Skip to content

Cyber Essentials

Cyber Essentials

Cyber Essentials is the minimum standard of cyber security the UK Government recommends for organisations of all sizes: five technical controls against common internet-based attacks. This guide covers the scheme, its two levels and how certification works.

Reviewed October 2026. Applies to: Cyber Essentials requirements for IT infrastructure v3.3 (NCSC, April 2026), the Danzell question set.

At a glance

TopicDetail
OwnerThe National Cyber Security Centre (NCSC), which writes the requirements
DeliveryIASME, the NCSC's Cyber Essentials Delivery Partner, and the Certification Bodies it licenses
StandardCyber Essentials: Requirements for IT Infrastructure v3.3, for applications started from 27 April 2026
Question setDanzell, introduced with v3.3 in April 2026
LevelsCyber Essentials (a verified self-assessment) and Cyber Essentials Plus (adds a technical audit)
ControlsFirewalls, secure configuration, security update management, user access control, malware protection
Validity12 months, renewed every year

What Cyber Essentials is

Cyber Essentials is a certification scheme built on five technical controls. The NCSC designed them to stop the most common attacks from the internet: low-skill, opportunistic attacks that use freely available tools to find an exposed service, a default password or a missing update.

The standard is a single NCSC document, Cyber Essentials: Requirements for IT Infrastructure. It sets out what is in scope and what each control requires. The NCSC and IASME review it every year. Version 3.3 applies to applications started on or after 27 April 2026; applications started before then may continue on version 3.2.

  • Firewalls: only secure, necessary services can be reached from the internet.
  • Secure configuration: default accounts, default passwords and unneeded software are removed.
  • Security update management: software is supported, and critical and high-risk fixes are installed within 14 days.
  • User access control: only authorised people have accounts, with only the access they need, and multi-factor authentication (MFA) where available.
  • Malware protection: anti-malware software or application allow listing stops malicious code running.

Cyber Essentials is a baseline, not a security programme. It does not ask for a risk assessment, an incident response plan or a management system; ISO 27001 covers those. Backups are not a requirement either, although the NCSC strongly recommends them.

Who runs the scheme

  • The NCSC owns the scheme and writes the requirements.
  • IASME is the NCSC's Cyber Essentials Delivery Partner. It publishes the question set, licenses the Certification Bodies, and is where you register for certification.
  • Certification Bodies are organisations licensed by IASME to assess applicants. Their assessors mark the self-assessment, carry out Cyber Essentials Plus audits, and award certification.
  • Cyber Advisors are organisations assured by the NCSC to give small and medium-sized organisations practical help putting the five controls in place.

To see whether an organisation holds a current certificate, use IASME's certificate search.

Cyber Essentials and Cyber Essentials Plus

Both levels assess the same five controls against the same requirements. The difference is how the controls are checked.

AspectCyber EssentialsCyber Essentials Plus
AssessmentA verified self-assessment: you answer the question set and an assessor marks itThe same self-assessment first, then a technical audit by a Certification Body
Who vouches for itA board member or equivalent signs a declaration that the answers are trueAn assessor tests a representative sample of your systems
TestingNoneExternal and authenticated vulnerability scans, malware, MFA and account separation tests
TimingSix months from application to passAudit completed within three months of the Cyber Essentials certificate
Pass barSome questions fail the assessment on their ownEvery test must pass; issues found must be fixed and retested
AssuranceBaselineHigher

What Cyber Essentials Plus tests

The NCSC's Cyber Essentials Plus Test Specification (v3.2) sets five test cases. The audit can be carried out remotely or on site.

  1. Remote vulnerability assessment: the assessor scans every public IP address in scope, including IaaS, with a scanner approved by IASME, and reviews each service that answers from the internet.
  2. Patching: an authenticated vulnerability scan of sampled end-user devices, servers and IaaS instances. A critical or high-risk vulnerability whose fix has been out for more than 14 days is a fail.
  3. Malware protection: test files sent by email and downloaded in a browser on sampled devices, or manual checks of the anti-malware software; for allow listing, checks that unsigned code will not run.
  4. Multi-factor authentication: users sign in to each cloud service from an untrusted device or private browser session and must be asked for a second factor. At least one standard user and one administrator are tested for each service.
  5. Account separation: a standard user tries to run an administrative task, which must ask for separate administrator credentials.

Since April 2026, the self-assessment must be finished, and any non-compliance in it fixed, before Plus testing starts; the answers cannot then be changed to match the audit. If sampled devices fail the update test, the retest adds a new random sample, and a second failure revokes the Cyber Essentials certificate.

Who needs Cyber Essentials

The NCSC recommends Cyber Essentials for organisations of every size. Many certify because a customer asks: the NCSC notes that a growing number of organisations require suppliers to be certified to bid for work, and it asks large organisations to build Cyber Essentials into their supply chains.

In UK central government, PPN 014 tells departments, their executive agencies and non-departmental public bodies, and NHS bodies to require Cyber Essentials for contracts with certain characteristics, such as a supplier handling citizens' personal information or supplying ICT that stores or processes OFFICIAL data. It is not meant for every contract, a supplier may show equivalent controls instead, and where certification is required it must be renewed every year for the life of the contract.

If a customer asks for Cyber Essentials, ask which level they need and what the certificate should cover. A certificate for one business unit says nothing about the rest of the organisation.

Where an external check fits

Ironfang is not a Certification Body and does not offer the Cyber Essentials assessment. Its External Security Check is an automated, low-impact check of a domain's public configuration: DNS, email authentication, TLS, HTTP headers, visible technologies and certificate transparency, and, for a domain you have verified, one connection attempt to each of 21 fixed ports.

Most of Cyber Essentials lives on devices and in accounts that no external check can see. An external check helps at the internet-facing edge: it can find services you did not mean to expose, list hostnames you had forgotten, and flag web servers that advertise unsupported software. That is useful preparation for the firewall and update controls, and for the external scan that opens a Cyber Essentials Plus audit. It is not that scan, and a clean result is not a Cyber Essentials result.

Cyber Essentials: technical and organisational evidence

Ironfang can check

  • Database, remote desktop, SSH, SMB, Telnet, FTP, Docker API and alternate web ports that accept a connection from the internet on a verified domain's hosts
  • Hostnames under your domain in certificate transparency logs, to compare with your scope
  • Web servers advertising a software version past its end of life
  • Changes to these between scheduled checks, with continuous monitoring

The organisation must establish

  • The scope: business units, locations, network boundary, legal entities, devices and cloud services
  • Firewall rules approved and documented with a business need
  • Account processes, separate administrator accounts and MFA on every cloud service
  • Supported software, with critical and high-risk fixes installed within 14 days on every device
  • Malware protection active on every device
  • A board-level declaration that the answers are true

Evidence to gather

The requirements say your Certification Body may ask for evidence before it awards certification, and a board member signs a declaration that your answers are true. Gather the evidence before you answer, so that every answer rests on something you can show.

  • Scope: the business units, locations and network boundary covered, each legal entity's name, address and company number, and the reason for any exclusion and how the excluded part is separated.
  • Devices: every end-user device, server and network device in scope, including personally owned devices that reach organisational data, with its operating system and version.
  • Cloud services: every service that stores or processes organisational data, which controls the provider implements, and the MFA setting for users and administrators.
  • Firewalls: the inbound rules on each boundary, software and cloud firewall, who approved each one and why, and how administration interfaces are protected.
  • Software and updates: what is installed, that each item is still supported, that automatic updates are on, and when critical and high-risk fixes were applied.
  • Accounts: how accounts are created, approved and removed, who has administrator rights and which separate accounts they use, and the password, throttling and lockout settings.
  • Malware protection: the method each device uses and how it is kept up to date.

Most of this is organisational evidence: lists, approvals, settings and records that only you hold. An external check adds technical evidence for the internet-facing part. The Cyber Essentials checklist turns each of these into items you can work through.

How certification works

Certification goes through IASME and the Certification Bodies it licenses. The NCSC describes two routes:

  • Self-led: you register and pay through IASME, complete the verified self-assessment, and an assessor marks it.
  • Supported: you hire a Certification Body to help you understand the questions and how they apply to your organisation.

IASME keeps a list of Certification Bodies. For Cyber Essentials Plus you need one, because the audit is carried out by a Certification Body's assessor.

The steps

  1. Read the requirements and download the free question set from IASME. The download is for preparation only; answers count only on the assessment platform.
  2. Define the scope and agree it with the Certification Body before the assessment begins.
  3. Close the gaps, control by control, and gather the evidence.
  4. Register, then answer the question set on the assessment platform. You have six months from application to pass.
  5. A senior board member, or equivalent, signs a declaration that the answers are true.
  6. An assessor marks the answers. A pass gives a certificate, which appears in IASME's certificate search.
  7. For Cyber Essentials Plus, book the audit with a Certification Body and complete it within three months of the Cyber Essentials certificate.

Automatic fails

Under the Danzell question set, some answers fail the whole assessment on their own. MFA missing on a cloud service that offers it, whether the option is free, included or paid, is one. Critical or high-risk updates not installed within 14 days of release is the other, asked in two questions: A6.4 for operating systems and router and firewall firmware, and A6.5 for applications and their files and extensions.

How long certification lasts

A certificate is valid for 12 months, so Cyber Essentials is renewed every year. IASME notes that a renewal certificate runs for 12 months from the date you submit, not from the old certificate's expiry, so time the renewal. The requirements and question set are reviewed every year: check which version applies before each renewal.

Sources

Checked on the review date above. Standards and schemes change; the source is the authority.