Cyber Essentials Certification

Pass Cyber Essentials and Cyber Essentials Plus first time. We find the gaps, fix them and guide you through certification, then keep the controls working all year.

Service Details

Cyber Essentials certification shows buyers and government departments that your organisation has the basic technical controls in place to stop the most common cyber attacks. With Falx, you get a pre-assessment, the fixes and a guided submission, so you pass Cyber Essentials, and Cyber Essentials Plus where it matters, on the first attempt.

Cyber Essentials is a UK government-backed scheme run by the National Cyber Security Centre (NCSC), with IASME as its delivery partner. It is part of our governance services, which take you from requirement to certificate and keep you there.

INFO

You get one team that finds the gaps, fixes them and manages the submission, so a failed first attempt does not cost you a tender deadline.


Who needs Cyber Essentials

Any UK organisation can certify, whatever its size or sector. Many central government contracts require it, particularly those involving personal information or certain IT services, and some ask for Cyber Essentials Plus.

It is also becoming a standard supplier check. Larger customers, insurers and partners ask for it to show your basic security has been independently verified, which makes it a common requirement in financial services, insurance, manufacturing and not-for-profit supply chains.

What it requires

Cyber Essentials checks five technical control themes across the devices, cloud services and networks in scope:

  1. Firewalls — Boundary firewalls and internet gateways protect every device that connects to the internet.
  2. Secure configuration — Devices and software are set up securely, with unused accounts, default passwords and unnecessary services removed.
  3. Security update management — Supported software only, with high-risk and critical updates applied within a set window.
  4. User access control — People only have the access they need, admin rights are restricted and multi-factor authentication (MFA) protects cloud services.
  5. Malware protection — Every device in scope is protected against malicious software.

There are two levels. Cyber Essentials is a verified self-assessment; Cyber Essentials Plus adds a hands-on technical audit of the same controls. Both are renewed every year.


Cyber Essentials certification, first time

The five controls are straightforward, but self-assessments fail on technical detail: one unpatched laptop, one old router password. We find and fix that detail before you submit.

We recommend preparing against the Cyber Essentials Plus standard either way. If you meet that bar, the basic certificate follows easily and Plus is within reach when a buyer asks for it.

Colleagues working side by side on laptops at a long office table

The five controls, handled

We implement and evidence each one across your estate:

Firewalls

Boundary defences configured and verified, including cloud services and home workers.

Secure Configuration

Hardened builds with unnecessary services, default passwords and unused accounts removed.

Security Updates

Unsupported software retired and critical updates applied within the required window.

User Access Control

Least-privilege accounts, restricted admin rights, MFA and a working leavers process.

Malware Protection

Protection confirmed as installed and running on every device in scope.


How we get you certified

We agree your scope, run a pre-assessment, fix the gaps it finds, complete the questionnaire with you and manage the submission to the certification body. For Cyber Essentials Plus, we prepare your team for the hands-on audit and attend on the day.

Pre-Assess

Find the gaps before the assessor does

Remediate

Fix firewalls, builds, accounts and updates

Certify

Submission managed through to certificate


Keeping the controls working all year

Controls drift after certification day: new laptops arrive, updates slip and leavers keep access. We fold the five controls into managed services or periodic security posture reviews, so renewal is paperwork rather than a project.

Threat and vulnerability management finds new weaknesses between renewals, and identity and access keeps accounts and admin rights under control. Our compliance support team packages the evidence for your assessor.

The technical controls, evidenced

Multi-factor authentication, hardened devices and protected accounts: we rolled these out across more than 200 identities and devices and ended rogue logins. That covers much of the Cyber Essentials ground once, properly, with the evidence the questionnaire asks for.


Cyber Essentials is the natural first step towards ISO 27001, and the same evidence supports UK GDPR security obligations. If you want a more detailed technical baseline, the CIS Controls build on the same five themes.

For a wider view of your exposure, add risk management or penetration testing. See how these fit together in our end-to-end compliance programme.


Frequently asked questions

Get certified first time

Tell us which contract or customer is asking for Cyber Essentials. You get a clear view of where your controls stand, what needs fixing and which certification level makes sense.