What is Cyber Essentials? The five controls and how certification works
A plain-English guide to Cyber Essentials: the UK government-backed scheme, its five technical controls, the two certification levels, and who actually needs it.

Cyber Essentials is the UK's entry point to demonstrable cyber security. It's a government-backed certification scheme, launched in 2014 and overseen by the National Cyber Security Centre (NCSC), designed to prove an organisation has the basics in place. Since 2020 it has been delivered by IASME on the NCSC's behalf, through a network of licensed certification bodies.
The pitch is deliberately modest. Cyber Essentials isn't a comprehensive security management system; it's a baseline. But it's a baseline that, correctly implemented, is designed to stop around 80% of common internet-based attacks, which is why UK buyers and government departments increasingly treat it as the minimum ticket to do business.
The five technical controls
Everything in Cyber Essentials hangs off five technical controls. Get these right across your whole scope and you've done the substance of the scheme:
- Firewalls: control the traffic coming into and out of your networks and devices, so only what you intend can connect.
- Secure configuration: set up devices and software to reduce their attack surface: remove or disable what you don't need, change default passwords, and turn off unnecessary accounts and services.
- Security update management: keep operating systems and software supported and patched, applying critical and high-severity updates promptly. Unpatched, out-of-support software is one of the most common ways in.
- User access control: give people the minimum access they need, control administrative privileges tightly, and protect accounts (including multi-factor authentication where it applies).
- Malware protection: defend devices against malicious software, whether through anti-malware, application allow-listing, or equivalent controls.
We go deeper on each in the five Cyber Essentials controls, explained.
The two levels: Cyber Essentials and Cyber Essentials Plus
The scheme has two tiers, and they test the same five controls in different ways:
- Cyber Essentials is a self-assessment. You complete a questionnaire confirming the controls are in place across your scope, and an IASME-licensed certification body reviews your answers and issues the certificate.
- Cyber Essentials Plus adds an independent technical audit. A qualified assessor doesn't just read your answers; they test a sample of your systems and devices hands-on to verify the controls actually work.
Which one you need is a common question, so it has its own guide: Cyber Essentials vs Cyber Essentials Plus.
How certification works, and how long it lasts
You (or a support partner) implement the controls across an agreed scope, ideally the whole organisation. You complete the self-assessment questionnaire for the certification cycle. A certification body reviews it, and for Plus an assessor also runs the technical audit. Certification is then valid for 12 months, so it's an annual cycle rather than a one-off, and the controls have to hold up all year, not just on assessment day.
Who needs it, and why bother
Three groups usually pursue Cyber Essentials:
- Anyone bidding for UK government or public-sector work. Cyber Essentials is frequently a mandatory requirement in these contracts, and Plus is sometimes specified. No certificate, no bid.
- Small and mid-sized businesses that need a credible trust signal fast. It's quicker and cheaper than a full certification like ISO 27001, and it answers a customer's basic "are you secure?" question with a recognised badge.
- Organisations at the start of a longer journey. The five controls are foundational, so Cyber Essentials is a natural first step before a broader ISO 27001 or SOC 2 programme, and most of the work carries forward.
There's also a practical perk: certifying to Cyber Essentials at the whole-organisation level typically includes free cyber liability insurance for eligible UK-domiciled organisations under a set turnover threshold, which is worth checking against your current cover.
The controls themselves aren't hard; keeping them true across every device, all year, is the real work. ResiliencePilot tracks that continuously and maps it toward your wider framework goals. See the Cyber Essentials solution, the Cyber Essentials hub, or book a demo.