NCSC (technical authority); IASME Consortium (delivery partner) · United Kingdom

Cyber Essentials and Cyber Essentials Plus (v3.3) compliance software

Prepare for Cyber Essentials and Cyber Essentials Plus under v3.3 and the Danzell question set: the five technical controls, the scope rules, the automatic-fail checks and the CE+ technical verification, tracked per certified entity and across the group.

At a glance
  • Owner and deliveryNCSC (requirements); IASME Consortium and its licensed certification bodies (assessment)
  • VersionRequirements for IT Infrastructure v3.3 and the Danzell question set, for accounts created from 27 April 2026
  • Assessable items115 requirements in 8 domains, 50 of them critical and 18 automatic-fail
  • Technical controlsFirewalls, secure configuration, security update management, user access control, malware protection
  • LevelsCyber Essentials (verified self-assessment); Cyber Essentials Plus (technical audit within 3 months of the CE certificate)
  • ScopeGroup or certified legal entity; profiles Cyber Essentials and Cyber Essentials Plus
Cyber EssentialsAvailable
Overview

What Cyber Essentials requires

Who it applies to

  • Suppliers to central government departments, executive agencies, NDPBs and NHS bodies under PPN 014, for contracts that handle personal data, OFFICIAL ICT systems or day-to-day government business
  • MOD suppliers and subcontractors working towards Defence Cyber Certification, which requires Cyber Essentials at every level and CE+ at Levels 2 and 3
  • Small and medium organisations, charities and public bodies certifying for customers, supply chains and the cyber liability insurance included for eligible organisations
  • Groups with several legal entities, sub-sets and cloud tenants, which v3.3 lets list every in-scope entity on one certificate or certify separately

Cyber Essentials is the UK government-backed certification for five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. NCSC is the technical authority and owns the requirements; IASME Consortium is the sole delivery partner and runs the scheme through licensed certification bodies. Cyber Essentials is a verified self-assessment, signed off by a board member or equivalent and marked by an assessor; Cyber Essentials Plus adds an independent technical audit of a sample of devices, every internet gateway and every internet-facing server. Certificates are valid for 12 months.

Version 3.3, answered through the Danzell question set, applies to assessment accounts created from 27 April 2026. Multi-factor authentication is now mandatory on every cloud service where it is available, and its absence is an automatic fail; so is not installing high-risk or critical updates for operating systems, router and firewall firmware or applications within 14 days. Cloud services can no longer be excluded from scope, every exclusion must be justified, the declaration now covers ongoing compliance, and a second failed CE+ update-management test revokes the Cyber Essentials certificate.

The scheme is voluntary in law but widely required by contract: central government asks for it under PPN 014, the MOD's Defence Cyber Certification requires it at every level and CE+ at Levels 2 and 3, and signatories of the Cyber Resilience Pledge commit to requiring it across their supply chains on a risk basis. 61,430 certificates were awarded between July 2025 and June 2026: 46,245 Cyber Essentials and 15,185 Cyber Essentials Plus.

In the platform

How GRCLens supports Cyber Essentials

Cyber Essentials runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.

Automatic fails surfaced first

The 18 checks that fail certification outright are flagged apart from the rest: MFA on every cloud service that offers it, high-risk and critical updates within 14 days (Danzell A6.4 and A6.5), unsupported software in scope, cloud services or end-user devices left out of scope, the board declaration and each CE+ test case. One of them answered No fails the whole submission, so it is shown as a fail rather than averaged into a score.

CE+ technical verification readiness

The Cyber Essentials Plus domain follows NCSC's current test specification (v3.2) with IASME's April 2026 changes: the external vulnerability scan, the authenticated scan of sampled devices, malware-protection tests, the MFA check on every cloud service and account separation, with the 3-month window, the retest on a new random sample and revocation on a second failure.

Group roll-up and four stakeholder dashboards

Each certified legal entity is assessed on its own and rolls up into a group view with a heat map across 15 risk areas and the five controls. The board sees readiness and automatic fails; the CISO and risk team the heat map and control scores; operations the control validation and open remediation; third-party and procurement teams supplier certificates, PPN 014 evidence and Pledge commitments.

Continuous assurance from connectors

Vulnerability and patch, identity and MFA, backup and restore, incident records, the third-party register, resilience testing, training (LMS) and log monitoring are read against the questionnaire, alongside the existing Entra, Tenable, Qualys, Splunk and ITSM connectors. A failing check whose requirement was answered Implemented is flagged as a contradiction.

Assurance register, remediation and KRIs

Each requirement can carry several owners in the assurance register. Gaps become owned, dated actions in the remediation and risk treatment plan, and key risk indicators name the requirements they measure, so an indicator outside appetite beside an answer of Implemented is a finding.

Baseerah summary, Word and PDF reports

Baseerah, the platform's AI assistant running on a self-hosted language model, writes a one-paragraph executive summary for the board and the CISO. Entity and group reports export as Word and PDF.

Questions

Cyber Essentials frequently asked questions

What changed in Cyber Essentials v3.3?

v3.3 and the Danzell question set apply to assessment accounts created from 27 April 2026; accounts opened earlier have six months to certify on v3.2. MFA became mandatory on every cloud service where it is available, and its absence an automatic fail; two new automatic-fail questions require high-risk or critical updates to be installed within 14 days; cloud services cannot be excluded from scope; certificates list every in-scope legal entity; and the board-level declaration now covers ongoing compliance.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a verified self-assessment: the organisation answers the question set, a board member or equivalent signs it off, and an assessor at a certification body marks it. Cyber Essentials Plus covers the same five controls but adds an independent technical audit of a sample of devices, every internet gateway and every internet-facing server, completed within three months of the Cyber Essentials certificate. Both certificates are valid for 12 months.

Which answers fail Cyber Essentials automatically?

Missing MFA on any in-scope cloud service that offers it, and high-risk or critical updates not installed within 14 days (Danzell A6.4 for operating systems and router and firewall firmware, A6.5 for applications). Unsupported software left in scope, a scope that excludes cloud services or contains no end-user devices, and a missing board declaration also fail. In Cyber Essentials Plus any failed sub-test fails the assessment unless the delivery partner accepts it as a marginal deviation, and a second update-management failure revokes the Cyber Essentials certificate.

Is Cyber Essentials mandatory?

Not in law, but often by contract. PPN 014 (17 February 2025) requires it, or independently verified equivalent controls, for central government contracts that handle personal data, OFFICIAL ICT systems or day-to-day government business. The MOD's Defence Cyber Certification requires it at every level, and Cyber Resilience Pledge signatories commit to requiring it across their supply chains on a risk basis.

Does GRCLens issue Cyber Essentials certificates?

No. Certificates are issued through IASME's licensed certification bodies, which mark the self-assessment and carry out the CE+ audit. GRCLens prepares and evidences the answers, and tracks readiness against the requirements, the automatic-fail checks and the CE+ test cases before the submission goes in.

Talk to us about Cyber Essentials

Security Solution Consultants provides Cyber Essentials readiness and advisory alongside the platform, so you can combine tooling with hands-on expertise.