Cyber Essentials controls, verified before the assessor asks.
Cyber Essentials rests on five technical control themes, and secure configuration is the hardest to prove. CISGuard verifies it continuously across every device with CIS benchmark scans, keeping you audit-ready for Plus.
Cyber Essentials at a glance, for fast retrieval.
Atomic factual claims auditors and search engines can cite verbatim.
- Scheme owner
- UK National Cyber Security Centre (NCSC); delivered by IASME
- Levels
- Cyber Essentials (verified self-assessment); Cyber Essentials Plus (independent technical audit)
- Control themes
- Firewalls, secure configuration, security update management, user access control, malware protection
- Validity
- 12 months; annual recertification
- Procurement relevance
- Required for certain UK government contracts
- CISGuard role
- Continuous verification of configuration-based themes; certification is issued by IASME-licensed bodies
What is Cyber Essentials?
Cyber Essentials is the UK government-backed certification scheme run by the NCSC and delivered through IASME. It defines five technical control themes: firewalls, secure configuration, security update management, user access control, and malware protection. Basic Cyber Essentials is a verified self-assessment; Cyber Essentials Plus adds an independent hands-on technical audit of a sample of systems, testing that the declared controls are actually in place. Certification is valid for twelve months, and holding it is a requirement for certain UK government contracts, particularly those involving personal information or the provision of certain technical services. The scheme's challenge is not conceptual but operational: the five themes describe configuration states that drift constantly across a real estate of laptops, servers, and cloud services. CISGuard makes the two most configuration-heavy themes, secure configuration and update management, continuously verifiable through CIS benchmark scanning, and evidences access control and malware protection settings from the same scans.
Cyber Essentials themes CISGuard automates.
Each CIS control is tagged with its corresponding framework reference. A single scan produces per-framework coverage reports.
- Secure configuration
- Controls
- Theme: remove default accounts, disable unneeded services, harden settings
- Mapped by
- Continuous scanning against 22 CIS Benchmarks (3,928 controls)
- Security update management
- Controls
- Theme: supported software, timely patching of high and critical updates
- Mapped by
- CIS update and patch state benchmarks
- User access control
- Controls
- Theme: unique accounts, least privilege, controlled admin access
- Mapped by
- CIS Account + Privilege Management benchmarks
- Malware protection
- Controls
- Theme: anti-malware active, configured, and updating
- Mapped by
- CIS anti-malware configuration benchmarks
- Firewalls
- Controls
- Theme: boundary and host-based firewall configuration
- Mapped by
- CIS host firewall configuration benchmarks (Windows + Linux)
How CISGuard automates Cyber Essentials evidence.
The gap between Cyber Essentials and Cyber Essentials Plus is proof. For basic certification you declare your configuration state; for Plus, an assessor tests devices and finds whatever drifted since the declaration. CISGuard closes that gap by making the declaration continuously true. Every in-scope Windows and Linux system is scanned against its CIS Benchmark on schedule, checking exactly the territory the five themes cover: default accounts and unnecessary services (secure configuration), patch currency (update management), unique accounts, least privilege and admin separation (user access control), anti-malware state (malware protection), and host firewall settings (firewalls). Drift detection alerts you when a device falls out of its declared state, so the Plus audit sample finds systems that match the self-assessment answers rather than contradicting them. For annual recertification, the Framework Coverage Report and posture history show at a glance whether the estate still meets each theme. CISGuard does not issue certificates; IASME-licensed certification bodies do. It ensures the estate they test is the estate you declared.
Evidence artifacts CISGuard generates.
Auditor-grade outputs in PDF/CSV. No spreadsheets, no screenshots, no manual cross-referencing.
- Per-device CIS benchmark reports covering secure configuration checks
- Patch and update posture reports across the in-scope estate
- Account and privilege configuration state evidencing user access control
- Anti-malware and host firewall configuration status per device
- Drift detection alerts flagging devices that fall out of declared state
- Posture trend history supporting annual recertification
Cyber Essentials questions, answered directly.
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is a verified self-assessment: you answer a question set about the five control themes and a certification body reviews the answers. Cyber Essentials Plus covers the same controls but adds an independent hands-on technical audit, including testing a sample of your devices. Plus fails when real configurations contradict declared answers, which is exactly the drift CISGuard's continuous scanning is designed to catch first.
What are the five Cyber Essentials control themes?
Firewalls, secure configuration, security update management, user access control, and malware protection. All five are technical configuration states rather than paperwork. CISGuard verifies them continuously through CIS benchmark scans: hardening checks for secure configuration, patch state for update management, account and privilege checks for access control, plus anti-malware and host firewall configuration status per device.
Is Cyber Essentials required for UK government contracts?
For certain contracts, yes. UK government procurement policy requires Cyber Essentials for suppliers on contracts involving the handling of certain personal information or the provision of certain technical products and services. Individual departments and prime contractors may also require it, and many specify Cyber Essentials Plus. Check the specific contract requirements; holding certification ahead of bidding removes the bottleneck.
How does CISGuard help me pass the Cyber Essentials Plus audit?
By eliminating surprises. The Plus assessor tests a sample of real devices against your declared configuration. CISGuard scans every in-scope device continuously against CIS Benchmarks, covering default accounts, unnecessary services, patch currency, privilege separation, anti-malware, and firewall settings, and raises drift alerts when a device diverges. You remediate before the audit, so the sample confirms rather than contradicts the self-assessment.
Does CISGuard issue the Cyber Essentials certificate?
No. Certification is issued by certification bodies licensed by IASME, the NCSC's delivery partner for the scheme. CISGuard provides the continuous technical evidence layer underneath: per-device CIS benchmark results, patch posture, access control state, and drift history across the five themes. That keeps the estate certifiably configured year-round instead of hardened once per renewal.
Continue exploring CISGuard coverage.
ISO 27001
CISGuard maps 36 ISO/IEC 27001:2022 Annex A controls to CIS benchmark scans, automating the technical evidence that certification audits demand and continuous-monitoring requirements imply.
Read more →ISO 27002
ISO/IEC 27002:2022 tells you how to implement the 93 controls behind ISO 27001 Annex A. CISGuard proves the technological ones are actually in place, with continuous CIS benchmark scans as the implementation evidence.
Read more →NIS2
CISGuard automates the cybersecurity risk-management measures NIS2 Article 21 requires of EU Essential and Important Entities, with continuous evidence the national supervisory authorities expect.
Read more →SOC 2
SOC 2 Type II requires evidence of controls operating effectively over a period. CISGuard provides that period evidence automatically: 26 Trust Services Criteria mapped, continuous monitoring satisfying the "over time" requirement.
Read more →Ready for Cyber Essentials readiness?
Our compliance engineers have helped organizations achieve regulatory readiness in as little as one business day.