Glossary · Related frameworks

Cyber Essentials

Definition

Cyber Essentials is a UK government-backed certification scheme, launched in 2014 and overseen by the NCSC, that verifies five baseline technical controls against common internet-based attacks. Cyber Essentials Plus adds independent technical testing. The Cyber Security and Resilience Bill does not require it, and certification alone does not meet the Bill’s duties.

What does Cyber Essentials cover?

The scheme was launched by the UK government in 2014 and is overseen by the NCSC, with IASME as delivery partner since 2020. It is designed to stop the most common, low-skill internet attacks, such as exploitation of unpatched software, weak default settings and phishing-borne malware.

Basic certification is a verified self-assessment questionnaire. Cyber Essentials Plus adds a hands-on technical audit, including vulnerability scans and checks on sampled devices. Both test the same five controls, and certification must be renewed every year.

  • Firewalls
  • Secure configuration
  • Security update management
  • User access control
  • Malware protection

Why is Cyber Essentials not enough for the Bill?

The Bill’s security duties are outcome-based and scaled to the risk to essential or digital services. Regulators assess them using the Cyber Assessment Framework, which covers governance, supply chain, monitoring and recovery.

Cyber Essentials says nothing about detecting an incident quickly enough to meet the 24-hour clock, or about reporting to a regulator. A certified managed service provider still has registration, security and reporting duties once the Bill commences, and can face penalties in the higher band, the greater of £17m and 4% of turnover, for security or notification failures.

Cyber Essentials compared with the Bill’s duties

AreaCyber EssentialsCyber Security and Resilience Bill
Legal statusVoluntary certificationStatutory duties with penalties
ScopeFive technical controlsWhole-organisation risk management
Incident reportingNot covered24-hour initial and 72-hour full report
AssessmentSelf-assessment or Plus auditRegulator oversight, often against the CAF

Common misconceptions

Myth: Cyber Essentials makes you compliant with the Bill.

Reality: It does not. It shows a baseline of technical hygiene, but the Bill requires risk-based measures, incident reporting and regulator engagement that the scheme does not cover.

Where it appears in the Bill

  • Clause 19Regulator guidance on appropriate and proportionate measures; no named certification.
  • Clause 36Power to issue a code of practice; content not yet published.

References are to HL Bill 32 as brought from the Commons. Read the Bill.

Frequently asked questions

Does the Cyber Security and Resilience Bill require Cyber Essentials certification?

No. The Bill does not mention Cyber Essentials. Regulated organisations must take appropriate and proportionate security measures and report significant incidents. Regulators judge those measures against outcome-based frameworks such as the CAF, so certification is helpful supporting evidence but not a legal requirement or a route to compliance.

Is Cyber Essentials still worth having if my organisation is in scope?

Yes, as a baseline. It evidences basic hygiene, is often required in public sector contracts, and helps customers screen suppliers. Organisations in scope of the Bill should treat it as a floor and build CAF-level governance, monitoring and incident response on top, because those are the areas the new duties focus on.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Both cover the same five technical controls. Cyber Essentials is a verified self-assessment questionnaire. Cyber Essentials Plus adds an independent hands-on audit, including vulnerability scanning and checks that the controls work on sampled devices. Neither addresses the incident reporting or governance duties in the Cyber Security and Resilience Bill.

Related guidance

Official sources

More in Related frameworks

Full glossary