Lesson 10.4 — Final remediation sprint: fixing gaps before submission, prioritising controls and preparing for Cyber Essentials Plus
This lesson helps the learner run a final remediation sprint before Cyber Essentials submission.
What You'll Be Able to Do
By the end of this lesson, you will be able to:
- run a focused remediation sprint
- triage gaps by severity
- identify submission blockers
- assign owners and deadlines
- verify remediation with evidence
- avoid paper-only fixes
Why This Matters
It explains how to prioritise gaps, decide what must be fixed before submission, separate evidence issues from real control failures, close gaps properly, avoid superficial fixes, coordinate suppliers, prepare leadership sign-off, and use the same work to prepare for Cyber Essentials Plus where relevant.
The Core Rule
The final remediation sprint is where the organisation fixes the real gaps before submission.
Separate evidence gaps from control gaps.
What the CE Assessor Looks For
A strong position shows:
- all gaps are listed;
- each gap is ranked by severity;
- evidence gaps and control gaps are separated;
- critical blockers are fixed before submission;
- owners and deadlines are assigned;
- suppliers are contacted early;
Copy This
Keep this rule visible:
Do not submit because the form is complete. Submit because the controls are ready, the evidence proves it, and the remaining risks are understood.
Quick Checklist
Before moving on, make sure you can say yes to these:
- [ ] What is the purpose of a final remediation sprint?
- [ ] What is the difference between an evidence gap and a control gap?
- [ ] Why should critical gaps block submission?
- [ ] Why is paper-only remediation weak?
- [ ] What should happen after a control is fixed?
Your Action
Do this now — it takes 10–20 minutes.
List every gap your dry run revealed. Prioritise by which gaps are most likely to cause a failure and fix those first.
Key Takeaway
Do not submit because the form is complete. Submit because the controls are ready, the evidence proves it, and the remaining risks are understood.
Your Workbook Activity
Complete: Final remediation sprint and Cyber Essentials Plus preparation record
Next Lesson
In the next lesson: Final course close: maintaining Cyber Essentials, recertification, management review and continuous improvement