Cyber attacks do not always rely on sophisticated techniques. Many incidents begin with common weaknesses such as unsupported software, poor access controls, insecure configurations, exposed services, or insufficient protection against malware.
Cyber Essentials is a UK Government-backed cyber security certification scheme designed to help organisations address these fundamental risks. It establishes a baseline of technical controls intended to protect organisations against many of the most common internet-based cyber attacks.
The scheme is suitable for organisations of all sizes and sectors, from small businesses and charities to larger enterprises and public-sector suppliers. Certification can also provide customers, partners and procurement teams with evidence that an organisation has implemented recognised baseline security measures.
This article explains what Cyber Essentials is, the five technical controls organisations must address, the difference between Cyber Essentials and Cyber Essentials Plus, how certification works, and how the scheme fits into a wider cyber security and assurance programme.
What Is Cyber Essentials?
Cyber Essentials is a UK Government-backed certification scheme overseen by the National Cyber Security Centre, or NCSC, and delivered through approved certification bodies.
The scheme focuses on a defined set of security controls that organisations can implement to reduce their exposure to common cyber threats.
Cyber Essentials is not intended to address every possible security risk. It is primarily designed to defend against common attacks that exploit widely understood weaknesses and techniques.
The scheme therefore provides a cyber security baseline rather than a complete security programme.
Organisations with more complex environments, sensitive information, critical infrastructure, or exposure to advanced targeted threats may require additional controls, testing, monitoring and assurance beyond Cyber Essentials.
However, establishing these basic protections can significantly reduce unnecessary exposure and provide a stronger foundation for wider security activity.
What Are the Five Cyber Essentials Controls?
The Cyber Essentials requirements are organised around five technical control areas:
- Firewalls
- Secure configuration
- Security update management
- User access control
- Malware protection
The current Cyber Essentials Requirements for IT Infrastructure are version 3.3, effective from 27 April 2026. The requirements are reviewed periodically so the scheme can continue reflecting changes in technology and working practices.
1. Firewalls
Firewalls control network traffic between devices, networks and the internet.
The purpose of the Cyber Essentials firewall control is to ensure that only secure and necessary network services can be accessed from the internet.
Organisations should protect devices within scope using appropriately configured firewalls or equivalent network controls.
Important requirements include:
- Changing default administrative passwords
- Preventing unnecessary internet access to firewall administration interfaces
- Protecting authorised remote administration appropriately
- Blocking unauthenticated inbound connections by default
- Documenting and approving necessary inbound firewall rules
- Removing rules that are no longer required
- Using software firewalls where devices operate on networks the organisation does not control
Firewalls reduce the number of services exposed directly to attackers and help limit unnecessary routes into organisational systems.
2. Secure Configuration
Devices and software are not always secure when first installed.
Default configurations may include unnecessary applications, unused accounts, publicly known passwords, excessive privileges, or services that the organisation does not require.
Cyber Essentials therefore requires organisations to actively manage their systems and reduce unnecessary functionality.
This includes activities such as:
- Removing unused user accounts
- Changing default or easily guessed passwords
- Removing unnecessary applications and services
- Disabling unnecessary automatic execution features
- Requiring users to authenticate before accessing organisational information or services
- Applying appropriate locking controls to devices
The principle is straightforward: the fewer unnecessary services, accounts and features that exist, the fewer opportunities an attacker has to exploit them.
3. Security Update Management
Software vulnerabilities are regularly discovered in operating systems, applications, network devices and cloud services.
Once vulnerabilities become publicly known, attackers may attempt to exploit organisations that have not applied the available fixes.
Cyber Essentials therefore requires organisations to maintain supported software and apply relevant security updates.
Under the current requirements, software within scope must:
- Be licensed and supported
- Be removed when it becomes unsupported, unless appropriately isolated outside the assessment scope
- Have automatic updates enabled where possible
- Receive qualifying high-risk or critical vulnerability fixes within 14 days of release
The requirements apply particularly where a vulnerability is described by the vendor as critical or high risk, or has a CVSS v3 base score of 7 or above.
Timely update management helps reduce the window in which attackers can exploit known vulnerabilities.
4. User Access Control
Not every user needs access to every system, application or piece of information.
Cyber Essentials requires organisations to ensure that accounts are provided only to authorised users and that access is limited according to business need.
Organisations should have processes for:
- Creating and approving user accounts
- Providing individual credentials
- Removing accounts when they are no longer required
- Reviewing and removing unnecessary privileges
- Separating administrative activities from normal day-to-day user activity
- Protecting authentication appropriately
Administrative accounts require particular care because compromising one can give an attacker much greater control over systems and information.
The current Cyber Essentials requirements also require multi-factor authentication for cloud services.
MFA provides an additional layer of protection if a password is stolen, guessed or otherwise compromised.
5. Malware Protection
Malware includes threats such as viruses, ransomware, malicious code and other software designed to damage systems or gain unauthorised access.
Cyber Essentials requires organisations to ensure that an appropriate malware-protection mechanism is active on devices within scope.
Depending on the technology involved, this may include:
- Anti-malware software
- Application allow-listing
- Built-in platform security controls
- Preventing malicious code from executing
- Blocking connections to known malicious websites
- Restricting software installation to approved applications
Malware protection works alongside the other Cyber Essentials controls. For example, secure configuration and timely updates reduce the opportunity for malicious software to gain access, while access controls help limit what malware can do if an account becomes compromised.
Cyber Essentials and the Scope of Certification
Defining the assessment scope is an important part of Cyber Essentials.
The scheme recommends that certification covers the organisation’s entire IT infrastructure used to conduct its business. Where necessary, a clearly defined and separately managed subset may be certified instead.
The organisation must clearly establish the boundary of the assessment and agree the scope with its Certification Body.
The current requirements also make clear that:
- End-user devices cannot simply be excluded from scope
- Cloud services hosting organisational data or services must be included
- Organisation-owned accounts used by suppliers, contractors or managed service providers remain in scope
- Relevant home and remote-working devices are normally in scope
- Certain employee-owned devices accessing organisational data or services may also fall within scope
Cloud services are particularly important. The current requirements explicitly state that cloud services containing organisational data or services cannot simply be excluded from certification scope.
Cloud Services and Shared Responsibility
Modern organisations increasingly rely on services such as Microsoft 365, Google Workspace, cloud infrastructure, hosted applications and other SaaS platforms.
Cyber Essentials recognises three broad cloud models:
- Infrastructure as a Service
- Platform as a Service
- Software as a Service
Responsibility for particular technical controls may differ depending on the service model.
For example, a cloud provider may be responsible for maintaining parts of the underlying infrastructure, while the customer remains responsible for identities, permissions and secure configuration.
Where a cloud provider implements controls on an organisation’s behalf, the organisation should be able to establish that those responsibilities are reflected in contractual documentation or the provider’s published security commitments.
Using a cloud provider therefore does not remove the organisation’s responsibility for ensuring that the Cyber Essentials requirements are met.
Cyber Essentials vs Cyber Essentials Plus
There are two certification levels within the scheme:
Cyber Essentials
Cyber Essentials uses a verified self-assessment model.
The organisation answers questions describing how it implements the five technical controls. An independent Certification Body then reviews the submission and determines whether the requirements have been met.
This provides a recognised baseline level of assurance.
Cyber Essentials Plus
Cyber Essentials Plus covers the same five technical controls but adds independent technical testing.
An approved assessor tests a representative sample of the organisation’s systems to verify that the controls described during certification are operating effectively in practice.
Cyber Essentials Plus therefore provides a higher level of assurance because it does not rely solely on the organisation describing its controls.
Both certifications address the same underlying security requirements; the difference is principally the level of independent technical verification.
How Does Cyber Essentials Certification Work?
The exact process can vary according to the Certification Body, but the basic Cyber Essentials process normally involves several stages.
1. Define the Scope
Determine which systems, devices, networks, software and cloud services will be covered by the certification.
Where possible, whole-organisation certification provides the clearest assurance.
2. Review the Requirements
Assess the organisation against the five Cyber Essentials technical control areas.
This may identify gaps such as:
- Unsupported software
- Missing MFA
- Weak administrative access
- Insecure firewall configuration
- Unnecessary accounts
- Missing security updates
- Inadequate malware protection
3. Remediate Identified Gaps
Correct weaknesses before submitting the assessment.
For smaller organisations that need assistance implementing the controls, the NCSC also operates the Cyber Advisor scheme through assured providers.
4. Complete the Assessment
For Cyber Essentials, the organisation completes the assessment questionnaire and submits it for independent verification by an approved Certification Body.
5. Complete Technical Testing for Cyber Essentials Plus
Organisations pursuing Cyber Essentials Plus undergo additional independent technical assessment of systems within scope.
6. Maintain the Controls
Certification is not permanent.
Cyber Essentials certificates are valid for one year, meaning organisations need to maintain their controls and renew certification if they want to continue demonstrating current compliance with the scheme.
Why Is Cyber Essentials Important for UK Organisations?
Cyber Essentials provides several practical benefits.
Establishing a Security Baseline
The five controls address common weaknesses that frequently provide attackers with straightforward entry points.
Implementing them creates a consistent minimum standard across devices, users and services.
Demonstrating Security to Customers
Certification provides independent evidence that an organisation has addressed recognised baseline cyber security controls.
This can support customer assurance, supplier due diligence and commercial conversations.
Supporting Supply-Chain Assurance
Cyber Essentials is increasingly used by organisations seeking assurance that suppliers maintain appropriate baseline security.
The NCSC encourages larger organisations to consider Cyber Essentials as part of improving cyber resilience within their supply chains.
Supporting Government Procurement
Cyber Essentials is also relevant to certain UK public-sector contracts.
Current government procurement policy requires appropriate Cyber Essentials controls for particular types of contracts, including some involving personal information and ICT systems or services.
However, Cyber Essentials is not automatically mandatory for every government contract or every UK organisation. The requirement depends on the procurement and associated cyber risk.
Cyber Insurance
UK organisations with annual turnover below £20 million that achieve qualifying whole-organisation Cyber Essentials certification may also be eligible for cyber liability insurance arranged through the scheme’s delivery partner.
Eligibility and cover remain subject to the scheme’s applicable conditions.
What Cyber Essentials Does Not Cover
Cyber Essentials should not be treated as proof that an organisation is completely secure.
The scheme deliberately focuses on foundational controls and common internet-based attacks.
It does not replace activities such as:
- Security risk assessment
- Vulnerability management
- Penetration testing
- Security monitoring
- Incident response
- Backup and recovery planning
- Supplier risk management
- Application-security testing
- Security awareness
- Business continuity
- Wider regulatory compliance
For example, the current technical requirements strongly recommend backups but explicitly state that backup itself is not one of the five Cyber Essentials technical requirements.
Likewise, an organisation may meet Cyber Essentials requirements while still having security risks associated with business-specific applications, internal processes, sophisticated attackers, third parties or technology outside the scope of the certification.
Cyber Essentials is therefore most valuable when used as part of a broader security and assurance strategy.
Moving Beyond Certification
Achieving Cyber Essentials is an important milestone, but maintaining cyber resilience requires more than passing an assessment once a year.
Organisations should continue reviewing their infrastructure as technology changes, new cloud services are introduced, employees join or leave, vulnerabilities are discovered and suppliers gain access to organisational systems.
Cyber Essentials can provide a strong baseline against which these changes are managed.
From there, organisations can build additional assurance through activities such as:
- Regular control validation
- Vulnerability assessment
- Penetration testing
- Supplier assurance
- Risk-based remediation
- Security monitoring
- Evidence collection
- Assessment against additional standards and frameworks
Strengthening Cyber Resilience with Cyber Essentials
Cyber Essentials provides UK organisations with a clear and practical baseline for protecting systems against many common cyber attacks. Its five technical controls address fundamental areas of cyber hygiene: firewalls, secure configuration, security updates, user access and malware protection.
Cyber Essentials Plus adds independent technical testing, providing greater assurance that those protections have been implemented effectively.
Certification should nevertheless be viewed as the beginning of a wider assurance process rather than the end of one. Organisations still need to understand their particular risks, validate controls, address vulnerabilities and adapt their security posture as their technology and threat environment change.
SeCore’s Security Assurance services help organisations assess controls, identify security gaps, generate structured evidence and prioritise remediation against relevant standards and business risks. By combining recognised baselines such as Cyber Essentials with wider quantitative security assurance, organisations can move beyond certification towards a clearer and more measurable understanding of their cyber resilience.