ResourcesGuide · 12-minute read

Cyber Essentials, made straightforward.

A clear walk-through of what Cyber Essentials asks of you, how the assessment works, and how to prepare before you sit it. Written for leadership teams and IT leads to read side by side.

What Cyber Essentials actually is

Cyber Essentials is a UK government-backed certification covering five technical controls: boundary firewalls, secure configuration, user access control, malware protection, and patch management. It's the baseline that says you've done the work most cyber attacks rely on you not having done.

There are two levels. Standard Cyber Essentials is self-assessed: you answer a structured questionnaire, an IASME-accredited Certification Body reviews it, and you receive a certificate. Cyber Essentials Plus is the audited variant: an independent assessor runs technical tests on a sample of your devices.

Why most organisations are doing this now

Three reasons, usually in this order: an insurer asked for it at renewal, a customer asked for it during a procurement exercise, or the board asked for it after a near-miss. Procurement teams across UK government and the public sector now treat Cyber Essentials as a baseline rather than a differentiator.

It's also the cheapest meaningful security certification on the market. The controls are practical and the scope is bounded; the work doesn't require a six-figure programme.

What we recommend before you sit the assessment

Run a readiness review against the five controls and write down where the gaps are. The standard moves slightly each year, so don't assume last year's setup still passes.

Prioritise the gaps by likely exploitation, not by how easy they are to close. Patch cadence and admin separation usually matter more than another endpoint tool.

Get the evidence ready before you start the questionnaire. The questionnaire isn't hard; assembling the evidence from a fragmented IT estate is what takes the time.

What the assessment process actually looks like

You scope what's in (which sites, networks, devices, and cloud services), answer the questionnaire, attach the evidence, submit, and the certifier reviews. If anything's missing they come back with questions; once it's clean you receive the certificate within days.

For Cyber Essentials Plus you also book a technical audit, sample devices are tested for vulnerability scanning, MFA enforcement, and the technical control set. Pass cleanly and the certificate is issued; fail on a control and you remediate and re-test.

After you certify

The certificate is annual. Most of the work to recertify is keeping the controls running, not redoing them. The standard updates each cycle (most recent: the Montpellier release moved guidance on MFA, BYOD, and cloud services), so review what's changed before renewal.

If Cyber Essentials Plus is a future requirement, do the work now: the remediation is identical, the difference is the independent audit and a slightly tighter evidence pack.

Would you like help certifying?

Osiris IT is an IASME-accredited Cyber Essentials Certification Body. We can take you from readiness through to certification directly, with no reseller margin in between.