Framework guide • United Kingdom

Cyber Essentials: the UK’s five-control baseline

Cyber Essentials is a UK government-backed scheme, supported by the NCSC, that protects against the most common cyber attacks through five technical controls: firewalls, secure configuration, user access control, malware protection, and security update management. Standard Cyber Essentials is a self-assessment; Cyber Essentials Plus adds an independent, hands-on audit.

What it is

Cyber Essentials is a UK government-backed baseline, supported by the National Cyber Security Centre (NCSC). Its five technical controls block the majority of common, high-volume internet attacks. It’s a practical starting point for cyber hygiene rather than a comprehensive security standard.

Who benefits

Any organization wanting an affordable baseline — especially small and medium-sized businesses. It’s often required to win UK public-sector contracts, and many private buyers ask for it too. Even when not mandated, it’s a quick way to prove you’ve covered the fundamentals.

The five controls

Five controls that stop common attacks

Implement these five well and you block the bulk of everyday internet-based threats.

1

Firewalls

Boundary firewalls and internet gateways that control traffic in and out of your networks and devices, keeping untrusted connections out.

2

Secure configuration

Devices and software set up securely — removing default passwords, unnecessary accounts, and features you don't need before they go into use.

3

User access control

Access granted on a least-privilege basis, with administrative rights tightly managed so users only have the access they actually need.

4

Malware protection

Defences against malicious software — anti-malware, allow-listing, or sandboxing — to stop harmful code running on your systems.

5

Security update management

Patching and updates applied promptly so known vulnerabilities in operating systems and applications are fixed before they're exploited.

Self-assessed vs audited

Cyber Essentials vs Cyber Essentials Plus

Same five controls, different levels of verification.

 Cyber EssentialsCyber Essentials Plus
How it's verifiedSelf-assessment questionnaireIndependent technical audit
Hands-on testing by assessor
Covers the five controls
Assurance levelBaselineHigher / audited
Good forA quick, low-cost baselineStronger proof for buyers

A stepping stone to ISO 27001

Cyber Essentials is a focused baseline of five technical controls; ISO 27001 is the comprehensive, internationally recognized certification for an entire Information Security Management System. Cyber Essentials is a fast win and a natural first step; ISO 27001 is the deeper standard larger and international buyers often expect.

Many organizations achieve Cyber Essentials first, then build toward certification. Read our ISO 27001 guide to see where you’re heading, then let Komply map both onto one control set so the work compounds instead of repeating.

FAQ

Cyber Essentials, answered

Cover the fundamentals, then go further

Komply organizes your five Cyber Essentials controls alongside ISO 27001 in one control set — drafting policies, tracking evidence, and keeping you audit-ready.