Ready to Pursue Cyber Essentials Certification?
Get a readiness assessment against all five control themes before you submit a self-assessment or book a Cyber Essentials Plus audit.
Cyber Essentials is the UK government-backed baseline cybersecurity certification, overseen by the NCSC and delivered through IASME's certification-body network. Cyberox provides readiness assessment and remediation support ahead of self-assessment (Cyber Essentials) or independent technical verification (Cyber Essentials Plus).
Last reviewed: September 2026. Verify current requirements against the official regulator before acting — sources linked below.
Cyber Essentials is a UK government-backed scheme launched in 2014 and owned by the National Cyber Security Centre (NCSC), with IASME acting as the NCSC's delivery partner managing the network of certification bodies and assessors since 2020.
Cyber Essentials is a self-assessed questionnaire verified by a certification body. Cyber Essentials Plus covers the same five control themes but requires an independent assessor to technically verify the controls are actually implemented and working on live systems — a materially higher bar.
The scheme's five core control themes remain unchanged, but the April 2026 update raises the minimum password length to 12 characters (from 8), places greater emphasis on passwordless authentication and MFA (including passkeys), and tightens requirements around cloud services, home working, thin clients and BYOD.
Cyber Essentials is commonly required as a condition of UK government contracts and is increasingly requested by private-sector buyers and insurers as baseline evidence of cybersecurity hygiene — including from suppliers outside the UK bidding into UK supply chains.
Non-UK organizations selling into UK public-sector or enterprise supply chains, or seeking a fast, internationally recognized baseline certification alongside ISO 27001, often pursue Cyber Essentials specifically for that purpose.
Confirm current scheme requirements, assessment-account timing (the April 2026 changes apply to assessment accounts created after that date) and certification-body process directly with IASME or the NCSC before starting.
We assess your environment against all five control themes before you submit a self-assessment or book an independent Cyber Essentials Plus audit — so gaps are found by us, not by the assessor.
A broader ISMS certification that Cyber Essentials' technical controls fit naturally within.
Learn moreTechnical testing that supports Cyber Essentials' secure-configuration and patch-management themes.
Learn moreRelated EU/UK-adjacent regulatory obligations for organizations serving both markets.
Learn moreGet a readiness assessment against all five control themes before you submit a self-assessment or book a Cyber Essentials Plus audit.