We think Cyber Essentials is, well, still essential ...

In November 2021 the NCSC announced an overhaul of the Cyber Essentials technical controls and a change to the pricing structure. Both these changes come into effect on 24 January 2022.
Updating the technical controls
When we announced plans to update the Cyber Essential requirements, we said this update was the biggest overhaul of the scheme’s technical controls since its launch in 2014. Six years is a long time in cyber security, but we still believe the basic principles are sound and that Cyber Essentials represents a minimum baseline standard for cyber security in the UK.
But today’s organisations are operating in a very different context to 2014. We’ve seen the rise of cloud computing, greater availability of multi-factor authentication, the pervasive threat of ransomware and of course the global pandemic, which has brought an unprecedented change in the way organisations are working and technology is used.
This means that although the control themes of firewalls, secure configuration, user access control, malware protection and software updates remain the same, the actual requirements have been expanded to address a range of new scenarios, including home working, the use of BYOD and cloud services. This blog summarises the key points with the details in the updated Requirements for IT infrastructure document and some helpful FAQs on our website.
Cloud services
For cloud services, we’ve implemented a shared responsibility model. This is a common method that dictates the security obligations of each party − the cloud provider and the cloud user − to ensure accountability is clear. To help organisations, we’ve also mapped the five technical controls to the three main types of cloud service (IaaS, PaaS, SaaS). But this is a guide only; the ultimate responsibility to ensure the cloud provider is implementing services properly is with the applicant.
Home working
When Cyber Essentials was first launched, home working was viewed as an exception and the guidance was written from that standpoint. That has clearly changed, and for many organisations it has become the norm and is here to stay. We have updated the guidance to reflect this and to clarify what should be included in the assessment scope.
One frequently asked question is the role of Internet Service Providers (ISP) routers in a home working scenario. We have consciously taken them out of scope, because expecting individuals to configure routers correctly, even with company guidance, is impractical. But this makes it even more important that firewall controls are correctly applied to end user devices.
Passwords and multi-factor authentication
Multi-factor authentication (MFA) adds a layer of extra protection for accounts and is now widespread and available for free with most services. We have therefore included information from the NCSC guidance on choosing the right additional factor for your organisation. Whichever method chosen, the most important thing to remember is that it should be usable and accessible to your employees.
The password requirement has also been updated to align with current NCSC guidance. This includes a reference to ‘Three Random Words’ advice. But we're not mandating that approach for Cyber Essentials as it could discourage other methods such as using a password manager or other strategies in our password administration guidance.
A final note on scope
Most changes to scope are to encompass these new requirements. But the scope of certification in the Cyber Essentials certification process is often misunderstood, which is why we've included some additional guidance to mitigate some of the most common issues our Certification Bodies see. It's important that the scope of a certification should cover the IT infrastructure used across all of an organisation's business functions, or a well-defined sub-set of it. To help with this we have provided a new definition of ‘sub-set'.
And finally on scope, we've reinforced that it is never acceptable to exclude end user devices.
Why no backups?
We’re frequently asked about backups and why we don't include them in the Cyber Essentials controls. It’s certainly not because we don’t think they are important. The main reason is that we don’t want to overload organisations in the certification process. Implementing the controls properly makes your organisation a harder target for common types of cyber attack, such as ransomware, and therefore reduces the criticality of backups.
But the NCSC always strongly recommends that all organisations, regardless of size, have a backup and recovery regime, and we now reference this under further guidance in the new Cyber Essentials technical requirements. Belt and braces wins the day!
What about the cost?
With the updates to the technical controls, it also felt like the right time to reconsider the price, which hasn't changed since 2014 regardless of the size and complexity of the applicant organisation. The price change takes account of the new technologies and scenarios our Certification Bodies are grappling that can make certification more time consuming.
We have worked with our partner IASME to balance the price increase and to make sure it doesn't unduly impact smaller organisations − while also ensuring that our Certification Bodies are fairly remunerated for their work. We've adopted a tiered approach with the cost remaining the same for small and micro companies: £300 + VAT for micro companies and rising to £500 + VAT for larger organisations.
We believe that this still represents excellent value for money compared to other certifications.
And what’s next for Cyber Essentials ?
We still view Cyber Essentials as the minimum standard for cyber security in the UK but we also need to ensure it keeps evolving as the threat landscape and technology change. This major update is part of that ongoing regular review. We couldn't do this without our partners in IASME and their Certification Bodies. They keep us on our toes by helping us to understand the cyber security challenges that all organisations face, particularly smaller ones.
We are also looking at what other services we can introduce to support Cyber Essentials. This includes providing an advisory service to help organisations that don't have their own technical support with the practical configuration of their systems, and how to address the security challenges that larger organisations with complex IT estates face to meet the minimum standard.
We really welcome continued feedback on Cyber Essentials. Personally I’m encouraged by the continued growth in the scheme uptake and the valuable cyber security conversations that are happening because of it.
If you have any thoughts about Cyber Essentials, please get in touch and keep things moving in the right direction. You can find all the important details on the NCSC Cyber Essentials pages and in a blog by our Cyber Essentials partner IASME.


