Compliance

Cyber Essentials,explained

6 min read · Updated June 2026

Cyber Essentials is the UK government-backed scheme, run under the NCSC, built on five technical controls that protect against the most common internet-based attacks. Base Cyber Essentials is a verified self-assessment; Cyber Essentials Plus adds an independent, hands-on technical audit of the same five controls.

What Cyber Essentials is

Cyber Essentials is a UK certification scheme, backed by the government and run under the National Cyber Security Centre (NCSC). It is deliberately a baseline: five technical controls that block the bulk of commodity, internet-based attacks, rather than a full management system.

That simplicity is the point. It is a quick, recognised first step, and it is frequently a requirement for UK public-sector contracts.

The five controls

  • Firewalls: control the traffic in and out of your networks and devices.
  • Secure configuration: remove or disable unnecessary functionality and default accounts.
  • Security update management: keep software supported and patched promptly.
  • User access control: manage accounts, apply least privilege, and protect admin access.
  • Malware protection: defend devices with anti-malware, allow-listing, or sandboxing.

Cyber Essentials vs Cyber Essentials Plus

Both cover the same five controls. The difference is how they are assured. Cyber Essentials is a self-assessment questionnaire that is independently verified. Cyber Essentials Plus adds a hands-on technical audit, where an assessor tests that the controls are actually in place. Plus carries more assurance weight with buyers.

How it relates to ISO 27001

Cyber Essentials is a baseline of five technical controls; ISO 27001 is a full information-security management system. The five themes are a subset of what ISO 27001 covers, so Cyber Essentials is a sensible quick win, and the work carries over if you go on to pursue ISO 27001 later.

How to get certified

  1. 1Confirm the scope: the devices, users, and networks in your assessment.
  2. 2Implement the five controls and gather evidence that they are in place.
  3. 3Complete the verified self-assessment for Cyber Essentials.
  4. 4Book the hands-on assessment if you need Cyber Essentials Plus.
  5. 5Recertify annually, keeping the evidence current in between.

Frequently asked questions

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Both cover the same five technical controls. Cyber Essentials is a verified self-assessment, while Cyber Essentials Plus adds an independent, hands-on technical audit that checks the controls are actually in place. Plus carries more assurance weight.

Who needs Cyber Essentials?

Any UK organisation wanting a recognised security baseline, and in particular suppliers bidding for UK public-sector contracts, which often require Cyber Essentials or Cyber Essentials Plus.

How long does Cyber Essentials last?

Certification runs for a year, so organisations recertify annually. Keeping the five controls and their evidence current in between makes each recertification straightforward.

Do this in a fraction of the time

Diligio centralises your approved answers, drafts each response grounded in your sources, and independently verifies it before you review. RFPs, DDQs, and security questionnaires, answered from one knowledge base.

Related guides

Due diligence

What is a DDQ (due-diligence questionnaire)?

Due diligence

DDQ vs RFP: what is the difference?

RFPs

RFP vs RFI vs RFQ: what is the difference?

RFPs

The RFP response process: a step-by-step guide

RFPs

How to build an RFP content library

RFPs

The bid/no-bid decision: when to respond to an RFP

Security questionnaires

How to respond to security questionnaires faster

Security questionnaires

SIG vs CAIQ vs VSAQ: the security questionnaires explained

Security questionnaires

Vendor security assessment checklist

Compliance

SOC 2 vs ISO 27001: what is the difference?

Compliance

ISO 27001 readiness checklist: how to prepare for certification

Compliance

SOC 2 for startups: a practical guide

Compliance

GDPR compliance for SaaS: a practical guide

Compliance

HIPAA compliance for software vendors

Compliance

PCI DSS compliance, explained

Compliance

The NIST Cybersecurity Framework, explained

Compliance

ISO 42001, the AI management standard, explained

Compliance

ISO 27017 and ISO 27018: cloud security and privacy, explained

Compliance

ISO 22301 and business continuity, explained

Compliance

DORA, explained

Compliance

The CCPA and CPRA, explained

Compliance

NIST 800-53, explained

Compliance

NIST 800-171 and CMMC, explained

Compliance

FedRAMP, explained

Compliance

HITRUST CSF, explained

Financial regulation

BSA/AML, explained

Financial regulation

The FATF 40 Recommendations, explained

Financial regulation

MiFID II and MAR, explained

Financial regulation

Consumer credit and fair lending, explained

Due diligence

Third-party risk management (TPRM): a practical guide

Putting Cyber Essentials into practice? See Diligio Compliance for Cyber Essentials.