Firewalls
Control connections between your systems and the internet.
A practical guide for UK organisations deciding whether to certify and how to prepare properly.
Talk to an expertCyber Essentials is the UK government-backed baseline for protecting an organisation against common internet-based attacks. It gives customers and supply-chain partners a straightforward way to see that essential controls are in place.
It is not a replacement for wider monitoring or incident response. It creates a clear minimum standard and exposes practical gaps in devices, updates, access and cloud services.
The current scheme assesses five connected technical control areas.
Control connections between your systems and the internet.
Remove unnecessary accounts, services and insecure defaults.
Keep devices, applications and firmware supported and patched.
Give people only the access they need and protect privileged accounts.
Prevent malicious software from running or reaching users.
Prevent malicious software from running or reaching users.
Certification turns a technical baseline into evidence that customers, insurers and procurement teams can understand.
Not for every UK organisation. It may be required for particular contracts, procurement exercises or supply chains. Even when optional, it provides useful independent evidence for customers, insurers, trustees and commissioners.
Many organisations certify at the standard level first, resolve any issues, then move to Plus when a contract or risk profile justifies it.
A clear sequence prevents the assessment becoming a paperwork exercise.
Confirm the organisation, locations, users, devices and cloud services included.
Record devices, operating systems, applications and network equipment.
Remove unused accounts and privileges that people no longer require.
Review updates, firewalls, malware protection and secure configuration.
Use the official question set and readiness tool before assessment.
Keep the controls working and recertify after 12 months.
Straight answers to the questions businesses ask before starting.
Cyber Essentials is a UK government-backed certification scheme built around five technical controls that help organisations protect themselves against common internet-based cyber attacks.
It is not a universal legal requirement for every UK organisation, but it can be required for certain contracts, procurement exercises or supply chains. Even when it is not mandatory, the controls provide a recognised baseline for cyber security.
Cyber Essentials combines self-assessment with independent verification. Cyber Essentials Plus uses the same control requirements but adds a more rigorous independent technical assessment.
Cyber Essentials certification is valid for 12 months, after which the organisation must recertify to maintain current certified status.
Requirements can change. Check the NCSC overview and current technical requirements before assessment.
We can review your environment, explain the questions and fix practical gaps before assessment.
Reviews