Cyber Essentials is the UK Government-backed certification scheme designed to help organisations protect themselves against common internet-based cyber threats. The National Cyber Security Centre describes it as the minimum standard of cyber security it recommends for organisations of all sizes.
The scheme is deliberately focused. Rather than trying to cover every aspect of cybersecurity governance, it concentrates on five technical controls that address many of the weaknesses routinely exploited in commodity attacks.
The five Cyber Essentials technical controls
Firewalls
Firewalls create a security boundary between trusted systems and the internet. The requirement is not simply to own a firewall, but to configure boundary and host-based protections so that unnecessary access is not exposed.
Secure configuration
Devices and software should be configured for their business purpose, with unnecessary accounts, services and functionality removed or disabled. Default credentials and insecure settings should not remain in use.
Security update management
In-scope software must be licensed and supported, with security updates applied within the required timescales. Under the current version 3.3 requirements, certain vulnerability fixes must be installed within 14 days of release, including fixes for vulnerabilities described as critical or high risk and those with a CVSS v3 base score of 7 or above.
User access control
Access should be granted according to business need. Administrative privileges should be restricted, user accounts should be individually assigned and authentication controls should reduce the risk of unauthorised access. Multi-factor authentication is mandatory for cloud services where it is available under the current requirements.
Malware protection
Organisations must use appropriate measures to prevent malware from executing or causing harm. The implementation can vary by platform, but the outcome is consistent: malicious software should be blocked, contained or prevented from running.
Cyber Essentials and Cyber Essentials Plus
Both certification levels are based on the same five controls, but the assurance process is different.
Cyber Essentials is an independently verified self-assessment. The organisation describes its scope and how it meets the requirements, a board member or equivalent signs the declaration and a licensed assessor reviews the submission.
Cyber Essentials Plus adds independent technical testing to verify that the controls are operating in practice. It provides a higher level of assurance, but it does not introduce a separate set of technical controls.
Who is Cyber Essentials for?
The scheme is intended for organisations, not individual consumers. It can be used by small businesses, charities, public-sector bodies and large enterprises. The complexity of preparation changes significantly with the size and structure of the organisation, but the underlying control objectives remain the same.
For larger organisations, the biggest challenge is often not understanding the five controls. It is applying them consistently across a complicated estate with multiple locations, cloud services, identity platforms, suppliers and ownership boundaries.
Scope matters
Cyber Essentials certification applies to a defined organisational and technical scope. That scope needs to make sense in the context of how the organisation operates and how its data and services are delivered.
Cloud services that host organisational data or services cannot simply be ignored. Shared-responsibility arrangements also need to be understood so that the organisation can explain which controls it implements and which are delivered by the provider.
For complex environments, agreeing scope early can prevent major rework later in the certification process.
What Cyber Essentials does not mean
Certification is valuable assurance, but it is not a claim that an organisation is immune from cyber attack or that every security risk has been eliminated. The scheme focuses on a defined baseline of technical controls intended to reduce exposure to common attacks.
Organisations may still need broader risk management, monitoring, incident response, vulnerability management, penetration testing, secure development and governance depending on their environment and obligations.
How to prepare
A sensible preparation sequence is:
- confirm the business reason and target timeframe
- define the proposed certification scope
- compare the environment with the current requirements
- remediate technical and evidence gaps
- complete the verified self-assessment
- if Cyber Essentials Plus is required, prepare the full declared scope for independent technical assessment
For a complex organisation, a gap assessment before formal submission can make this process substantially more controlled.
