Cyber Security
Cyber Security Glossary

Cyber Essentials

A UK government-backed scheme covering five technical controls that protect against the most common internet-based attacks.

What it is
A government-backed certification scheme
Delivered by
IASME, on behalf of the NCSC
Covers
Five technical controls
Valid for
Twelve months, for the certified scope

Cyber Essentials is a UK government-backed certification scheme, delivered by IASME on behalf of the National Cyber Security Centre. It defines five technical controls that guard against the most common, untargeted internet-based attacks.

It is deliberately a baseline rather than a comprehensive security standard. Its value lies in addressing the attacks that most organisations actually face, and in being achievable for smaller organisations without a dedicated security team.

It is widely used as a procurement requirement, and is mandatory for suppliers on many UK central government contracts.

The five technical controls

  1. FirewallsControl what can reach your systems from the internet, so that services are not unnecessarily exposed.
  2. Secure configurationRemove default accounts, default passwords and unnecessary functionality that attackers routinely rely on.
  3. Security update managementKeep software supported and patched promptly, because unpatched known vulnerabilities remain one of the most common routes in.
  4. User access controlGrant people the minimum access they need and control administrative privileges, limiting what a compromised account can do.
  5. Malware protectionPrevent and detect malicious software reaching or running on your devices.

Cyber Essentials and Cyber Essentials Plus

Cyber Essentials is a verified self-assessment. The organisation answers a defined question set, which is then reviewed and certified. Cyber Essentials Plus covers exactly the same five controls, but adds hands-on technical verification by an assessor, who tests a sample of devices and systems rather than taking the answers at face value.

Both are annual, and both apply only to the scope that was assessed. The scope therefore matters as much as the certificate itself — a certificate covering a small part of an organisation says little about the rest of it.

What it does and does not cover

Cyber Essentials addresses common, untargeted attacks — the automated scanning and commodity malware that affects organisations indiscriminately. It is genuinely effective against that category of threat.

It is not designed to withstand a determined or well-resourced adversary, and it does not address governance, supply chain, monitoring or incident response in any depth. Organisations facing higher consequence need considerably more, which is where frameworks such as the CAF apply.

Cyber Essentials, answered

What is the difference between Cyber Essentials and Cyber Essentials Plus?
The five controls are identical. Cyber Essentials is a verified self-assessment, whereas Cyber Essentials Plus adds independent hands-on technical testing of a sample of devices and systems by an assessor.
How long does certification last?
Certification is annual and needs renewing each year. It also applies only to the scope that was assessed, so a partial scope produces a partial assurance.
Is Cyber Essentials enough on its own?
It is a baseline against common untargeted attacks rather than protection against a determined or targeted adversary. Organisations facing higher risk need considerably more, which is where frameworks such as the CAF apply.
Is Cyber Essentials required to work with government?
It is mandatory for suppliers on many UK central government contracts, particularly where the contract involves handling certain government information. Some buyers require Cyber Essentials Plus for higher-risk work.

Related terms

Authoritative sources

How we help

We help organisations reach and maintain certification, and work out what is genuinely needed beyond the baseline for the risks they actually face.