What is Cyber Essentials? (CE)

Cyber Essentials is a government-backed, industry-supported scheme to help organisations protect themselves against common cyber attacks. The certification demonstrates to customers, clients and other stakeholders that the organisation has taken the necessary measures to protect their data and systems from cyber threats.

What does Cyber Essentials involve?

The certification process involves a self-assessment questionnaire, and an external vulnerability scan of the organisation’s internet-facing IP addresses.

How long is Cyber Essentials valid for?

The certification is valid for one year and requires annual renewal.

What are the 5 basic technical controls of Cyber Essentials?

The certification is focused on 5 basic technical controls:

  1. Boundary firewalls and internet gateways: protecting against unauthorised access.
  2. Secure configuration: ensuring systems are configured securely.
  3. Access control: controlling who can access systems and data.
  4. Malware protection: protecting against malware and viruses.
  5. Patch management: keeping software up-to-date.
Is Cyber Essentials a legal requirement?

Obtaining CE certification is voluntary and it is not a legal requirement. However, having CE certification demonstrates an organisation’s commitment to cyber security and can be a requirement for bidding on many public-sector contracts.

How much does Cyber Essentials cost?

Cyber Essentials is charged on a tiered system depending on your organisation size

  • Micro Organisation – 0-9 Employees – starting from £300+*
  • Small Organisation – 10-49 employees – starting from £400+*
  • Medium organisation – 50-249 employees – starting from £450+*
  • Large organisation – 250+ employees – starting from £500+*

Please note these prices are a baseline and will differ depending on the Certification Body.

*Excludes VAT.

How long does Cyber Essentials take?

This depends on the size of the company, and the complexity of its infrastructure, but it can take as little as 24 hours to achieve CE.

What is the difference between Cyber Essentials and Cyber Essentials Plus? (CE+)

CE and CE+ are both government-backed, industry-supported schemes to help organisations protect themselves against common cyber attacks. However, there are some key differences between the two:

  1. CE focuses on self-assessment, whereas CE+ includes an external assessment: Organisations can self-asses their compliance with the CE+ scheme by completing a questionnaire, but with CE+, and external certification body will conduct an on-site assessment of the organisation’s technical control.
  2. CE+ includes additional testing: In addition to the self-assessment questionnaire and external vulnerability scan required for CE, CE+ also includes internal and external penetration testing. These tests simulate a cyber attack on the organisation’s systems to identify any vulnerabilities that may have been missed by the self-assessment and external scan.
  3. CE+ is a higher level of certification: The additional testing and external assessment required for CE+ means that it is considered a higher level of certification than CE. Organisations that are certified to CE+ can demonstrate a higher level of cyber security maturity to customers and other stakeholders.

In summary, CE focuses on self-assessment of an organisation’s technical controls, while CE+ includes additional testing and an external assessment verify an organisation’s cyber security maturity.

Can I achieve Cyber Essentials Plus without Cyber Essentials?

To be able to achieve CE+, you must first achieve CE, which you must submit within 6 months of receiving the questionnaire. After completing CE, you can work on CE+ plus and this must be achieved within 3 months of CE being completed, or else the whole process will have to be started again.

What is the difference between Cyber Essentials and IASME gold?

CE and IASME Gold are both certification schemes that help organisations protect themselves against common cyber attacks. However, there are some key differences between the two:

  1. CE is a government-backed scheme, while IASME Gold is an industry-supported certification scheme that was developed independently of the government.
  2. Different levels of certifications: Both CE and IASME Gold offer different levels of certification, but the requirements for each level are different. CE has one certification level, which focuses on self-assessment of an organisation’s technical controls. IASME Gold, on the the other hand, offers two levels of certification: IASME Governance, and IASME Governance Audited (known as IASME Gold).
  3. The focus of the certification: CE certification focuses on the technical controls an organisation has in place to protect against common cyber threats, IAMSE gold certification is more focused on the overall governance of an organisations’ security posture, including risk management, incident management, and business continuity.

Both CE and IASME Gold are certification schemes that help organisations protect themselves against common cyber attacks. While CE is a government-backed scheme that focuses on self-assessment of an organisation’s technical controls, IASME Gold is an industry-supported scheme that offers multiple levels of certification and a more comprehensive focus.