Framework guide
Cyber Essentials and Cyber Essentials Plus
The UK government-backed certification that public-sector, NHS and MoD contracts ask for first. Five technical controls, two certification routes, and a 12-month cycle. Here is how it works and how it fits alongside ISO 27001 and SOC 2.
What is Cyber Essentials? Cyber Essentials is a UK government scheme, run by the National Cyber Security Centre through IASME, that certifies an organisation has five baseline technical controls in place: firewalls, secure configuration, security update management, user access control, and malware protection. Cyber Essentials is a verified self-assessment; Cyber Essentials Plus adds an independent technical audit. Both are valid for 12 months and are required for most UK central government contracts that handle personal or sensitive data.
Who asks for it
UK central government departments require it for suppliers handling personal data or providing certain ICT services. The NHS expects it through the Data Security and Protection Toolkit. The Ministry of Defence requires it, often at Plus, for its supply chain. Beyond mandates, UK enterprise procurement teams use it as the quickest signal that a SaaS vendor has the basics covered. It is also the cheapest certification to obtain, which makes it a sensible first step before ISO 27001.
The five controls
1
Firewalls
Boundary firewalls or equivalent on every internet connection; administrative interfaces not exposed; default passwords changed.
2
Secure configuration
Unnecessary software and accounts removed, autorun disabled, device lock and password or MFA policy in place.
3
Security update management
Licensed, supported software only; critical and high-risk updates applied within 14 days; unsupported software removed.
4
User access control
Unique accounts, least privilege, admin accounts used only for admin tasks, MFA on cloud services.
5
Malware protection
Anti-malware or application allow-listing on all in-scope devices, kept current.
Boundary
Scope
Which devices, cloud services and networks are in scope. Whole-organisation scope is the default and strongest.
Cyber Essentials versus Cyber Essentials Plus
| Cyber Essentials | Cyber Essentials Plus | |
|---|---|---|
| Method | Self-assessment questionnaire, verified by a certification body | Self-assessment plus independent technical audit: vulnerability scan, device sampling, email and browser tests |
| Time from start | 2 to 4 weeks with the controls in place | 4 to 8 weeks; Plus must be completed within 3 months of the basic certificate |
| Typical fee to the certification body | Tiered by organisation size; a few hundred pounds | Higher; depends on scope and device count |
| Who requires it | Most government contracts handling personal data | MoD supply chain and higher-risk contracts |
| Validity | 12 months | 12 months |
How it fits with ISO 27001 and SOC 2
Cyber Essentials covers technical hygiene, not a management system. If you hold ISO 27001 you already meet most of the five controls and the certificate is a matter of scoping and evidence. If you are starting from nothing, Cyber Essentials first is a fast, cheap win that satisfies UK buyers while the ISO 27001 programme runs. In Certifyi the five controls are mapped to the same control library, so the evidence for patching, MFA and endpoint protection is collected once and reused.
Timeline with Certifyi
A compliance lead confirms scope in the first session, runs the readiness check against the current question set, closes gaps (most often MFA coverage, patch timelines and unsupported software), and submits the assessment. For Plus, the audit is scheduled with an accredited assessor and the device sample is prepared in advance.
Go deeper
Cyber Essentials questions we hear most
Is Cyber Essentials a legal requirement?
No, but it is a contractual requirement for most UK central government contracts involving personal or sensitive data, and increasingly for NHS and MoD suppliers.
Can a company outside the UK get certified?
Yes. The scheme is open to any organisation; UK buyers ask for it regardless of where the supplier is based.
Does cloud-only infrastructure still need the firewall control?
Yes. The control applies to cloud security groups and network rules as well as physical firewalls, and to the devices your staff use.
How does it compare to Essential Eight?
Both are baseline technical control sets. Cyber Essentials is the UK scheme with five controls; Essential Eight is the Australian equivalent with eight mitigation strategies and maturity levels. Certifyi maps both to the shared control library.
Need Cyber Essentials for a UK contract?
Tell us the deadline. Most organisations with cloud infrastructure and MFA are certifiable within a month.