Back to Frameworks
Frameworks

NCSC Cyber Essentials (United Kingdom)

Framework Name

NCSC Cyber Essentials

Type

Voluntary, though mandatory as a prerequisite for many UK government contracts, and increasingly required contractually by larger private-sector customers of their suppliers

Region / Jurisdiction

United Kingdom

Enforcing Body / Certifying Party

National Cyber Security Centre (NCSC), which owns the scheme, delivered through IASME as the NCSC's sole delivery partner since 2020, with assessments carried out by IASME-accredited certification bodies

Penalty / Consequence of Non-Compliance

No direct legal penalty. The consequence is commercial and contractual: losing eligibility to bid on UK government contracts that require it under procurement policy, and increasingly losing business from larger private-sector customers who now require certification from their suppliers as a baseline

What It Is & Why It Matters

Cyber Essentials is a UK government-backed scheme built around five technical controls, firewalls, secure configuration, user access control, malware protection, and security update management, chosen specifically because evidence showed these five basic measures would have stopped the majority of common internet-based attacks the scheme's predecessor investigated. It comes in two tiers: Cyber Essentials, a self-assessment questionnaire independently verified by an assessor, and Cyber Essentials Plus, which adds hands-on technical testing of the organization's actual systems, a meaningfully higher bar than the base tier's paperwork-driven review.

It matters because of its scale and reach: more than 215,000 certificates have been awarded since the scheme launched, spanning businesses, charities, schools, universities, and local authorities, and it's a required prerequisite for many UK public sector contracts under Procurement Policy Note 014. It's also increasingly becoming a de facto supply chain requirement well beyond government work, the NCSC published a Cyber Essentials supply chain playbook in 2026 specifically encouraging larger organizations to require it from their suppliers, and a Cyber Security and Resilience Bill currently progressing through Parliament is expected to push supply chain security scrutiny further still.

Who Needs It

  • You are a UK organization of any size wanting a recognized, government-backed baseline cybersecurity certification
  • You're bidding on UK government contracts that require Cyber Essentials certification under PPN 014
  • You're an SME supplying a larger UK business that has started requiring Cyber Essentials certification from its suppliers
  • You want independently verified technical assurance (Cyber Essentials Plus) rather than the self-assessed base tier
Book A Demo