Cyber Essentials certification

Get Cyber Essentials certified without an IT security team.

Cyber Essentials is the UK government-backed certification that shows your organization has five basic technical controls in place, and many public sector and enterprise buyers ask for it before they sign. A dedicated SecureSlate compliance lead scopes your certification, closes the gaps across devices, cloud services, and accounts, and prepares your answers for the assessment, while our compliance automation platform keeps evidence current for Cyber Essentials Plus and renewal. One fixed price covers the work.

Cyber Essentials29 requirements

Cyber Essentials: 29 requirements, 4 Scope, 6 Firewalls, 6 Secure configuration, 4 Security update management, 7 User access control, 2 Malware protection. 8 highlighted: Checked by included scanning and device checks.

Checked by included scanning and device checksScoped with your compliance lead
Scheme
UK government-backed, run by the NCSC and IASME
Levels
Cyber Essentials and Cyber Essentials Plus
Certificate
Valid for 12 months
The standard

Cyber Essentials certification checks five technical controls, not a management system.

Cyber Essentials is a UK government-backed scheme that sets a baseline against the most common internet-based attacks. It covers the whole organization or a defined part of it, including cloud services, remote workers, and personal devices that access company data.

Five technical controls

Firewalls, secure configuration, security update management, user access control, and malware protection. The requirements are specific, such as installing high and critical security updates within 14 days and using multi-factor authentication on cloud services, so each one is either met or it is not.

Two levels of assurance

Cyber Essentials is a self-assessment questionnaire, signed off by a board-level contact and marked by a certification body. Cyber Essentials Plus adds a hands-on technical audit of a sample of your devices and accounts, completed within three months of the basic certificate.

An annual certificate

Certificates are valid for 12 months, and government contracts expect a current one. The requirements are updated periodically, so each renewal is assessed against the version in force at the time.
How it works

We get you through Cyber Essentials, then keep you ready for Plus and every renewal.

Four stages from the scoping call to a certificate, with a named compliance lead accountable at every one.

Set the scope

We agree whether the whole organization or a defined sub-set is certified, then list the devices, cloud services, networks, and remote or personal devices that fall inside it.

Run the gap assessment

Your compliance lead checks each requirement against how your devices, accounts, and cloud services are really configured, and gives every gap an owner and a fix.

Close the gaps and answer the questionnaire

Updates, multi-factor authentication, firewall rules, admin accounts, and malware protection are fixed first. Your compliance lead then drafts the self-assessment answers for your board-level signatory to review before submission.

Plus, renewal, and every year after

For Cyber Essentials Plus, we prepare you for the assessor's device sampling and vulnerability tests. Continuous monitoring keeps configurations compliant between annual renewals, so each one starts from a pass instead of a scramble.
What is included

Everything your Cyber Essentials assessor checks, prepared before they ask.

Cyber Essentials compliance software and the expert who runs it arrive together under one fixed price, so certification does not become a side project for whoever looks after IT.

A dedicated compliance lead

One experienced practitioner owns your Cyber Essentials program end to end. They set the scope, find the gaps, draft the questionnaire answers, and prepare you for the Plus assessor, so your team fixes and approves instead of interpreting the requirements.

A requirement-by-requirement gap assessment

Every Cyber Essentials requirement mapped to the configuration and evidence that meet it, with each gap owned and scheduled, and the controls that already count toward ISO 27001 marked.

Devices and remote workers

Company and personal devices that access company data are checked on a schedule for screen lock, antivirus, and encryption, so remote and hybrid teams stay inside the requirements.

Access reviews and multi-factor authentication

User accounts reviewed on a schedule, with leavers removed, administrator privileges kept separate, and multi-factor authentication confirmed on cloud services.

Evidence from the stack you already run

Connect your cloud provider, identity provider, and devices once. Configurations are tested continuously, so drift from the requirements shows up before your renewal, not during it.

A Trust Center for buyers

Publish your Cyber Essentials certificate alongside your security documentation on a live page, so procurement teams can confirm it without sending another questionnaire.
Checked automatically

Eight Cyber Essentials requirements are checked automatically.

Every engagement includes security scanning and device checks. These are the requirements they evidence directly, including parts of what a Cyber Essentials Plus assessor tests.
FW3 Administrative interfaces, FW4 Inbound connections

Public surface monitoring

Your domains and forgotten subdomains scanned on a schedule and when you ship, flagging vulnerabilities and exposed services from the outside view a Cyber Essentials Plus external scan also takes.
SU1 Supported software, SU2 Unsupported software

End-of-life software

Runtimes, frameworks, and packages in your repositories checked for end of life, with the date support ended and the supported version to move to, so unsupported software is replaced.
SC6 Device locking, MP1 Anti-malware

Device checks

Screen lock, antivirus, and encryption checked on the devices in scope, including remote workers' laptops, with the results kept as evidence between renewals.
UA4 MFA for cloud services

Cloud misconfiguration checks

AWS, Azure, and GCP configurations checked through read-only access for risky settings in access, encryption, logging, and networking, so cloud accounts meet the requirements too.
UA7 Password-based authentication

Dark web monitoring

Company email addresses checked against known breach data, so you can change passwords promptly when an account may be compromised.
UA7 Password-based authentication

Secrets detection

API keys, tokens, and credentials committed to source code, found and pinpointed to the file and line, so exposed credentials are rotated before anyone misuses them.
Beyond Cyber Essentials

One Cyber Essentials program that also serves your other frameworks.

The five controls are the technical baseline of most security frameworks, so the work you do here counts again when buyers ask for more.

ISO 27001

The natural next step for UK companies selling to larger buyers. The five Cyber Essentials controls map into ISO 27001's Annex A, so the technical work carries straight across.

GDPR

UK GDPR requires appropriate security for personal data. Cyber Essentials is a recognized baseline for the technical side of that duty.

SOC 2

US customers ask for a SOC 2 report instead. The access, configuration, and patching controls built for Cyber Essentials serve both.

NIST CSF

The CSF describes security outcomes in a language US and global buyers recognize. Cyber Essentials covers much of its Protect function.

NIS 2

UK companies with EU operations may fall under NIS 2, whose Article 21 measures include cyber hygiene, access control, and multi-factor authentication.

DORA

ICT providers serving EU financial entities face DORA contract terms and resilience questions that go beyond Cyber Essentials, though the technical baseline carries over.
Cyber Essentials guides

What Cyber Essentials actually checks

Three deep dives your team can read before the scoping call, from the five controls to what certification costs.

5 controls
What is Cyber Essentials: the five controls, the two levels, and who needs it
Plus
The Cyber Essentials Plus audit, and how to prepare for the assessor's tests
12 months
How much Cyber Essentials certification costs, and what drives the price
Resources

Read up before your scoping call.

Practical guides to Cyber Essentials, from who should certify to how it compares with ISO 27001.

FAQs

What teams ask before starting Cyber Essentials.

Find out what your Cyber Essentials certificate will take

Bring your devices, cloud services, and the contract asking for the certificate. You will leave the call with a gap summary, a timeline, and a fixed price, whether or not you work with us.

Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?