Skip to main content
[MSP Guide]_

Cyber Essentials for MSPs: How the Scheme Works and How to Deliver It

A practitioner guide to the UK's NCSC-owned certification scheme: what the five controls actually check, when Cyber Essentials Plus applies, and how to deliver it for clients from scoping through to renewal.

The Basics

What Cyber Essentials Is

Cyber Essentials is a UK government-backed scheme, owned by the National Cyber Security Centre (NCSC) and delivered by IASME as the sole delivery partner. It sets out five technical controls that guard against common cyber attacks, verified either by self-assessment (Cyber Essentials) or by independent testing on top of that (Cyber Essentials Plus).

Cyber Essentials is voluntary for most organisations, but it becomes a contractual requirement for specific categories of UK central-government contract under the current policy instrument, PPN (Procurement Policy Note) Action Note 014, updated February 2025 and in force from 24 February 2025. PPN 014 supersedes PPN 09/14 and PPN 09/23, the two earlier versions of the same requirement.

PPN 014 is explicit that this is not a blanket rule: "In-scope organisations must not take a blanket approach" to requiring Cyber Essentials — it applies where a contract handles citizens' or civil servants' personal data, processes data at OFFICIAL classification, or is otherwise part of day-to-day government or public-finance business. That's useful MSP guidance in its own right: check the actual contract characteristics before assuming certification is required.

One disambiguation worth making early: Singapore's Cyber Security Agency (CSA) runs its own, separate "Cyber Essentials mark" under a different scheme. It shares the name but not the requirements — this page is about the UK's NCSC/IASME scheme.

Two Levels

Cyber Essentials vs Cyber Essentials Plus

Both assess the same five technical controls. The difference is how that's verified, and — for Plus — when it commonly needs to happen relative to the base certificate.

Assessment method

Cyber Essentials
A self-assessment questionnaire, verified by an independent certification body.
Cyber Essentials Plus
The same five controls, plus independent remote and on-site vulnerability testing using commodity attack tools.

What it confirms

Cyber Essentials
That the five controls are declared, understood, and in place — a basic level of assurance.
Cyber Essentials Plus
That the controls actually hold up against a hands-on attempt to get through them — a more rigorous assessment.

Timing relative to base CE

Cyber Essentials
Stands on its own; renewed independently each cycle.
Cyber Essentials Plus
Commonly expected within 3 months of the base Cyber Essentials certificate — check the current window with your certification body.

Renewal

Cyber Essentials
Every 12 months.
Cyber Essentials Plus
Every 12 months, alongside the base certificate.
The Controls

The Five Technical Controls

PPN 014's own annex names these five control themes. NCSC's requirements document uses "user access control" for the fourth; PPN 014's shorter "access control" phrasing refers to the same theme.

Boundary firewalls and internet gateways

What assessors check: Every internet-facing boundary device has its default administrative password changed, unnecessary services and ports closed, and its management interface kept off the open internet.

Common failure points: Default router or firewall admin credentials left unchanged, or a management interface reachable from the internet.

Secure configuration

What assessors check: Unnecessary user accounts, software, and auto-run features are removed or disabled before a device goes into service, and out-of-the-box defaults have been reviewed rather than left as shipped.

Common failure points: Unused default accounts or services left enabled, or auto-run features not disabled.

User access control

What assessors check: User accounts are set up and approved by someone with the authority to do so, administrator rights are restricted to a separate account used only for admin tasks, and accounts are removed or disabled when no longer needed.

Common failure points: Shared admin accounts, or an admin account also used for email and everyday browsing.

Malware protection

What assessors check: Anti-malware software is installed and kept up to date on every in-scope device, or an equivalent control such as application allow-listing or sandboxing is in place.

Common failure points: Malware protection missing, disabled, or out of date on a subset of in-scope devices.

Security update management

What assessors check: All in-scope software is licensed and vendor-supported, and security updates rated critical or high severity (or unrated, treated as high by default) are applied within 14 days of release.

Common failure points: Unsupported or end-of-life software still in scope, or a critical/high-severity update applied outside the 14-day window.

Version and Timing

Which Requirements Version Applies

The question set behind Cyber Essentials is updated periodically. "Danzell" (v3.3) took effect from 27 April 2026 and is now the question set for new assessments. The previous version, "Willow" (v3.2, April 2025), may still apply to assessment accounts opened before that date during a transition period — check IASME for the question set that applies on your client's assessment date.

Under Danzell (v3.3), multi-factor authentication must be enabled for every user account on all in-scope cloud services, including where it is only available as a paid upgrade. Willow (v3.2) required it "where available". Check IASME for the exact scope and timing before telling a client MFA is optional on any cloud service.

Scope

Getting the Scope Right

The default scope is the legal entity delivering the goods or services — not the wider corporate group it might belong to. A supplier can voluntarily restrict certification to part of that entity, but the certification body has to agree the boundary is reasonable; it isn't the supplier's call alone.

Cloud services, most bring-your-own-device use, and home or remote worker devices are in scope by default if they can access organisational data or services — a common scoping mistake is excluding them because they aren't company-owned. Certification also doesn't automatically extend assurance to a third party the organisation shares data with, such as a cloud provider.

Delivery Workflow

How an MSP Delivers Cyber Essentials for a Client

Seven phases, working from first contact through to the annual renewal cycle.

Confirm the need

Check whether Cyber Essentials is being pursued for a specific contract — and, if so, whether that contract genuinely fits PPN 014’s characteristics — or as a general security baseline the client wants regardless.

Agree the scope

Default to the legal entity delivering the service. If a narrower boundary is proposed, it has to be agreed as reasonable by the certification body, not just by the client.

Run a gap check against the five controls

Compare current firewalls, configuration, access control, malware protection, and update management against what the applicable question set asks for.

Remediate

Close the gaps the check found — commonly MFA on cloud services, separating admin accounts, and catching up overdue security updates.

Complete the question set and submit

Complete the self-assessment questionnaire for the version that applies on the assessment date, and submit it to a certification body for verification.

Add Cyber Essentials Plus testing if required

If the client needs Plus, book the independent vulnerability testing — commonly expected within 3 months of the base certificate.

Track renewal and requirements changes

Certification lapses after 12 months, and the question set itself changes periodically — track which version applies at each client’s renewal date.

MSPs that want to offer NCSC-assured advice on top of certification support can look at the Cyber Advisor scheme: IASME partners with the NCSC to run it, and an individual becomes a Cyber Advisor by passing an assessment run by The Cyber Scheme. To offer Cyber Advisor services formally, the MSP itself registers with IASME as an Assured Service Provider and employs or contracts at least one assessed Cyber Advisor. Check IASME for the current registration requirements before advertising either credential to clients.

Cost

What It Costs

PPN 014 itself cites the cost for smaller companies to be Cyber Essentials certified as "currently expected to range between £300 and £500+VAT at basic level" (February 2025) — and notes that costs may change over time, so treat this as an anchor figure rather than a fixed price. Cyber Essentials Plus and larger organisations cost more, driven by network size and complexity; check the certification body's current price list for a specific quote.

Basic-level Cyber Essentials certification has historically bundled free cyber liability insurance for eligible organisations. Eligibility and terms have changed over time and the cover is tied to the certificate — check IASME's current terms rather than quoting a fixed limit to a client.

Where GetCybr Fits

Where GetCybr Fits

The workflow above is scheme knowledge any MSP can run manually. GetCybr's role is to make it easier to run at scale, across every client in a portfolio — it's part of GetCybr's 50+ compliance frameworks.

Maps client evidence to all five technical controls in one place.

Organises the evidence assessors and certification bodies ask for, by control and by client.

Prepares the self-assessment question set from evidence already tracked in the platform.

Tracks remediation items for each control gap through to closure.

Gives a single, multi-client view across every Cyber Essentials engagement in the portfolio.

Tracks the 12-month renewal cycle for every client.

See the full catalog on the frameworks page, or check current packaging on vCISO pricing.

Sources

Some current requirement dates and figures above (the Danzell effective date, the 3-month Cyber Essentials Plus window, and the cyber liability insurance benefit) are corroborated across multiple independent secondary sources rather than an NCSC/IASME page fetched directly this session — check IASME for the current position before relying on them for a specific client deadline.

Help Center

FAQs have moved to the Help Center

Find current answers for the topics covered on this page in our consolidated FAQ.

Cyber Intelligence Digest

Track Requirements Changes

Get weekly vCISO and compliance updates for MSPs — including scheme and requirements changes as they're published.

No spam. Unsubscribe anytime.

Ready to Run Cyber Essentials Across Every Client?

See how GetCybr maps the five controls, organises the evidence, and tracks renewal across your whole portfolio — not just one client at a time.