Cyber Essentials

Achieve the UK government-backed certification that opens the door to public sector contracts and demonstrates baseline security.

Key Deliverables

Scope Definition
Firewall & Gateway Controls
Secure Configuration
Access Control Review
Malware Protection
Patch Management
Overview

About This Service

Cyber Essentials is the UK government-backed certification scheme for baseline technical cyber security controls. Required for most UK public sector contracts handling sensitive data, it covers five core control areas. We prepare your organisation for both Cyber Essentials and Cyber Essentials Plus certification.
6
Deliverables
5
Key Benefits
3
FAQs Answered

Ready to get started?

Book a free 30-minute discovery call. No commitments.

Talk to an Expertor take our free assessment

Cyber Essentials Certification UK Government-Backed Baseline Cyber Security for Every Organisation

Cyber Essentials is a UK government-backed cyber security certification scheme designed to help organisations protect themselves against the most common cyber attacks. Developed by the National Cyber Security Centre (NCSC), it defines a set of baseline technical controls that, when properly implemented, defend against the vast majority of commodity cyber threats — the automated, opportunistic attacks that account for the bulk of cyber incidents affecting UK businesses.

Since 2014, Cyber Essentials certification has been a mandatory requirement for UK government contracts that involve handling sensitive or personal information. Increasingly, it is also required by private sector organisations as a minimum vendor security standard. For businesses selling to the UK market, Cyber Essentials is often the first cyber security credential that clients ask for.

01

Cyber Essentials vs Cyber Essentials Plus

The scheme operates at two levels, and the distinction matters.

Cyber Essentials is a self-assessment certification. The organisation completes a questionnaire covering the five technical control areas, which is reviewed and verified by a licensed Certification Body. The assessment is based on the organisation’s own declarations about its controls. This is the baseline certification that satisfies most government contract requirements.

Cyber Essentials Plus includes an independent technical audit. A qualified assessor conducts hands-on testing of your systems to verify that the declared controls are actually in place and functioning correctly. This includes vulnerability scanning, testing of email and web browsing protections, and verification of access controls. Cyber Essentials Plus provides a significantly higher level of assurance and is increasingly preferred by both government and commercial clients.

02

The five technical control areas

Cyber Essentials focuses on five specific areas that, together, address the most common attack vectors.

Firewalls and internet gateways: Every device that connects to the internet must be protected by a properly configured firewall. This includes boundary firewalls, software firewalls on individual devices, and cloud security groups. Default firewall rules, unnecessary open ports, and administrative interfaces exposed to the internet are common failure points.

Secure configuration: Systems must be configured to reduce vulnerabilities. This means removing unnecessary software and services, changing default passwords, disabling unnecessary user accounts, and ensuring that only required functionality is enabled. The principle is simple: reduce the attack surface by removing everything that is not needed.

Access control: User accounts must be controlled and managed. This includes using individual accounts (not shared credentials), granting the minimum privileges necessary for each user’s role, controlling administrative access, and implementing strong authentication. Multi-factor authentication for administrative and cloud service accounts is now a requirement.

Malware protection: Systems must be protected against malicious software through anti-malware solutions, application whitelisting, or sandboxing. The approach can vary depending on the platform and operating environment, but the outcome must be effective protection against known malware.

Patch management: Software and firmware must be kept up to date with security patches. High-risk and critical vulnerabilities must be patched within 14 days of a fix being available. Unsupported software — products that no longer receive security updates — must be removed or isolated.

03

Who needs Cyber Essentials

Any organisation bidding for UK government contracts that involve handling sensitive or personal information — certification is a mandatory procurement requirement. UK-based businesses of any size that want to demonstrate baseline cyber security to clients, partners, and insurers. Non-UK businesses selling to the UK market, particularly to government, healthcare, education, and financial services clients. Organisations seeking to reduce their cyber insurance premiums — many insurers offer discounts for Cyber Essentials certified organisations. Supply chain participants where the prime contractor requires security certification from subcontractors.

04

How we help

We prepare organisations for both Cyber Essentials and Cyber Essentials Plus certification. Our process begins with a pre-assessment against the five control areas to identify gaps before you submit for certification. We help you remediate any gaps — whether that involves firewall rule reviews, system hardening, access control improvements, or patch management process changes. For Cyber Essentials, we guide you through the self-assessment questionnaire to ensure accurate and complete responses. For Cyber Essentials Plus, we conduct pre-audit technical testing to identify and resolve issues before the assessor arrives.

Why It Matters

What Cyber Essentials gives your business

01

UK public sector access

Cyber Essentials certification is a mandatory requirement for government contracts involving sensitive or personal information, opening a significant revenue channel

02

Fast certification

with proper preparation, Cyber Essentials certification can be achieved in two to four weeks, making it one of the fastest security credentials to obtain

03

Insurance benefits

many UK cyber insurance providers offer premium discounts for Cyber Essentials certified organisations, and some include free cyber insurance with certification

04

Supply chain credibility

increasing numbers of private sector organisations require Cyber Essentials from their suppliers, making certification a competitive advantage in procurement

05

Foundation for further certification

Cyber Essentials controls form a subset of ISO 27001 Annex A, meaning certification effort contributes directly to future ISO 27001 implementation

FAQ

Common questions

Can't find what you need? Talk to our team.

Should we go for Cyber Essentials or Cyber Essentials Plus?
If your immediate need is to satisfy a government contract requirement, check the specific tender — most require basic Cyber Essentials, but some specify Plus. For commercial credibility, Cyber Essentials Plus provides significantly more assurance because it includes independent technical verification. Many organisations start with Cyber Essentials and upgrade to Plus within the same year. We recommend Plus for any organisation that wants to demonstrate genuine security posture rather than just check a box.
How long does Cyber Essentials certification take?
With proper preparation, basic Cyber Essentials certification can be completed in two to four weeks from initial assessment to certificate. Cyber Essentials Plus takes longer due to the technical audit component — typically four to six weeks including remediation of any findings. The main variable is how many gaps need to be remediated before certification can proceed. Organisations with well-managed IT environments can move faster; those with significant technical debt may need more preparation time.
We are not a UK company. Can we still get Cyber Essentials?
Yes. Cyber Essentials is available to organisations of any size and in any country. While the primary driver is UK government contract requirements, non-UK organisations can and do certify — particularly if they sell to UK clients or want a recognised baseline security credential. The certification is issued by UK-licensed Certification Bodies, and the assessment can be conducted remotely.

Start your Cyber Essentials journey today.

Every engagement begins with a free discovery call. No commitments, no pressure — just a clear picture of where you stand.