Cyber Essentials Compliance

What is it?

Technical Controls

Cyber Essentials seeks to apply basic protections across 5 key areas of risk:

  • Firewalls
  • Secure Configuration
  • User Access Control
  • Malware Protection
  • Software Update Management
Requirements Updated Annually
  • To ensure relevance to the current threat landscape is maintained, the CE standard is reviewed and updated annually.


  • As such, annual recertification is also necessary.

Further guidance is included around backups but, this is not a requirement to meet the standards for certification.

Why you need it...

Cyber Liability Insurance

  • If your annual turnover is below £20m, and you elect to include the entire organisation within the scope of assessment, insurance to cover many of the costs arising from a cyber attack is included at no extra charge.





It’s the Base Standard

  • As previously mentioned, Cyber Essentials certification requires merely that you’ve done the absolute minimum to protect yourself against the threats we know are the starting point for most cyber attacks, including the most devastating, Ransomware.


  • When you do fall victim to a successful attack, if you’ve not done the basics right, and you have no insurance, how can you possibly expect to recover?


