Quick answer
Cyber Essentials' five themes are almost entirely machine-verifiable, which makes it a natural fit for OptiTech's integration checks: firewall and configuration state from your cloud, access control and MFA from your identity provider, malware protection and patch status from your MDM and endpoint tools. The self-assessment answers come from live control status, and the annual renewal is a calendar event, not a project.
The checks behind the five themes
- Access control: MFA coverage, unique accounts, admin separation, and offboarding within 24 hours verified against Entra ID or Google Workspace.
- Secure configuration: cloud and device baseline checks: default credentials, exposed services, device lock policies from Intune or Jamf.
- Update management: the 14-day high-severity patch requirement runs as a per-device check with an actual clock: devices out of window become findings routed to IT, before the assessment asks.
- Malware protection: endpoint protection presence and status from CrowdStrike or Defender.
- Firewalls: boundary configuration checks from your cloud integrations.
Unsupported software, the silent Cyber Essentials killer, surfaces through inventory checks: operating systems and applications past end-of-support get flagged as they age out, not when the questionnaire asks.
Scope honesty, including BYOD
The assessment scope includes devices that touch organizational data. The asset inventory gives you a defensible scope statement: managed devices enumerate from the MDM, cloud services from the integrations, and the BYOD question gets answered by policy plus conditional-access checks rather than optimism.
Plus, and beyond
For Cyber Essentials Plus, the independent tester verifies what your dashboard already shows, so surprises are rare and remediation pre-empted. And since the five themes are a strict subset of ISO 27001 and NIS 2 territory, the certificate is a cheap, UK-recognized byproduct of the program you run anyway, worth holding if UK deals are in your pipeline.

Get a personalized walkthrough of automated compliance for your team. No commitment required.