Firewalls
Control connections between in-scope systems and the internet, including appropriate boundary and host-based firewall configuration.
Certify against the current Cyber Essentials requirements with Meta Defence Labs, an IASME-licensed Certification Body. We help organisations define scope, understand the verified self-assessment and resolve readiness issues without making the process unnecessarily complicated.
Discuss Cyber EssentialsCyber Essentials focuses on a defined set of technical controls designed to reduce exposure to common internet-based attacks. The principles are clear, but scope, cloud services, remote working and larger technology estates can make implementation and evidence more complicated.
The current NCSC requirements organise Cyber Essentials around five technical controls. Every applicable requirement must be met for the organisation and technology included within the declared scope.
Control connections between in-scope systems and the internet, including appropriate boundary and host-based firewall configuration.
Remove or change insecure defaults, unnecessary services and avoidable functionality so systems are configured securely for their purpose.
Keep supported software and operating systems appropriately updated and address security vulnerabilities within the scheme requirements.
Limit accounts and privileges to what people need, with appropriate authentication and administrative access controls.
Use appropriate technical measures to prevent or reduce the execution of malicious software on in-scope devices.
Identify the organisation, systems and services to be covered. Make dependencies and responsibilities explicit.
Review the self-assessment questions, supporting information and work needed before submission. Agree priorities with the teams responsible for delivery.
Complete the verified Cyber Essentials self-assessment with a clear, accurate description of the organisation and technology included within the declared scope.
Cyber Essentials is a UK Government-backed certification scheme covering five technical control areas. Certification combines a self-assessment completed by the applicant with independent verification by a licensed Certification Body.
Both address the same Cyber Essentials control areas. Cyber Essentials Plus adds independent technical testing to verify that the controls are implemented effectively within the assessed environment.
The certificate describes an assessed scope, so the legal entity, users, devices, networks and cloud services represented by that scope need to be understood and described accurately.
Technical guidance and readiness support can form part of the agreed engagement. Assessment responsibilities and any impartiality requirements must remain clear.
An outline of your estate, approximate organisation size, current certification status, target date and the business requirement behind certification.
Scheme reference: NCSC Cyber Essentials resources
Scheme guidance checked 9 September 2026. Current Cyber Essentials Requirements for IT infrastructure: version 3.3, effective from 27 April 2026.
A structured gap assessment can help clarify scope, identify control or evidence gaps and organise remediation before the formal certification process.
Explore Cyber Essentials gap assessment →For a global travel management organisation whose certification supports UK Government contractual requirements, continuity matters. MDLabs has worked with the organisation for five consecutive years to revalidate scope, review control implementation, identify issues early and complete renewal within the required timeframe.
Read the five-year case study →Technology estates change, products reach end of support and Cyber Essentials requirements evolve. The programme is designed around early review and evidence rather than assuming that last year's compliant environment is unchanged.
The result is a predictable annual assurance cycle with time to resolve issues before they threaten the certification deadline.
Cyber Essentials Plus assesses the same five control areas but adds independent technical testing to verify that the controls are working in practice.
Explore Cyber Essentials Plus →Tell us about your organisation, current status and target timeframe. Start with a practical conversation about scope and the right next step.