Guide

Get Cyber Essentials ready

For UK organisations preparing for certification

Cyber Essentials is the UK government-backed certification scheme, run by the NCSC through IASME, that shows your organisation has the fundamental technical controls in place against the most common internet-borne attacks. For many UK businesses it is the first certification customers and public-sector contracts ask for - and for MOD and many central government contracts it is mandatory.

What the scheme actually checks

Certification is a self-assessment questionnaire, signed off at board level and verified by an assessor. Every question maps to five control themes:

The most common reasons applications fail are unsupported operating systems, missed 14-day patch windows, shared or over-privileged admin accounts, and cloud services quietly left out of scope. None of these are hard to fix - they are hard to find when nobody has taken stock.

The sensible order of work

How Assura helps

Assura includes a guided Cyber Essentials assessment among its 20 frameworks. You answer in plain English, attach evidence as you go, and Assura scores each requirement in the scheme's own language - compliant, partially compliant, not compliant - with written reasoning. When you finish you get the full picture in one pass:

Assura prepares you for certification; the certificate itself is issued through an IASME-licensed certification body. Arriving with your gaps already closed makes that final step routine.

Check your readiness with Assura

Related guides: ISO 27001 · NIST CSF 2.0 · SOC 2