Cyber Essentials

Prepare for Cyber Essentials with practical support.

CompTech helps organisations define the scope, fix technical gaps, gather accurate evidence and prepare for Cyber Essentials or Cyber Essentials Plus assessment. Certification is awarded through the formal scheme.

A recognised baseline

Cyber Essentials gives you a practical security baseline.

Cyber Essentials focuses on a limited set of important technical controls designed to reduce exposure to common internet-based attacks.

It gives organisations a recognised way to demonstrate that baseline around devices, software, access and malware protection.

Certification can also help with customer or supplier assurance and with contracts or procurement processes where Cyber Essentials is requested, while still remaining a baseline rather than a complete cyber security programme.

Two levels of assurance

Cyber Essentials and Cyber Essentials Plus are not the same thing.

Cyber Essentials

Cyber Essentials uses a verified self-assessment covering the organisation’s implementation of the five technical controls.

It provides a recognised baseline and is often the right starting point for organisations that want to demonstrate that the core controls are in place.

Cyber Essentials Plus

Cyber Essentials Plus covers the same five technical controls but adds an independent technical audit of the in-scope environment.

The assessment uses technical checks and representative sampling to verify that the controls are working in practice, rather than relying only on the organisation’s questionnaire responses.

Cyber Essentials Plus does not mean an organisation is fully secure or protected from every attack.

Five technical controls

What does Cyber Essentials actually look at?

Firewalls

Check that devices and services are not unnecessarily exposed and that appropriate firewall controls are in place.

Secure configuration

Remove unnecessary software, services and default settings that could make devices easier to compromise.

Security update management

Keep supported operating systems, firmware and applications updated so known vulnerabilities are not left open.

User access control

Limit administrative access, remove unnecessary privileges and make sure users only have access appropriate to their role.

Malware protection

Use appropriate controls to reduce the risk from malicious software and unsafe applications.

Define the scope

Define what is in scope before the assessment starts.

The organisation applying for certification is responsible for defining its assessment boundary and agreeing the scope with the Certification Body before assessment begins.

CompTech can help map the users, devices, networks, cloud services and externally managed systems involved, identify potential exclusions and make sure the proposed scope is understood before evidence is prepared.

Under the current requirements, cloud services that host or process organisational data or services must be included in scope rather than simply excluded for convenience.

For Microsoft 365 identity, access and tenant management, see our Microsoft 365 support approach.

  • office, remote and home-working users and devices
  • company-owned and personally owned devices used for organisational services
  • Microsoft 365 and other cloud services
  • servers, virtual machines and internet-facing services
  • firewalls, connectivity and the network boundary
  • legacy, third-party and externally managed systems or services

Prepare early

Common issues worth finding before assessment.

Finding these issues early gives the organisation time to remediate them before the formal assessment begins.

For ongoing management of supported devices, updates and patching, see our managed IT support approach.

  • unsupported operating systems, firmware or applications
  • security updates covered by the scheme’s 14-day requirement not installed within that period
  • MFA missing from in-scope cloud services where it is available
  • unnecessary administrator or local administrator rights
  • exposed services or inappropriate firewall rules
  • unknown devices, unclear scope or unmanaged systems
  • insecure defaults, unnecessary software or services
  • inconsistent malware protection or incomplete asset and assessment information

Certification readiness

We help you get ready before the formal assessment.

1. Review

Understand the current environment, proposed scope and likely gaps before the assessment begins.

2. Remediate

Fix technical issues that could prevent certification.

3. Evidence

Gather the information needed to complete the verified self-assessment accurately.

4. Prepare

Review the final position so the organisation understands what will be submitted and, for Cyber Essentials Plus, what may be technically tested.

CompTech helps with readiness and preparation. Certification is awarded through the formal scheme, and no preparation process can guarantee an assessment result.

Technical verification

Cyber Essentials Plus needs the basics to work in practice.

Cyber Essentials Plus adds technical verification of the Cyber Essentials controls. The assessment uses technical checks across the in-scope environment, including representative sampling rather than testing every device individually.

Preparation can include checking representative devices, security updates, account separation, MFA, firewall exposure, malware protection and assessment information before the Plus audit.

Beyond certification

Certification is useful, but it is not the end of cyber security.

Cyber Essentials gives organisations a strong baseline, but risks continue to change after certification.

Identity monitoring, Microsoft 365 security, staff awareness, backup, vulnerability management and recovery planning may still need attention depending on the organisation.

Maintain the baseline

What happens after certification?

Cyber Essentials and Cyber Essentials Plus certificates are valid for 12 months and need to be renewed annually. Certification reflects the environment at a point in time, so changes during the year can affect whether the controls still match the certified position.

The scheme requirements can also change between renewals, so recertification should be prepared against the current requirements rather than simply reusing the previous year’s answers.

  • new devices, users, joiners and leavers
  • supported software and security updates
  • administrative access and MFA
  • firewalls, cloud services and other changes to the assessment boundary
  • changes to remote working or how staff access organisational services

Prepare for assessment

Want help preparing for Cyber Essentials?

Tell us whether you are aiming for Cyber Essentials or Cyber Essentials Plus and what your current IT environment looks like.

We’ll help you understand the proposed scope, identify technical gaps and work through the preparation needed before formal assessment.