Skip to main content
Home/ Cyber Essentials
Cyber Essentials

Cyber Essentials certification with experienced assessor support

Certify against the current Cyber Essentials requirements with Meta Defence Labs, an IASME-licensed Certification Body. We help organisations define scope, understand the verified self-assessment and resolve readiness issues without making the process unnecessarily complicated.

Discuss Cyber Essentials

Verify on IASME: search Meta Defence Labs ↗

Cyber Essentials & CE+
Certification Body
NCSC-assured
Cyber Advisor service ↗
DCC Level 0 & Level 1
Assessment capability
Established in 2015
Experienced assessors

A straightforward framework that still depends on accurate scope.

Cyber Essentials focuses on a defined set of technical controls designed to reduce exposure to common internet-based attacks. The principles are clear, but scope, cloud services, remote working and larger technology estates can make implementation and evidence more complicated.

Where certification becomes more complex

  • Multiple sites, legal entities and stakeholder groups
  • Mixed operating systems and endpoint populations
  • Cloud services, identity platforms and remote working
  • Contractual requirements and fixed procurement milestones

How MDLabs supports the process

  • Scoping and certification strategy
  • Self-assessment and supporting information review
  • Readiness review and practical remediation guidance
  • Assessment preparation and certification lifecycle planning
Current technical requirements

The five Cyber Essentials control areas

The current NCSC requirements organise Cyber Essentials around five technical controls. Every applicable requirement must be met for the organisation and technology included within the declared scope.

Firewalls

Control connections between in-scope systems and the internet, including appropriate boundary and host-based firewall configuration.

Secure Configuration

Remove or change insecure defaults, unnecessary services and avoidable functionality so systems are configured securely for their purpose.

Security Update Management

Keep supported software and operating systems appropriately updated and address security vulnerabilities within the scheme requirements.

User Access Control

Limit accounts and privileges to what people need, with appropriate authentication and administrative access controls.

Malware Protection

Use appropriate technical measures to prevent or reduce the execution of malicious software on in-scope devices.

From scope to certification.

01 / Scope

Agree the boundary

Identify the organisation, systems and services to be covered. Make dependencies and responsibilities explicit.

02 / Prepare

Understand readiness

Review the self-assessment questions, supporting information and work needed before submission. Agree priorities with the teams responsible for delivery.

03 / Assess

Demonstrate the controls

Complete the verified Cyber Essentials self-assessment with a clear, accurate description of the organisation and technology included within the declared scope.

Cyber Essentials questions

What is Cyber Essentials?

Cyber Essentials is a UK Government-backed certification scheme covering five technical control areas. Certification combines a self-assessment completed by the applicant with independent verification by a licensed Certification Body.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Both address the same Cyber Essentials control areas. Cyber Essentials Plus adds independent technical testing to verify that the controls are implemented effectively within the assessed environment.

Why does scope matter?

The certificate describes an assessed scope, so the legal entity, users, devices, networks and cloud services represented by that scope need to be understood and described accurately.

Can you help with remediation?

Technical guidance and readiness support can form part of the agreed engagement. Assessment responsibilities and any impartiality requirements must remain clear.

What should we prepare for an initial discussion?

An outline of your estate, approximate organisation size, current certification status, target date and the business requirement behind certification.

Scheme reference: NCSC Cyber Essentials resources

Scheme guidance checked 9 September 2026. Current Cyber Essentials Requirements for IT infrastructure: version 3.3, effective from 27 April 2026.

Need to prepare before certification?

A structured gap assessment can help clarify scope, identify control or evidence gaps and organise remediation before the formal certification process.

Explore Cyber Essentials gap assessment →
Certification continuity

Five years. Five annual Cyber Essentials renewal cycles.

For a global travel management organisation whose certification supports UK Government contractual requirements, continuity matters. MDLabs has worked with the organisation for five consecutive years to revalidate scope, review control implementation, identify issues early and complete renewal within the required timeframe.

Read the five-year case study →

Why annual renewal needs active assurance

Technology estates change, products reach end of support and Cyber Essentials requirements evolve. The programme is designed around early review and evidence rather than assuming that last year's compliant environment is unchanged.

The result is a predictable annual assurance cycle with time to resolve issues before they threaten the certification deadline.

Higher assurance

Need independent technical verification?

Cyber Essentials Plus assesses the same five control areas but adds independent technical testing to verify that the controls are working in practice.

Explore Cyber Essentials Plus →

Planning Cyber Essentials?

Tell us about your organisation, current status and target timeframe. Start with a practical conversation about scope and the right next step.

Discuss Cyber Essentials