What is Cyber Essentials? A Guide for UK Businesses

Cyber Essentials is a UK Government-backed certification that helps businesses protect themselves against common cyber threats. It also demonstrates to customers that key cyber security controls are in place and is increasingly required when tendering for contracts or joining supplier frameworks.
certification essentials cyber

If a customer, tender document or procurement team has told you that your business needs Cyber Essentials certification, you may be wondering exactly what it is, why you need it and what you have to do to become certified.

Cyber Essentials is a UK Government-backed cyber security certification scheme designed to help organisations protect themselves against the most common cyber threats.

For many businesses, however, Cyber Essentials is becoming important for another reason: customers increasingly want evidence that the companies they work with take cyber security seriously.

That means Cyber Essentials can be about more than protecting your IT systems. In some cases, achieving certification can be a requirement for winning new contracts, joining an approved supplier list or continuing to work with an existing customer.

Protect Your Business Cyber Security Matters in the UK

What is Cyber Essentials?

Cyber Essentials sets out a recognised baseline for cyber security.

Developed by the National Cyber Security Centre (NCSC), it focuses on five technical controls that organisations should have in place to reduce their exposure to common internet-based cyber attacks.

The five areas are:

  • Firewalls
  • Secure configuration
  • Security update management
  • User access control
  • Malware protection

Rather than trying to address every possible cyber security risk, Cyber Essentials concentrates on getting these fundamental protections right.

For an SME, that can make the certification considerably more understandable and achievable than some of the more complex cyber security standards.

Why has a customer asked us for Cyber Essentials?

This is an increasingly common reason for businesses to start looking at Cyber Essentials.

When a larger organisation appoints a supplier, it isn’t only its own IT security that matters. Suppliers may have access to customer information, shared systems, cloud platforms or other commercially sensitive data.

That creates what is often referred to as supply chain risk.

A customer may therefore ask suppliers to demonstrate that appropriate cyber security measures are in place before it awards them a contract.

Cyber Essentials gives them a recognised way of doing this.

Instead of relying entirely on a supplier saying that its systems are secure, the customer can ask whether the business holds a current Cyber Essentials certificate.

For the supplier, this can also make future procurement exercises easier. Once certification is in place, it can provide recognised evidence of your basic cyber security controls when other prospective customers ask similar questions.

 

Do I need Cyber Essentials to win a contract?

Not every UK business is legally required to have Cyber Essentials.

However, that doesn’t mean it won’t be a requirement for your business.

A prospective customer can make Cyber Essentials part of its supplier requirements, tender process or contract conditions. It is also already required for certain UK Government contracts.

So if a tender specifies that suppliers must hold Cyber Essentials certification, obtaining it can become a practical requirement for winning that particular piece of work.

We’re also seeing cyber security feature more prominently in supplier questionnaires and procurement processes.

If a major customer has asked you whether you are Cyber Essentials certified, it is worth establishing exactly what level of certification they require and when they expect it to be in place.

What does Cyber Essentials actually check?

Cyber Essentials is based around five core technical controls.

1. Firewalls

Firewalls help create a protective barrier between your devices or network and the internet.

Cyber Essentials looks at whether appropriate firewall protection is in place and whether it is configured securely.

2. Secure configuration

New devices and software don’t necessarily arrive configured in the most secure way for your organisation.

Default accounts, unnecessary services, applications and inappropriate settings can create vulnerabilities.

Secure configuration is about ensuring that the computers, devices and services your organisation uses are set up appropriately and unnecessary security risks are removed.

3. Security update management

Software vulnerabilities are regularly discovered and manufacturers release security updates to address them.

Cyber Essentials requires organisations to manage these vulnerabilities appropriately, including ensuring that software is supported and relevant security updates are applied within the required timescales.

This is an area where older computers, operating systems or applications can sometimes cause problems when preparing for certification.

4. User access control

Not everyone in a business needs access to everything.

Cyber Essentials looks at how user accounts are managed, how access is granted and how privileged or administrator accounts are controlled.

It also covers important areas such as authentication and multi-factor authentication (MFA).

5. Malware protection

Businesses need appropriate measures to prevent malicious software from compromising their systems.

Depending on the devices and systems being used, this can involve anti-malware software, application controls and other measures designed to prevent malicious code from running.

Is Cyber Essentials difficult to achieve?

For a business with well-managed and up-to-date IT, Cyber Essentials may be relatively straightforward.

The difficulty usually arises when an organisation assumes it is compliant without checking the requirements properly.

For example, a business may discover that it has:

  • Old or unsupported software still in use
  • Devices that aren’t receiving security updates
  • Users with unnecessary administrator privileges
  • Inconsistent use of multi-factor authentication
  • Former employees with accounts that haven’t been removed
  • Home or remote-working devices that haven’t been considered
  • Cloud services that haven’t been included correctly
  • Software or equipment that nobody realised was still part of the IT environment

This is why it can be useful to review your IT environment before submitting your Cyber Essentials assessment.

The objective isn’t simply to answer the questions correctly. Your organisation needs to have the required controls in place.

What is included in a Cyber Essentials assessment?

The standard Cyber Essentials certification process uses a verified self-assessment.

Your organisation answers questions about its IT environment and the security measures it has in place. The answers are signed off by a board member or equivalent and assessed by an accredited Certification Body.

Before starting, it is important to understand the scope of the assessment – in other words, which systems, devices, users and services need to be included.

For businesses using Microsoft 365 and other cloud-based services, laptops, mobile devices and remote working, the scope can be broader than simply looking at the computers sitting in the office.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Both certifications are based on the same five technical controls.

The principal difference is how those controls are assessed.

With Cyber Essentials, your organisation completes a verified self-assessment which is reviewed by a Certification Body.

With Cyber Essentials Plus, independent technical testing is also carried out to verify that the controls are working effectively in practice.

Cyber Essentials Plus therefore provides a higher level of assurance.

If a customer has specifically asked you for certification, check whether they require Cyber Essentials or Cyber Essentials Plus before starting the process.

What happens if we’re not ready for Cyber Essentials?

Finding that you aren’t currently ready for certification doesn’t necessarily mean you have a major cyber security problem.

It may simply identify areas of your IT that need attention.

For example, you might need to update or remove a piece of unsupported software, change user permissions, introduce MFA on a service or adjust the configuration of certain devices.

The important thing is to identify these gaps early – particularly if you have a deadline connected with a tender or customer contract.

Leaving the assessment until just before a procurement deadline can create unnecessary pressure if changes are required.

What if we need Cyber Essentials quickly?

If certification is needed to satisfy a customer or submit a tender, start by establishing three things:

  1. Which certification is required?
    Cyber Essentials or Cyber Essentials Plus?
  2. When do you need it?
    Is certification required when the tender is submitted, before the contract is awarded or before work begins?
  3. Is your IT environment ready?
    Check your systems against the current Cyber Essentials requirements before relying on certification being straightforward.

This gives you an opportunity to identify and correct potential issues before they delay the certification process.

Can our IT company help us get Cyber Essentials?

Yes. There are two routes to Cyber Essentials certification: organisations can take a self-led approach or obtain support from an appropriate Certification Body.

For businesses without dedicated internal cyber security expertise, supported certification can make the process easier to understand.

It can be particularly useful when you have been given a deadline by a customer and need to determine whether your existing IT environment meets the requirements.

Is Cyber Essentials worth having if nobody has asked for it?

There are good reasons to consider certification even if it isn’t currently a contractual requirement.

Cyber Essentials provides a recognised baseline for protecting your organisation against common cyber attacks and demonstrates to customers and other stakeholders that fundamental cyber security measures are in place.

It can also put you in a stronger position when a future tender or supplier questionnaire asks about your cyber security arrangements.

Rather than discovering at the start of an important procurement exercise that certification is required, you already have it.

Need Cyber Essentials to win a contract?

If you’ve been told that your business needs Cyber Essentials certification for a customer, tender or new contract, ICM can help you understand what’s required and identify whether your existing IT environment is ready for assessment.

Our team can review your current setup, help address potential gaps and support you through the certification process.

Find out more about Cyber Essentials certification support from ICM.

Share this post
Facebook
Twitter
LinkedIn
WhatsApp

More from the category

Featured articles

From our book shop