IASME Cyber Essentials & Cyber Essentials Plus

Cyber Essentials Certification – When Trust Demands Proof

Clear assessor support, practical remediation guidance, and a process built around the realities of UK procurement.
Whether certification is needed for a tender, supplier review, client request, insurance conversation, or a stronger security baseline, Cyber Essentials Online helps you understand what needs to happen next.
  • CREST-accredited
  • IASME-authorised
  • NCSC-aligned
  • Cyber Essentials certifying body
What is Cyber Essentialss?

Five Practical Controls That Cover The Fundamentals

Cyber Essentials focuses on the technical controls that prevent many common attacks. The assessment is structured, but the answers still need to reflect how your organisation actually works.

The scheme is built around five foundational technical controls, set by the National Cyber Security Centre and managed through IASME. Together, they give customers, suppliers, insurers, and procurement teams a clear signal that basic cyber hygiene is in place.

Firewalls and internet gateways

Checking that network boundaries are configured to reduce unauthorised access.

Secure configuration

Making sure systems are set up securely rather than relying on risky defaults.

User access control

Confirming that people only have the access they need, when they need it.

Malware protection

Reviewing how devices are protected from malicious software and unsafe applications.

Security update management

Checking that supported software is kept up to date within the required timeframes.

Why it Matters

Certification Pressure Is No Longer Limited to Government Contracts

Cyber Essentials still matters for UK Government procurement, but it has also become a common requirement in supply chains, insurance conversations, and client due diligence.

For many organisations, the question is no longer whether Cyber Essentials is useful. It is whether certification is needed now, before a tender, renewal, client review, or insurer request makes it urgent.

Procurement & Tendering

Ensuring networks are protected against unauthorised access by reviewing firewall placement, configuration, rule-set management, and vulnerable services.

Supply Chain Assurance

Larger organisations often need evidence that suppliers have basic cyber controls in place. Certification gives buyers a clear, recognisable assurance signal.

Insurance & Risk Reviews

Cyber insurers and risk teams may ask for evidence of baseline controls, including patching, access control, malware protection, and secure configuration.

Internal Security Hygiene

Certification creates a practical framework for checking whether basic controls are in place, documented, and understood across the organisation.

Cyber Essentials Adoption

A Recognised Baseline for UK Cyber Assurance

Cyber Essentials has moved from a procurement requirement to a widely recognised signal of baseline cyber maturity.
The scheme is widely used by UK organisations that need a practical way to show customers, procurement teams, insurers, and partners that core controls are in place.
0
Certificates Awarded
Cyber Essentials certificates awarded from January to December 2025.
0
CE Standard
Standard Cyber Essentials certificates awarded in the same reporting period.
0
CE Plus
Cyber Essentials Plus certificates awarded where independent technical verification was required.
0%
Lower Claim Likelihood
Organisations with Cyber Essentials are reported as less likely to make a cyber insurance claim.
Source: GOV.UK Cyber Essentials management information, January to December 2025; NCSC Annual Review 2025.

Cyber attacks come in many shapes and sizes, but the vast majority are very basic in nature. They’re the digital equivalent of a thief trying your front door to see if it’s unlocked.

National Cyber Security Centre

Certification Choice

Cyber Essentials vs Cyber Essentials Plus

Both certifications are built around the same five controls. The difference is how much independent technical verification is involved.
Baseline Assurance

Cyber Essentials

Best when you need a recognised baseline certification, often for procurement, supply-chain checks, or internal security hygiene.
Assessment Self-assessment questionnaire.
Validation No external system testing.
Typical Timing Usually 1–2 weeks, depending on readiness.
Best For Most organisations seeking a practical starting point.
Independently Verified

Cyber Essentials Plus

Best when clients, contracts, or internal risk expectations call for independent technical verification of the five controls.
Assessment External technical assessment after Cyber Essentials.
Validation Vulnerability scanning and sample testing.
Typical Timing Usually 2–4 weeks, depending on remediation.
Best For Higher-risk environments or stronger assurance needs
Cyber Essentials Certification

Ready for Cyber Essentials Certification?

Speak to 2-sec about your Cyber Essentials scope, readiness, testing requirements, and assessment window.
Whether certification is needed for a tender, supplier review, client request, insurance conversation, or a stronger security baseline, 2-sec Cyber Essentials Online helps you understand what needs to happen next.
  • CREST-accredited
  • IASME-authorised
  • NCSC-aligned
  • Cyber Essentials certifying body
Scroll to Top