UK government-backed certification verifying technical controls against the most common cyber threats — and the standard we hold our own operations to.
National Cyber Security Centre
The Standard
Cyber Essentials Plus is the UK's most widely recognised baseline for cyber security hygiene — here's what the standard covers and what independent verification means in practice.
Cyber Essentials is a UK government scheme that defines five technical controls every organisation should have in place. It exists because most successful cyber attacks exploit basic weaknesses — unpatched software, weak passwords, uncontrolled access — that these controls directly address.
The scheme covers boundary firewalls, secure system configuration, access controls, malware protection, and patch management. The Plus variant goes further: rather than accepting self-certification, an external assessor tests the controls hands-on and verifies they actually work.
Many public sector bodies and regulated enterprises now ask their technology suppliers to demonstrate Cyber Essentials compliance. For NCSC-aligned procurement frameworks and defence contracts, it is a baseline requirement — not optional.
Why It Matters
Cyber Essentials alignment in your supply chain is not just a compliance formality — it has real, practical consequences for your exposure.
NHS organisations, government departments, and many regulated enterprises require Cyber Essentials compliance from their technology suppliers. Knowing your provider operates to the same controls removes a procurement barrier and simplifies your own supplier risk assessments.
The overwhelming majority of successful cyber attacks exploit preventable weaknesses. Cyber Essentials Plus demonstrates that a provider has done the unglamorous work — patched systems, locked down access, configured firewalls — rather than just investing in security theatre.
When your technology partners implement strong access controls and secure configurations, your attack surface shrinks alongside theirs. Cyber Essentials alignment in your supply chain is a meaningful risk reduction, not a paperwork exercise.
How We Operate
We implement the five controls that Cyber Essentials Plus requires across every environment and engagement we operate. Here is what that looks like in practice.
Every environment we build and operate is subject to firewall rules that permit only what is explicitly required. Inbound access is restricted by default; we do not expose services to the internet unless there is a specific, documented reason to do so. This is standard practice on every engagement, not an optional add-on.
Systems we deploy are configured securely from the outset — unnecessary services disabled, default credentials changed, and attack surface minimised before anything else is built on top. We do not rely on infrastructure providers' defaults and assume they are safe.
User accounts and service credentials are granted only the permissions required for a specific function. Administrative access is tightly controlled, audited, and revoked when no longer needed. No standing production access, no shared credentials.
We apply security patches on a defined schedule and maintain endpoint protection across the systems we operate. Vulnerabilities in licensed software and operating systems are tracked and addressed, not left to accumulate.
Related Services
These are the parts of our practice where Cyber Essentials alignment is most directly relevant.
The secure, controlled environments we build and manage — where boundary controls and hardened configuration are the starting point.
Applications developed with security built in from the start, not bolted on after the fact.
AI-powered systems designed and deployed within the same secure operating principles we apply across every engagement.
Work With Us
We operate to the same technical controls that Cyber Essentials Plus requires — applied consistently across every environment and engagement. If you'd like to understand how that applies to your procurement requirements, we're happy to talk it through.