Cyber Essentials: the UK’s five-control baseline
Cyber Essentials is a UK government-backed scheme, supported by the NCSC, that protects against the most common cyber attacks through five technical controls: firewalls, secure configuration, user access control, malware protection, and security update management. Standard Cyber Essentials is a self-assessment; Cyber Essentials Plus adds an independent, hands-on audit.
What it is
Cyber Essentials is a UK government-backed baseline, supported by the National Cyber Security Centre (NCSC). Its five technical controls block the majority of common, high-volume internet attacks. It’s a practical starting point for cyber hygiene rather than a comprehensive security standard.
Who benefits
Any organization wanting an affordable baseline — especially small and medium-sized businesses. It’s often required to win UK public-sector contracts, and many private buyers ask for it too. Even when not mandated, it’s a quick way to prove you’ve covered the fundamentals.
Five controls that stop common attacks
Implement these five well and you block the bulk of everyday internet-based threats.
Firewalls
Boundary firewalls and internet gateways that control traffic in and out of your networks and devices, keeping untrusted connections out.
Secure configuration
Devices and software set up securely — removing default passwords, unnecessary accounts, and features you don't need before they go into use.
User access control
Access granted on a least-privilege basis, with administrative rights tightly managed so users only have the access they actually need.
Malware protection
Defences against malicious software — anti-malware, allow-listing, or sandboxing — to stop harmful code running on your systems.
Security update management
Patching and updates applied promptly so known vulnerabilities in operating systems and applications are fixed before they're exploited.
Cyber Essentials vs Cyber Essentials Plus
Same five controls, different levels of verification.
| Cyber Essentials | Cyber Essentials Plus | |
|---|---|---|
| How it's verified | Self-assessment questionnaire | Independent technical audit |
| Hands-on testing by assessor | ||
| Covers the five controls | ||
| Assurance level | Baseline | Higher / audited |
| Good for | A quick, low-cost baseline | Stronger proof for buyers |
A stepping stone to ISO 27001
Cyber Essentials is a focused baseline of five technical controls; ISO 27001 is the comprehensive, internationally recognized certification for an entire Information Security Management System. Cyber Essentials is a fast win and a natural first step; ISO 27001 is the deeper standard larger and international buyers often expect.
Many organizations achieve Cyber Essentials first, then build toward certification. Read our ISO 27001 guide to see where you’re heading, then let Komply map both onto one control set so the work compounds instead of repeating.
Cyber Essentials, answered
Cover the fundamentals, then go further
Komply organizes your five Cyber Essentials controls alongside ISO 27001 in one control set — drafting policies, tracking evidence, and keeping you audit-ready.