Cyber Essentials certification guide
The UK government's baseline cybersecurity certification, explained step by step. The five controls, the self-assessment, what trips most applicants up — and how to certify in a fortnight.
The UK government's baseline cybersecurity certification, explained step by step. The five controls, the self-assessment, what trips most applicants up — and how to certify in a fortnight.
Cyber Essentials is a UK government–backed certification scheme operated by IASME on behalf of the National Cyber Security Centre (NCSC). It certifies that your organisation has implemented five fundamental technical controls that, according to NCSC, protect against around 80% of common internet-borne attacks.
It is a verified self-assessment: you complete a questionnaire, an assessor reviews it, and a pass earns a one-year certificate. It is the entry-level scheme — Cyber Essentials Plus adds an independent audit.
Every control in Cyber Essentials maps directly to ISO 27001 Annex A. If you're aiming for ISO 27001 within the next 12 months, doing Cyber Essentials first is a low-cost way to validate the technical baseline before the bigger audit.
ISO-STANDARD.app ships a ready-to-adopt Cyber Essentials workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.
Prefer a conversation? Email hello@iso-standard.app — a real human responds within one business day.