Cyber Essentials for MSPs: How the Scheme Works and How to Deliver It
A practitioner guide to the UK's NCSC-owned certification scheme: what the five controls actually check, when Cyber Essentials Plus applies, and how to deliver it for clients from scoping through to renewal.
What Cyber Essentials Is
Cyber Essentials is a UK government-backed scheme, owned by the National Cyber Security Centre (NCSC) and delivered by IASME as the sole delivery partner. It sets out five technical controls that guard against common cyber attacks, verified either by self-assessment (Cyber Essentials) or by independent testing on top of that (Cyber Essentials Plus).
Cyber Essentials is voluntary for most organisations, but it becomes a contractual requirement for specific categories of UK central-government contract under the current policy instrument, PPN (Procurement Policy Note) Action Note 014, updated February 2025 and in force from 24 February 2025. PPN 014 supersedes PPN 09/14 and PPN 09/23, the two earlier versions of the same requirement.
PPN 014 is explicit that this is not a blanket rule: "In-scope organisations must not take a blanket approach" to requiring Cyber Essentials — it applies where a contract handles citizens' or civil servants' personal data, processes data at OFFICIAL classification, or is otherwise part of day-to-day government or public-finance business. That's useful MSP guidance in its own right: check the actual contract characteristics before assuming certification is required.
One disambiguation worth making early: Singapore's Cyber Security Agency (CSA) runs its own, separate "Cyber Essentials mark" under a different scheme. It shares the name but not the requirements — this page is about the UK's NCSC/IASME scheme.
Cyber Essentials vs Cyber Essentials Plus
Both assess the same five technical controls. The difference is how that's verified, and — for Plus — when it commonly needs to happen relative to the base certificate.
| Aspect | Cyber Essentials | Cyber Essentials Plus |
|---|---|---|
| Assessment method | A self-assessment questionnaire, verified by an independent certification body. | The same five controls, plus independent remote and on-site vulnerability testing using commodity attack tools. |
| What it confirms | That the five controls are declared, understood, and in place — a basic level of assurance. | That the controls actually hold up against a hands-on attempt to get through them — a more rigorous assessment. |
| Timing relative to base CE | Stands on its own; renewed independently each cycle. | Commonly expected within 3 months of the base Cyber Essentials certificate — check the current window with your certification body. |
| Renewal | Every 12 months. | Every 12 months, alongside the base certificate. |
Assessment method
- Cyber Essentials
- A self-assessment questionnaire, verified by an independent certification body.
- Cyber Essentials Plus
- The same five controls, plus independent remote and on-site vulnerability testing using commodity attack tools.
What it confirms
- Cyber Essentials
- That the five controls are declared, understood, and in place — a basic level of assurance.
- Cyber Essentials Plus
- That the controls actually hold up against a hands-on attempt to get through them — a more rigorous assessment.
Timing relative to base CE
- Cyber Essentials
- Stands on its own; renewed independently each cycle.
- Cyber Essentials Plus
- Commonly expected within 3 months of the base Cyber Essentials certificate — check the current window with your certification body.
Renewal
- Cyber Essentials
- Every 12 months.
- Cyber Essentials Plus
- Every 12 months, alongside the base certificate.
The Five Technical Controls
PPN 014's own annex names these five control themes. NCSC's requirements document uses "user access control" for the fourth; PPN 014's shorter "access control" phrasing refers to the same theme.
Boundary firewalls and internet gateways
What assessors check: Every internet-facing boundary device has its default administrative password changed, unnecessary services and ports closed, and its management interface kept off the open internet.
Common failure points: Default router or firewall admin credentials left unchanged, or a management interface reachable from the internet.
Secure configuration
What assessors check: Unnecessary user accounts, software, and auto-run features are removed or disabled before a device goes into service, and out-of-the-box defaults have been reviewed rather than left as shipped.
Common failure points: Unused default accounts or services left enabled, or auto-run features not disabled.
User access control
What assessors check: User accounts are set up and approved by someone with the authority to do so, administrator rights are restricted to a separate account used only for admin tasks, and accounts are removed or disabled when no longer needed.
Common failure points: Shared admin accounts, or an admin account also used for email and everyday browsing.
Malware protection
What assessors check: Anti-malware software is installed and kept up to date on every in-scope device, or an equivalent control such as application allow-listing or sandboxing is in place.
Common failure points: Malware protection missing, disabled, or out of date on a subset of in-scope devices.
Security update management
What assessors check: All in-scope software is licensed and vendor-supported, and security updates rated critical or high severity (or unrated, treated as high by default) are applied within 14 days of release.
Common failure points: Unsupported or end-of-life software still in scope, or a critical/high-severity update applied outside the 14-day window.
Which Requirements Version Applies
The question set behind Cyber Essentials is updated periodically. "Danzell" (v3.3) took effect from 27 April 2026 and is now the question set for new assessments. The previous version, "Willow" (v3.2, April 2025), may still apply to assessment accounts opened before that date during a transition period — check IASME for the question set that applies on your client's assessment date.
Under Danzell (v3.3), multi-factor authentication must be enabled for every user account on all in-scope cloud services, including where it is only available as a paid upgrade. Willow (v3.2) required it "where available". Check IASME for the exact scope and timing before telling a client MFA is optional on any cloud service.
Getting the Scope Right
The default scope is the legal entity delivering the goods or services — not the wider corporate group it might belong to. A supplier can voluntarily restrict certification to part of that entity, but the certification body has to agree the boundary is reasonable; it isn't the supplier's call alone.
Cloud services, most bring-your-own-device use, and home or remote worker devices are in scope by default if they can access organisational data or services — a common scoping mistake is excluding them because they aren't company-owned. Certification also doesn't automatically extend assurance to a third party the organisation shares data with, such as a cloud provider.
How an MSP Delivers Cyber Essentials for a Client
Seven phases, working from first contact through to the annual renewal cycle.
Confirm the need
Check whether Cyber Essentials is being pursued for a specific contract — and, if so, whether that contract genuinely fits PPN 014’s characteristics — or as a general security baseline the client wants regardless.
Agree the scope
Default to the legal entity delivering the service. If a narrower boundary is proposed, it has to be agreed as reasonable by the certification body, not just by the client.
Run a gap check against the five controls
Compare current firewalls, configuration, access control, malware protection, and update management against what the applicable question set asks for.
Remediate
Close the gaps the check found — commonly MFA on cloud services, separating admin accounts, and catching up overdue security updates.
Complete the question set and submit
Complete the self-assessment questionnaire for the version that applies on the assessment date, and submit it to a certification body for verification.
Add Cyber Essentials Plus testing if required
If the client needs Plus, book the independent vulnerability testing — commonly expected within 3 months of the base certificate.
Track renewal and requirements changes
Certification lapses after 12 months, and the question set itself changes periodically — track which version applies at each client’s renewal date.
MSPs that want to offer NCSC-assured advice on top of certification support can look at the Cyber Advisor scheme: IASME partners with the NCSC to run it, and an individual becomes a Cyber Advisor by passing an assessment run by The Cyber Scheme. To offer Cyber Advisor services formally, the MSP itself registers with IASME as an Assured Service Provider and employs or contracts at least one assessed Cyber Advisor. Check IASME for the current registration requirements before advertising either credential to clients.
What It Costs
PPN 014 itself cites the cost for smaller companies to be Cyber Essentials certified as "currently expected to range between £300 and £500+VAT at basic level" (February 2025) — and notes that costs may change over time, so treat this as an anchor figure rather than a fixed price. Cyber Essentials Plus and larger organisations cost more, driven by network size and complexity; check the certification body's current price list for a specific quote.
Basic-level Cyber Essentials certification has historically bundled free cyber liability insurance for eligible organisations. Eligibility and terms have changed over time and the cover is tied to the certificate — check IASME's current terms rather than quoting a fixed limit to a client.
Where GetCybr Fits
The workflow above is scheme knowledge any MSP can run manually. GetCybr's role is to make it easier to run at scale, across every client in a portfolio — it's part of GetCybr's 50+ compliance frameworks.
Maps client evidence to all five technical controls in one place.
Organises the evidence assessors and certification bodies ask for, by control and by client.
Prepares the self-assessment question set from evidence already tracked in the platform.
Tracks remediation items for each control gap through to closure.
Gives a single, multi-client view across every Cyber Essentials engagement in the portfolio.
Tracks the 12-month renewal cycle for every client.
See the full catalog on the frameworks page, or check current packaging on vCISO pricing.
Sources
- PPN Action Note 014 — Cyber Essentials scheme (gov.uk, updated February 2025) — accessed 16 September 2026. Legal status, renewal, cost, and scope.
- NCSC — Cyber Essentials Requirements for IT Infrastructure v3.2 — accessed 16 September 2026. The Willow (v3.2) requirements document, superseded by Danzell (v3.3) from 27 April 2026.
- IASME — Our Schemes — accessed 16 September 2026. Delivery partner role and certification process.
- IASME — Cyber Advisor scheme — accessed 16 September 2026. Cyber Advisor and Assured Service Provider routes for MSPs.
- The Cyber Scheme — Cyber Advisor assessment — accessed 16 September 2026. How an individual becomes an assessed Cyber Advisor.
Some current requirement dates and figures above (the Danzell effective date, the 3-month Cyber Essentials Plus window, and the cyber liability insurance benefit) are corroborated across multiple independent secondary sources rather than an NCSC/IASME page fetched directly this session — check IASME for the current position before relying on them for a specific client deadline.
Help Center
FAQs have moved to the Help Center
Find current answers for the topics covered on this page in our consolidated FAQ.
Track Requirements Changes
Get weekly vCISO and compliance updates for MSPs — including scheme and requirements changes as they're published.
No spam. Unsubscribe anytime.
Ready to Run Cyber Essentials Across Every Client?
See how GetCybr maps the five controls, organises the evidence, and tracks renewal across your whole portfolio — not just one client at a time.