How this links to the Cyber Security and Resilience Bill
Nothing in the Cyber Security and Resilience Bill requires Cyber Essentials. The Bill’s duty is to take appropriate and proportionate measures, judged by regulators using outcome-based frameworks such as the CAF. Cyber Essentials is a useful baseline and supply chain signal, but it covers only a fraction of what the Bill expects.
- The five controls map to part of CAF Objective B (protection), not to detection, response or governance.
- It does not address the 24-hour and 72-hour incident reporting duties or customer notification.
- Buyers may still use it to screen suppliers, including potential critical suppliers.
- Any future code of practice under clause 36 could reference it, but nothing is settled.
What does Cyber Essentials cover?
The scheme was launched by the UK government in 2014 and is overseen by the NCSC, with IASME as delivery partner since 2020. It is designed to stop the most common, low-skill internet attacks, such as exploitation of unpatched software, weak default settings and phishing-borne malware.
Basic certification is a verified self-assessment questionnaire. Cyber Essentials Plus adds a hands-on technical audit, including vulnerability scans and checks on sampled devices. Both test the same five controls, and certification must be renewed every year.
- Firewalls
- Secure configuration
- Security update management
- User access control
- Malware protection
Why is Cyber Essentials not enough for the Bill?
The Bill’s security duties are outcome-based and scaled to the risk to essential or digital services. Regulators assess them using the Cyber Assessment Framework, which covers governance, supply chain, monitoring and recovery.
Cyber Essentials says nothing about detecting an incident quickly enough to meet the 24-hour clock, or about reporting to a regulator. A certified managed service provider still has registration, security and reporting duties once the Bill commences, and can face penalties in the higher band, the greater of £17m and 4% of turnover, for security or notification failures.
Cyber Essentials compared with the Bill’s duties
| Area | Cyber Essentials | Cyber Security and Resilience Bill |
|---|---|---|
| Legal status | Voluntary certification | Statutory duties with penalties |
| Scope | Five technical controls | Whole-organisation risk management |
| Incident reporting | Not covered | 24-hour initial and 72-hour full report |
| Assessment | Self-assessment or Plus audit | Regulator oversight, often against the CAF |
Common misconceptions
Myth: Cyber Essentials makes you compliant with the Bill.
Reality: It does not. It shows a baseline of technical hygiene, but the Bill requires risk-based measures, incident reporting and regulator engagement that the scheme does not cover.
Where it appears in the Bill
- Clause 19Regulator guidance on appropriate and proportionate measures; no named certification.
- Clause 36Power to issue a code of practice; content not yet published.
References are to HL Bill 32 as brought from the Commons. Read the Bill.
Frequently asked questions
Does the Cyber Security and Resilience Bill require Cyber Essentials certification?
No. The Bill does not mention Cyber Essentials. Regulated organisations must take appropriate and proportionate security measures and report significant incidents. Regulators judge those measures against outcome-based frameworks such as the CAF, so certification is helpful supporting evidence but not a legal requirement or a route to compliance.
Is Cyber Essentials still worth having if my organisation is in scope?
Yes, as a baseline. It evidences basic hygiene, is often required in public sector contracts, and helps customers screen suppliers. Organisations in scope of the Bill should treat it as a floor and build CAF-level governance, monitoring and incident response on top, because those are the areas the new duties focus on.
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Both cover the same five technical controls. Cyber Essentials is a verified self-assessment questionnaire. Cyber Essentials Plus adds an independent hands-on audit, including vulnerability scanning and checks that the controls work on sampled devices. Neither addresses the incident reporting or governance duties in the Cyber Security and Resilience Bill.