Cyber Essentials
Cyber Essentials is the UK government-backed baseline scheme run by IASME on behalf of the NCSC. Self-assessment covers five technical control areas. Certification is annual.
Who it applies to
Any UK organisation of any size — mandatory for many UK government contracts handling sensitive information.
How ISO-STANDARD.app helps with Cyber Essentials
10 in-depth articles
The five Cyber Essentials controls in plain English
Firewalls, secure configuration, access control, malware protection, patching. Simple to name, easy to get wrong on scope.
Firewalls and internet gateways
Every device connecting to the internet needs a properly configured firewall. Home routers count when staff work from home.
Secure configuration
Default passwords changed, unused accounts and software removed, auto-run disabled. This is the control that catches the most self-assessment errors.
User access control
Least privilege, separate admin accounts, MFA on cloud services and admin accounts. Not just enterprise identity — every SaaS matters.
Malware protection
Anti-malware, application allow-listing, or a sandboxed application execution model. Any one of these approaches passes, done properly.
Security update management
OS and application updates applied within 14 days of release for high or critical severity. This is a hard deadline, not a target.
How ISO-STANDARD.app helps with Cyber Essentials
Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials shape.
Getting your Cyber Essentials scope right
Scope is where assessors find issues. Include too little and you fail; include too much and you fail differently.
The default: whole organisation
IASME expects you to scope your whole organisation by default. Sub-scoping requires a defensible boundary and is scrutinised.
Cloud services
In-scope cloud services must meet MFA and access requirements. That includes SaaS marketing tools, not just AWS.
BYOD
Personal devices used for work are typically in scope — including for email. Address BYOD properly or exclude the use case.
Boundary documentation
Draw a boundary diagram. If you can't explain scope in a diagram, you can't defend it in an assessment.
How ISO-STANDARD.app helps with Cyber Essentials
Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials shape.
Cyber Essentials MFA: what actually counts
MFA looks simple until you read the requirements. SMS is on the edge; app-based prompts are the safer path.
Cloud services
MFA required on all cloud services accessed by users, and admin accounts on cloud services.
Admin accounts everywhere
Admin accounts on servers, endpoints, and cloud consoles require MFA — a common miss for on-prem estates.
Acceptable factors
Authenticator apps, hardware keys, biometrics. SMS is discouraged but not banned outright — expect assessor pushback.
Legacy exceptions
Legacy systems that genuinely cannot support MFA need a documented compensating control. This is a narrow path — most legacy systems can be fronted by an SSO that adds MFA.
How ISO-STANDARD.app helps with Cyber Essentials
Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials shape.
The 14-day patching window: how to actually hit it
'Within 14 days of release' is a real deadline. Metrics beat wishful thinking.
The rule
Critical and high-severity vulnerabilities patched within 14 days of vendor release. This applies to OS, browsers, and applications.
Auto-update where possible
Consumer OS and Office suites default to acceptable. Server and business applications usually need managed patching.
EOL software
Software that's out of support cannot receive patches — so it fails Cyber Essentials. Replace or isolate before assessment.
Evidence
You need patch reports covering the 30 days before assessment. Screenshots of your patch tool are usually accepted.
How ISO-STANDARD.app helps with Cyber Essentials
Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials shape.
The seven most common Cyber Essentials failure points
IASME publishes trends. The failure list barely changes year to year — which means most failures are avoidable.
Unsupported software in scope
Windows Server 2012 R2, old macOS, old iOS. Inventory your fleet by OS version before applying.
MFA gaps on cloud admin accounts
Users MFA'd, admins forgotten. Or MFA on Microsoft 365 users but not on the tenant admin.
Firewall not verified
Default rules not reviewed. Home-worker routers unchecked. Assessors ask for specifics — 'we have a firewall' is not enough.
Patching evidence weak
Reports going back 30 days are the standard. Manual patching without reporting rarely convinces.
Personal devices
BYOD ignored, then discovered. Either enrol properly with MDM or exclude the use case.
User inventory outdated
Leavers not fully offboarded. Every quarter, review joiners/movers/leavers before applying.
Cloud service inventory incomplete
Marketing SaaS, sales SaaS, HR SaaS all count. Inventory beyond the IT-managed list.
How ISO-STANDARD.app helps with Cyber Essentials
Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials shape.
Cyber Essentials vs Cyber Essentials Plus: what's the extra work?
CE is self-assessment. CE+ adds hands-on testing by an assessor. Same controls, higher assurance.
Same technical requirements
CE and CE+ measure against the same five control areas. If CE passes, the control model is right.
Testing added
CE+ adds an on-site (or remote) test: external vulnerability scan, authenticated scan of a sample of devices, email and browser MFA verification, malware protection test.
Sample selection
The assessor selects the sample from your device inventory. A messy inventory means a bad sample and a hard day.
Timing
CE+ must be done within three months of CE. Plan the CE application knowing CE+ is coming.
How ISO-STANDARD.app helps with Cyber Essentials
Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials shape.
Why buyers ask for Cyber Essentials
It's the fastest, cheapest signal in UK B2B that basic hygiene is in place. That's why procurement asks.
UK Government contracts
Central government contracts handling sensitive information typically require CE. Many require CE+. This is a bid gate, not a nice-to-have.
Wider procurement usage
Local government, NHS, MoD supply chain, financial services procurement teams increasingly ask. Having it removes friction.
Marketing signal
The badge on the website tells UK SME buyers you've cleared a basic bar. It's a small signal but a well-recognised one.
Insurance
Some cyber insurers reduce premiums or waive excess for CE-certified firms. Ask when renewing.
How ISO-STANDARD.app helps with Cyber Essentials
Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials shape.
Navigating the IASME question set
The question set is dense. Read it once end-to-end before you answer anything.
Read first, answer second
The questions interlock. Answers about scope drive answers about controls. Reading end-to-end prevents contradictions the assessor will pick up.
Screenshots and evidence
Some questions expect specifics: 'How do you know?' Take screenshots as you verify controls.
Honesty saves time
If a control isn't in place, say so and remediate before submission. Claiming a control you don't have wastes everyone's time.
Second reviewer
Have someone other than the applicant review the submission. Fresh eyes catch inconsistencies.
How ISO-STANDARD.app helps with Cyber Essentials
Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials shape.
Cyber Essentials for remote and hybrid workers
Home working made scope harder. Address it head-on rather than pretending it doesn't exist.
Corporate devices at home
Same controls apply as in the office: patching, MFA, malware protection, secure configuration. Home broadband is not in scope; the device is.
Home routers
Home routers are generally out of scope if the device has its own firewall and it's configured to treat the home network as untrusted.
BYOD from home
Same rules as any BYOD — MDM or exclusion. Half-measures fail.
Data on home devices
Cloud-first storage, not local. If local files are unavoidable, encryption and endpoint policy matter more.
How ISO-STANDARD.app helps with Cyber Essentials
Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials shape.
Cyber Essentials renewal: turning it into continuous improvement
Certification is a moment. What buyers actually value is the year-round posture behind the badge.
Annual renewal
The certificate is valid for 12 months. Renewal is a fresh assessment, not a rollover.
Between certifications
Quarterly control checks stop drift. Patching reports, MFA coverage, joiner/mover/leaver — instrument the controls that fail most often.
Feed the Trust Center
Publish your current CE status, badge and expiry date. Buyers appreciate the transparency and stop asking.
Upgrade path
CE this year, CE+ next, ISO 27001 the year after. Signal a maturity trajectory, not just a point-in-time badge.
How ISO-STANDARD.app helps with Cyber Essentials
Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials shape.
Ready to evidence Cyber Essentials?
Load the pre-mapped controls, capture evidence continuously, and publish your Cyber Essentials posture to buyers on demand.
Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.