Compliance

Cyber Essentials

Cyber Essentials certification

Cyber Essentials is a UK government-backed certification scheme, overseen by the National Cyber Security Centre and delivered operationally through IASME as the appointed delivery partner, that checks a defined set of basic technical controls proven to protect organisations against the most common internet-based cyber attacks.

Why Cyber Essentials matters in a Microsoft estate

Cyber Essentials matters because customers, resellers, and procurement teams need evidence that controls are defined, operated, and reviewable. A useful glossary definition should help a reader connect the term to audit preparation, policy work, or repeatable assurance activity.

How Cyber Essentials shows up in practice

The scheme deliberately does not attempt to cover every possible security control. It focuses on five specific technical areas chosen because they close the attack paths most commonly exploited in practice: firewalls and internet gateways controlling network traffic at the boundary, secure configuration removing unnecessary default accounts and settings on devices and software, user access control ensuring accounts and administrative privilege are granted only where genuinely needed, malware protection, and security update management ensuring software and operating systems are patched promptly rather than left exposed to known, already-fixed vulnerabilities. Certification is achieved through a self-assessment questionnaire, verified by an accredited certification body, and it needs renewing annually, since the controls being checked and the threat landscape they are meant to counter both continue to evolve.

For UK organisations, Cyber Essentials has become a genuinely practical commercial requirement rather than a purely voluntary security exercise. It is mandatory for suppliers bidding on many UK government contracts, and it has increasingly become an implicit baseline expectation in wider commercial procurement and cyber insurance underwriting. Failing to hold current certification can therefore function as a real, immediate barrier to specific revenue, rather than only a theoretical security gap. The assurance level is important to be precise about. Standard Cyber Essentials certification is based on self-assessment, verified by the certification body reviewing the submitted questionnaire responses rather than independently testing the organisation's actual systems. This is the exact gap the higher-assurance Cyber Essentials Plus adds, through independent technical verification, and organisations should be clear about which level a specific customer, contract, or insurer is actually asking for before assuming standard certification is sufficient.

Glossary