Compliance · Cyber Essentials
Cyber Essentials & Cyber Essentials Plus
The UK government-backed baseline for cyber hygiene. Cyber Essentials is a verified self-assessment; Cyber Essentials Plus adds an independent, hands-on technical audit.
What it is
A baseline that proves the basics are in place.
Cyber Essentials covers five technical control areas: firewalls, secure configuration, user access control, malware protection, and security update management.
Cyber Essentials (the standard tier) is a self-assessment that is independently verified. Cyber Essentials Plus adds a hands-on technical audit of your systems for stronger assurance.
Current requirements
What changed in April 2026.
Accounts registered from 27 April 2026 are assessed against the current IASME question set, known as Danzell, which implements version 3.3 of the Requirements for IT Infrastructure.
- Cloud services that hold your organisation’s data are in scope and can no longer be excluded
- Multi-factor authentication is required on every cloud service that offers it
- Passwordless methods such as passkeys and FIDO2 security keys are formally accepted as MFA
- Critical and high-risk security updates must still be applied within 14 days, and unsupported software removed or segregated
Who needs it
Often the first ask, and a sensible floor for everyone.
It is required for many UK public-sector contracts and increasingly named in client supplier audits and insurance questionnaires.
Even where it is not mandated, it is a credible, affordable baseline that demonstrates you take the fundamentals seriously.
How we help
From scope to certificate, then kept current.
- Scope the assessment and identify gaps before you submit
- Close those gaps and gather the evidence assessors actually accept
- Certification delivered through certified assessment partners
- Maintain it year-round through continuous compliance, so renewal is routine
Ready for Cyber Essentials?
Tell us about your setup and we’ll map the quickest credible path to certification.
Book a call