Funded Cyber Essentials Programme
Small organisations from specific sectors in the UK are invited to take part in the Funded Cyber Essentials Programme.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening

The NCSC’s Funded Cyber Essentials Programme aims to help small companies and organisations within sectors most at risk of cyber attack with free, hands-on help to implement the cyber security controls that prevent most common types of attacks.
The Funded Cyber Essentials Programme is now closed.
Some sectors are at greater risk of cyber attack than others, perhaps because of sensitive information they deal with, or because they're seen as an ‘easy target’ for cyber criminals. The focus of the Funded Cyber Essentials Programme is on supporting small companies who have a low level of cyber maturity and work with data that is sensitive and would have significant impact if disrupted. The programme will offer Cyber Essentials Plus to specific sectors that are at high risk of cyber attack, at no cost.
Cyber Essentials is an effective, Government backed scheme that will help you to protect your organisation, whatever its size, against a whole range of the most common cyber attacks.
The Funded Cyber Essentials Programme is now closed.
The Funded Cyber Essentials Programme will seek to help UK companies meet the five technical controls of Cyber Essentials – firewalls, secure settings, access controls, malware and software updates – by identifying and implementing improvements that are right for the size and needs of the organisation.
Companies that meet the criteria and that are eligible for the programme will receive hands-on support from a Cyber Advisor at no cost, although please note that the NCSC and IASME won't provide any additional software or hardware that the advisor identifies as required to achieve Cyber Essentials.
Qualifying companies will receive around 20 hours of remote support with a Cyber Advisor. This time will be used to support an organisation in implementing the five Cyber Essentials technical controls, followed by a hands-on technical verification that the controls have been put in place. Working with IASME, organisations will receive a set amount of hands-on support from a Cyber Advisor to review technical controls and make configuration changes to the organisation’s systems if required.
Even if it's not possible for the organisation to achieve Cyber Essentials Plus, the Advisor will help it to implement as many of the technical controls as possible and give a clear list of the additional actions the company needs to take to be compliant. Those taking part in this scheme don't need Cyber Essentials certification, as the programme is designed to lead an organisation through the technical controls required to achieve certification. However a Cyber Essentials assessment will need to be completed before assessing for Plus.
Under the scheme, those organisations who are eligible and sign up will receive support through one of IASME’s network of NCSC Assured Service Providers. Cyber Advisors will be used to deliver the Funded Cyber Essentials Programme on behalf of the NCSC, and all advisors must go through training and pass the relevant assessments and exams before working on the programme.


