Cyber Essentials managed service — what it covers and how it runs
The Cyber Essentials managed service provides outsourced delivery of the NCSC-backed Cyber Essentials standard, handling self-assessment, evidence-gathering and basic technical controls so you can achieve or renew certification; certificates are valid for 12 months and providers typically include patching, MFA checks and audit support.
First week
In the first week a managed service will map your scope and collect the obvious evidence: user lists, device inventory and current firewall settings. Expect a short intake call and a remote scan; the provider will usually run automated checks and flag missing simple controls such as basic patching and password policies. This stage is about eliminating easy failures that block certification rather than fixing deep platform problems. You should come away with a clear, prioritised list of tasks the provider will either resolve for you or hand back to internal staff. If you want to verify what the standard requires, refer to the NCSC’s Cyber Essentials overview for the official scope and core controls.
First month
Over the next few weeks the managed service implements the basics and prepares your self-assessment evidence. Typical activity here includes:
- Applying missing security updates and basic patching coverage.
- Enforcing multi-factor authentication where supported.
- Configuring boundary firewalls and reviewing remote access settings.
- Compiling the documentation pack for your Cyber Essentials submission.
The provider will also guide you through the self-assessment questionnaire or, if they offer full certification support, submit the evidence on your behalf. What you should expect by the end of month one is a completed evidence set and either a pass or a short list of corrective actions that are usually low-effort. For a clear statement of managed service features and subscription options, check Aurora’s Cyber Essentials managed service page which explains typical inclusions and ongoing checks.
First quarter
In the first quarter the focus shifts from reaching certification to making those controls stick. The managed service typically runs recurring tasks and monitoring so the same misconfigurations don’t reappear. Common regular activities are quarterly vulnerability scans, scheduled patch cycles and user-awareness prompts. Benefits in this phase become tangible: fewer avoidable outages, a simpler annual renewal and a clearer compliance posture for audits. Look for reporting that connects work done to business outcomes — not just a list of technical fixes but evidence showing reduced exposure. If your provider supplies SLAs for patching or response times, this is when you can measure delivery against them and adjust the scope if certain systems need stronger protection.
First year
Across the first 12 months the managed service should treat the Cyber Essentials certificate as a living item: maintaining controls, logging changes, and preparing for re-assessment before expiry. Expect an annual review that repeats the intake, rescans the estate and refreshes the self-assessment evidence. Good providers will package continuous hygiene (patching, MFA checks, backup reviews) alongside a single renewal workflow so you avoid last-minute scrambles. Certification validity is typically 12 months, so plan budgets and internal time around an annual cycle rather than an ad-hoc project. By month twelve you should be able to show an audit trail of fixes and a single consolidated report that makes renewal straightforward.
What to watch for next
After the first year turn your attention to a few recurring signals: rising false negatives in automated scans, gaps where legacy devices drop off patch schedules, and staff turnover that removes people listed on evidence documents. Demand clear, dated reports and a renewal plan at least six weeks before expiry. If scope or infrastructure changes, ask for an interim review rather than waiting for renewal time. A sensible next step is to agree a yearly calendar with your provider that slots in scans, patch windows and the reassessment window so you preserve time and budget.
Related reading
- our cyber essentials guide
- Cyber Essentials vs ISO 27001: which is right for your UK SME?
- Cyber Essentials service provider — who should certify your business?
- Cyber Essentials IT Support: A Practical Guide for UK SMEs
- Cyber Essentials Certification for Financial Services
FAQ
How long does a Cyber Essentials managed service contract usually last?
Contracts typically align to the certification cycle, so most are organised on a 12-month basis to cover assessment and renewal work.
Can a managed service complete the self-assessment for us?
Yes — many providers will collate evidence, run scans and submit the self-assessment with your authorisation, but you must retain ultimate sign-off as the certificate holder.
Will a managed service replace our internal IT team?
No. A managed service handles standard controls and compliance paperwork; internal IT still manages bespoke systems, business apps and user training where deep knowledge of your processes is needed.
What common blind spot should I check in proposals?
Check whether the proposal includes ongoing patching and MFA verification as standard; absence of these is the usual gap that causes a failed renewal.







