Skip to main content

Explainers

Cyber Essentials Explained: What Buyers Should Check

Cyber Essentials is a UK government-backed scheme with a 12-month certificate and an IASME-run register. Here is what basic versus Plus actually proves.

Solomon AmosPublished 24 Sep 20269 min read

Cyber Essentials is a UK government-backed certification scheme that asks an organisation to prove five technical controls are in place: firewalls, secure configuration, user access control, malware protection and patch management. It was created by the National Cyber Security Centre (NCSC) and is delivered on the NCSC's behalf by IASME, which accredits a network of Certification Bodies to carry out assessments and issue certificates. For a buyer looking at a vendor's Cyber Essentials badge, the certificate answers a narrow question: has this organisation self-assessed, or been technically tested, against a fixed baseline of five controls, and is that assessment still inside its 12-month window. It does not tell you anything about data processing agreements, subprocessors or incident history. This article explains what the badge covers, how basic Cyber Essentials differs from Cyber Essentials Plus, and what a buyer can actually verify before relying on it.

What Cyber Essentials actually certifies

NCSC owns Cyber Essentials and defines what it tests: five technical controls aimed at the kind of opportunistic attack that scans the whole internet rather than targeting one organisation. Boundary firewalls and internet gateways, secure configuration of devices and software, security update management (patching known vulnerabilities), user access control, and malware protection. Nothing in the scheme asks about data processing agreements, subprocessor lists, breach notification timelines or the scope of a wider information security management system. A vendor can hold current Cyber Essentials and still have no public Data Privacy Framework listing, no SOC 2 report and no signed BAA on file. The certificate is a narrow, useful signal about baseline IT hygiene, not a general security certification, and a buyer who reads it as anything wider is asking it to answer a question it was never designed to answer.

Basic Cyber Essentials vs Cyber Essentials Plus

The scheme has two levels, and the certificate itself states which one a vendor holds. The five underlying controls are identical between levels; what changes is how the answers get checked and by whom.

AspectCyber Essentials (basic)Cyber Essentials Plus
Assessment methodSelf-assessment questionnaire, reviewed by an independent assessorThe same questionnaire plus an independent technical audit
Who tests the systemsThe vendor answers; no external scan is runA Certification Body runs external vulnerability scans and samples internal devices
Typical evidence a buyer seesA certificate number and a badgeThe same certificate number, marked Plus, with the same 12-month validity
What it provesThe organisation states its five controls are configured this wayAn assessor independently checked a sample of devices and confirmed the controls in place

Basic Cyber Essentials is a reviewed questionnaire. Cyber Essentials Plus adds an independent technical audit of the same five controls.

In practice this means basic Cyber Essentials tells you the vendor answered a questionnaire and an assessor found the answers plausible. Cyber Essentials Plus tells you an assessor actually ran external scans and looked inside a sample of laptops and servers to confirm the questionnaire matched reality. For contracts that specifically require Cyber Essentials Plus, a basic certificate does not satisfy the requirement, even though both badges share the same scheme name and the same 12-month cycle.

Diagram comparing the assessment steps for basic Cyber Essentials and Cyber Essentials Plus
Basic Cyber Essentials is a reviewed questionnaire; Plus adds an external scan and device sampling.

Who runs the scheme: NCSC, IASME and the certification bodies

NCSC sets the scheme's technical requirements and licenses the Cyber Essentials brand. Since April 2020, IASME has been NCSC's sole delivery partner, running the public certification register and accrediting a network of independent Certification Bodies, listed alongside other auditors and certification bodies, who carry out the actual assessments and issue certificates on IASME's behalf. IASME does not assess most applicants directly; it licenses and audits the Certification Bodies that do, and all of them work from the same NCSC-set technical requirement document, so the bar for a pass is meant to be consistent regardless of which body carried out the check. This matters for a buyer because a certificate should always trace back to a named Certification Body and a certificate number you can look up, not just a badge image pasted onto a marketing page.

Cyber Essentials is a Government backed, industry supported scheme to help organisations protect themselves against common online security threats.

The 12-month validity clock

A Cyber Essentials or Cyber Essentials Plus certificate runs for 12 months from its certification date, not from the date the vendor started the application or paid the fee. There is no partial renewal and no grace period built into the badge itself: to stay current, the organisation repeats the full assessment before the window closes. Unlike an ISO 27001 certificate, which can carry a multi-year cycle with annual surveillance visits, or a SOC 2 report, which covers a stated audit period, Cyber Essentials is a single fixed-length window that either has or has not been renewed. A badge with no visible date attached is not evidence of anything current.

12 months
Certificate validity
Runs from the certification date, per IASME's published scheme rules
5
Technical controls assessed
Firewalls, secure configuration, patch management, access control, malware protection
2
Certification levels
Basic Cyber Essentials and Cyber Essentials Plus

The same discipline applies to any dated certificate: check the expiry, not just the badge. CertReports has documented what happens when a certificate keeps appearing after its own deadline, in the case of ISO 27001 certificates written against the 2013 edition, and the lesson carries over directly to Cyber Essentials. A badge on a homepage tells you nothing about the date; only the certificate number and the register entry do.

When UK government buyers require it

UK government contracts have referenced Cyber Essentials since Procurement Policy Note 09/14 took effect in October 2014. The requirement is set contract by contract, not scheme-wide: buying departments apply it to procurements assessed as carrying certain risks, and ask for the higher Cyber Essentials Plus level where the risk is judged greater.

  • Handling personal information as part of delivering the contract
  • Providing certain networked IT hardware, software or services to government
  • Contracts a buying department has flagged as higher risk, where Cyber Essentials Plus rather than the basic level is specified

A vendor's marketing page saying it holds Cyber Essentials for government work does not tell you which contracts that covers or which level applies. If Cyber Essentials sits in your own procurement requirements, ask the specific department or contract owner what was actually specified, then check the vendor's certificate against that requirement rather than assuming the badge alone closes the question.

How to verify a Cyber Essentials certificate

  1. 1

    Get the certificate number

    Ask the vendor directly, or find it printed on the certificate or badge, rather than relying on a logo alone.

  2. 2

    Search the official register

    Enter the number in the Cyber Essentials certification search to confirm the holder's registered name, certification level and dates.

  3. 3

    Match the legal entity

    Confirm the certified organisation is the one actually delivering your contract, since a parent company's certificate does not automatically cover a subsidiary or reseller.

  4. 4

    Check the level against the requirement

    If your contract or policy specifies Cyber Essentials Plus, a basic certificate does not satisfy it, even though both use the same scheme name.

  5. 5

    Check the expiry date

    Certificates run for 12 months; treat one with no visible date, or a date more than a year old, the same way you would treat any other stale piece of evidence.

Timeline showing a Cyber Essentials certificate's 12-month validity window and renewal point
A Cyber Essentials certificate covers a fixed 12-month window and must be reassessed in full to renew.

Reading a UK government-backed scheme on a trust centre

Cyber Essentials rarely sits alone on a vendor's trust centre. Larger vendors often list it, or a similar government-backed data security scheme, alongside broader frameworks like SOC 2 or CSA STAR, each with its own verification method and its own renewal date. 8x8's trust centre is a useful example of that pattern: it carries NHS DSPT next to CSA STAR verification, a Data Privacy Framework listing, and stated SOC 2 and ISO 27001 evidence. Look at how each row states what was checked and when, the same way you would want to read a trust centre for any other vendor rather than treating one badge as a stand-in for the rest.

8x8 logo

8x8 · Trust report

Communications and CPaaS · Public evidence as of 29 Sep 2026

5Documents and agreements

Legal and review documents 8x8 publishes or offers, as of 29 Sep 2026.

  • Data processing agreement · On request
  • Standard contractual clauses · On request
  • Subprocessor list · Public
  • Privacy policy · Public
  • Public trust centre documents · 8x8 Cyber Essentials Plus 2026-2027; 8x8 ISO 14001 2023-2026; 8x8 ISO 27001 2025-2027; 8x8 ISO 27017 2025-2027; 8x8 ISO 27018 2025-2027; 8x8 SOC3 Certificate 2025

26Subprocessors

Named on 8x8's public subprocessor list, last seen 29 Sep 2026.

A government-backed scheme sits next to CSA STAR, DPF and SOC 2 rows on the same trust centre page. Every line is a dated public record from the CSA STAR registry, the Data Privacy Framework list and 8x8's trust centre. A framework not shown means no public evidence was found, not that 8x8 lacks it.CertReports

What Cyber Essentials Plus does not replace

Even at the Plus level, Cyber Essentials is not a substitute for a SOC 2 report, an ISO 27001 certificate or a signed BAA. It checks five specific controls at a point in time and says nothing about data processing agreements, subprocessor lists, breach notification commitments or the scope of a wider information security management system. A vendor can hold Cyber Essentials Plus and still have no public subprocessor list and no answer on where customer data is processed. Treat the badge as one line in a wider review, alongside the kind of 30-minute vendor security review that checks each framework against what it actually proves rather than what its badge implies.

People also ask

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Basic Cyber Essentials is a self-assessment questionnaire covering five technical controls (firewalls, secure configuration, patch management, access control and malware protection), reviewed and verified by an independent assessor at a Certification Body. Cyber Essentials Plus asks for the same five controls but adds an independent technical audit: external vulnerability scanning plus sampling of internal devices to confirm the questionnaire answers actually match what is configured. Both carry the same 12-month validity.

How long is Cyber Essentials valid?

A Cyber Essentials or Cyber Essentials Plus certificate is valid for 12 months from its certification date, not from the date the vendor applied or paid. There is no partial renewal: to keep the badge current, the organisation must repeat the full assessment before the 12 months end. If you see a certificate on a trust centre or marketing page, check the date against today's date rather than assuming it is still current.

Is Cyber Essentials mandatory for government suppliers?

Not for every UK government supplier. Since Procurement Policy Note 09/14 took effect in October 2014, certain central government contracts, mainly those involving personal information or certain networked IT products or services, have required the supplier to hold Cyber Essentials, with higher risk contracts sometimes asking for Cyber Essentials Plus. It is a contract-by-contract requirement set by the buying department, not a blanket rule covering all public sector procurement.

How do I check a Cyber Essentials certificate?

Ask the vendor for its certificate number, then look it up on the official Cyber Essentials certification search to confirm the holder's legal name, the level (basic or Plus) and the certification and expiry dates. Check that the certified entity matches the one actually delivering your contract, since a parent company's certificate does not cover a subsidiary. Treat an expired or unmatched result the same way you would treat no public evidence: as something to ask about directly.

cyber-essentialsuk-compliancegovernment-procurementcertification
S

Solomon Amos · Founder, CertReports

Solomon builds CertReports, the public evidence index for vendor security reviews. PhD in machine learning and cybersecurity, two years embedded at HMRC digital programmes, founder of TapTax. He writes about what registries, trust centres and auditors actually publish, and how buyers can use it before the questionnaire goes out.

Read next on CertReports

You might also like