CE in five steps for a 30-person agency
If you have decided your agency needs Cyber Essentials, the next question is usually where to actually start. For a business around 30 people, the process is manageable, but only if you follow it in order. Skip ahead and you end up doing rework. Here is the five step version.
Step 1: understand what’s in scope
Cyber Essentials assesses every device and system your business uses to handle work, including anything staff access remotely and any cloud service that stores or processes company data. For a 30-person agency that usually means laptops, phones, your Microsoft 365 or Google Workspace tenant, your CRM, and any design or file sharing tools your team logs into daily. Under the current version of the scheme, cloud services are explicitly in scope, so tools like Slack, Adobe Creative Cloud, or a project management platform all count. Write the full list down before you go further. Most agencies underestimate this list on the first attempt.
Step 2: run a gap assessment
Once you know what’s in scope, check it against the five controls: firewalls, secure configuration, access control, malware protection, and patch management. This is where most agencies find out where they actually stand rather than where they assumed they stood. A gap assessment is not about passing or failing, it is a working document that tells you exactly what needs fixing before submission. If you want a quick first pass before commissioning a full assessment, our CyberCheck tool gives you a scored breakdown across these areas in about ten minutes.
Step 3: remediate the gaps
This is usually the longest step, and for a 30-person agency it commonly comes down to three things: enabling multi-factor authentication everywhere, not just on email; tightening admin access so it sits with the people who need it rather than everyone who has ever asked; and getting a proper patching routine in place across every device, including staff laptops that are not always in the office. None of this requires an enterprise budget. It requires someone taking ownership of the list from step 2 and working through it methodically.
Step 4: submit your assessment
Cyber Essentials is a self-assessment questionnaire, reviewed and verified by an external certifying body. You will need someone who understands your IT setup well enough to answer technical questions accurately, since vague or incorrect answers are one of the most common reasons assessments get sent back. This is usually the point where agencies bring in outside support, either to complete the submission directly or to review it before it goes in.
Step 5: certify and maintain
Certification lasts twelve months. The mistake most agencies make is treating that date as the next time they think about security. New starters need onboarding into your access control setup, leavers need removing the same day, and patching needs to stay routine rather than becoming a pre-renewal scramble. Agencies that build these into normal operations find renewal straightforward. Agencies that don’t end up doing steps 2 and 3 all over again every year.
What this means for your agency
Five steps sounds simple written down, and for a lean team it genuinely can be, provided someone owns the process end to end. The most common failure point isn’t technical, it’s momentum: gap assessments that get done and then sit unactioned for months. If you are planning to get certified this quarter, we can walk through your current setup with you and tell you exactly where you stand against the five controls.