Movegistics AI Product Updates
Release notes, feature announcements, and improvements from the product team.
Release notes, feature announcements, and improvements from the product team.
Release notes, feature announcements, and improvements from the product team.
Setting up your Cyber Essentials Plus (CEP) vulnerability scan is now quicker. You can deploy Qualys directly from your CyberSmart dashboard once you enter pre-audit preparation.
You’ll now be able to deploy Qualys from the CEP Certificate page -

Already using CSVM? You'll already have Qualys in place and can continue as you do today — nothing changes for you with this update.
Using a different scanner? If you use your own PCI-DSS approved scanning tool, you can let us know which one directly in the dashboard, and we'll review this with you offline.
Coverage Requirements
Your Audit Support team can now drop you a note with coverage requirements for Qualys. This will appear in your dashboard next to the installation guidance.
When you’ve got Qualys deployed you can notify the audit team directly with the ‘Ask audit team to review’ button. They can review and confirm you have the coverage you need ahead of your audit.

Installation Instructions and Tips
You’ll find detailed support instructions in the page. Just click the ‘Installation guides’ tab on the righthand side!
Previously, setting up your vulnerability scan meant waiting for your Audit Support Agent to manually share Qualys installers and credentials by email. This change puts the setup directly in your hands, so you can get up and running in minutes instead of waiting on back-and-forth emails.
This is available now for any Cyber Essentials Plus audits currently in preparation. If you're mid-way through using the previous process, our Audit Support team will still be on hand to help — there's no action needed on your part to switch over.
We've made it easier to get ready for your Cyber Essentials Plus (CEP) audit. Two of the steps that used to mean downloading documents and emailing them back and forth — your Audit Authorisation form and your Asset list — can now be completed directly in your CyberSmart dashboard.

Audit Authorisation form, done online
No more printing, signing and emailing a form back to us. Complete your authorisation form right on the CEP Certificates page — add in scope IP addresses, confirm your contact, sign digitally, and submit. If you don't have everything to hand, save your progress and finish it later.
You can also share with a non-dashboard user for completion and exported a completed form as a PDF.

Asset list upload, made straightforward
Download a ready-made template so you know exactly what information we need, then upload your completed list (CSV or Excel) directly from the Certificates page. Drag and drop, or browse to select — whichever's easier.

Always know where you stand
Both tasks show a live status — so you can see at a glance whether something's outstanding, submitted, or approved, without needing to check in with us.
We know chasing paperwork by email slows audits down. Bringing these steps into the dashboard means less back-and-forth, more visibility on progress, and fewer delays getting to ready for your Cyber Essentials Plus Audit.

IMPORTANT: The following changes will only apply to Active Protect 5.7.0 and beyond
From CAP v5.7.0, we are changing how devices authenticate with CyberSmart Active Protect (CAP) by introducing a revocable authentication mechanism.
For organisations using centralised (bulk) deployment, an Activation Key will now be displayed when downloading CAP from the web application. This replaces the existing Activation Token.
For organisations using individual deployment, an Activation Key will be automatically embedded in the CAP installer.
Previously each organisation installer had a single per-organisation Activation Token which allowed CyberSmart Active Protect (CAP) desktop to be activated and communicate with the CyberSmart dashboard.
To improve security and facilitate installation management, we’ve added unique Activation Keys per installer and added the ability for you to control their validity.
By default, newly created Activation Keys have a 7 day expiry which can be adjusted in the Activation Keys view.
Full guide and instructions can be found in our Knowledge Base.
New Activation keys page sitting underneath 'Manage organisation'

Editing an Activation key

What's changed
Refreshed Certificates page The certifications page has a new look, with separate tabs for Cyber Essentials and Cyber Essentials Plus, making it easier to navigate between the two.

Certificate Timeline Certificate history now lives in a dedicated Timeline view — a cleaner way to review all your previous certificates in one place.

Cyber Essentials Plus preparation Once your Cyber Essentials assessment has been submitted for declaration, you'll see a new button inviting you to start preparing for Cyber Essentials Plus. Clicking it notifies the CyberSmart team, who'll work with you from there. As tasks are completed, they'll be checked off by CyberSmart with full visibility in your dashboard.

We've updated how Cyber Essentials and Cyber Essentials Plus version names are displayed across the CyberSmart platform.
Previously, version names were shown alongside the year they were published, for example, Montpellier (2024). Following customer feedback, we’re now showing the corresponding NCSC requirements document version instead.
This means you'll now see:
This change is designed to make version naming clearer and more consistent with the official requirements documentation.

This change will go live in the next couple of weeks but wanted to give you a heads up.

We've been working on some changes around our Organisation Certificates page and, as part of that work, we've decided to freshen up the look of our certificate status links around the product!
The goal is to make it easier to understand at a glance when something is in progress, needs your attention, or has been completed.

New courses added to CyberSmart Learn
We’ve added a range of new courses to CyberSmart Learn, helping organisations build stronger security awareness and support compliance across their teams.
The new courses cover:
🔐 Cybersecurity
🎣 Social Engineering
📋 Compliance & Standards
🌱 Environmental
👥 Soft Skills
All courses are available now in the Learn library.
Take a look in the platform and start assigning them to your users today.

We've launched a NIS2 specific Learn course which will be available for all Complete or Learn subscribers.
Check out your course library!

We’ve refreshed our NIS2 self-assessment with an optimised experience in the new Assessments module of the CyberSmart web application. This will make it simpler for organisations to understand their current security posture in relation to the NIS2 directive and identify where to focus next. The updated flow is designed to be clearer and easier to navigate, helping teams move through the assessment with confidence and maintain momentum as they work towards stronger compliance.
The new look assessment highlights areas that require attention and provides an in-assessment view of progress and compliance status, so it’s easy to see what’s complete and what still needs action. Organisations can save their progress, return at any time, and keep responses up to date as their security posture changes — supporting continuous improvement rather than a one-off exercise.

Each question includes clear answer options and space to add supporting context, helping teams capture evidence and internal notes as they go. This makes it easier to collaborate, track improvements over time, and use the assessment as a practical tool for strengthening security controls aligned to NIS2 expectations.

We’ve seen a rise in Cyber Essentials pushbacks recently, with our assessors asking for clarification across many of the same areas. In fact, just 20 questions account for around 75% of all Cyber Essentials assessor notes, and in January alone there were nearly 200 assessor notes on just two questions.
To help reduce delays and make the assessment process smoother, we’ve added new, detailed guidance for the top 20 most frequently pushed-back questions. This unofficial guidance clearly explains what assessors are looking for, and offers examples of answers that would meet the standard first time.

Our aim is simple: fewer pushbacks, faster assessments, and clearer expectations for everyone involved.
To view the guidance, simply click the “additional guidance” button to see exactly what the assessors are looking for in your answers:
