BACK TO BLOGS Back to Press Releases

Cyber Essentials: What you need to know about UK cybersecurity compliance

Written by:

Alex Keeling, Special Projects IT Engineer

Written by:

For many UK organizations, it is no longer a question of if, but when a cyberattack will occur, and customers and businesses alike are increasingly looking for assurances that their data and systems are safe.

While sophisticated cyberattacks against large organizations often receive more media coverage, many successful breaches stem from small issues such as unpatched software, weak or default passwords, and excessive user privileges.  

There are various compliance and regulatory frameworks businesses are required or encouraged to follow, one of which is UK Cyber Essentials.  

Cyber Essentials was created to help organizations address these common security gaps through a government-backed cybersecurity framework. Whether your organization is bidding on public sector contracts or simply looking to strengthen its security posture, understanding Cyber Essentials is an important first step.

What is Cyber Essentials?

Cyber Essentials is a UK government-backed and industry-supported certification scheme designed to help organizations protect themselves against online security threats. It represents a government-backed baseline for cybersecurity that organizations can implement to defend against common cyber threats.  

Developed by experts at the National Cyber Security Centre (NCSC), Cyber Essentials is built around five technical controls designed to help prevent the most common cybersecurity threats.

Cyber Essentials certification offers several benefits, including:

  • A baseline that helps defend against many common cyber threats, including phishing, malware, ransomware, and credential theft
  • An actionable checklist for organizations to improve their security posture
  • Evidence that your organization is committed to data protection and security, demonstrating that you take cybersecurity seriously and are actively working to reduce risk
  • May lower costs of cyber insurance premiums
  • Streamline compliance with other regulations such as GDPR in the UK

While not required across all industries, having a Cyber Essentials certification is often a mandatory requirement for bidding on UK government, Ministry of Defence, and NHS contracts.

Why was Cyber Essentials created?

Cyber Essentials was created to provide a baseline for small and medium sized organizations that often did not have an established cybersecurity posture.  

This made them susceptible to common cyber threats that exploit outdated software, weak passwords, and other security gaps through phishing, malware, ransomware, and credential theft.  

Research showed that implementing five basic technical controls could prevent many of these breaches, giving organizations an actionable checklist of how to better protect themselves.

Who needs Cyber Essentials certification?

Cyber Essentials was designed to be used by organizations of all sizes and in any sector, but is most beneficial for small and medium sized organizations.  

Cyber Essentials certification is typically required for organizations bidding on UK government, Ministry of Defence, or NHS contracts, and it is also highly recommended for organizations that handle sensitive information.

What are the Cyber Essentials five technical controls?

To obtain Cyber Essentials certification, an organization must implement the five foundational security controls listed below.

Firewalls and routers

Create a security filter to secure the connection between the internet and your network.

Secure configuration

Set up computers securely to minimize ways that a cybercriminal can find a way in.

Patch management

Ensuring operating systems, software, and firmware are updated which helps prevent cybercriminals using vulnerabilities they find in software as an entry point into your systems.

User access control

Control who can access your data and services and what level of access they have.

Malware protection

Identify and stop viruses or other malicious software before it has a chance to cause damage.

What is the Cyber Essentials certification process?

Organizations are required to implement the five core technical controls listed above. They can then pursue either the standard Cyber Essentials self-assessment or Cyber Essentials Plus, which includes hands-on verification by an external auditor.

Step-by-step overview:

  1. Assess current environment: The organization’s current environment (devices, configurations, access controls) is compared to Cyber Essentials controls.
  2. Implement required controls: Address any gaps identified during the assessment to ensure the environment meets the requirements.
  3. Complete a self-assessment questionnaire: Visit the IASME portal to register for the assessment.
  4. Submit for review: A certified assessor will review the completed self-assessment. Any questions from the assessor on the self-assessment must be addressed.
  5. Receive certification: Upon successful review by the certified assessor, a certificate is issued.
  6. Renew annually: Cyber Essentials certifications are only valid for 12 months.

What is Cyber Essentials Plus?

Cyber Essentials Plus is an advanced certification requiring an independent, hands-on technical audit. A basic Cyber Essentials certification issued within the last three months is required before pursuing Cyber Essentials Plus.

The audit must be performed by an external auditor who also runs vulnerability scans, checks for malware and configurations on a sample set of organization devices.

Common challenges in achieving Cyber Essentials certification

While Cyber Essentials is designed to be used by organizations of all sizes, many organizations encounter challenges when implementing and maintaining the required controls.

  • Managing user access: Ensuring users have least privilege access and restricting administrator accounts specifically for administrator tasks.
  • Patch compliance: Cyber Essentials requires operating systems and software to be updated within 14 days of a critical update.
  • Remote environments: Remote users pose a security challenge as well, ensuring remote devices remain in compliance with organization device usage policies including updates and maintenance.
  • Legacy systems: Some organizations run legacy or end of life operating systems or software, additionally users can be resistant to performing device or software updates.
  • Ongoing maintenance: Integral systems that require downtime necessary for updates introduce challenges with scheduling around the system being available for user work, while also remaining within the time frame for critical updates.
  • Shadow IT: Unknown devices connected to the organization’s network that are not correctly secured or approved by IT. Personal devices and unapproved apps add additional challenges to enforcing security.

How does Cyber Essentials compare to other cybersecurity frameworks?

Some cybersecurity frameworks serve a specific purpose for specific industries while others act as a set of guidelines for organizations to follow regardless of industry or size.

  • Cyber Essentials is a pass/fail certification through either a self-assessment or through an external auditor.  
  • ISO 27001 is a blueprint for building and running an Information Security Management System (ISMS) and requires ongoing third-party audits.  
  • SOC 2 is a voluntary auditing framework developed by the American Institute of Certified Public Accounts to evaluate how well an organization protects client data and requires a report from an auditor.
  • NIST Cybersecurity Framework provides a foundation of cybersecurity best practices designed to be used by any organization. It is a voluntary assessment and guidance framework, not a certification.
  • GDPR (General Data Protection Regulation) is a European regulation that mandates how organizations protect personal data.  

The primary focus of Cyber Essentials is on basic cyber hygiene. Things that should be implemented and in place as a minimum level of cyber defense. Achieving Cyber Essentials certification can also support compliance efforts for many other frameworks.

How Zero Trust and Cyber Essentials work together

Cyber Essentials establishes the baseline security controls that support a Zero Trust approach. User access controls help enforce least privilege principles, while secure configuration and patch management help to reduce the organization’s attack surface.

Zero Trust builds upon Cyber Essentials by continuously verifying users, devices, applications, and activity instead of assuming trust based on network location. Allowlisting helps to ensure that only approved software can be executed, helping to reduce the risk of malware and ransomware.

ThreatLocker can help companies reach Cyber Essentials certification through policy-based controls including Allowlisting, Privileged Access Management, and Patch Management.

But completing a compliance checklist should not be the end goal.

Cyber Essentials provides a strong foundation for reducing common cyber risks. Zero Trust extends those principles beyond certification by continuously enforcing least privilege, preventing unauthorized activity, and limiting what trusted applications can do. Together, they help organizations move from meeting a baseline standard to maintaining a security posture designed to prevent breaches and contain threats when they occur.

Start your path to stronger defenses

Start your trial

Try ThreatLocker free for 30 days and experience full Zero Trust protection in your own environment.

Book a demo

Schedule a customized demo and explore how ThreatLocker aligns with your security goals.

Ask an expert

Just starting to explore our platform? Find out what ThreatLocker is, how it works, and how it’s different.