Cyber Essentials

What is Cyber Essentials?

Cyber Essentials is a government-backed cybersecurity certification scheme that demonstrates an organisation has the technical controls in place to protect against the most common cyber threats. It is widely required across government supply chains, public sector contracts and as a baseline condition for cyber insurance.

What does Cyber Essentials cover?

Cyber Essentials focuses on five specific technical controls. These were selected because they address the attack methods responsible for the majority of successful cyber incidents against organisations. Achieving the certification means demonstrating all five are in place and configured correctly.

Control What it requires Why it matters
Firewalls Boundary firewalls configured to block unauthorised access Prevents external attackers from reaching internal systems directly
Secure configuration Devices configured securely — default settings changed, unnecessary services disabled Reduces attack surface by removing unnecessary entry points
Access control User accounts with appropriate access, admin rights limited, MFA for remote access Limits what an attacker can do if they compromise a user account
Malware protection Anti-malware software active and up to date, or application allow-listing in place Prevents malicious software from executing on devices
Patch management Operating systems and software kept up to date, high-risk patches applied within 14 days Closes known vulnerabilities before attackers can exploit them

Who needs Cyber Essentials?

Cyber Essentials is mandatory for all organisations that want to bid for UK government contracts involving handling personal information or providing certain technical products and services. Beyond government, it is widely required or expected by enterprise buyers as a supply chain baseline, by cyber insurers as a condition of coverage and by regulated sector organisations managing third-party risk.

Even where it is not contractually required, Cyber Essentials is a practical way to demonstrate a baseline security position to clients, boards and partners without the overhead of a full management system standard.

Cyber Essentials or Cyber Essentials Plus?

Cyber Essentials uses a verified self-assessment — the organisation answers a questionnaire and an assessor verifies the answers remotely. Cyber Essentials Plus adds independent technical testing where an assessor tests the controls directly on your systems. CE+ provides stronger evidence that controls work in practice, not just on paper. The right choice depends on what buyers or contracts specifically require.

How long does Cyber Essentials take?

For organisations with reasonable existing technical controls, the process can typically be completed in two to four weeks. The main variable is how much remediation is needed before the assessment. YDC helps identify gaps early so the timeline is realistic.

Does Cyber Essentials need to be renewed?

Yes. Cyber Essentials certification is valid for 12 months and requires annual renewal. The annual process reassesses the controls to account for changes in the threat landscape and your technology environment.

Is Cyber Essentials the same as ISO 27001?

No. Cyber Essentials focuses on five specific technical controls. ISO 27001 is a comprehensive information security management system standard covering risk management, governance, policies, supplier oversight and continual improvement. They serve different commercial purposes and are not direct alternatives.

Ready to get certified?

YDC makes Cyber Essentials straightforward — not a guessing game.

We review your current position, identify what needs to change and support the assessment so you go in ready.

Related pages.