Skip to main content
← All frameworks
Cyber Essentials + CE Plus Automation

Cyber Essentials controls, verified before the assessor asks.

Cyber Essentials rests on five technical control themes, and secure configuration is the hardest to prove. CISGuard verifies it continuously across every device with CIS benchmark scans, keeping you audit-ready for Plus.

United KingdomAll industries; required for certain UK government contracts
Quick Facts

Cyber Essentials at a glance, for fast retrieval.

Atomic factual claims auditors and search engines can cite verbatim.

Scheme owner
UK National Cyber Security Centre (NCSC); delivered by IASME
Levels
Cyber Essentials (verified self-assessment); Cyber Essentials Plus (independent technical audit)
Control themes
Firewalls, secure configuration, security update management, user access control, malware protection
Validity
12 months; annual recertification
Procurement relevance
Required for certain UK government contracts
CISGuard role
Continuous verification of configuration-based themes; certification is issued by IASME-licensed bodies
Overview

What is Cyber Essentials?

Cyber Essentials is the UK government-backed certification scheme run by the NCSC and delivered through IASME. It defines five technical control themes: firewalls, secure configuration, security update management, user access control, and malware protection. Basic Cyber Essentials is a verified self-assessment; Cyber Essentials Plus adds an independent hands-on technical audit of a sample of systems, testing that the declared controls are actually in place. Certification is valid for twelve months, and holding it is a requirement for certain UK government contracts, particularly those involving personal information or the provision of certain technical services. The scheme's challenge is not conceptual but operational: the five themes describe configuration states that drift constantly across a real estate of laptops, servers, and cloud services. CISGuard makes the two most configuration-heavy themes, secure configuration and update management, continuously verifiable through CIS benchmark scanning, and evidences access control and malware protection settings from the same scans.

Control Mapping

Cyber Essentials themes CISGuard automates.

Each CIS control is tagged with its corresponding framework reference. A single scan produces per-framework coverage reports.

  • Secure configuration
    Controls
    Theme: remove default accounts, disable unneeded services, harden settings
    Mapped by
    Continuous scanning against 22 CIS Benchmarks (3,928 controls)
  • Security update management
    Controls
    Theme: supported software, timely patching of high and critical updates
    Mapped by
    CIS update and patch state benchmarks
  • User access control
    Controls
    Theme: unique accounts, least privilege, controlled admin access
    Mapped by
    CIS Account + Privilege Management benchmarks
  • Malware protection
    Controls
    Theme: anti-malware active, configured, and updating
    Mapped by
    CIS anti-malware configuration benchmarks
  • Firewalls
    Controls
    Theme: boundary and host-based firewall configuration
    Mapped by
    CIS host firewall configuration benchmarks (Windows + Linux)
How It Works

How CISGuard automates Cyber Essentials evidence.

The gap between Cyber Essentials and Cyber Essentials Plus is proof. For basic certification you declare your configuration state; for Plus, an assessor tests devices and finds whatever drifted since the declaration. CISGuard closes that gap by making the declaration continuously true. Every in-scope Windows and Linux system is scanned against its CIS Benchmark on schedule, checking exactly the territory the five themes cover: default accounts and unnecessary services (secure configuration), patch currency (update management), unique accounts, least privilege and admin separation (user access control), anti-malware state (malware protection), and host firewall settings (firewalls). Drift detection alerts you when a device falls out of its declared state, so the Plus audit sample finds systems that match the self-assessment answers rather than contradicting them. For annual recertification, the Framework Coverage Report and posture history show at a glance whether the estate still meets each theme. CISGuard does not issue certificates; IASME-licensed certification bodies do. It ensures the estate they test is the estate you declared.

Auditor Evidence

Evidence artifacts CISGuard generates.

Auditor-grade outputs in PDF/CSV. No spreadsheets, no screenshots, no manual cross-referencing.

  • Per-device CIS benchmark reports covering secure configuration checks
  • Patch and update posture reports across the in-scope estate
  • Account and privilege configuration state evidencing user access control
  • Anti-malware and host firewall configuration status per device
  • Drift detection alerts flagging devices that fall out of declared state
  • Posture trend history supporting annual recertification
Frequently Asked

Cyber Essentials questions, answered directly.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a verified self-assessment: you answer a question set about the five control themes and a certification body reviews the answers. Cyber Essentials Plus covers the same controls but adds an independent hands-on technical audit, including testing a sample of your devices. Plus fails when real configurations contradict declared answers, which is exactly the drift CISGuard's continuous scanning is designed to catch first.

What are the five Cyber Essentials control themes?

Firewalls, secure configuration, security update management, user access control, and malware protection. All five are technical configuration states rather than paperwork. CISGuard verifies them continuously through CIS benchmark scans: hardening checks for secure configuration, patch state for update management, account and privilege checks for access control, plus anti-malware and host firewall configuration status per device.

Is Cyber Essentials required for UK government contracts?

For certain contracts, yes. UK government procurement policy requires Cyber Essentials for suppliers on contracts involving the handling of certain personal information or the provision of certain technical products and services. Individual departments and prime contractors may also require it, and many specify Cyber Essentials Plus. Check the specific contract requirements; holding certification ahead of bidding removes the bottleneck.

How does CISGuard help me pass the Cyber Essentials Plus audit?

By eliminating surprises. The Plus assessor tests a sample of real devices against your declared configuration. CISGuard scans every in-scope device continuously against CIS Benchmarks, covering default accounts, unnecessary services, patch currency, privilege separation, anti-malware, and firewall settings, and raises drift alerts when a device diverges. You remediate before the audit, so the sample confirms rather than contradicts the self-assessment.

Does CISGuard issue the Cyber Essentials certificate?

No. Certification is issued by certification bodies licensed by IASME, the NCSC's delivery partner for the scheme. CISGuard provides the continuous technical evidence layer underneath: per-device CIS benchmark results, patch posture, access control state, and drift history across the five themes. That keeps the estate certifiably configured year-round instead of hardened once per renewal.

Ready for Cyber Essentials readiness?

Our compliance engineers have helped organizations achieve regulatory readiness in as little as one business day.