
A UK government-backed scheme covering five technical controls that protect against the most common internet-based attacks.
Cyber Essentials is a UK government-backed certification scheme, delivered by IASME on behalf of the National Cyber Security Centre. It defines five technical controls that guard against the most common, untargeted internet-based attacks.
It is deliberately a baseline rather than a comprehensive security standard. Its value lies in addressing the attacks that most organisations actually face, and in being achievable for smaller organisations without a dedicated security team.
It is widely used as a procurement requirement, and is mandatory for suppliers on many UK central government contracts.
Cyber Essentials is a verified self-assessment. The organisation answers a defined question set, which is then reviewed and certified. Cyber Essentials Plus covers exactly the same five controls, but adds hands-on technical verification by an assessor, who tests a sample of devices and systems rather than taking the answers at face value.
Both are annual, and both apply only to the scope that was assessed. The scope therefore matters as much as the certificate itself — a certificate covering a small part of an organisation says little about the rest of it.
Cyber Essentials addresses common, untargeted attacks — the automated scanning and commodity malware that affects organisations indiscriminately. It is genuinely effective against that category of threat.
It is not designed to withstand a determined or well-resourced adversary, and it does not address governance, supply chain, monitoring or incident response in any depth. Organisations facing higher consequence need considerably more, which is where frameworks such as the CAF apply.