Get a free audit

Cyber Essentials · United Kingdom

Cyber Essentials covers five controls. An attacker starts at six.

Get certified. It closes the common attacks and it opens procurement doors. Then read the second half of this page, because the certificate was never designed to answer the question your board actually asks: what happens once somebody is already inside?

We do not issue Cyber Essentials certificates · we test what happens after them · CREST-certified operators

What is Cyber Essentials?

Cyber Essentials is a UK government-backed certification scheme owned by the National Cyber Security Centre and delivered by IASME. It certifies that an organisation has five basic technical controls in place: firewalls, secure configuration, security update management, user access control and malware protection. Certification runs for twelve months.

It is genuinely worth having. Those five controls block the large majority of untargeted, opportunistic attacks, which is most of what hits a typical UK business. Certification is also mandatory for some central government contracts and increasingly demanded in commercial supply-chain questionnaires, so it opens doors that stay shut without it.

We are not a certification body and we do not issue Cyber Essentials certificates. We are the team you call afterwards, when somebody asks what the certificate does not cover. This page answers both halves honestly.

43%

Of UK businesses reported a cyber breach or attack in the prior 12 months. Certification rates have risen over the same period.

Cyber Security Breaches Survey 2025/2026, GOV.UK (DSIT)

38%

Were hit by phishing. Among breached firms, 69% called phishing their most disruptive attack. No technical control certifies your people.

Cyber Security Breaches Survey 2025/2026, GOV.UK (DSIT)

£300m

Hit to Marks & Spencer operating profit from the Easter 2025 attack. Large UK firms hold certifications and still went dark.

Bloomberg, May 2025

The scheme

The five technical controls

Every Cyber Essentials assessment, at either level, comes down to these five. They are basic on purpose: the scheme is a floor, not a ceiling.

ControlWhat it requiresWhat it stops
FirewallsBoundary firewalls and device firewalls configured to block unapproved inbound traffic, with default administrative passwords changed.Casual scanning and direct exploitation of services you never meant to expose.
Secure configurationUnnecessary accounts, software and services removed. Default passwords changed. Auto-run disabled.The attacks that rely on shipped defaults nobody ever touched.
Security update managementSupported software only, with high and critical security updates applied within fourteen days of release.Mass exploitation of known vulnerabilities, which is how most opportunistic compromise happens.
User access controlAccounts assigned to named individuals, administrative rights granted only where needed, and multi-factor authentication on cloud services.Credential reuse turning into full control of your environment.
Malware protectionAnti-malware on devices, or application allow-listing, kept current.Commodity malware arriving by email or download.

The gap

Where certification stops and testing starts

Six questions your certificate does not answer. A penetration test answers all six with evidence.

  1. 01

    Can one phished account reach your crown jewels?

    The five controls assume an attacker is outside. Phishing reached 38% of UK businesses last year, so plan for the attacker being inside. An internal penetration test starts from that position and maps every step to your finance share, your customer database and domain admin.

  2. 02

    Does your network segmentation actually hold?

    Cyber Essentials does not look at segmentation. Plenty of UK networks have boundaries that exist on a diagram and nowhere in the traffic. Testing that means sitting on each segment and trying to cross it.

  3. 03

    Can an attacker reach your backups?

    Ransomware ends a business when the recovery path fails alongside production. The scheme has nothing to say about backup access. It is the first thing a competent attacker checks and it should be the first thing you check.

  4. 04

    Does your web application leak other customers’ data?

    Broken access control is the most common serious web application flaw, and it is invisible to every one of the five controls. One changed identifier in a request can return a record that belongs to somebody else.

  5. 05

    What are you exposing that is not in your asset register?

    The scheme assesses the scope you declare. An attacker attacks the scope that exists: the forgotten subdomain, the legacy login page, the test environment somebody stood up two years ago and never switched off.

  6. 06

    Would you notice?

    Certification says nothing about detection. A red team measures how far an attacker travels before anyone raises an alarm, which for most organisations is considerably further than they expect.

Which one do you need?

Cyber Essentials vs Cyber Essentials Plus

Same five controls. The difference is who checks, and how hard.

Cyber EssentialsCyber Essentials Plus
How it is assessedSelf-assessment questionnaire, signed off by a board-level representative and reviewed by a certification body.The same questionnaire, plus a hands-on technical audit carried out by an external assessor.
What the assessor doesReads your answers.Tests a sample of your devices directly: patch levels, malware protection, account separation, and simulated malicious email and file downloads.
What it provesThat you say the five controls are in place.That an assessor confirmed the five controls are in place on the machines they sampled.
PrerequisiteNone.A current Cyber Essentials certification, obtained shortly beforehand.
Typically demanded byGeneral supply-chain questionnaires and many commercial contracts.Central government contracts handling sensitive or personal data, and larger enterprise procurement.

The sensible order

Certify, then test what the certificate skips

Both, in that order. Certification for the procurement gate. Testing for the actual risk.

How UK firms usually sequence it
  • Get Cyber Essentials certified through IASME or an accredited certification body. It closes the common attacks and unlocks contracts.
  • Add Cyber Essentials Plus if your contracts demand a verified assessment rather than a self-declaration.
  • Run a free audit with us to see what an attacker reaches that the five controls never covered.
  • Scope a penetration test on the surface that matters most: external, internal, web application or cloud.
  • Take the ranked fix list to your board alongside the certificate, so the two together describe your real position.
  • Keep the picture current with a year of unlimited re-tests through RTP Robin, because your surface changes weekly and your certificate renews annually.
CRESTISO/IEC 27001Cyber EssentialsOffensive Security OSCPGIAC GXPNGIAC GWAPTGIAC Advisory BoardCompTIAOWASPNISTCRESTISO/IEC 27001Cyber EssentialsOffensive Security OSCPGIAC GXPNGIAC GWAPTGIAC Advisory BoardCompTIAOWASPNIST

Before you ask

Cyber Essentials, answered

Every assessment starts where an attacker would: outside, watching, looking for the one door left ajar. We find it, then we show you the walk-through.

What is Cyber Essentials?

Cyber Essentials is a UK government-backed certification scheme owned by the National Cyber Security Centre and delivered by IASME. It certifies that an organisation has five basic technical controls in place: firewalls, secure configuration, security update management, user access control and malware protection. Certification is valid for twelve months and is assessed through a self-assessment questionnaire reviewed by a certification body.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Both cover the same five technical controls. Cyber Essentials is a self-assessment: you complete a questionnaire, a board-level representative signs it, and a certification body reviews the answers. Cyber Essentials Plus adds an independent technical audit, in which an assessor tests a sample of your devices directly, checking patch levels, malware protection and account separation, and running simulated malicious emails and file downloads. Plus requires a current Cyber Essentials certification first. In short, one records what you say, the other verifies a sample of it.

How much does Cyber Essentials cost?

IASME sets certification pricing in bands based on organisation size, and Cyber Essentials Plus is priced separately and quoted by the certification body because it involves an assessor’s time on your devices. Because the bands are reviewed periodically, check the current figures with IASME or an accredited certification body rather than relying on a number quoted on a third-party page. We do not issue certificates and take no fee from the scheme.

Do we need Cyber Essentials?

If you bid for central government contracts involving sensitive or personal data, some require it, and Cyber Essentials Plus specifically. Beyond that it appears constantly in commercial supply-chain questionnaires and increasingly in cyber insurance applications. On the security merits alone it is worth doing, because the five controls block most opportunistic attacks. Treat it as the floor rather than the goal.

Is Cyber Essentials a penetration test?

No. Cyber Essentials is a self-assessment against five controls. Cyber Essentials Plus adds a technical audit that samples your devices to verify those same five controls, which makes it a verification exercise rather than an attack. A penetration test has no fixed control list: a tester attacks your systems to find the paths that actually work, including privilege escalation, lateral movement, segmentation failures, business logic flaws and everything else outside the five controls. The two are complementary and neither replaces the other.

We passed Cyber Essentials Plus. Why would we still need testing?

Because the assessment answered a narrow question well and left the broader one untouched. Cyber Essentials Plus confirms that a sample of your devices has the five controls applied. It does not examine whether one compromised user account reaches domain admin, whether your segmentation holds, whether an attacker can delete your backups, or whether your application exposes one customer’s data to another. Jaguar Land Rover, Marks & Spencer and the Co-op all held certifications and ran serious security programmes. All three went dark. An assessor checks whether controls exist. An attacker checks whether they hold.

Can Red Team Partners certify us for Cyber Essentials?

No. We are an offensive security firm, not an accredited certification body, so we cannot issue Cyber Essentials or Cyber Essentials Plus certificates and we would rather tell you that plainly than sell you something adjacent. Go to IASME or an accredited certification body for the certificate. Come to us for the test that shows what an attacker reaches once those five controls are in place, and we will write the findings so your assessor, your board and your engineers can all use them.

You have the certificate. Now see what it never tested.

Get a free audit