Cyber Essentials is the UK government-backed certification showing an organization has baseline cyber hygiene in place, built on five technical control themes. It is required in much UK public-sector procurement and increasingly requested in private supply chains. The scheme is run by the UK NCSC.
Key facts:
- Two levels: Cyber Essentials (self-assessment, independently verified) and Cyber Essentials Plus (adds a hands-on technical audit).
- The five control themes: firewalls, secure configuration, security update management, user access control, and malware protection.
- Certification is annual and deliberately achievable for small organizations; it signals hygiene, not advanced security.
The five controls and the inbox
Phishing is the attack the scheme most explicitly aims to blunt, and two themes run straight through email: malware protection (malicious attachments and links) and user access control (what happens after credentials are phished). Passing the checklist without genuinely protecting the mailbox satisfies the letter but not the point.
Where email security fits, honestly
Sentaro supports the malware protection and access control themes with AI-native filtering of phishing, malicious content and OAuth abuse in Google Workspace and Microsoft 365, plus the visibility evidence for the questionnaire and Plus audit. Scoping, configuration standards, patching and the certification process itself remain yours. For organizations that go further, ISO 27001 and NIS2 build on the same hygiene foundations.
This page is general guidance, not legal advice.