Cyber Essentials software

Keep Cyber Essentials actions and evidence ready all year

Organise scope, asset information, action owners, evidence and renewal dates around the five Cyber Essentials controls, then keep the work connected to your wider compliance calendar.

Obligary is not a certification body, does not perform the official assessment and cannot guarantee Cyber Essentials or Cyber Essentials Plus certification.

Plain-English definition

Ongoing management after the readiness questionnaire

Cyber Essentials is the UK Government-backed scheme built around five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. Official NCSC and IASME resources explain the scheme and assessment route. Obligary provides the operational layer for keeping actions, records, evidence and renewal preparation current between assessments.

How it works

Keep the routine clear from action to evidence.

01

Define scope and assets

Keep the organisation, boundary, devices, services and relevant asset information used in preparation visible and reviewable.

  • Scope records
  • Asset information
  • Planned review dates
02

Map the five controls

Organise work around firewalls, secure configuration, security updates, access control and malware protection.

  • Control-focused records
  • Named action owners
  • Clear status and notes
03

Turn gaps into actions

Move an identified weakness into a task with an owner and due date rather than leaving it inside a one-off assessment response.

  • Gap tracking
  • Due dates and reminders
  • Follow-up visibility
04

Collect supporting evidence

Attach screenshots, configuration records, approvals and other useful proof to the related control work.

  • Secure evidence requests
  • Control and task links
  • Evidence review states
05

Prepare for renewal

Keep recurring checks and renewal dates in the calendar so preparation is maintained throughout the year.

  • Renewal reminders
  • Recurring control reviews
  • Current evidence checks
06

Support Plus preparation

Maintain organised records for conversations with an assessor while recognising that the assessor determines the evidence and testing required.

  • Preparation records
  • Evidence index
  • Open-action reporting

A clearer operating system

Keep the official route and the ongoing routine distinct

The official assessment and readiness resources remain authoritative. Obligary helps teams maintain the operational work and evidence around that route.

One-off readiness exercise

  • Answers and screenshots gathered close to renewal
  • Actions lose owners after the assessment window
  • Cyber work sits apart from other business deadlines

Year-round management in Obligary

  • Control actions stay assigned and reviewable
  • Evidence remains connected to the relevant work
  • Renewal preparation shares the wider compliance calendar

Explore the workflow

Related product pages and practical guides

FAQs

Common questions

Is Obligary the official Cyber Essentials readiness tool?

No. The NCSC and IASME provide official scheme and readiness resources. Obligary helps manage ongoing actions, evidence, responsibilities and renewal preparation.

What are the five Cyber Essentials controls?

They are firewalls, secure configuration, security update management, user access control and malware protection.

Can Obligary award Cyber Essentials certification?

No. Certification and assessment are handled through the official scheme and authorised assessment route.

Can Cyber work appear with our other compliance tasks?

Yes. Cyber Essentials actions and renewal work can sit in the same shared calendar and evidence workflow as wider compliance activity.

Put the next task, its owner and its evidence in one place.

Create a free Obligary workspace in minutes. No card, enterprise contract or long implementation required.

Create a free workspace