Framework · UK government cyber baseline
Cyber Essentials
The UK government-backed cyber security baseline scheme, developed and endorsed by the National Cyber Security Centre (NCSC), administered through IASME.
WHERE THIS FRAMEWORK FITS
Where this framework fits at Goldline
Goldline does not deliver Cyber Essentials as a standalone certification service. For organisations approaching this framework, we typically recommend a partner referral to an IASME-licensed Certification Body for the technical assessment, and where appropriate, we deliver the ISO 27001 implementation that gives you a broader information security management system foundation.
For active engagement, book a free 45 minute diagnostic and we will confirm whether the ISO 27001 Sprint (or, where AI governance is also in scope, the ISO 42001 Sprint) fits your specific circumstances.
Book the Free DiagnosticWhat is Cyber Essentials?
Prevents cyber attack: protects an organisation from common internet-based cyber security threats
Minimum recommended standard: the minimum baseline cyber security standard recommended for UK organisations by the NCSC
Cost-effective: designed to help organisations of all sizes protect against common forms of cyber attack
Five technical controls: firewalls, secure configuration, security updates, user access control, malware protection
Verified self-assessment: Cyber Essentials Level One is an independently verified self-assessment, signed off by a board member or equivalent senior representative
Annual certification: annually renewable certification, aligned with the five technical controls, assessed by an IASME Certification Body
The five technical controls
Cyber Essentials organises its requirements around five technical control themes that together protect against the most common forms of internet-based cyber attack.
Firewalls
Boundary firewalls and internet gateways that separate trusted internal networks from untrusted external ones.
Secure configuration
Secure device and software configuration, removing unnecessary functionality and default credentials.
Security update management
Timely patching of software and operating systems to close known vulnerabilities.
User access control
Managing user accounts and permissions on the principle of least privilege.
Malware protection
Anti-malware measures on all devices in scope to detect and block malicious software.
Who Cyber Essentials applies to
All UK organisations pursuing government or public sector contracts
All organisations required to demonstrate baseline cyber posture in supply chain due diligence
Any UK organisation seeking to reduce common cyber attack risk
Organisations pursuing Cyber Essentials Plus, IASME Cyber Assurance, or ISO 27001 certification (Cyber Essentials sits as an entry-level step in the certification staircase)
Related pages
Cyber Essentials sits at the entry point of a longer certification staircase. Explore the delivery programme and the frameworks that most Goldline clients progress to next.
Frequently asked questions
Discuss where this framework fits your programme
Cyber Essentials is not a service Goldline delivers as a standalone product. Book the Free Diagnostic to discuss the right route to certification and whether ISO 27001 implementation is the right foundation for your organisation.
