What is the Cyber Essentials scheme?
Cyber Essentials is a UK government scheme supported by the NCSC (National Cyber Security Centre) that sets out five basic security controls to protect organisations from around 80% of common cyber attacks.
The scheme’s certification process is managed by the IASME Consortium, which licenses certification bodies to carry out Cyber Essentials and Cyber Essentials Plus certifications.
Cyber Essentials is designed to help organisations of any size demonstrate their commitment to cyber security – while keeping the approach simple, and the costs low.
Apply for Cyber Essentials certification now
Achieve certification first-time with IT Governance. View our range of affordable certification options for Cyber Essentials and Cyber Essentials Plus.
Why do I need Cyber Essentials?
Prevent around 80% of cyber attacks
Correctly implementing five basic security controls will protect your organisation against the most common cyber threats.
Demonstrate supply chain security
Achieving Cyber Essentials certification will help you demonstrate your commitment to data protection and cyber security.
Win new business
Cyber Essentials certification will help boost your reputation and give you a better chance of winning new business.
Drive business efficiency
You can focus on your core business objectives knowing you are protected from the most common cyber attacks.
Reduce cyber insurance premiums
Cyber insurance agencies look more favourably on organisations that have achieved Cyber Essentials certification.
Work with the UK government & MOD
Cyber Essentials will permit you to work with the UK government and Cyber Essentials Plus will allow you to work with the MOD.
Learn more about the benefits of Cyber Essentials certification
Get Cyber Essentials certified with IT Governance
Our simple five-step methodology:
Define the scope
Certification can apply to an organisation’s full enterprise IT or just to a subset. Either way, the scope needs to be clearly defined before the certification process can get underway.
The next step is to complete the required SAQ. We review the completed SAQ before submission to check it meets the scheme's requirements. Successful applications are issued a Cyber Essentials certificate.
Organisations seeking certification to Cyber Essentials Plus will be required to go through a technical audit, which includes a series of internal vulnerability scans and tests of the in-scope system(s), and the SAQ.
An external vulnerability scan of your Internet-facing networks and applications is used to verify that there are no obvious vulnerabilities. As the tests are external, they are performed off-site.
Once the on-site assessment, internal vulnerability scan and external vulnerability scan have been successfully completed and approved, you will be issued with your Cyber Essentials Plus certificate.