Cyber Essentials

Cyber Essentials is the UK government-backed baseline scheme run by IASME on behalf of the NCSC. Self-assessment covers five technical control areas. Certification is annual.

Who it applies to

Any UK organisation of any size — mandatory for many UK government contracts handling sensitive information.

How ISO-STANDARD.app helps with Cyber Essentials

Pre-loaded Cyber Essentials control mapping crosswalked to ISO 27001 Annex A so you don't duplicate work.

Evidence Vault stores signed, versioned artefacts (screenshots, logs, attestations) auditors and buyers accept.

Trust Center publishes your current Cyber Essentials posture to prospects on demand — no PDF chase.

Internal Audit, CAPA and Management Review workflows built in, mapped to Cyber Essentials clauses.

Policy templates with attestation, review cycles and change history that satisfy assessor sampling.

10 in-depth articles

The five Cyber Essentials controls in plain English

Firewalls, secure configuration, access control, malware protection, patching. Simple to name, easy to get wrong on scope.

Firewalls and internet gateways

Every device connecting to the internet needs a properly configured firewall. Home routers count when staff work from home.

Secure configuration

Default passwords changed, unused accounts and software removed, auto-run disabled. This is the control that catches the most self-assessment errors.

User access control

Least privilege, separate admin accounts, MFA on cloud services and admin accounts. Not just enterprise identity — every SaaS matters.

Malware protection

Anti-malware, application allow-listing, or a sandboxed application execution model. Any one of these approaches passes, done properly.

Security update management

OS and application updates applied within 14 days of release for high or critical severity. This is a hard deadline, not a target.

How ISO-STANDARD.app helps with Cyber Essentials

Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials shape.

Getting your Cyber Essentials scope right

Scope is where assessors find issues. Include too little and you fail; include too much and you fail differently.

The default: whole organisation

IASME expects you to scope your whole organisation by default. Sub-scoping requires a defensible boundary and is scrutinised.

Cloud services

In-scope cloud services must meet MFA and access requirements. That includes SaaS marketing tools, not just AWS.

BYOD

Personal devices used for work are typically in scope — including for email. Address BYOD properly or exclude the use case.

Boundary documentation

Draw a boundary diagram. If you can't explain scope in a diagram, you can't defend it in an assessment.

How ISO-STANDARD.app helps with Cyber Essentials

Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials shape.

Cyber Essentials MFA: what actually counts

MFA looks simple until you read the requirements. SMS is on the edge; app-based prompts are the safer path.

Cloud services

MFA required on all cloud services accessed by users, and admin accounts on cloud services.

Admin accounts everywhere

Admin accounts on servers, endpoints, and cloud consoles require MFA — a common miss for on-prem estates.

Acceptable factors

Authenticator apps, hardware keys, biometrics. SMS is discouraged but not banned outright — expect assessor pushback.

Legacy exceptions

Legacy systems that genuinely cannot support MFA need a documented compensating control. This is a narrow path — most legacy systems can be fronted by an SSO that adds MFA.

How ISO-STANDARD.app helps with Cyber Essentials

Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials shape.

The 14-day patching window: how to actually hit it

'Within 14 days of release' is a real deadline. Metrics beat wishful thinking.

The rule

Critical and high-severity vulnerabilities patched within 14 days of vendor release. This applies to OS, browsers, and applications.

Auto-update where possible

Consumer OS and Office suites default to acceptable. Server and business applications usually need managed patching.

EOL software

Software that's out of support cannot receive patches — so it fails Cyber Essentials. Replace or isolate before assessment.

Evidence

You need patch reports covering the 30 days before assessment. Screenshots of your patch tool are usually accepted.

How ISO-STANDARD.app helps with Cyber Essentials

Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials shape.

The seven most common Cyber Essentials failure points

IASME publishes trends. The failure list barely changes year to year — which means most failures are avoidable.

Unsupported software in scope

Windows Server 2012 R2, old macOS, old iOS. Inventory your fleet by OS version before applying.

MFA gaps on cloud admin accounts

Users MFA'd, admins forgotten. Or MFA on Microsoft 365 users but not on the tenant admin.

Firewall not verified

Default rules not reviewed. Home-worker routers unchecked. Assessors ask for specifics — 'we have a firewall' is not enough.

Patching evidence weak

Reports going back 30 days are the standard. Manual patching without reporting rarely convinces.

Personal devices

BYOD ignored, then discovered. Either enrol properly with MDM or exclude the use case.

User inventory outdated

Leavers not fully offboarded. Every quarter, review joiners/movers/leavers before applying.

Cloud service inventory incomplete

Marketing SaaS, sales SaaS, HR SaaS all count. Inventory beyond the IT-managed list.

How ISO-STANDARD.app helps with Cyber Essentials

Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials shape.

Cyber Essentials vs Cyber Essentials Plus: what's the extra work?

CE is self-assessment. CE+ adds hands-on testing by an assessor. Same controls, higher assurance.

Same technical requirements

CE and CE+ measure against the same five control areas. If CE passes, the control model is right.

Testing added

CE+ adds an on-site (or remote) test: external vulnerability scan, authenticated scan of a sample of devices, email and browser MFA verification, malware protection test.

Sample selection

The assessor selects the sample from your device inventory. A messy inventory means a bad sample and a hard day.

Timing

CE+ must be done within three months of CE. Plan the CE application knowing CE+ is coming.

How ISO-STANDARD.app helps with Cyber Essentials

Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials shape.

Why buyers ask for Cyber Essentials

It's the fastest, cheapest signal in UK B2B that basic hygiene is in place. That's why procurement asks.

UK Government contracts

Central government contracts handling sensitive information typically require CE. Many require CE+. This is a bid gate, not a nice-to-have.

Wider procurement usage

Local government, NHS, MoD supply chain, financial services procurement teams increasingly ask. Having it removes friction.

Marketing signal

The badge on the website tells UK SME buyers you've cleared a basic bar. It's a small signal but a well-recognised one.

Insurance

Some cyber insurers reduce premiums or waive excess for CE-certified firms. Ask when renewing.

How ISO-STANDARD.app helps with Cyber Essentials

Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials shape.

Navigating the IASME question set

The question set is dense. Read it once end-to-end before you answer anything.

Read first, answer second

The questions interlock. Answers about scope drive answers about controls. Reading end-to-end prevents contradictions the assessor will pick up.

Screenshots and evidence

Some questions expect specifics: 'How do you know?' Take screenshots as you verify controls.

Honesty saves time

If a control isn't in place, say so and remediate before submission. Claiming a control you don't have wastes everyone's time.

Second reviewer

Have someone other than the applicant review the submission. Fresh eyes catch inconsistencies.

How ISO-STANDARD.app helps with Cyber Essentials

Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials shape.

Cyber Essentials for remote and hybrid workers

Home working made scope harder. Address it head-on rather than pretending it doesn't exist.

Corporate devices at home

Same controls apply as in the office: patching, MFA, malware protection, secure configuration. Home broadband is not in scope; the device is.

Home routers

Home routers are generally out of scope if the device has its own firewall and it's configured to treat the home network as untrusted.

BYOD from home

Same rules as any BYOD — MDM or exclusion. Half-measures fail.

Data on home devices

Cloud-first storage, not local. If local files are unavoidable, encryption and endpoint policy matter more.

How ISO-STANDARD.app helps with Cyber Essentials

Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials shape.

Cyber Essentials renewal: turning it into continuous improvement

Certification is a moment. What buyers actually value is the year-round posture behind the badge.

Annual renewal

The certificate is valid for 12 months. Renewal is a fresh assessment, not a rollover.

Between certifications

Quarterly control checks stop drift. Patching reports, MFA coverage, joiner/mover/leaver — instrument the controls that fail most often.

Feed the Trust Center

Publish your current CE status, badge and expiry date. Buyers appreciate the transparency and stop asking.

Upgrade path

CE this year, CE+ next, ISO 27001 the year after. Signal a maturity trajectory, not just a point-in-time badge.

How ISO-STANDARD.app helps with Cyber Essentials

Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials shape.

Ready to evidence Cyber Essentials?

Load the pre-mapped controls, capture evidence continuously, and publish your Cyber Essentials posture to buyers on demand.

Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.

AI-enabled — privacy-respecting

AI does the drafting. You keep the control — and the data.

How we handle data →
  • AI that assists — not replaces

    Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.

  • Opt-in, workspace-scoped

    AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.

  • Your data stays yours

    Prompts routed via the Lovable AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.

  • Isolated by design

    Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.

We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.

MM
Michael McCarroll
Founder · 25+ years
IT governance · Information security · AI
Why this platform exists

Enterprise-grade governance — built for the SMEs and consultants enterprise GRC forgets.

I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.