Cyber Essentials
Achieve the UK government-backed certification that opens the door to public sector contracts and demonstrates baseline security.
Key Deliverables
About This Service
Ready to get started?
Book a free 30-minute discovery call. No commitments.
Talk to an Expertor take our free assessmentCyber Essentials Certification UK Government-Backed Baseline Cyber Security for Every Organisation
Cyber Essentials is a UK government-backed cyber security certification scheme designed to help organisations protect themselves against the most common cyber attacks. Developed by the National Cyber Security Centre (NCSC), it defines a set of baseline technical controls that, when properly implemented, defend against the vast majority of commodity cyber threats — the automated, opportunistic attacks that account for the bulk of cyber incidents affecting UK businesses.
Since 2014, Cyber Essentials certification has been a mandatory requirement for UK government contracts that involve handling sensitive or personal information. Increasingly, it is also required by private sector organisations as a minimum vendor security standard. For businesses selling to the UK market, Cyber Essentials is often the first cyber security credential that clients ask for.
Cyber Essentials vs Cyber Essentials Plus
The scheme operates at two levels, and the distinction matters.
Cyber Essentials is a self-assessment certification. The organisation completes a questionnaire covering the five technical control areas, which is reviewed and verified by a licensed Certification Body. The assessment is based on the organisation’s own declarations about its controls. This is the baseline certification that satisfies most government contract requirements.
Cyber Essentials Plus includes an independent technical audit. A qualified assessor conducts hands-on testing of your systems to verify that the declared controls are actually in place and functioning correctly. This includes vulnerability scanning, testing of email and web browsing protections, and verification of access controls. Cyber Essentials Plus provides a significantly higher level of assurance and is increasingly preferred by both government and commercial clients.
The five technical control areas
Cyber Essentials focuses on five specific areas that, together, address the most common attack vectors.
Firewalls and internet gateways: Every device that connects to the internet must be protected by a properly configured firewall. This includes boundary firewalls, software firewalls on individual devices, and cloud security groups. Default firewall rules, unnecessary open ports, and administrative interfaces exposed to the internet are common failure points.
Secure configuration: Systems must be configured to reduce vulnerabilities. This means removing unnecessary software and services, changing default passwords, disabling unnecessary user accounts, and ensuring that only required functionality is enabled. The principle is simple: reduce the attack surface by removing everything that is not needed.
Access control: User accounts must be controlled and managed. This includes using individual accounts (not shared credentials), granting the minimum privileges necessary for each user’s role, controlling administrative access, and implementing strong authentication. Multi-factor authentication for administrative and cloud service accounts is now a requirement.
Malware protection: Systems must be protected against malicious software through anti-malware solutions, application whitelisting, or sandboxing. The approach can vary depending on the platform and operating environment, but the outcome must be effective protection against known malware.
Patch management: Software and firmware must be kept up to date with security patches. High-risk and critical vulnerabilities must be patched within 14 days of a fix being available. Unsupported software — products that no longer receive security updates — must be removed or isolated.
Who needs Cyber Essentials
Any organisation bidding for UK government contracts that involve handling sensitive or personal information — certification is a mandatory procurement requirement. UK-based businesses of any size that want to demonstrate baseline cyber security to clients, partners, and insurers. Non-UK businesses selling to the UK market, particularly to government, healthcare, education, and financial services clients. Organisations seeking to reduce their cyber insurance premiums — many insurers offer discounts for Cyber Essentials certified organisations. Supply chain participants where the prime contractor requires security certification from subcontractors.
How we help
We prepare organisations for both Cyber Essentials and Cyber Essentials Plus certification. Our process begins with a pre-assessment against the five control areas to identify gaps before you submit for certification. We help you remediate any gaps — whether that involves firewall rule reviews, system hardening, access control improvements, or patch management process changes. For Cyber Essentials, we guide you through the self-assessment questionnaire to ensure accurate and complete responses. For Cyber Essentials Plus, we conduct pre-audit technical testing to identify and resolve issues before the assessor arrives.
What Cyber Essentials gives your business
UK public sector access
Cyber Essentials certification is a mandatory requirement for government contracts involving sensitive or personal information, opening a significant revenue channel
Fast certification
with proper preparation, Cyber Essentials certification can be achieved in two to four weeks, making it one of the fastest security credentials to obtain
Insurance benefits
many UK cyber insurance providers offer premium discounts for Cyber Essentials certified organisations, and some include free cyber insurance with certification
Supply chain credibility
increasing numbers of private sector organisations require Cyber Essentials from their suppliers, making certification a competitive advantage in procurement
Foundation for further certification
Cyber Essentials controls form a subset of ISO 27001 Annex A, meaning certification effort contributes directly to future ISO 27001 implementation
Should we go for Cyber Essentials or Cyber Essentials Plus?
How long does Cyber Essentials certification take?
We are not a UK company. Can we still get Cyber Essentials?
Start your Cyber Essentials journey today.
Every engagement begins with a free discovery call. No commitments, no pressure — just a clear picture of where you stand.
Other Services
SOC 2 Type I & II
Demonstrate security and reliability with the Trust Services Criteria.
Learn moreMost requestedISO/IEC 27001:2022
Build a certified ISMS that satisfies enterprise clients, regulators, and procurement teams worldwide.
Learn moreISO 42001AI Governance (ISO/IEC 42001)
Govern AI responsibly with the world’s first international standard for AI Management Systems.
Learn more