A market that checks twice
FreshWave’s public sector prospects wanted certification before they would contract, and in this market certification is never a one-off event. Cyber Essentials Plus is reassessed every year, ISO 27001 brings surveillance audits, and a security posture assembled for a single assessment date tends to be found out at the next one, at exactly the moment a contract depends on it.
Hardening built into routine
A senior CyPro practitioner shaped FreshWave’s controls around what the business could genuinely keep doing. Systems were hardened as engineering work rather than as recommendations left in a report, and the evidence assessors needed grew out of normal operations instead of a scramble before each audit. The certifications followed, and with them the public sector wins the company was after.
What certification evidence rests on
Both of FreshWave’s certifications lean on demonstrable vulnerability management. A Cyber Essentials Plus assessor scans the systems in scope and expects the results to hold up, and ISO 27001 asks, through control A.8.8, for evidence that technical vulnerabilities are identified, evaluated and dealt with. Neither is satisfied by a tidy document set. They are satisfied by a scanning cadence with findings triaged, fixed and recorded, month after month, which is precisely the routine a managed scanning service leaves running between audits. FreshWave’s engagement went wider than scanning, but the principle it proves is the one a scanning buyer should hold onto: the evidence you show an assessor is a by-product of vulnerability work you actually do, and it is worth very little produced any other way.