Leeds manufacturer passes Cyber Essentials Plus first time to win a supply-chain contract
A 78-staff precision manufacturer in Leeds achieved Cyber Essentials Plus certification first time in six weeks, reaching 98% patch compliance within 14 days with no production downtime, and retained a supply-chain contract that required the certification.
A tier-two automotive supplier was told by its largest customer that Cyber Essentials Plus would become a condition of contract renewal within one quarter. An earlier self-assessment attempt had stalled on unsupported operating systems and inconsistent patching across the shop floor.
Client: 78-staff precision manufacturer. Name withheld under our confidentiality terms.
At a glance
- Client
- 78-staff precision manufacturer
- Sector
- Manufacturing
- Location
- Leeds, West Yorkshire
- Size
- 78 employees, 3 sites
- Services
- Cyber Essentials Plus, Vulnerability Management, EDR
- Timeline
- 6 weeks from kick-off to certification
- Headline result
- 100% — First-time pass at Cyber Essentials Plus
Measured results
- First-time pass at Cyber Essentials Plus
- 100%First-time pass at Cyber Essentials Plus
- From kick-off to certificate
- 6 weeksFrom kick-off to certificate
- Patch compliance within 14 days, sustained
- 98%Patch compliance within 14 days, sustained
- Production downtime during remediation
- 0Production downtime during remediation
The challenge
- Contract worth a significant share of annual revenue was conditional on Cyber Essentials Plus certification.
- Eleven shop-floor PCs ran an unsupported operating system tied to machine control software.
- No central patching: workstations were updated ad hoc by a part-time IT contractor.
- Local administrator rights were shared across production staff, failing user access control.
What we did
- 1
Ran a gap assessment against the five Cyber Essentials controls and produced a costed remediation plan in week one.
- 2
Segmented the eleven legacy machine-control PCs onto an isolated VLAN with no internet access, taking them out of scope in line with IASME guidance.
- 3
Deployed managed patching across all in-scope endpoints and servers, with monthly compliance reporting.
- 4
Removed standing local admin rights and replaced them with a request-based elevation process.
- 5
Rolled out EDR with 24/7 SOC monitoring across every in-scope device.
- 6
Compiled the evidence pack, submitted the self-assessment, and hosted the external Plus audit.
The outcome
- The supply-chain contract was renewed on schedule.
- Legacy machine-control systems stayed in production without blocking certification.
- Patching moved from ad hoc to a measured monthly cycle with reporting the board can read.
- Cyber insurance renewal completed at a lower premium the following year.
“The customer deadline was not negotiable. Having someone scope it properly, tell us what was actually in scope, and then run the audit for us was the difference between renewing and not.”
The concepts behind this engagement
Plain-English reference pages explaining the certifications, threats and controls involved in this piece of work.
Where this fits in what Complete Cyber Security does
FAQ
Questions about this engagement
The questions businesses in a similar position ask most often before starting.
How long does Cyber Essentials Plus take for a manufacturer with legacy equipment?
+
For this engagement it took six weeks from kick-off to certificate, including remediation. Legacy machine-control systems are the usual cause of delay, because unsupported operating systems cannot pass the malware protection and patch management controls. The practical route is nearly always network segmentation: the legacy device is placed on an isolated network with no internet access and no route to corporate systems, which removes it from assessment scope while keeping the machine in production. Where segmentation is not possible, the alternative is replacement or a supported upgrade, which lengthens the project. A gap assessment in week one is what makes a six-week timeline realistic rather than optimistic.
Does removing local administrator rights disrupt production staff?
+
It did not here, because the change was paired with a request-based elevation process rather than a flat removal. Production staff rarely need standing administrator rights; they need a small number of specific actions, such as installing an approved tool or changing a printer setting. We logged which elevated actions were actually used over a two-week baseline, allowed those by policy, and routed anything else through a request that IT approves within the working day. Standing local admin rights are one of the most common Cyber Essentials failures and one of the most effective ransomware controls to remove, so it is worth doing properly.
What does Cyber Essentials Plus cost a business of this size?
+
Cost has two parts: the certification body fee, which scales with the size and complexity of your estate, and the remediation work needed to pass. For a 78-staff manufacturer across three sites the audit fee sat in the low four figures, and the larger cost was the managed patching and endpoint protection introduced to meet the controls — services this business needed regardless of certification. Businesses that already run centrally managed patching, EDR and MFA typically pay little beyond the audit fee. We quote both parts separately after a gap assessment, so there is no open-ended remediation bill.

