Featured guide
Create and assess a risk
Learn how to complete CIA and FAIR assessments, add controls, assign treatment actions and manage risk exceptions.
Read the guideUse PurpleWASP to define scope, complete the Cyber Essentials questionnaire and five technical-control workspaces, resolve readiness gaps, and prepare the evidence and testing workflow for Cyber Essentials Plus.
PurpleWASP provides a connected Cyber Essentials readiness workspace and a separate Cyber Essentials Plus technical-assurance workflow. The Cyber Essentials side combines scope, the Danzell questionnaire, the five technical areas, remediation, management declaration and submission review. Cyber Essentials Plus adds preflight, sampling, technical tests, findings, an outcome view, an assessor evidence pack and certificate/renewal records.
| Area | PurpleWASP capability |
|---|---|
| Scope | Define the assessment boundary before questionnaire/readiness work is treated as authoritative. |
| Questionnaire | Complete the Danzell question set with conditional questions and progress tracking. |
| Technical areas | Work through Firewalls, Secure Configuration, Security Update Management, User Access Control and Malware Protection. |
| Readiness | Review evaluated gaps, human-review items, remediation and the internal readiness score/driver model. |
| Submission preparation | Record management declaration, perform submission review and retain certificate/renewal history where applicable. |
| Cyber Essentials Plus | Run technical preflight, sampling, testing, findings/remediation, outcome review and evidence-pack preparation. |
Start from the Cyber Essentials dashboard and open Scope. Define the organisation, systems and assessment boundary that the questionnaire will describe. Complete scope before relying on downstream readiness results.
Use the questionnaire workspace to answer the complete assessment set. Conditional questions count only when they apply, and the workspace separates unanswered items, evaluated gaps and responses that require human review.
PurpleWASP provides dedicated workspaces for the five Cyber Essentials technical areas:
Where organisation Controls or evidence already exist in Control Management, reuse those records rather than creating duplicate assurance artefacts only for Cyber Essentials.
The Readiness Review brings together questionnaire completion, evaluated gaps and responses that require human judgement. The Remediation workspace gives the assessment team a consolidated place to work outstanding items before declaration.
When readiness blockers have been resolved, use the Management Declaration and Submission Review workspaces to perform the organisation-side confirmation before submission to the appropriate certification process. Certificate and renewal records can then be retained in PurpleWASP for lifecycle visibility.
Cyber Essentials Plus is managed as a distinct technical-assurance workflow rather than as another questionnaire page.
The Cyber Essentials and Cyber Essentials Plus dashboards include PurpleWASP internal readiness scores. Use View Drivers to understand the components contributing to the score and Improve Score to see the highest-impact outstanding work.
PurpleWASP organises the assessment, readiness, technical-assurance and evidence work. It does not make the independent Cyber Essentials or Cyber Essentials Plus certification decision.
Use the first-time handbook for organisations preparing for Cyber Essentials/Cyber Essentials Plus and the technical guide for PurpleWASP developers, administrators and implementation partners.
Download the Cyber Essentials first-time implementation handbook
Download the Cyber Essentials technical implementation guide
Open Readiness Review and check evaluated gaps and the human-review queue. A completed answer count does not mean every response is satisfactory.
Review Plus Preflight and the underlying Cyber Essentials assessment state. Confirm the prerequisite scope and assessment records are complete before creating the technical sample.
Open View Drivers and inspect the specific incomplete driver. Update the authoritative questionnaire, remediation, technical-test, evidence or finding record and then refresh the dashboard.