What is Cyber Essentials?
Cyber Essentials is the UK government's baseline cybersecurity scheme, originally launched in 2014 by the Department for Science, Innovation and Technology, now governed by the IASME Consortium under contract from the National Cyber Security Centre (NCSC).
The scheme defines five technical control areas:
- Boundary firewalls and internet gateways
- Secure configuration
- User access control
- Malware protection
- Security update management
Two tiers exist: Cyber Essentials (self-assessed, verified) and Cyber Essentials Plus (CE plus an independent technical assessment).
Why Cyber Essentials matters for MSPs in or selling to the UK
- Mandatory for UK government work. Procurement Policy Note 09/14 requires CE for any UK central government contract handling personal/sensitive information. Many councils, NHS bodies, and defence supply chain partners extend the requirement.
- Insurance leverage. UK cyber insurance carriers reward CE/CE Plus with reduced premiums.
- Recurring service line. MSPs offering CE/CE Plus implementation to UK SMB clients build a high-velocity, low-friction compliance practice. The annual cycle drives recurring revenue.
Where Cyber Essentials applies
Cyber Essentials is UK-specific but recognized as a meaningful baseline in international supply chain conversations. Non-UK MSPs serving UK clients sometimes hold CE for credibility even without UK contracts.
How Cyber Verify accelerates Cyber Essentials
- Pre-built CE / CE Plus assessment templates aligned to current IASME question set
- All 5 control areas mapped to UCS Practice Domains
- Technical assessment pre-check workflow for CE Plus candidates
- Stacking guidance for CE → ISO 27001 progression
- Recertification cadence tracker