Skip to content
Cyber Essentials

Cyber Essentials readiness and certification.

Gap analysis against the NCSC Cyber Essentials scheme. Five control areas. Certification readiness assessment and submission support.

5

Technical control areas

Full scheme

CE and CE+ covered

NCSC-backed

UK government cyber scheme

Submission support

Guidance through the process

Overview

What Cyber Essentials covers.

Cyber Essentials is the UK government-backed certification scheme for cyber security. It specifies five technical controls that organisations must have in place to protect against the most common cyber attacks. Certification is increasingly required for UK public sector contracts, NHS work, and enterprise supplier agreements.

Our assessment provides a gap analysis against the Cyber Essentials technical requirements before you submit for certification. This means you know exactly what needs to be fixed before your assessor reviews your environment, reducing the risk of a failed assessment.

5
Technical control areas
2
Certification levels: CE and CE+
NCSC
National Cyber Security Centre backing
Five pillars

The five Cyber Essentials control areas.

Every Cyber Essentials assessment covers these five technical areas.

01

Firewalls

Boundary and software firewalls configured to prevent unauthorised access from the internet and other networks.

02

Secure Configuration

Devices and software configured securely, removing unnecessary software, disabling default credentials, and applying security settings.

03

User Access Control

User accounts with only the access required, privileged accounts minimised, and strong authentication in place.

04

Malware Protection

Anti-malware software deployed and up to date, or application allowlisting in use where appropriate.

05

Security Update Management

Software and operating systems kept up to date, patches applied within defined timescales.

Certification levels

Cyber Essentials and Cyber Essentials Plus.

Cyber Essentials

Self-assessed certification.

Cyber Essentials is a self-assessment certification. Your organisation answers a questionnaire about its controls, which is reviewed by an assessor. Our readiness assessment prepares you for the questionnaire by identifying gaps before submission.

CE is the entry-level certification and is required for most UK public sector and NHS supplier contracts.

Get a quote
Cyber Essentials Plus

Independently verified certification.

CE+ includes an independent technical verification of the controls. An assessor tests your environment directly rather than relying on a questionnaire. This provides stronger assurance and may be required by certain government contracts or enterprise clients.

Our CE+ readiness assessment prepares you for the technical verification and reduces the risk of a failed assessment.

Get a quote
Who needs it

Cyber Essentials is increasingly mandatory.

Public sector suppliers

All UK government contracts involving the handling of personal data or sensitive information require Cyber Essentials certification.

NHS and healthcare

NHS suppliers and digital health organisations are required to hold Cyber Essentials as a minimum. CE+ is required for many clinical systems contracts.

Enterprise supplier requirements

Large enterprises increasingly require Cyber Essentials from SMB suppliers before awarding contracts, particularly in financial services and defence.

Get ready for Cyber Essentials.

Get in touch to discuss your certification timeline and what the readiness assessment covers.