Framework guide

Cyber Essentials and Cyber Essentials Plus

The UK government-backed certification that public-sector, NHS and MoD contracts ask for first. Five technical controls, two certification routes, and a 12-month cycle. Here is how it works and how it fits alongside ISO 27001 and SOC 2.
What is Cyber Essentials? Cyber Essentials is a UK government scheme, run by the National Cyber Security Centre through IASME, that certifies an organisation has five baseline technical controls in place: firewalls, secure configuration, security update management, user access control, and malware protection. Cyber Essentials is a verified self-assessment; Cyber Essentials Plus adds an independent technical audit. Both are valid for 12 months and are required for most UK central government contracts that handle personal or sensitive data.

Who asks for it

UK central government departments require it for suppliers handling personal data or providing certain ICT services. The NHS expects it through the Data Security and Protection Toolkit. The Ministry of Defence requires it, often at Plus, for its supply chain. Beyond mandates, UK enterprise procurement teams use it as the quickest signal that a SaaS vendor has the basics covered. It is also the cheapest certification to obtain, which makes it a sensible first step before ISO 27001.

The five controls

1

Firewalls

Boundary firewalls or equivalent on every internet connection; administrative interfaces not exposed; default passwords changed.

2

Secure configuration

Unnecessary software and accounts removed, autorun disabled, device lock and password or MFA policy in place.

3

Security update management

Licensed, supported software only; critical and high-risk updates applied within 14 days; unsupported software removed.

4

User access control

Unique accounts, least privilege, admin accounts used only for admin tasks, MFA on cloud services.

5

Malware protection

Anti-malware or application allow-listing on all in-scope devices, kept current.

Boundary

Scope

Which devices, cloud services and networks are in scope. Whole-organisation scope is the default and strongest.

Cyber Essentials versus Cyber Essentials Plus

Cyber EssentialsCyber Essentials Plus
MethodSelf-assessment questionnaire, verified by a certification bodySelf-assessment plus independent technical audit: vulnerability scan, device sampling, email and browser tests
Time from start2 to 4 weeks with the controls in place4 to 8 weeks; Plus must be completed within 3 months of the basic certificate
Typical fee to the certification bodyTiered by organisation size; a few hundred poundsHigher; depends on scope and device count
Who requires itMost government contracts handling personal dataMoD supply chain and higher-risk contracts
Validity12 months12 months

How it fits with ISO 27001 and SOC 2

Cyber Essentials covers technical hygiene, not a management system. If you hold ISO 27001 you already meet most of the five controls and the certificate is a matter of scoping and evidence. If you are starting from nothing, Cyber Essentials first is a fast, cheap win that satisfies UK buyers while the ISO 27001 programme runs. In Certifyi the five controls are mapped to the same control library, so the evidence for patching, MFA and endpoint protection is collected once and reused.

Timeline with Certifyi

A compliance lead confirms scope in the first session, runs the readiness check against the current question set, closes gaps (most often MFA coverage, patch timelines and unsupported software), and submits the assessment. For Plus, the audit is scheduled with an accredited assessor and the device sample is prepared in advance.

Cyber Essentials questions we hear most

No, but it is a contractual requirement for most UK central government contracts involving personal or sensitive data, and increasingly for NHS and MoD suppliers.

Yes. The scheme is open to any organisation; UK buyers ask for it regardless of where the supplier is based.

Yes. The control applies to cloud security groups and network rules as well as physical firewalls, and to the devices your staff use.

Both are baseline technical control sets. Cyber Essentials is the UK scheme with five controls; Essential Eight is the Australian equivalent with eight mitigation strategies and maturity levels. Certifyi maps both to the shared control library.

Need Cyber Essentials for a UK contract?

Tell us the deadline. Most organisations with cloud infrastructure and MFA are certifiable within a month.
Scroll to Top