← Glossary

Cyber Essentials

The UK government-backed certification of basic cyber hygiene, built on five technical control themes and required in much UK public procurement.

Updated

Cyber Essentials is the UK government-backed certification showing an organization has baseline cyber hygiene in place, built on five technical control themes. It is required in much UK public-sector procurement and increasingly requested in private supply chains. The scheme is run by the UK NCSC.

Key facts:

  • Two levels: Cyber Essentials (self-assessment, independently verified) and Cyber Essentials Plus (adds a hands-on technical audit).
  • The five control themes: firewalls, secure configuration, security update management, user access control, and malware protection.
  • Certification is annual and deliberately achievable for small organizations; it signals hygiene, not advanced security.

The five controls and the inbox

Phishing is the attack the scheme most explicitly aims to blunt, and two themes run straight through email: malware protection (malicious attachments and links) and user access control (what happens after credentials are phished). Passing the checklist without genuinely protecting the mailbox satisfies the letter but not the point.

Where email security fits, honestly

Sentaro supports the malware protection and access control themes with AI-native filtering of phishing, malicious content and OAuth abuse in Google Workspace and Microsoft 365, plus the visibility evidence for the questionnaire and Plus audit. Scoping, configuration standards, patching and the certification process itself remain yours. For organizations that go further, ISO 27001 and NIS2 build on the same hygiene foundations.

This page is general guidance, not legal advice.

Questions we get asked.

What is Cyber Essentials in simple terms?

A UK certification confirming baseline cyber hygiene across five control themes, verified annually. It is often mandatory for UK government contracts.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

The base level is a verified self-assessment; Plus adds an independent technical audit including vulnerability scans and malware protection tests.

Do non-UK companies need Cyber Essentials?

Only if they bid on UK contracts that require it or face customers who ask. Elsewhere, ISO 27001 or SOC 2 carry more weight.

Does email security help with Cyber Essentials?

Yes: malware protection is one of the five themes and phishing is the primary threat the scheme addresses, but certification also covers firewalls, configuration, patching and access management.

Stop reading about it. Watch it get blocked.

Free for one account. Four minutes to connect.