Cyber Essentials is often treated as a technical certification, but compliance managers play a central role in making it work. IT, security or an external provider may implement the controls, yet compliance usually coordinates scope, ownership, evidence, risk decisions and certification activity.
The scheme provides a baseline for protecting organisations against common internet-based threats. It is suitable for organisations of all sizes and is increasingly requested by customers, government bodies and supply-chain partners.
The National Cyber Security Centre’s Cyber Essentials overview explains the scheme, its five technical controls and the difference between Cyber Essentials and Cyber Essentials Plus.
What Cyber Essentials covers
Cyber Essentials is based on five technical control areas:
- Firewalls.
- Secure configuration.
- Security update management.
- User access control.
- Malware protection.
The current technical requirements are reviewed periodically. Organisations preparing an assessment should check the latest Cyber Essentials Requirements for IT Infrastructure, including any changes affecting cloud services, remote working, third-party access or device scope.
Cyber Essentials is not a complete information-security management system. It focuses on fundamental technical measures that reduce exposure to common attacks. It does not replace broader work on risk management, supplier governance, incident response, privacy, business continuity or management oversight.
The compliance manager’s role
Define and document the scope
Scope is one of the most important decisions in the Cyber Essentials process. The organisation must identify the systems, devices, users, networks, cloud services and accounts covered by the assessment.
A compliance manager should coordinate with IT, security, engineering, operations and relevant suppliers to clarify:
- Which legal entity or business unit is applying.
- Which products and services are included.
- Which offices and locations are in scope.
- Which employee and contractor devices are included.
- Which cloud accounts and infrastructure are covered.
- Which remote-working arrangements need to be assessed.
- Which third-party administrators have access.
- Which systems are excluded and why.
A narrow scope is not automatically a problem, but it must be accurate and defensible. Excluding a system that supports an in-scope service or processes relevant data can create a misleading result.
A risk management framework can help connect the scope decision to ownership, treatment decisions, evidence and ongoing review.
Assign control owners
Cyber Essentials should not be owned by one person alone. The compliance manager may coordinate the programme, but each technical area should have a responsible owner.
For example:
- IT or network security may own firewall configuration.
- Infrastructure teams may own secure configuration.
- IT operations may own security updates.
- Identity or IT teams may own access controls.
- Endpoint or security teams may own malware protection.
- Procurement or compliance may coordinate supplier evidence.
- Senior management may approve the scope and certification submission.
The owner should be able to explain how the control operates, what evidence supports it and what happens when it fails.
Understand shared responsibility
Cloud providers, managed service providers and outsourced IT teams may implement some controls on the organisation’s behalf. That does not automatically remove the organisation’s responsibility.
The compliance manager should record:
- Which control is being provided by the supplier.
- What evidence confirms that responsibility.
- Which parts remain the organisation’s responsibility.
- How changes or incidents will be communicated.
- Whether the supplier’s scope matches the organisation’s assessed environment.
For SaaS businesses, this should also connect with the wider SaaS privacy and supplier-risk picture. PrivaLex can help review supplier evidence, shared-responsibility arrangements and the effect of third-party access on the Cyber Essentials scope.
Preparing for Cyber Essentials with PrivaLex
Our compliance consultancy services help organisations prepare for Cyber Essentials by connecting the technical requirements with scope, ownership, risk and evidence.
We support the initial scope decision, including systems, devices, cloud services, suppliers, remote-working arrangements and third-party administration. We then help map each Cyber Essentials control to a responsible owner and supporting record.
Where gaps exist, we help prioritise remediation, document exceptions and establish realistic deadlines. This may include improving access reviews, patch-management records, secure-configuration standards and endpoint-protection evidence.
The security-update process can also be connected to an ISO 27001 risk treatment plan. This helps ensure that overdue patches, unsupported systems and approved exceptions have a defined owner, deadline, treatment decision and review date.
For organisations using SaaS providers, cloud infrastructure or managed IT services, we help clarify shared responsibility. This includes reviewing supplier evidence, documenting contractual expectations and identifying which controls must be operated internally.
For Cyber Essentials Plus, we help prepare for independent technical testing by reviewing the evidence, checking the consistency of control implementation and identifying areas that could cause an assessment failure. Where cloud exposure or sensitive data is a concern, PrivaLex’s approach to creating an ISO 27001 risk assessment can help identify assets, access risks and control gaps.
Where ISO 27001, UK GDPR, NIS2, DORA, ENS or customer-security requirements also apply, we map shared controls and evidence into one programme. This reduces duplicated work while keeping each framework’s specific obligations visible.
The independent certification body remains responsible for the certification decision, but PrivaLex helps make the preparation more structured, practical and easier for teams to maintain.
Cyber Essentials and Cyber Essentials Plus
Cyber Essentials and Cyber Essentials Plus assess the same five technical control areas, but they provide different levels of assurance.
| Area | Cyber Essentials | Cyber Essentials Plus |
| Assessment approach | Verified self-assessment | Self-assessment followed by independent technical testing |
| Technical controls | The same five controls | The same five controls |
| Independent testing | No technical testing of the environment | Includes technical testing and sampling |
| Level of assurance | Baseline assurance | Higher assurance that controls work in practice |
| Suitable for | Organisations establishing a recognised technical baseline | Organisations facing higher customer, contractual or supply-chain expectations |
Cyber Essentials may be enough for an organisation that needs to demonstrate a baseline of controls. Cyber Essentials Plus can be more appropriate where customers, government contracts or risk exposure require independent verification.
Certification is not permanent. Organisations should continue monitoring their environment, because changes to systems, devices, software, cloud services and access arrangements can affect whether the controls remain effective.
Preparing for the 5 technical controls
- Firewalls
Firewalls create a security boundary between trusted and untrusted networks. The organisation should understand how internet traffic reaches its systems and which services are deliberately exposed.
Preparation should include identifying internet-facing services, removing unnecessary open ports, reviewing inbound and outbound rules, restricting administration interfaces and documenting exceptions. Cloud security groups and network controls should also be included where they form part of the assessed environment.
PrivaLex can help connect firewall evidence with the wider risk register and determine whether exposed services create additional customer, privacy or continuity concerns.
- Secure configuration
Secure configuration reduces unnecessary exposure by removing default accounts, disabling unused services, changing default passwords and applying appropriate security settings.
The compliance manager should confirm whether standard builds are documented, unnecessary services are disabled, administrative privileges are restricted and secure settings are applied consistently across devices and cloud resources.
Configuration standards should be practical enough for teams to follow and specific enough to support assessment evidence. Exceptions should be documented and reviewed rather than handled through informal workarounds.
- Security update management
Security updates reduce the risk that attackers will exploit known vulnerabilities. The organisation should have a defined process for identifying, prioritising, deploying and verifying updates.
This includes:
- Maintaining an inventory of devices and software.
- Tracking supported and unsupported versions.
- Applying updates within required timeframes.
- Prioritising actively exploited or high-impact vulnerabilities.
- Recording exceptions where updates cannot be applied.
- Verifying that updates have been deployed.
- Escalating overdue remediation.
The process should cover laptops, servers, network devices, cloud workloads, applications and relevant third-party components. It should also connect with the organisation’s broader approach to protecting infrastructure from cyber attacks, so asset coverage, patching and access controls are assessed together.
PrivaLex can help turn patching and vulnerability findings into assigned actions, risk decisions and evidence that can be reviewed by management or an assessor.
- User access control
User access controls ensure that people have access only to the systems and information required for their role.
A compliance manager should coordinate evidence for:
- User account creation and approval.
- Joiner, mover and leaver processes.
- Administrative accounts.
- Multi-factor authentication where required.
- Password and authentication controls.
- Privileged-access reviews.
- Dormant and shared accounts.
- Contractor and supplier access.
- Periodic access recertification.
Access should be removed promptly when a person leaves or no longer needs it. Privileged access should be limited, monitored and reviewed more frequently than ordinary user access.
- Malware protection
Malware protection should reduce the chance that malicious software can execute, spread or access systems and data.
The organisation should be able to demonstrate endpoint protection coverage, protection-status monitoring, restrictions on unauthorised software, secure handling of removable media, alerting and response procedures, and escalation when protection is disabled.
The compliance manager should verify that the technical control applies to the actual devices within scope, not only to centrally managed office equipment. PrivaLex can help identify gaps between endpoint policy and the devices employees, contractors or suppliers actually use.
Evidence that supports certification
The Cyber Essentials assessment may rely on answers and supporting information, but evidence should be collected before the assessment begins.
Useful evidence can include:
- Network and firewall diagrams.
- Asset and device inventories.
- Secure-configuration standards.
- Patch and vulnerability reports.
- Endpoint-protection dashboards.
- Access-review records.
- Joiner, mover and leaver procedures.
- Supplier contracts and shared-responsibility statements.
- Cloud security documentation.
- Approved exceptions.
- Incident and remediation records.
- Management approval of scope and key risk decisions.
Evidence should be current and connected to the assessed environment. A policy that has not been implemented or a screenshot from an unrelated system will not provide meaningful assurance.
A central evidence register can help the compliance manager track the control being evidenced, the evidence owner, the date collected, the period covered, any limitations or exclusions, the next review date and corrective actions.
PrivaLex can help organise this evidence so that it supports Cyber Essentials, customer due diligence, ISO 27001 preparation and broader security reviews without creating separate documentation for every request.
7 Common Cyber Essentials Gaps
1. Incomplete asset inventories
Devices, cloud accounts, test environments and supplier-managed systems are often missing from the inventory. This creates a scope problem because the organisation cannot demonstrate that every relevant asset is covered by the required controls.
The inventory should be reconciled against procurement records, identity systems, cloud accounts, endpoint tools and supplier arrangements. A cloud data security platform can also improve visibility into cloud assets, sensitive data and access paths.
Every asset should have an owner and a review process so that new systems are included promptly.
2. Outdated software and unsupported systems
Unsupported operating systems, applications or network devices may no longer receive security updates. They can remain unnoticed when the organisation lacks a complete software inventory or relies on individual teams to manage updates independently.
A compliance manager should ensure that unsupported systems have a documented replacement or isolation plan. If a temporary exception is required, it should include a risk owner, compensating controls and a deadline for removal.
These decisions can be tracked through an ISO 27001 risk treatment plan, with PrivaLex helping to connect overdue vulnerabilities to owners, deadlines and management review.
3. Excessive administrative access
Too many users may have privileged permissions, or administrator accounts may be shared and not reviewed. This increases the potential impact of stolen credentials or insider misuse.
The organisation should define who needs administrative access, separate ordinary and privileged accounts where appropriate, apply stronger authentication and review permissions periodically. Former employees, contractors and suppliers should be removed without delay.
4. Unclear cloud responsibility
Organisations sometimes assume that a cloud provider manages every security control. In practice, the provider and customer share responsibility for configuration, accounts, workloads, data and access.
The organisation should document which controls are provided by the cloud provider and which are managed internally. Supplier contracts, trust-centre documents and configuration records should support the assessment answers.
5. Weak leaver processes
Access can remain active after employees, contractors or suppliers leave. This is particularly risky when identity systems, cloud consoles, repositories and support tools are managed by different teams.
A reliable leaver process should identify all relevant accounts, assign responsibility for disabling them and record completion. Periodic reconciliation can reveal accounts that were missed during individual departures.
6. Unmanaged remote devices
Home-working devices and personally used systems may not receive the same configuration, update or malware protection as office equipment. This can create gaps in the assessed environment and make it difficult to confirm whether controls operate consistently.
The organisation should define which remote devices are permitted, how they are managed and what happens when a device falls outside the required standard. Remote access should also be reviewed alongside identity and endpoint controls.
7. Undocumented exceptions
Teams may rely on informal workarounds when a patch cannot be applied, a legacy system cannot be replaced or a control is temporarily unavailable. If these exceptions are not recorded, management cannot understand the remaining exposure.
Each exception should explain the affected system, reason, compensating controls, risk owner, target date and review date. Exceptions should be visible during management review and closed when the underlying issue is resolved.
How Cyber Essentials supports other frameworks
Cyber Essentials can provide a useful technical baseline for an ISO 27001 programme, but it does not replace the management-system requirements of ISO 27001.
ISO 27001 requires the organisation to define its scope, assess risks, select treatments, assign responsibilities, operate controls, collect evidence, perform internal audits and conduct management reviews.
The two can work together:
- Cyber Essentials supports baseline technical security.
- ISO 27001 provides risk-based governance and continual improvement.
- UK GDPR requires accountability for personal-data processing.
- Supplier reviews connect technical controls with contractual and operational risk.
- Incident management demonstrates how the organisation responds when controls fail.
ISO 27001 certification support can help organisations connect Cyber Essentials with a broader information-security management system instead of managing each requirement as a separate project.
Conclusion
Cyber Essentials gives organisations a practical baseline for defending against common cyber threats. For a compliance manager, success depends on more than completing the assessment. It requires a defensible scope, clear ownership, reliable evidence and a process for addressing changes and exceptions.
The five technical controls should be implemented as part of normal operations, not treated as a one-time certification exercise. Organisations should also connect Cyber Essentials with their wider vulnerability management, supplier oversight, privacy and information-security programmes.
PrivaLex supports organisations that need to make Cyber Essentials practical, auditable and connected to broader security and compliance objectives.
If your organisation is preparing for Cyber Essentials or Cyber Essentials Plus, request a free risk assessment to identify the most important gaps before the assessment begins.
Frequently Asked Questions (FAQs)
Cyber Essentials is a UK government-backed certification scheme based on five technical controls designed to protect organisations against common internet-based cyber threats.
The five controls are firewalls, secure configuration, security update management, user access control and malware protection.
Cyber Essentials involves a verified self-assessment. Cyber Essentials Plus assesses the same five controls but adds independent technical testing to verify that they work in practice.
No. ISO 27001 and Cyber Essentials have different purposes. ISO 27001 is a risk-based information-security management-system standard, while Cyber Essentials focuses on five fundamental technical controls.
Cyber Essentials certification is generally valid for twelve months. Organisations should continue reviewing their systems and controls because changes can affect compliance before the certificate expires.
No. It is not mandatory for every UK company, but customers, public-sector contracts, insurers and supply-chain partners may require Cyber Essentials or Cyber Essentials Plus.
Yes. PrivaLex can support scope definition, gap assessment, control ownership, evidence preparation, remediation planning and integration with ISO 27001, UK GDPR and wider security requirements. The certification body remains responsible for the independent assessment and certification decision.
