Skip to main content
Guidance

NCSC Annual Review 2021

Making the UK the safest place to live and work online

Page 40 of 44

Setting standards, certifying professional practice and assuring services and products



There are two levels of certification to demonstrate an organisation’s implementation of a set of technical controls:

  • Cyber Essentials, an independently verified self assessment
  • Cyber Essentials Plus, has the addition of a technical audit by a qualified assessor

Benefits of being certified include:

  • automatic cyber liability insurance for any UK organisation who certifies their whole organisation and have less than £20m annual turnover
  • you can demonstrate compliance with government procurement rules
  • reassure customers and potential new business leads that cyber security is taken seriously



Participating in the i100 programme challenged my way of thinking and allowed my firm to help the NCSC with their objectives in a really beneficial way. We all gained from the insight and relationships which developed through working together.

It gave me the opportunity to collaborate with peers from the legal profession and to talk about the challenges we faced as an industry with more than a little sensitive data to manage. It also provided an open channel for the NCSC to provide feedback on events in the legal sector and ensured their guidance reached the desired audience.

The Information Security and Compliance Manager at a large European Law Firm and a member of the i100 Legal group



Published

Reviewed

Version

1.0

Written for