submission review. Cyber Essentials Plus adds preflight, sampling, technical tests, findings, an outcome view, an assessor evidence pack and certificate/renewal records.

AreaPurpleWASP capability
ScopeDefine the assessment boundary before questionnaire/readiness work is treated as authoritative.
QuestionnaireComplete the Danzell question set with conditional questions and progress tracking.
Technical areasWork through Firewalls, Secure Configuration, Security Update Management, User Access Control and Malware Protection.
ReadinessReview evaluated gaps, human-review items, remediation and the internal readiness score/driver model.
Submission preparationRecord management declaration, perform submission review and retain certificate/renewal history where applicable.
Cyber Essentials PlusRun technical preflight, sampling, testing, findings/remediation, outcome review and evidence-pack preparation.

1. Confirm the assessment scope

Start from the Cyber Essentials dashboard and open Scope. Define the organisation, systems and assessment boundary that the questionnaire will describe. Complete scope before relying on downstream readiness results.

Scope is foundational. Questionnaire answers and technical readiness are meaningful only when they refer to the boundary actually being assessed.

2. Complete the Danzell questionnaire

Use the questionnaire workspace to answer the complete assessment set. Conditional questions count only when they apply, and the workspace separates unanswered items, evaluated gaps and responses that require human review.

  • Answer from the organisation's real technical configuration rather than the desired future state.
  • Use supporting notes where an answer needs explanation.
  • Review automatic-fail gaps immediately instead of waiting for the final submission review.
  • Use the section cards to move between the questionnaire and the detailed technical workspaces.

3. Work through the five technical areas

PurpleWASP provides dedicated workspaces for the five Cyber Essentials technical areas:

  • Firewalls — review boundary and host firewall arrangements.
  • Secure Configuration — track secure build/configuration requirements.
  • Security Update Management — review supported software and update/patch practices.
  • User Access Control — review accounts, privileges and access governance.
  • Malware Protection — record the malware-protection approach in the assessed environment.

Where organisation Controls or evidence already exist in Control Management, reuse those records rather than creating duplicate assurance artefacts only for Cyber Essentials.

4. Resolve readiness gaps and remediation

The Readiness Review brings together questionnaire completion, evaluated gaps and responses that require human judgement. The Remediation workspace gives the assessment team a consolidated place to work outstanding items before declaration.

  • Resolve unanswered applicable questions.
  • Address automatic-fail/evaluated gaps.
  • Complete the human-review queue for narrative or gateway responses that cannot safely be reduced to a simple Yes/No rule.
  • Follow unresolved technical issues back to the owning system, Control or evidence record.

5. Prepare declaration and submission review

When readiness blockers have been resolved, use the Management Declaration and Submission Review workspaces to perform the organisation-side confirmation before submission to the appropriate certification process. Certificate and renewal records can then be retained in PurpleWASP for lifecycle visibility.

6. Run the Cyber Essentials Plus technical-assurance workflow

Cyber Essentials Plus is managed as a distinct technical-assurance workflow rather than as another questionnaire page.

  1. Preflight — confirm the prerequisite assessment state and readiness for technical verification.
  2. Sampling — establish the systems/devices/accounts or other technical sample that will be tested.
  3. Technical Testing — record tests and results against the Plus work programme.
  4. Findings & Remediation — track technical failures through remediation.
  5. Outcome — consolidate the technical-assurance position.
  6. Assessor Evidence Pack — prepare the traceable evidence package used to support the external assessment.
  7. Plus Certificate — retain certificate/renewal information after the authoritative external decision.

Readiness score and Drivers / Improve Score

The Cyber Essentials and Cyber Essentials Plus dashboards include PurpleWASP internal readiness scores. Use View Drivers to understand the components contributing to the score and Improve Score to see the highest-impact outstanding work.

The score is a management/preparation indicator. It is not a Cyber Essentials or Cyber Essentials Plus certification score and does not replace the Certification Body or Assessor decision.

Certification boundary

PurpleWASP organises the assessment, readiness, technical-assurance and evidence work. It does not make the independent Cyber Essentials or Cyber Essentials Plus certification decision.

  • A high internal readiness score is not a certificate.
  • Completing the questionnaire is not the same as certification.
  • For Plus, PurpleWASP records and packages technical-assurance work; the authorised external assessment remains authoritative.

Implementation guides

Use the first-time handbook for organisations preparing for Cyber Essentials/Cyber Essentials Plus and the technical guide for PurpleWASP developers, administrators and implementation partners.

Download the Cyber Essentials first-time implementation handbook

Download the Cyber Essentials technical implementation guide

Common problems

Readiness is blocked even though the questionnaire looks complete

Open Readiness Review and check evaluated gaps and the human-review queue. A completed answer count does not mean every response is satisfactory.

The Plus workflow is not ready to start

Review Plus Preflight and the underlying Cyber Essentials assessment state. Confirm the prerequisite scope and assessment records are complete before creating the technical sample.

The dashboard score did not improve

Open View Drivers and inspect the specific incomplete driver. Update the authoritative questionnaire, remediation, technical-test, evidence or finding record and then refresh the dashboard.