Start with the requirement
Find the exact wording of the customer, contract or tender requirement. Cyber Essentials and Cyber Essentials Plus are different assessment routes; knowing which is requested avoids planning for the wrong outcome. Share the deadline and clarify whether it relates to submission, assessment or receipt of the certificate.
Map who uses what
Bring a current view of your people, devices and services. Include remote workers and the systems managed by an external provider. A simple inventory with an owner is more useful than a polished document that leaves part of the organisation out.
Bring the right people into the conversation
Your organisation owns the answers, but the details may sit with an MSP, an internal administrator or individual service owners. Identify those contacts early and agree who can make changes. This helps avoid a queue of questions that nobody has authority to resolve.
Check the current question set
Use the official scheme documents for your assessment. Requirements can change, so copying last year's answers without reviewing them creates avoidable work. Keep a record of the setup you are describing and check that the answers match it.
Leave room for action
Preparation may reveal work to do. Put actions in one place, give each an owner and agree when it will be checked. Where device vulnerabilities are involved, scanning can help identify issues to investigate. It does not replace the assessment or decide the result.
A useful first-call checklist
Bring the requirement and deadline, your device and service inventory, your previous certificate if you have one, and the contact details for your IT provider. We can use that to agree the scope and the next steps.
