Cyber Essentials is a UK government-backed scheme, run with the NCSC and delivered by IASME through certification bodies, that verifies five technical controls. Neither the FCA, the PRA nor the SRA requires it, but it is a low-cost, well-recognised baseline that clients, insurers and some government contracts ask for. ISO 27001 and the regulators’ rules cover much more.
Cyber Essentials is a scheme developed by the UK’s National Cyber Security Centre (NCSC) and delivered by IASME. It checks that you have five basic technical controls in place, which together are designed to protect against the most common internet-based attacks:
There are two levels. Cyber Essentials is a self-assessment that a certification body verifies. Cyber Essentials Plus adds hands-on technical testing by an assessor.
The requirements moved to version 3.3 and a new question set, Danzell, which replaces Willow, for new assessments from 27 April 2026. Organisations whose assessment account already existed have a six-month transition. The five controls are unchanged, but marking is stricter:
Neither the FCA, the PRA nor the SRA requires Cyber Essentials. It is still one of the quickest ways for a regulated firm to show that the basics are in place: client due diligence questionnaires, cyber insurers and some UK government contracts ask for it, and it gives your board an independent check of the controls that most attacks exploit.
It lines up well with the protective controls regulators expect (authentication, patching, malware protection and access control), which makes it a practical first milestone. It does not cover governance, operational resilience, incident response or third-party oversight, which regulators also expect.
| Cyber Essentials | ISO 27001:2022 | FCA, PRA and SRA rules | |
|---|---|---|---|
| What it is | UK government-backed baseline scheme | International standard for an information security management system | Regulatory rules for authorised firms |
| What it covers | Five technical controls | Governance, risk, people, suppliers and technology | Governance, technical controls, third parties, incidents and reporting |
| How you show it | Certificate (Essentials or Plus), renewed every 12 months | Certificate from an accredited body, audited each year | Evidence to the regulator on request, plus incident reporting |
| Mandatory for regulated firms? | No | No | Yes |
Certification itself is carried out by a certification body licensed by IASME. An MSP can prepare you and supply the technical evidence, and Cre8 IT helps clients scope, fix and evidence their controls, but no MSP can certify you.
Last reviewed 25 September 2026. This guide is general information, not legal or regulatory advice. Rules change, so check the current text and take advice from your compliance officer or legal adviser before relying on it.
