Generated paid-report sample · fictional data

Cyber Essentials detailed action planGenerated 26 August 202610 actions

RightCyber average implementation indicator83%

Requirements not yet fully confirmed

18 of 24 core preparation checks were reported fully implemented and evidenced. 2 potential automatic-fail conditions need attention; 2 scope checks are not fully confirmed; 2 other requirements are not fully confirmed. Resolve the reported gaps and evidence uncertainties before deciding whether to apply. This is a RightCyber preparation view, not an assessor decision or pass prediction.

Core checks fully in place18 of 24
Response coverage100%
Response certaintyLow — 2 scope checks are not fully confirmed
Evidence statusSelf-reportedNot independently verified

This is an internal average implementation indicator, not an official marking method, pass probability or assessor decision.

Start here

Three actions to move first

Paid reports contain up to 10 prioritised actions when supported by the answers. This fictional plan contains 10; this sample expands the first three as fully detailed task records rather than generic recommendations.

Where attention is concentrated

Submitted response profile

These area scores, response counts and critical-check statuses come directly from the fictional 0–5 answers. They are implementation indicators, not an official Cyber Essentials result.

Self-reported score by area

Original 24 core checks only; paid refinements are excluded. Unanswered core checks remain unevidenced.

  1. Scope47% · 3/3 answered
  2. Firewalls100% · 4/4 answered
  3. Secure configuration100% · 4/4 answered
  4. Security updates65% · 4/4 answered
  5. User access80% · 6/6 answered
  6. Malware protection100% · 3/3 answered

Submitted response distribution

Original 24 core checks only; paid refinements are excluded. 24 of 24 applicable core checks received a scored response.

0/5
1
2/5
1
3/5
1
4/5
1
5/5
18
Not sure
2

Critical-check status

Factual response status only; this is not an assessor result or pass/fail decision.

Reported 5/5
2
Below 5/5
2
Not sure or unanswered
0

Original 24 core checks only; paid refinements are excluded. These charts are not an audit, compliance percentage, maturity rating or pass probability.

Delivery sequence

Named action roadmap

Expanded actions link back to their task records; the remaining entries retain their action reference, area, action type, owner and suggested target without pretending that this public extract includes every detail.

Now

Start here

Begin with the first actions in the register’s prerequisite-aware order.

  1. Action 1 · Scope · Gap closureIT asset and scope owner · Suggested target: 5 September 2026
  2. Action 2 · User access · Gap closureIdentity and access lead · Suggested target: 9 September 2026
  3. Action 3 · Scope · Gap closureIT asset and scope owner · Suggested target: 13 September 2026
Next

Complete within 30 days

Continue with the remaining near-term actions after their dependencies are ready.

  1. Action 4 · Security updates · Gap closurePatch and vulnerability lead · Suggested target: 17 September 2026
  2. Action 5 · User access · Gap closureIdentity and access lead · Suggested target: 21 September 2026
  3. Action 6 · Security updates · Gap closurePatch and vulnerability lead · Suggested target: 25 September 2026
Later

Complete within 90 days

Deliver the later controls and verify that earlier changes remain effective.

  1. Action 7 · Security updates · Gap closurePatch and vulnerability lead · Suggested target: 10 October 2026
  2. Action 8 · Secure configuration · VerificationEndpoint engineering lead · Suggested target: 25 October 2026
  3. Action 9 · Firewalls · VerificationNetwork and infrastructure lead · Suggested target: 9 November 2026
  4. Action 10 · Malware protection · VerificationEndpoint security lead · Suggested target: 24 November 2026
Suggested next step

Work through the evidence checklist and action plan, then safely sample the weakest assessment areas before relying on the result or arranging any external assessment.

Closure evidence

Evidence checklist extract

Keep references or suitably redacted records in approved systems. Never include credentials or exploitable configuration details.

User access

User access control

  • Joiner, mover and leaver records
  • Access and privilege review
  • Administrator account inventory
  • Cloud MFA enforcement report
  • Password and compromised-account procedures
Scope

Scope and asset coverage

  • Scope statement
  • Asset and software inventory
  • Cloud service register
  • Network boundary or exclusion diagram
  • Supplier shared-responsibility records
How this fictional sample was produced and its limitations

This shortened extract is generated from fabricated answers through the same deterministic scoring, action and report-model pipeline used for customer plans. It contains no customer data.

Automated, name-minimised preparation review aligned to NCSC Cyber Essentials Requirements for IT Infrastructure v3.3 (effective 27 April 2026). RightCyber-authored questions; not the official questionnaire, an assessment, a certification decision, or a Cyber Essentials Plus technical audit.

This internal percentage averages the 0–5 implementation value for every applicable original core check, divides the result by 5, converts it to a percentage and rounds to the nearest whole percent. Each applicable original core check is weighted equally; permitted N/A responses and paid follow-up questions are excluded, while Not sure and unanswered checks are conservatively treated as 0. It is not the Cyber Essentials marking method, a pass probability or a certification decision; an unresolved automatic-fail requirement or inaccurate scope can prevent certification regardless of the total.

Scores, readiness classifications, findings, priorities, action wording and execution fields were produced deterministically. No external AI narrative enhancement was used.

This Cyber Essentials report is an independent preparation tool based on self-reported answers. It is not the official questionnaire, an assessment or certificate, and does not predict a pass. Certification decisions are made by an authorised Certification Body.

  • This sample uses fabricated answers and does not describe a real organisation.
  • Only an authorised assessor determines the result of an official Cyber Essentials assessment.
  • Actual report depth depends on answer coverage and the quality of information supplied.
  • Suggested actions require accountable human review before implementation.
  • Suggested target dates are assumption-based planning aids calculated from the report date, assigned timeframe and prerequisite order; they are not agreed deadlines.