Black Opal

Cyber Essentials Plus

UK government-backed certification verifying technical controls against the most common cyber threats — and the standard we hold our own operations to.

National Cyber Security Centre

The Standard

What It Is

Cyber Essentials Plus is the UK's most widely recognised baseline for cyber security hygiene — here's what the standard covers and what independent verification means in practice.

A government-backed baseline with real teeth

Cyber Essentials is a UK government scheme that defines five technical controls every organisation should have in place. It exists because most successful cyber attacks exploit basic weaknesses — unpatched software, weak passwords, uncontrolled access — that these controls directly address.

Five controls, independently verified

The scheme covers boundary firewalls, secure system configuration, access controls, malware protection, and patch management. The Plus variant goes further: rather than accepting self-certification, an external assessor tests the controls hands-on and verifies they actually work.

Increasingly required, not just recommended

Many public sector bodies and regulated enterprises now ask their technology suppliers to demonstrate Cyber Essentials compliance. For NCSC-aligned procurement frameworks and defence contracts, it is a baseline requirement — not optional.

Why It Matters

What It Means For You

Cyber Essentials alignment in your supply chain is not just a compliance formality — it has real, practical consequences for your exposure.

Required for public sector and regulated contracts

NHS organisations, government departments, and many regulated enterprises require Cyber Essentials compliance from their technology suppliers. Knowing your provider operates to the same controls removes a procurement barrier and simplifies your own supplier risk assessments.

Proof that basic hygiene is in place

The overwhelming majority of successful cyber attacks exploit preventable weaknesses. Cyber Essentials Plus demonstrates that a provider has done the unglamorous work — patched systems, locked down access, configured firewalls — rather than just investing in security theatre.

Reduces your exposure through your supply chain

When your technology partners implement strong access controls and secure configurations, your attack surface shrinks alongside theirs. Cyber Essentials alignment in your supply chain is a meaningful risk reduction, not a paperwork exercise.

How We Operate

Cyber Essentials in Practice

We implement the five controls that Cyber Essentials Plus requires across every environment and engagement we operate. Here is what that looks like in practice.

Controlled network boundaries across every environment

Every environment we build and operate is subject to firewall rules that permit only what is explicitly required. Inbound access is restricted by default; we do not expose services to the internet unless there is a specific, documented reason to do so. This is standard practice on every engagement, not an optional add-on.

Secure configuration as the starting point

Systems we deploy are configured securely from the outset — unnecessary services disabled, default credentials changed, and attack surface minimised before anything else is built on top. We do not rely on infrastructure providers' defaults and assume they are safe.

Access controls and least privilege, applied consistently

User accounts and service credentials are granted only the permissions required for a specific function. Administrative access is tightly controlled, audited, and revoked when no longer needed. No standing production access, no shared credentials.

Patched software and active malware protection

We apply security patches on a defined schedule and maintain endpoint protection across the systems we operate. Vulnerabilities in licensed software and operating systems are tracked and addressed, not left to accumulate.

Related Services

Where This Shows Up

These are the parts of our practice where Cyber Essentials alignment is most directly relevant.

Work With Us

Controls In Place. No Compromises.

We operate to the same technical controls that Cyber Essentials Plus requires — applied consistently across every environment and engagement. If you'd like to understand how that applies to your procurement requirements, we're happy to talk it through.