How can I help with Cyber Essentials?

Free AI guidance for Cyber Essentials certification.

About the Cyber Essentials assistant

Seeded with Cyber Essentials concepts: the UK government-backed scheme developed by the NCSC and delivered through IASME, the five technical control themes (firewalls, secure configuration, security update management, user access control, and malware protection), the verified self-assessment route and the independent technical testing added at Cyber Essentials Plus, the scoping rules for end-user devices, cloud services, home and remote working, and BYOD, and the 12-month certification cycle.

  • Prepare your self-assessment answers theme by theme, working through what good looks like for firewalls, secure configuration, security update management, user access control, and malware protection across the devices, software, and services your organisation uses.
  • Set a defensible certification scope: the whole organisation or a well-defined, separately managed sub-set, knowing that end-user devices must be included and cloud services that hold organisational data or services cannot be excluded, and work out which home and remote working and user-owned (BYOD) devices fall in scope.
  • Plan the step up to Cyber Essentials Plus and the annual renewal, understand the independent technical testing an assessor carries out on in-scope devices, and prepare for bids where UK public-sector buyers ask for Cyber Essentials certification.

It gives preparation guidance to speed up your work. It is not a certification body, it cannot award Cyber Essentials or Cyber Essentials Plus, and it is not a substitute for assessment by a licensed certification body.

Read the full Cyber Essentials guide