What happens in Cyber Essentials?
You complete the scheme questionnaire against the required scope and five technical controls. The submission is independently assessed. NCSC currently describes Cyber Essentials as the baseline certification route, priced by organisation size.
What changes for Cyber Essentials Plus?
Cyber Essentials Plus uses the same control framework but adds a technical audit to verify that the controls are working in practice. IASME states that a valid Cyber Essentials verified self-assessment is a prerequisite for Cyber Essentials Plus.
What should you prepare before assessment?
- Define the organisation and technology that are in scope.
- Confirm internet gateways, user devices, servers and relevant cloud services.
- Review account privileges and multi-factor authentication where required.
- Check supported software and security update management.
- Collect evidence before the assessor asks for it.
Current security-update rule
Under the current Cyber Essentials Requirements for IT Infrastructure v3.3, in-scope software must be supported and relevant vulnerability fixes must be applied within 14 days where the vendor classifies the issue as critical/high risk, the CVSS v3 base score is 7 or above, or severity information is unavailable.