Why put the business through Cyber Essentials Plus as well?
That's a question Samm Mackay, Head of Operations at FlowMoCo, can now answer from experience.
During her first year at FlowMoCo, Samm has taken the operational lead on the company's growing portfolio of certifications and accreditations. Some were renewals. Others were new. For Samm personally, however, they were all a first.
Having now successfully navigated Cyber Essentials Plus, she has one overriding piece of advice for anyone about to do the same:
Start earlier than you think you need to.
What is Cyber Essentials Plus?
Cyber Essentials is the UK government-backed scheme designed to help organisations protect themselves against common cyber attacks.
Cyber Essentials Plus builds on the same technical controls but adds independent technical verification. That difference is important.
Rather than relying solely on an organisation's assessment of its controls, Cyber Essentials Plus involves technical testing to verify that appropriate protections are operating.
For FlowMoCo, that meant scanning systems, sampling devices and demonstrating that security controls were actually working.
As Samm puts it:
"It's ones or zeros."
What's the difference between Cyber Essentials and Cyber Essentials Plus?
FlowMoCo began with the detailed Cyber Essentials self-assessment.
Working with Citation, Samm collaborated particularly closely with the DevOps team on areas including access control, firewall protection and the company's wider technical environment.
Then came Cyber Essentials Plus.
Scanning software was deployed across selected machines and systems to identify vulnerabilities. Issues identified during the process needed to be addressed before the final assessment.
Individual devices were then sampled.
Developers had to demonstrate that operating systems and applications were appropriately updated and that security controls were functioning correctly. Malware protection was tested. Device settings were checked.
Evidence was required. For Samm, this was one of the most valuable aspects of the process.
A business can have a policy saying what should happen.
Cyber Essentials Plus provides additional assurance that what the policy describes is actually happening on the technology people use every day.
Cyber Essentials Plus vs ISO 27001: why have both?
This was particularly relevant for FlowMoCo because Cyber Essentials Plus wasn't the company's first security or operational certification.
FlowMoCo already had a substantial accreditation stack:
ISO 9001 — Quality Management
ISO 22301 — Business Continuity Management
ISO/IEC 27001 — Information Security Management
ISO/IEC 42001 — Artificial Intelligence Management
Cyber Essentials
Cyber Essentials Plus
So why add another?
One trigger was commercial.
As FlowMoCo explored government tenders and other potential projects, Cyber Essentials emerged as a requirement. Its recognition in the UK also made it a useful complement to the company's existing ISO certifications.
But Samm found the experience distinctly different. Cyber Essentials Plus brought a very practical focus to the technology estate itself.For a software development company trusted with clients' systems, data and business-critical applications, that additional scrutiny has real value.
How much work does Cyber Essentials Plus involve?
Don't underestimate the people time.
Samm estimates that her own contribution was equivalent to roughly two intensive weeks spread across the wider process. Engineering and DevOps time was required alongside it.
The final stages became particularly demanding. Reports were being produced. Updates had to be completed. Devices needed to be prepared. Any vulnerabilities identified needed attention.
And normal client work didn't disappear while this was happening. That's particularly significant in a software business.
A developer working towards a production release can't necessarily make major changes to their environment immediately simply because an assessment is approaching. Compliance has to work alongside delivery. That requires coordination across Operations, DevOps and Engineering rather than treating certification as one person's administrative project.
How should you prepare for Cyber Essentials Plus?
Samm came away with three practical lessons.
1. Start early
"There’s never a good time to do these things."
Her recommendation is to work through as much of the assessment as possible early and take advantage of opportunities for review. Doing that exposes both what you already have covered and where work remains. Don't discover those gaps immediately before assessment.
2. Involve the right people
Cyber Essentials Plus isn't something Operations can achieve alone. Samm worked closely with FlowMoCo's technical teams, including senior engineer Rob during the Plus assessment, while Poppy has provided valuable support across the wider ISO administration programme. Knowing who owns which piece of evidence or technical environment makes the process considerably easier. It also turns accreditation from an Operations responsibility into an organisational responsibility.
3. Don't prepare once a year
Perhaps the biggest lesson was to stop thinking about compliance as an annual event. FlowMoCo is now creating tickets and breaking requirements into smaller activities that can be completed throughout the year. As Samm explains:
"Ticking a little bit off each month makes it a lot smoother of a process."
The objective isn't to become compliant immediately before somebody checks. It's to operate that way routinely. That philosophy also extends beyond Cyber Essentials. Samm and the wider team are continuing to strengthen
FlowMoCo's processes, including the secure development lifecycle from discovery through development and ultimately into delivery. Accreditation becomes part of the operating system of the company rather than an exercise performed for an auditor.
The board-level question: how do you know?
There is a bigger governance issue underneath all of this. Boards are increasingly expected to understand cyber security, operational resilience and AI governance.
A board can approve a security policy. Management can report that devices are updated. An engineering team can say that it follows secure development practices. But an important question remains:
How do you know?
That's where independent standards and external assessment can become more than badges on a website. For FlowMoCo, ISO 9001, ISO 22301, ISO/IEC 27001, ISO/IEC 42001 and Cyber Essentials Plus provide different layers of assurance around quality, continuity, information security, AI management and practical cyber security controls.
Certification doesn't eliminate risk, and it isn't a substitute for good governance. What it can provide is evidence.
Policies become processes. Processes produce evidence. And assumptions about how an organisation operates can be independently challenged and tested. For a board selecting a partner to develop business-critical software, that's significant.
The question isn't simply:
"Do they have good developers?"
It's also:
"Does the organisation surrounding those developers have the operational discipline to protect our data, maintain its systems, manage disruption and consistently deliver against the standards it says it follows?"
That's a very different conversation from looking at a row of certification logos.
From first-time nerves to organisational rhythm
Samm's perspective is particularly useful because she hadn't personally led ISO certifications before joining FlowMoCo. Within weeks, she was involved in her first substantial ISO audit. A year later, things look very different.
She knows where the evidence is. She knows who to ask when something involves AWS or another specialist area. Processes have been established and supporting information is organised.
During a recent ISO/IEC 27001 audit, evidence that might previously have taken hours to assemble could be pulled together remarkably quickly.
Her lesson is simple:
"Organisation is key."
There's another important change too. The first time through an accreditation, you're learning the standard while simultaneously trying to satisfy it. You're discovering which people need to be involved, what evidence exists, where the gaps are and what an assessor actually expects.
The second time, you have a map.
That's why experience matters.
Doing Cyber Essentials Plus for the first time?
Samm expects FlowMoCo's next Cyber Essentials Plus cycle to feel considerably easier. Not because the standard will be less rigorous. Because the team now understands what's coming.
They know which questions to address early, who needs to be involved, what the technical assessment entails and how to integrate the requirements with everyday software delivery. Most importantly, the requirements can now become part of the normal rhythm of FlowMoCo rather than creating a scramble before assessment.
So Samm's advice for anyone preparing for Cyber Essentials or Cyber Essentials Plus for the first time is straightforward:
Start early. Break it into manageable pieces. Get organised. And, if you can, talk to someone who has already been through it.
Having recently completed that first journey herself, Samm is happy to share her experience with CTOs, Heads of Operations and other software businesses preparing for Cyber Essentials or Cyber Essentials Plus.
No sales pitch. Just a conversation with someone who remembers exactly what it feels like to be looking at the process for the first time.
If you're about to begin your own Cyber Essentials journey and would value a peer conversation, get in touch with Samm Mackay, Head of Operations at FlowMoCo.