🇬🇧 UK Government-backed scheme

Cyber Essentials, made straightforward.

Cyber Essentials is the UK government's cyber security certification scheme. Cyber Assure guides you through all five technical controls with expert-written, plain-English guidance - so you know exactly what to do and why.

Cyber Essentials Progress
In Progress
60% complete

3 of 5 sections complete

Firewalls
100%
Secure configuration
100%
Access control
65%
Malware protection
40%
Patch management
20%
Enable firewall on all devices and servers
Enable MFA for all user accounts accessing cloud services
Ensure automatic OS updates are enabled on all devices

The UK government's cyber security baseline - and a growing requirement.

Cyber Essentials is a UK government-backed certification scheme that defines five basic technical controls every organisation should have in place. It was developed by the NCSC (National Cyber Security Centre) and is widely recognised as the minimum standard for cyber security in the UK.

It is already required for organisations bidding for certain government contracts, and is increasingly expected by insurers, funders, and large clients as a condition of doing business.

Control 1
🔥
Firewalls

Boundary firewalls and internet gateways that protect your network from unauthorised access from the internet.

Control 2
⚙️
Secure Configuration

Computers and network devices configured to reduce vulnerabilities and provide only the services and software you actually need.

Control 3
🔐
Access Control

User accounts with appropriate privileges, strong passwords, and multi-factor authentication on internet-facing services.

Control 4
🛡
Malware Protection

Protection against malicious software through anti-malware tools, application controls, or sandboxing.

Control 5
🔄
Patch Management

Software and devices kept up to date with the latest security patches - within 14 days of a patch becoming available.

Expert guidance. Plain English. No consultant needed.

Most organisations find Cyber Essentials confusing. The technical language can be impenetrable, and it's not always clear what "meeting" a control actually means in practice for your specific setup.

📝

Expert-written guidance for every control

Each of the five controls is broken down into individual requirements with clear, plain-English explanations of what needs to be in place and why it matters - written by cyber security experts, not committees.

📊

Track your progress visually

See at a glance which controls you've met, which are partially complete, and which still need attention. No spreadsheets, no manual tracking.

💬

AskIT — gather evidence without being a technical expert

Each control includes tailored wording you can send directly to your IT team or provider to request the information or evidence needed. No technical knowledge required on your side.

📄

Evidence and audit trail

Document your controls and keep a clear record of what's in place. When it's time for formal certification, you have everything organised and ready.

🏆 Why get certified?

Required for UK government contracts handling personal data
Demonstrates commitment to cyber security to funders and clients
Can reduce cyber insurance premiums
Increasingly expected by larger organisations in your supply chain
Protects against the majority of common cyber attacks

Cyber Essentials vs Cyber Essentials Plus

Cyber Essentials is a self-assessment - you answer questions about your controls and a certifying body reviews your responses.

Cyber Essentials Plus goes further with an independent technical verification of your controls by an assessor. Cyber Assure's tracking helps you prepare for both.

Cyber Essentials is for every UK organisation.

While technically voluntary for most organisations, the practical and reputational benefits mean it is becoming a baseline expectation across all sectors.

❤️

Charities and Nonprofits

Many grant funders now ask about cyber security as part of due diligence. Cyber Essentials gives you a recognised, credible answer.

  • Demonstrates responsible data handling
  • Increasingly required by major funders
  • Protects donor and beneficiary data
🏫

Schools and Academies

The Department for Education's cyber security standards for schools align closely with Cyber Essentials. Many academy trusts require certification across the trust.

  • Aligns with DfE cyber standards
  • Required by some academy trusts
  • Supports Ofsted preparedness
🏢

SMEs and Businesses

If you supply to the public sector, work with larger organisations, or hold personal data, Cyber Essentials is increasingly a baseline requirement.

  • Required for some government contracts
  • Can reduce insurance premiums
  • Builds client and partner confidence

Start your Cyber Essentials journey today.

Cyber Essentials tracking is included in all Cyber Assure plans. Get in touch to see how it works for your organisation.

Get Started View Pricing