Cyber Essentials is the UK government-backed baseline, run by IASME. The technical requirements are refreshed periodically; the recent updates clarified passwordless authentication, brought home-working setups further into scope, and tightened language on unsupported software and asset management.
What usually causes a fail
In our experience the same three things:
- Unsupported operating systems or software still in use — an old Windows machine, an out-of-date server, a phone that stopped getting updates two years ago.
- MFA not applied to every cloud service, particularly the ones bought by a department rather than IT.
- No reliable asset list, so nobody can say with confidence what's on the network.
Why bother
- It's a common requirement in public-sector and enterprise supply chains.
- Basic certification includes cyber liability insurance for smaller UK organisations, subject to the scheme's conditions.
- It forces the boring, effective work: patching, MFA, admin separation, firewall configuration.
We take customers through certification start to finish, and the honest first step is usually an audit that tells you what would fail today.