Certification for Cyber Essentials и CE Plus
The five technical controls, proven in practice. We take you from gap analysis and remediation to verification and independent technical testing.
ce.readiness
live
Firewalls
100%
Secure configurations
88%
Access control
76%
Anti-malware
92%
Patches
64%
5
control
14d
patch deadline
// 01
What Cyber Essentials Checks
CONTROL // 01
Firewalls & gateways
The perimeter and any internet-connected device are behind a properly configured firewall, with no unnecessarily open ports and with documented exceptions.
CONTROL // 02
Secure configuration
Removal of factory passwords, unnecessary services and software, enabling screen locks, and hardening of servers and workstations.
CONTROL // 03
Access control
Unique accounts, the principle of least privilege, separate administrator profiles, and mandatory multi-factor authentication.
CONTROL // 04
Malware protection
Deployment and configuration of anti-malware/EDR solutions and email protection.
CONTROL // 05
Patch management
Keeping operating systems and applications up to date.
// 02
Two levels
Cyber Essentials
Self-assessment + verification- GAP analysis and action plan
- Implementing the required technical controls
- Completing the self-assessment questionnaire
- Submitting the questionnaire and evaluation by the certification body
Deadline
2–4 weeks
Cyber Essentials Plus
Independent technical testing- Completing the Cyber Essentials questionnaire
- Submission for evaluation by a certification body
- Independent technical assessment
- Issuance of the Cyber Essentials Plus certificate
Deadline
4–8 weeks
// 03
How We Get to the Certificate
01
Gap Analysis
We evaluate the current state against the Cyber Essentials requirements and draw up an action plan.
02
Plan and Scope
We prioritize tasks, determine the scope, and set implementation deadlines.
03
Implementation of Measures
We configure the necessary technical and organizational measures.
04
Preparation for Assessment
We verify the organization's readiness and assist with the self-assessment or technical verification.
// WHY CYBER ESSENTIALS
Why Organizations Choose Cyber Essentials?
Cyber Essentials is an internationally recognized standard that proves an organization implements essential and effective measures to protect against the most common cyber threats.
Internationally Recognized Standard
Used by organizations and public institutions worldwide.
Reduces Risk
Covers the five core technical controls against the most prevalent attacks.
Foundation for ISO 27001 and NIS2
The controls overlap with all information security regulations.
Competitive Advantage
Often a requirement or a major advantage in public procurement and corporate contracts.
// 03
Frequently Asked Questions
-
What is Cyber Essentials?
Cyber Essentials is a certification scheme that verifies an organization implements five core technical controls: firewalls, secure configurations, access control, malware protection, and patch management. The certificate is based on a self-assessment questionnaire verified by an accredited certification body.
-
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is demonstrated through self-assessment. Cyber Essentials Plus covers the same five controls, but they are verified through independent technical testing — vulnerability scanning on a sample of devices, email and web security testing, and malware simulation.
-
Is Cyber Essentials suitable for small companies?
Yes. The standard is designed to be applicable to both small and large organizations and is a suitable first step toward a more mature cybersecurity program.
-
How often is the certificate renewed?
Annually. A new assessment is conducted every year, and for Cyber Essentials Plus, new technical testing is performed as well.
-
Does CyPro issue the certificate?
No. The certificate is issued by an accredited certification body. CyPro is your consultant and technical partner — we prepare the environment, documentation, and evidence, and guide you to a successful result.
