Skip to main content

Framework · UK government cyber baseline

Cyber Essentials

The UK government-backed cyber security baseline scheme, developed and endorsed by the National Cyber Security Centre (NCSC), administered through IASME.

WHERE THIS FRAMEWORK FITS

Where this framework fits at Goldline

Goldline does not deliver Cyber Essentials as a standalone certification service. For organisations approaching this framework, we typically recommend a partner referral to an IASME-licensed Certification Body for the technical assessment, and where appropriate, we deliver the ISO 27001 implementation that gives you a broader information security management system foundation.

For active engagement, book a free 45 minute diagnostic and we will confirm whether the ISO 27001 Sprint (or, where AI governance is also in scope, the ISO 42001 Sprint) fits your specific circumstances.

Book the Free Diagnostic

Browse all frameworks

What is Cyber Essentials?

  • Prevents cyber attack: protects an organisation from common internet-based cyber security threats

  • Minimum recommended standard: the minimum baseline cyber security standard recommended for UK organisations by the NCSC

  • Cost-effective: designed to help organisations of all sizes protect against common forms of cyber attack

  • Five technical controls: firewalls, secure configuration, security updates, user access control, malware protection

  • Verified self-assessment: Cyber Essentials Level One is an independently verified self-assessment, signed off by a board member or equivalent senior representative

  • Annual certification: annually renewable certification, aligned with the five technical controls, assessed by an IASME Certification Body

The five technical controls

Cyber Essentials organises its requirements around five technical control themes that together protect against the most common forms of internet-based cyber attack.

Firewalls

Boundary firewalls and internet gateways that separate trusted internal networks from untrusted external ones.

Secure configuration

Secure device and software configuration, removing unnecessary functionality and default credentials.

Security update management

Timely patching of software and operating systems to close known vulnerabilities.

User access control

Managing user accounts and permissions on the principle of least privilege.

Malware protection

Anti-malware measures on all devices in scope to detect and block malicious software.

Who Cyber Essentials applies to

  • All UK organisations pursuing government or public sector contracts

  • All organisations required to demonstrate baseline cyber posture in supply chain due diligence

  • Any UK organisation seeking to reduce common cyber attack risk

  • Organisations pursuing Cyber Essentials Plus, IASME Cyber Assurance, or ISO 27001 certification (Cyber Essentials sits as an entry-level step in the certification staircase)

Frequently asked questions

Discuss where this framework fits your programme

Cyber Essentials is not a service Goldline delivers as a standalone product. Book the Free Diagnostic to discuss the right route to certification and whether ISO 27001 implementation is the right foundation for your organisation.

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.