Get Cyber Essentials ready
For UK organisations preparing for certification
Cyber Essentials is the UK government-backed certification scheme, run by the NCSC through IASME, that shows your organisation has the fundamental technical controls in place against the most common internet-borne attacks. For many UK businesses it is the first certification customers and public-sector contracts ask for - and for MOD and many central government contracts it is mandatory.
What the scheme actually checks
Certification is a self-assessment questionnaire, signed off at board level and verified by an assessor. Every question maps to five control themes:
- Firewalls - every device is protected by a correctly configured firewall or equivalent, and internet-exposed services are deliberate, not accidental.
- Secure configuration - default passwords are gone, unnecessary software and services are removed, and auto-run is off.
- Security update management - supported software only, with high and critical updates applied within 14 days.
- User access control - accounts are individual, least-privilege, and administrator accounts are separate from daily-driver accounts.
- Malware protection - anti-malware, application allow-listing or sandboxing on every in-scope device.
The most common reasons applications fail are unsupported operating systems, missed 14-day patch windows, shared or over-privileged admin accounts, and cloud services quietly left out of scope. None of these are hard to fix - they are hard to find when nobody has taken stock.
The sensible order of work
- 1. Scope honestly. Cyber Essentials covers your whole organisation by default - every device that touches organisational data, including home workers' machines and your cloud services.
- 2. Assess against the five themes before you apply, so the certification questionnaire holds no surprises.
- 3. Fix the gaps in priority order - unsupported software and admin-account hygiene first; they fail applications outright.
- 4. Keep evidence as you go. The assessor may ask how you know; screenshots and policy documents answer faster than memory.
- 5. Re-check before the anniversary. Certification lasts twelve months; drift is what fails renewals.
How Assura helps
Assura includes a guided Cyber Essentials assessment among its 20 frameworks. You answer in plain English, attach evidence as you go, and Assura scores each requirement in the scheme's own language - compliant, partially compliant, not compliant - with written reasoning. When you finish you get the full picture in one pass:
- a scored readiness view of all five control themes, so you know whether you would pass today;
- a prioritised gap list and remediation plan, ranked by severity;
- a live risk register that tracks each fix through to done;
- and because Assura maps controls across frameworks, your Cyber Essentials work pre-fills its counterparts when you later take on ISO 27001 or NIST CSF.
Assura prepares you for certification; the certificate itself is issued through an IASME-licensed certification body. Arriving with your gaps already closed makes that final step routine.
Check your readiness with Assura
Related guides: ISO 27001 · NIST CSF 2.0 · SOC 2