The Cyber Essentials Scheme

What is the Cyber Essentials scheme?

Cyber Essentials is a UK government scheme supported by the NCSC (National Cyber Security Centre) that sets out five basic security controls to protect organisations against around 80% of common cyber attacks. 

The scheme’s certification process is managed by the IASME (Consortium which licences certification bodies to carry out Cyber Essentials certifications.   

Cyber Essentials is designed to help organisations of any size demonstrate their commitment to cyber security – all while keeping the approach simple, and the costs low. 

Apply for Cyber Essentials certification now

Pass your certification first-time with IT Governance.

View our range of affordable certification options for Cyber Essentials and Cyber Essentials Plus

Why do I need Cyber Essentials? 

Prevent around 80% of cyber attacks

Correctly implementing five basic security controls will protect your organisation against the most common cyber threats.

Demonstrate supply chain security

Achieving Cyber Essentials certification will help you demonstrate your commitment to data protection and cyber security.

Win new business

Cyber Essentials certification will help boost your reputation and give you a better chance of winning new business.

Drive business efficiency

You can focus on your core business objectives while knowing that you are protected from the most common cyber attacks.

Reduce cyber insurance premiums

Cyber insurance agencies look more favourably on organisations that have achieved Cyber Essentials certification.

Work with the UK government & MoD

Cyber Essentials will permit you to work with the UK government and Cyber Essentials Plus will allow you to work with the MoD.

Learn more about the benefits of Cyber Essentials certification

What does Cyber Essentials cover?

Firewalls

Firewalls need to be properly set up to prevent unauthorised access to your internal networks.

Learn more about firewalls

Patch management

Software and operating systems should be regularly updated to fix known vulnerabilities.

 Learn more about patch management

Malware protection

Anti-malware software should be installed to protect your computers, important data and privacy.

Learn more about access control 

Access control

User accounts should be assigned only to authorised individuals, be managed effectively, and provide the minimum level of access.

Learn more about malware protection

Secure configuration

Computers and network devices should be configured to minimise vulnerabilities and provide only the services required.

Learn more about secure confirguaration

What’s the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials Certification

Cyber Essentials

Cyber Essentials includes an self-assessment
questionnaire (SAQ). 


Cyber Essentials is right for you if:

You want a base-level security certification to demonstrate that you have key controls in place.

Get started

Cyber Essentials Plus Certification

Cyber Essentials Plus

Cyber Essentials Plus includes an external vulnerability assessment, an internal scan and an on-site assessment.


Cyber Essentials Plus is right for you if:

Your employees work from remote locations, or third parties have access to your premises or IT.

Get started

Get Cyber Essentials certified with IT Governance

Our simple five-step methodology:

 

1.

Define the scope

Certification can apply to an organisation’s full enterprise IT or just to a subset. Either way, the scope needs to be clearly defined before the certification process can get underway. Our Cyber Essentials online portal guides you through this process.



2.

SAQ

The next step to certification is to complete the required SAQ.


3.

On-site assessment

Organisations seeking certification to Cyber Essentials Plus will be required to go through a series of external vulnerability scans, internal vulnerability tests of the system(s) in scope, and the SAQ.


4.

External scan

As a CREST-accredited certification body, we will review your SAQ to ensure it meets the scheme’s requirements, and conduct an external vulnerability scan of your Internet-facing networks and applications. This scan is used to verify that there are no obvious vulnerabilities.


5.

Certification

Once the SAQ and scans have been successfully completed and approved, you will be asked to confirm your details and sign off your application.

Why choose IT Governance as your Cyber Essentials partner?

  • Expertise – We’ve issued more than 4,800 certificates and we’ve been a certification body for the past 5 years.
  • One-stop shop - We provide all tools and resources needed to achieve certification at both levels of the Cyber Essentials scheme.
  • End-to-end support - We deliver all the technical tests and assessments, conducted by our experienced technical testers.
  • Tailored solutions - Our unique fixed-price bundles provide expert support and compliance tools at affordable rates.
  • Credentials - Our consultants are qualified, CREST-accredited cyber security practitioners.
  • Unrivalled expertise - Having led ISO 27001 implementations since the inception of the Standard, we have the knowledge and insight to help you take the next steps beyond Cyber Essentials.

Get started

We've helped hundreds of organisations like yours achieve Cyber Essentials

This website uses cookies. View our cookie policy
25% OFF TRAINING