Cyber Essentials and Cyber Essentials Plus
Cyber Essentials is the UK government-backed cyber security certification scheme, overseen by the National Cyber Security Centre (NCSC) and delivered through its partner IASME. It certifies that your organisation has a set of baseline technical controls in place, and it has become the standard way public buyers check a supplier's basic cyber hygiene.
The two levels
- Cyber Essentials is a verified self-assessment. You answer a question set about your systems and a licensed assessor reviews and certifies it.
- Cyber Essentials Plus covers the same controls but adds an independent technical audit, including vulnerability scans and hands-on testing of a sample of your devices.
Both certificates are valid for twelve months. A Plus audit must be completed within three months of the underlying Cyber Essentials assessment.
The five control areas
1. Firewalls 2. Secure configuration 3. Security update management (patching) 4. User access control 5. Malware protection
The scheme's requirements are updated periodically (cloud services, home working and multi-factor authentication have all been folded in over the years), so read the current question set at each renewal rather than reusing last year's answers.
When public buyers require it
Central government has required Cyber Essentials since 2014 for contracts that involve handling personal information or providing certain ICT products and services. In practice the requirement now appears well beyond Whitehall: councils, NHS bodies, housing associations and universities routinely ask for it on any contract where the supplier will touch their data or systems, which catches many firms that do not think of themselves as IT suppliers. Plus is demanded where the data or access is more sensitive. If your pipeline includes contracts involving personal data, treat basic Cyber Essentials as a standing cost of bidding.
How to get it
1. Read the current requirements and question set, published by NCSC and IASME. 2. Bring your IT estate into line first: supported operating systems, managed user accounts, multi-factor authentication where required, patching within the scheme's timescales. 3. Buy the assessment through IASME or one of its licensed certification bodies and complete the self-assessment. 4. For Plus, book the technical audit with a certification body within three months of passing the self-assessed level.
Cost and time
Cyber Essentials is priced in bands by organisation size, at a few hundred pounds plus VAT; check IASME for the current figures. If your IT already meets the controls, certification can complete in days. Cyber Essentials Plus costs more because of the hands-on audit, typically a four-figure sum depending on the assessor and the size of your network, and needs more lead time to schedule. The real cost driver at either level is remediation: old operating systems, unmanaged devices and missing multi-factor authentication are the common failures, and fixing them is what takes the time.
Tenderoo finds the tenders you fit and scores each one, so you only spend time on the work you can win. Look your company up, free.