Cyber Essentials Certification Support for UK Businesses
The UK baseline that most customers, insurers and public sector buyers now ask for. We get you from "we probably fail" to certified, and fix the underlying issues rather than coaching you through the answers.
What is Cyber Essentials?
Cyber Essentials is a UK government-backed certification scheme, delivered by IASME on behalf of the NCSC, that verifies an organisation has five fundamental technical controls in place: boundary firewalls, secure configuration, security update management, user access control and malware protection. Certification is renewed annually.
The five controls, in plain English
Cyber Essentials asks about five things. Firewalls: every device must sit behind a properly configured boundary firewall, or have a software firewall enabled, with no unnecessary services exposed to the internet. Secure configuration: default passwords changed, unnecessary software and accounts removed, auto-run disabled.
Security update management: everything must be supported by its vendor and patched within fourteen days for high-severity or critical fixes — this is the control that most often causes a failure, usually because of an unsupported operating system or an old phone still in use. User access control: individual accounts, administrative privileges granted only where needed and used only for administrative work, MFA on cloud services. Malware protection: anti-malware, application allow-listing or sandboxing on all in-scope devices.
- Firewalls — boundary and host-based, with no unnecessary internet-facing services
- Secure configuration — no default credentials, minimal installed software
- Security update management — supported software, critical patches within 14 days
- User access control — individual accounts, least privilege, MFA on cloud services
- Malware protection — anti-malware or allow-listing on every in-scope device
Why businesses fail, and how we avoid it
The most common causes of failure are entirely predictable. An unsupported operating system somewhere in the estate — often one machine driving a piece of equipment. Mobile phones running Android or iOS versions no longer receiving security updates, which are in scope if they access organisational data. Multi-factor authentication missing on a cloud service. Everyday accounts holding local administrator rights. Routers still on default credentials.
We find those first. The gap review deliberately runs before you engage a certification body, because discovering an unsupported server halfway through an assessment is expensive and delays certification by weeks. Fix first, then apply.
- Unsupported operating systems still in the scope boundary
- Staff mobile devices past their vendor security update window
- Cloud services without MFA enforced
- Day-to-day accounts with local administrator rights
- Network equipment on default or shared credentials
- Home working devices nobody has considered
Getting the scope right
Scope is the most consequential decision in a Cyber Essentials application, and the one people get wrong. The default expectation is whole-organisation certification, covering every device and cloud service used for organisational work — including staff-owned phones that access work email, and home routers where people work remotely.
A narrower sub-scope is possible where a segregated part of the business can be properly separated, but it must be genuinely separated by network controls, not merely described that way. And a narrow certificate is worth less commercially: customers reading it will see what it excludes. We advise on the trade-off rather than defaulting to the cheapest route.
What certification is actually worth
Cyber Essentials is required for many central government contracts involving sensitive or personal information, and it is increasingly asked for by large private-sector customers running supplier due diligence. It frequently replaces a bespoke security questionnaire, which is a real saving of management time.
It also matters to insurers, and it is genuinely useful as a baseline — the five controls, properly implemented, block a large share of commodity attacks. What it is not is a comprehensive security programme. It says nothing about backups, staff training, incident response or supplier risk. Treat it as the floor.
- Required for many UK central government and MOD contracts
- Frequently accepted in place of a bespoke customer security questionnaire
- Commonly requested by cyber insurers at application or renewal
- Provides a demonstrable baseline for client and tender due diligence
Included in every engagement
Fixed scope, agreed in writing before we start. If the scope changes, we stop and re-quote rather than invoicing the difference.
Master Services Agreement (MSA)
The umbrella commercial agreement: scope, fees, IP, liability, confidentiality and termination. Work is ordered under Statements of Work.
UK Electronic Communications Act 2000 · eIDAS (EU) No 910/2014 · SHA-256 Verified
Cyber Essentials — your questions answered
How much does Cyber Essentials cost?
How long does Cyber Essentials certification take?
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Do staff mobile phones count for Cyber Essentials?
How often does Cyber Essentials need renewing?
Do we need Cyber Essentials to win government contracts?
Question not answered here? Call +44 7424 967568 or email support@cipherknights.com.
You might also need
Ready to talk about cyber essentials?
Book a free, no-obligation consultation with our Leicester team, or call us and we will point you in the right direction whether or not you become a client.