Back to help

Cyber Essentials readiness

Prepare Cyber Essentials evidence without losing the routine work.

Use Obligary to define scope, collect useful evidence, turn gaps into tasks and keep Cyber Essentials and Plus preparation visible. Obligary supports organisation and evidence; it is not a certification body and does not guarantee an assessment outcome.

Recommended flow

1

Confirm scope

Record the devices, cloud services, user groups, suppliers and internet-facing services that are included in the readiness work.

2

Gather evidence

Attach screenshots, exports, supplier notes and review outcomes to the records they support.

3

Close gaps

Turn missing evidence, uncertain controls or remediation work into assigned calendar tasks with due dates.

4

Keep it current

Schedule reviews so annual Cyber Essentials and Plus preparation does not become a one-off scramble.

What this workspace is for

The Cyber workspace keeps readiness records, evidence and follow-up work together so the team can see what has been checked and what still needs attention.

  • Define the systems, devices, users, suppliers and services that make up the readiness scope.
  • Track technical-control checks in plain English with owners, review dates and evidence.
  • Keep Cyber Essentials Plus preparation records visible without mixing them into unrelated notes.
  • Use linked calendar tasks for renewals, annual reviews and gap-closing actions.

Evidence worth collecting

Aim for evidence that would help another person understand the current position later, without storing secrets or unnecessary personal data.

  • Device inventory, asset register or MDM export showing the equipment included in scope.
  • Cloud admin screenshots or exports showing MFA, access policies, administrator accounts and review outcomes.
  • Firewall, router, remote-access or internet-facing service notes showing ownership and review status.
  • Patch/update, malware protection, backup and secure-configuration evidence where relevant.
  • Supplier responsibility notes when a third party manages systems, hosting or support in scope.

How to use the registers

Each register is focused on one part of the preparation trail. Start with the records that explain scope before working through checks and actions.

  • Use Scope, devices and services to describe what is included before collecting technical evidence.
  • Use Technical-control checks for checks around configuration, updates, malware protection and related responsibilities.
  • Use Access and MFA reviews for administrator accounts, starters, leavers, role changes and periodic access checks.
  • Use Risks and gaps when a control is uncertain, unsupported, waiting for a decision or missing evidence.
  • Use Actions and Plus preparation to manage remediation, annual reviews, sample preparation and follow-up work.

Cyber Essentials Plus preparation

Plus preparation often needs a clearer evidence chain because checks may involve samples, remediation and retesting.

  • Use Plus preparation records to organise sample lists, technical-check preparation and remediation notes.
  • Attach evidence that shows what changed, who checked it and when the check was completed.
  • Keep unresolved Plus actions open until they have an owner, due date and outcome note.
  • Use the report view when you need a concise snapshot of open work, evidence coverage and recent progress.

Good practice boundaries

The Cyber workspace is designed to support preparation, not replace professional judgement or your certification body.

  • Do not store passwords, secret keys, recovery codes or sensitive identity documents in evidence.
  • Use Obligary to organise records, reminders and evidence; take qualified advice where you need assurance.
  • Review readiness records at least annually and after major changes to systems, sites, suppliers or ways of working.
  • Keep notes factual: what was checked, what evidence was used, what changed and who owns the next action.

Related guides

Important boundary

Obligary supports organisation and evidence. It does not replace professional judgement.

Use Obligary to manage tasks, owners, reminders, documents, evidence and reports. Your organisation remains responsible for deciding what applies and taking legal, regulatory or certification advice where needed.