Skip to main content

Cyber Essentials Pathways: from proof of concept to cyber confidence

An alternative path to Cyber Essentials Plus certification, without compromising the integrity of the scheme. 

Abstract branching grooves on a concrete surface filled with glowing spheres, illustrating routing, load balancing, parallel processing and flow optimization.

Eugene Mymrin via Getty Images

Large organisations often tell us the same thing. “We want to achieve Cyber Essentials Plus, but the way we operate does not align with the technical controls that Cyber Essentials Plus requires.” 

Complex architectures, legacy systems, and layered security requirements mean that a purely prescriptive approach can sometimes feel more like a constraint than something that enables better security outcomes.

Pathways was designed to respond to this challenge, providing a way for organisations to demonstrate that their controls deliver equivalent (or better) protection, even where they differ from the standard Cyber Essentials model.

Essentially, Pathways introduces flexibility without weakening trust.

It’s all about giving organisations more than one way to demonstrate that they are achieving the same overall outcome, rather than implementing the individual security controls. It effectively provides an ‘alternative pathway’ to achieving Cyber Essentials Plus certification, without compromising the integrity of the scheme. 

Over the last 18 months, we’ve been running the Cyber Essentials Pathways Proof of Concept (PoC) to see if organisations can demonstrate that their alternate controls manage the risks covered by Cyber Essentials. This culminated in one of the PoC organisations demonstrating that they could achieve Cyber Essentials plus using the Pathways approach.

In this blog we’ll explain what worked with the PoC, what didn't, what needs to change, and what happens next.


What we learned

The NCSC worked with 22 organisations, alongside IASME and their Certification Bodies, to: 

  • test how alternative controls could be assessed against Cyber Essentials requirements in a structured and defensible way 
  • understand what additional guidance and governance would be needed 

Some of what we learned confirmed our expectations, but some of it genuinely surprised us. 


What happens next?

We’re now ready to take the next step; opening Pathways to a broader (but still carefully managed) set of organisations, and testing how Pathways operates within the existing Cyber Essentials ecosystem, including Certification Body and Assessor qualifications. During this phase, we will build our knowledge of what works in particular contexts, and refine the methodology and supporting guidance. This approach allows us to scale carefully, maintaining trust in the scheme while continuing to learn and adapt.

The NCSC will act as the authority for confirming that Cyber Essentials risk is being appropriately managed, working closely with IASME and Certification Bodies. Only when we have sufficient confidence and consistency in the approach will the NCSC step back.

If your organisation operates at enterprise scale and believes Cyber Essentials Plus outcomes are achievable but difficult to demonstrate through the traditional CE approach, get in touch to discuss suitability, readiness, and potential engagement routes. 


Increasing flexibility, maintaining strength

Cyber Essentials remains a cornerstone of the UK’s cyber resilience. Pathways isn’t about changing that foundation; it’s about giving organisations more than one way to demonstrate that they are effectively managing the most fundamental risk faced on a day-to-day basis, without lowering the standard. Cyber Essentials works because it is clear, accessible, and trusted and remains just as relevant when countering today’s attacks. Pathways must protect those strengths, even as we introduce more flexibility. 

We’re really grateful to all the organisations and Certification Bodies who contributed to the PoC. Their openness, expertise and willingness to work through new (and sometimes complex) challenges has been instrumental in getting us to this point. Personally, one of the most encouraging aspects has been seeing how organisations responded when given a bit more flexibility. Not by lowering the bar, but by engaging more deeply with what good security looks like in their environment.

Anne W, Head of Industry Assurance

Written by

Anne W Head of NCSC Industry Assurance

Published

Part of blog