Cyber Essentials is a UK government-backed certification scheme that asks an organisation to prove five technical controls are in place: firewalls, secure configuration, user access control, malware protection and patch management. It was created by the National Cyber Security Centre (NCSC) and is delivered on the NCSC's behalf by IASME, which accredits a network of Certification Bodies to carry out assessments and issue certificates. For a buyer looking at a vendor's Cyber Essentials badge, the certificate answers a narrow question: has this organisation self-assessed, or been technically tested, against a fixed baseline of five controls, and is that assessment still inside its 12-month window. It does not tell you anything about data processing agreements, subprocessors or incident history. This article explains what the badge covers, how basic Cyber Essentials differs from Cyber Essentials Plus, and what a buyer can actually verify before relying on it.
What Cyber Essentials actually certifies
NCSC owns Cyber Essentials and defines what it tests: five technical controls aimed at the kind of opportunistic attack that scans the whole internet rather than targeting one organisation. Boundary firewalls and internet gateways, secure configuration of devices and software, security update management (patching known vulnerabilities), user access control, and malware protection. Nothing in the scheme asks about data processing agreements, subprocessor lists, breach notification timelines or the scope of a wider information security management system. A vendor can hold current Cyber Essentials and still have no public Data Privacy Framework listing, no SOC 2 report and no signed BAA on file. The certificate is a narrow, useful signal about baseline IT hygiene, not a general security certification, and a buyer who reads it as anything wider is asking it to answer a question it was never designed to answer.
Basic Cyber Essentials vs Cyber Essentials Plus
The scheme has two levels, and the certificate itself states which one a vendor holds. The five underlying controls are identical between levels; what changes is how the answers get checked and by whom.
| Aspect | Cyber Essentials (basic) | Cyber Essentials Plus |
|---|---|---|
| Assessment method | Self-assessment questionnaire, reviewed by an independent assessor | The same questionnaire plus an independent technical audit |
| Who tests the systems | The vendor answers; no external scan is run | A Certification Body runs external vulnerability scans and samples internal devices |
| Typical evidence a buyer sees | A certificate number and a badge | The same certificate number, marked Plus, with the same 12-month validity |
| What it proves | The organisation states its five controls are configured this way | An assessor independently checked a sample of devices and confirmed the controls in place |
Basic Cyber Essentials is a reviewed questionnaire. Cyber Essentials Plus adds an independent technical audit of the same five controls.
In practice this means basic Cyber Essentials tells you the vendor answered a questionnaire and an assessor found the answers plausible. Cyber Essentials Plus tells you an assessor actually ran external scans and looked inside a sample of laptops and servers to confirm the questionnaire matched reality. For contracts that specifically require Cyber Essentials Plus, a basic certificate does not satisfy the requirement, even though both badges share the same scheme name and the same 12-month cycle.
Who runs the scheme: NCSC, IASME and the certification bodies
NCSC sets the scheme's technical requirements and licenses the Cyber Essentials brand. Since April 2020, IASME has been NCSC's sole delivery partner, running the public certification register and accrediting a network of independent Certification Bodies, listed alongside other auditors and certification bodies, who carry out the actual assessments and issue certificates on IASME's behalf. IASME does not assess most applicants directly; it licenses and audits the Certification Bodies that do, and all of them work from the same NCSC-set technical requirement document, so the bar for a pass is meant to be consistent regardless of which body carried out the check. This matters for a buyer because a certificate should always trace back to a named Certification Body and a certificate number you can look up, not just a badge image pasted onto a marketing page.
Cyber Essentials is a Government backed, industry supported scheme to help organisations protect themselves against common online security threats.
The 12-month validity clock
A Cyber Essentials or Cyber Essentials Plus certificate runs for 12 months from its certification date, not from the date the vendor started the application or paid the fee. There is no partial renewal and no grace period built into the badge itself: to stay current, the organisation repeats the full assessment before the window closes. Unlike an ISO 27001 certificate, which can carry a multi-year cycle with annual surveillance visits, or a SOC 2 report, which covers a stated audit period, Cyber Essentials is a single fixed-length window that either has or has not been renewed. A badge with no visible date attached is not evidence of anything current.
- 12 months
- Certificate validity
- Runs from the certification date, per IASME's published scheme rules
- 5
- Technical controls assessed
- Firewalls, secure configuration, patch management, access control, malware protection
- 2
- Certification levels
- Basic Cyber Essentials and Cyber Essentials Plus
The same discipline applies to any dated certificate: check the expiry, not just the badge. CertReports has documented what happens when a certificate keeps appearing after its own deadline, in the case of ISO 27001 certificates written against the 2013 edition, and the lesson carries over directly to Cyber Essentials. A badge on a homepage tells you nothing about the date; only the certificate number and the register entry do.
When UK government buyers require it
UK government contracts have referenced Cyber Essentials since Procurement Policy Note 09/14 took effect in October 2014. The requirement is set contract by contract, not scheme-wide: buying departments apply it to procurements assessed as carrying certain risks, and ask for the higher Cyber Essentials Plus level where the risk is judged greater.
- Handling personal information as part of delivering the contract
- Providing certain networked IT hardware, software or services to government
- Contracts a buying department has flagged as higher risk, where Cyber Essentials Plus rather than the basic level is specified
A vendor's marketing page saying it holds Cyber Essentials for government work does not tell you which contracts that covers or which level applies. If Cyber Essentials sits in your own procurement requirements, ask the specific department or contract owner what was actually specified, then check the vendor's certificate against that requirement rather than assuming the badge alone closes the question.
How to verify a Cyber Essentials certificate
- 1
Get the certificate number
Ask the vendor directly, or find it printed on the certificate or badge, rather than relying on a logo alone.
- 2
Search the official register
Enter the number in the Cyber Essentials certification search to confirm the holder's registered name, certification level and dates.
- 3
Match the legal entity
Confirm the certified organisation is the one actually delivering your contract, since a parent company's certificate does not automatically cover a subsidiary or reseller.
- 4
Check the level against the requirement
If your contract or policy specifies Cyber Essentials Plus, a basic certificate does not satisfy it, even though both use the same scheme name.
- 5
Check the expiry date
Certificates run for 12 months; treat one with no visible date, or a date more than a year old, the same way you would treat any other stale piece of evidence.
Reading a UK government-backed scheme on a trust centre
Cyber Essentials rarely sits alone on a vendor's trust centre. Larger vendors often list it, or a similar government-backed data security scheme, alongside broader frameworks like SOC 2 or CSA STAR, each with its own verification method and its own renewal date. 8x8's trust centre is a useful example of that pattern: it carries NHS DSPT next to CSA STAR verification, a Data Privacy Framework listing, and stated SOC 2 and ISO 27001 evidence. Look at how each row states what was checked and when, the same way you would want to read a trust centre for any other vendor rather than treating one badge as a stand-in for the rest.

8x8 · Trust report
Communications and CPaaS · Public evidence as of 29 Sep 2026
Framework overview
CertReports state for each framework with public evidence: 2 verified, 8 vendor-stated.
NHS DSPTVendor-statedTrust centre · 29 Sep 2026
CSA STARVerifiedCSA STAR registry · 29 Sep 2026
DPFVerifiedValid to 28 Jan 2027
SOC 2Vendor-statedTrust centre · 29 Sep 2026GDPRVendor-statedTrust centre · 29 Sep 2026
PCI DSSVendor-statedTrust centre · 29 Sep 2026
ISO 27001Vendor-statedTrust centre · 29 Sep 2026
ISO 27017Vendor-statedTrust centre · 29 Sep 2026
ISO 27018Vendor-statedTrust centre · 29 Sep 2026
5Documents and agreements
Legal and review documents 8x8 publishes or offers, as of 29 Sep 2026.
- Data processing agreement · On request
- Standard contractual clauses · On request
- Subprocessor list · Public
- Privacy policy · Public
- Public trust centre documents · 8x8 Cyber Essentials Plus 2026-2027; 8x8 ISO 14001 2023-2026; 8x8 ISO 27001 2025-2027; 8x8 ISO 27017 2025-2027; 8x8 ISO 27018 2025-2027; 8x8 SOC3 Certificate 2025
26Subprocessors
Named on 8x8's public subprocessor list, last seen 29 Sep 2026.
8x8 Group Companies
Alchemer LLC
Amazon Web Services, Inc
Amplitude, Inc.
AnthropicCalabrio (Teleopti)
Cloudflare- CGCognigy GmbH
- and 18 more on the evidence page
What Cyber Essentials Plus does not replace
Even at the Plus level, Cyber Essentials is not a substitute for a SOC 2 report, an ISO 27001 certificate or a signed BAA. It checks five specific controls at a point in time and says nothing about data processing agreements, subprocessor lists, breach notification commitments or the scope of a wider information security management system. A vendor can hold Cyber Essentials Plus and still have no public subprocessor list and no answer on where customer data is processed. Treat the badge as one line in a wider review, alongside the kind of 30-minute vendor security review that checks each framework against what it actually proves rather than what its badge implies.
People also ask
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Basic Cyber Essentials is a self-assessment questionnaire covering five technical controls (firewalls, secure configuration, patch management, access control and malware protection), reviewed and verified by an independent assessor at a Certification Body. Cyber Essentials Plus asks for the same five controls but adds an independent technical audit: external vulnerability scanning plus sampling of internal devices to confirm the questionnaire answers actually match what is configured. Both carry the same 12-month validity.
How long is Cyber Essentials valid?
A Cyber Essentials or Cyber Essentials Plus certificate is valid for 12 months from its certification date, not from the date the vendor applied or paid. There is no partial renewal: to keep the badge current, the organisation must repeat the full assessment before the 12 months end. If you see a certificate on a trust centre or marketing page, check the date against today's date rather than assuming it is still current.
Is Cyber Essentials mandatory for government suppliers?
Not for every UK government supplier. Since Procurement Policy Note 09/14 took effect in October 2014, certain central government contracts, mainly those involving personal information or certain networked IT products or services, have required the supplier to hold Cyber Essentials, with higher risk contracts sometimes asking for Cyber Essentials Plus. It is a contract-by-contract requirement set by the buying department, not a blanket rule covering all public sector procurement.
How do I check a Cyber Essentials certificate?
Ask the vendor for its certificate number, then look it up on the official Cyber Essentials certification search to confirm the holder's legal name, the level (basic or Plus) and the certification and expiry dates. Check that the certified entity matches the one actually delivering your contract, since a parent company's certificate does not cover a subsidiary. Treat an expired or unmatched result the same way you would treat no public evidence: as something to ask about directly.
Solomon Amos · Founder, CertReports
Solomon builds CertReports, the public evidence index for vendor security reviews. PhD in machine learning and cybersecurity, two years embedded at HMRC digital programmes, founder of TapTax. He writes about what registries, trust centres and auditors actually publish, and how buyers can use it before the questionnaire goes out.
Read next on CertReports
You might also like
HIPAA Eligible vs HIPAA Compliant: What the BAA Requires
Solomon Amos · 21 Sep 2026 · 10 min read