Skip to main content
Jamie Levers

Jamie Levers

Security Consultant at URM Consulting and a Cyber Essentials / Cyber Essentials Plus certified assessor, with a background in penetration testing and offensive security.

Aug 20, 2026

14:00
So as we've conducted a number of assessments, what lessons have we learned as an assessment body that we can sort of pass over to applicants?
14:12
So probably one of the big ones is the scope in the assessment correctly.
14:18
We've had a number of organisations that maybe thought something could be out of scope when it couldn't.
14:26
or maybe they've just missed something on their questionnaire.
14:30
If the assessment isn't scoped correctly and you move on to CE+, when we come to conduct the technical scope verification, if we see something that doesn't add up, you'll have to go back and redo the cyber essentials questionnaire so that it does match up.
14:48
So scoping the assessment is essential.
14:52
And again, like you said, many people finding this out with excluding test and development networks maybe they're part of a group and they've previously done whole organization but now they can't because of the statements for designating who can and who can't be whole organization that ties in quite nicely with the next point so if you're not doing whole organization segregation has to be network based and that is VLAN or firewall, so layer two or layer three of the OSI model.

17 MINS LATER

32:52
Jamie, so from your perspective, from a certification body's perspective, what obviously we said a lot about what, you know, what to do, right? How How to do this and what are the steps? What steps should people be taking, whether it's research or fresh certification?

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.