Secure your business with confidence.
Cyber Essentials is a UK Government-backed cyber security certification scheme designed to help organisations protect themselves against the most common internet-based cyber attacks.
The scheme focuses on five fundamental technical controls that provide a strong baseline for cyber security and help reduce common vulnerabilities across your organisation.
There are two levels of certification: Cyber Essentials, which is independently verified through a self-assessment, and Cyber Essentials Plus, which adds a technical audit to confirm the controls are implemented effectively.
Secarma supports organisations through both certifications, helping you understand the requirements, prepare for assessment and achieve the level of assurance your business needs.
Many cyber attacks exploit common weaknesses such as insecure configurations, outdated software and poorly controlled access. Cyber Essentials provides a practical baseline for addressing these risks and demonstrating that fundamental security measures are in place.
Certification can also provide valuable assurance to customers, partners and suppliers, and is increasingly requested as part of contracts, tenders and supply chain requirements. Whether you're strengthening your own security or demonstrating it to others, Cyber Essentials provides an independently verified way to show that your organisation takes cyber risk seriously.
Cyber Essentials and Cyber Essentials Plus assess the same five technical controls. The key difference is the level of independent assurance provided.
Verified self-assessment
Your organisation completes an assessment covering the five Cyber Essentials technical controls. Your answers are independently reviewed by a qualified Cyber Essentials Assessor before certification is awarded.
It's a strong starting point for organisations looking to establish and demonstrate a recognised baseline of cyber security.
Independent technical verification
Cyber Essentials Plus assesses the same five controls but adds a hands-on technical audit of your in-scope systems to verify that those controls have been correctly implemented.
It provides a higher level of assurance and may be appropriate where Plus is required by a customer, contract or supply chain.
Already achieved Cyber Essentials? If you complete your Cyber Essentials Plus audit within three months of achieving Cyber Essentials, you won't need to repeat the self-assessment questionnaire.
Protecting the boundary between your devices and the internet and controlling unwanted access to your systems and services.
Ensuring devices, software and services are configured securely, with unnecessary functionality removed or disabled to reduce opportunities for attack.
Keeping operating systems, applications and software supported and appropriately updated to protect against known vulnerabilities.
Making sure users only have the accounts and permissions they need, with appropriate authentication and control over privileged access.
Using appropriate measures to prevent malicious software from compromising your devices, systems and data.
We'll help you understand the scope of your assessment so it's clear which systems, devices, users and services need to meet the Cyber Essentials requirements.
You'll complete the Cyber Essentials self-assessment covering your organisation and the five technical controls.
A qualified Cyber Essentials Assessor reviews your submission and provides feedback where answers need clarification or requirements haven't yet been met.
For Cyber Essentials Plus, your Assessor carries out technical testing of your in-scope infrastructure and a representative sample of devices to verify that the controls are operating effectively.
Once the requirements have been successfully met, you'll receive your Cyber Essentials or Cyber Essentials Plus certificate.
Certification is valid for 12 months and must be renewed annually to remain current.