UK’s trusted IT infrastructure partner since 2003
Servnet
FinanceToolsConfiguratorGet in Touch
Cyber Essentials UK · NCSC Certification

Cyber Essentials
Certification, Done Right.

Cyber Essentials is the UK government-backed cyber security certification scheme, developed by the NCSC. It defines five technical controls that protect against over 80% of common cyber attacks — and is mandatory for organisations supplying central government contracts.

Servnet assesses your readiness against all five controls, supplies the right technology to close gaps, and supports you through to certification — whether you need standard CE or the independently verified CE Plus.

CE Readiness CheckIn Progress
Firewalls72%
Secure Configuration55%
User Access Control68%
Malware Protection90%
Security Update Management48%
🏆 2 gaps identified — remediation available. CE certification achievable within 3–4 weeks.
80%
Of common attacks prevented by Cyber Essentials controls
£mandatory
For MoD, NHS & Crown commercial contracts
2 Tiers
Self-assessed CE & independently verified CE Plus
14 days
Maximum window to apply critical security patches
NCSC
Government-backed scheme — UK National Cyber Security Centre
12 months
Certificate validity — annual re-certification required
The Five Controls

What Cyber Essentials Requires

Five technical controls defined by the NCSC — each addressing a distinct category of common cyber attack. All five must be fully implemented to achieve certification.

🔥
Control 01
Firewalls
Requirement

Boundary and host-based firewalls must be configured with a default-deny policy. Only approved services and protocols should be permitted inbound.

Servnet Solutions
  • FortiGate NGFW — hardware-accelerated perimeter firewall with default-deny policy
  • Palo Alto PA-Series — App-ID blocks unapproved applications regardless of port
  • Windows Defender Firewall — host-based control for endpoints and servers
⚙️
Control 02
Secure Configuration
Requirement

Devices must be configured securely: default credentials changed, unnecessary accounts removed, auto-run disabled, and only required software installed.

Servnet Solutions
  • Microsoft Intune — enforces device configuration baselines at scale
  • CrowdStrike Falcon — detects misconfigured endpoints and policy drift
  • Fortinet FortiManager — centralised policy enforcement across network devices
👤
Control 03
User Access Control
Requirement

User accounts must follow least-privilege principles. MFA is required for all internet-facing services. Administrator accounts must not be used for everyday tasks.

Servnet Solutions
  • CyberArk Privilege Cloud — privileged account vaulting and JIT elevation
  • BeyondTrust Password Safe — PAM with session recording and approval workflows
  • Microsoft Entra ID — conditional access and phishing-resistant MFA (FIDO2)
🛡️
Control 04
Malware Protection
Requirement

All devices must run up-to-date anti-malware software. Application allow-listing or signature-based protection must be active. Malicious websites must be blocked.

Servnet Solutions
  • CrowdStrike Falcon — AI-native endpoint protection and EDR
  • SentinelOne Singularity — autonomous threat prevention without signature dependence
  • Fortinet FortiGuard — web filtering and AV integrated into FortiGate
📦
Control 05
Security Update Management
Requirement

All software, firmware, and operating systems must be kept up to date. Critical and high-severity patches must be applied within 14 days of release.

Servnet Solutions
  • Microsoft Intune — automated Windows patch deployment with compliance reporting
  • Fortinet FortiManager — centralised firmware update management for network devices
  • CrowdStrike Spotlight — vulnerability management and patch prioritisation
Cyber Essentials — the five foundational technical controls for UK government certification
Certification Tiers

CE vs CE Plus — Which Do You Need?

Both certifications are NCSC-registered and annually renewed. The key difference is verification — CE Plus includes independent hands-on technical testing.

Cyber Essentials

Self-Assessed
Typical Cost
~£300–500
Timeframe
1–2 weeks

Process: Online self-assessment questionnaire completed by your organisation, reviewed and verified by a Certification Body assessor.

Best for: SMEs, organisations seeking government contracts, businesses wanting to demonstrate baseline security to customers and insurers.

  • Online assessment questionnaire
  • CB review and verification
  • CE certificate (valid 12 months)
  • NCSC-registered certification
  • Cyber Essentials logo licence

Cyber Essentials Plus

Independently Verified
Typical Cost
~£1,500–3,000
Timeframe
2–4 weeks

Process: In addition to the self-assessment, an independent assessor performs technical verification — hands-on testing of your systems against all five controls.

Best for: Government suppliers, NHS contractors, organisations handling sensitive data, businesses with cyber insurance requirements.

  • Everything in Cyber Essentials
  • On-site/remote technical testing
  • Vulnerability scanning
  • Authenticated internal scan
  • CE Plus certificate (valid 12 months)
When Is It Required?

Sectors & Contracts Requiring Cyber Essentials

Ministry of Defence (MoD)

Mandatory CE for all suppliers handling government data. CE Plus required for sensitive contracts.

NHS & Healthcare

Required for NHS Digital supplier registration and Data Security and Protection Toolkit compliance.

Crown Commercial Service

Required for G-Cloud and Crown Marketplace frameworks — mandatory for all public sector IT suppliers.

Cyber Insurance

Major UK insurers require or offer significant premium discounts for CE/CE Plus certified organisations.

Servnet Delivery

End-to-End Certification Support

01
🔎

Gap Assessment

We review your current controls against all five Cyber Essentials requirements — identifying gaps and producing a prioritised remediation list before you submit the self-assessment.

02
🛠️

Remediation Support

Where gaps exist, we supply and deploy the right products — FortiGate for firewalls, CrowdStrike for malware protection, Intune for patch management — to meet the technical requirements.

03
📋

Pre-Assessment Review

We review your completed questionnaire before submission to identify any answers that may fail the CB review — reducing the risk of costly re-assessments.

04
🏆

Certification Body Referral

We work with IASME-accredited Certification Bodies and can refer you to a suitable assessor, managing the process end-to-end so you reach certification with minimal disruption.

Ready to achieve Cyber Essentials?

Whether you need CE for a government contract, cyber insurance, or simply to demonstrate security to your customers — Servnet will get you there, efficiently and correctly.

Request a CE Gap AssessmentAll Compliance Frameworks →
Related cyber security topics

Explore the full Servnet cyber security stack

Defence in depth means stacking complementary controls — start here for the topics that pair with this one.

Cyber Security · UK
Endpoint Security & XDR

AI-native EDR/XDR replacing legacy antivirus on every endpoint.

Cyber Security · UK
Network Security & NGFW

Next-gen firewalls, micro-segmentation and IPS for the perimeter and east-west.

Cyber Security · UK
Email Security

AI-powered email defence against BEC, phishing and credential theft.

Cyber Security · UK
Cloud Security & SASE

CSPM, CASB, CWP and SASE — secure workloads across AWS, Azure and GCP.

Cyber Security · UK
Identity & Access Management

IAM, PAM and zero-trust identity — verify every user, every session.

Cyber Security · UK
Managed Detection & Response

24/7 SOC analysts hunting threats across your environment.

Further reading · authoritative sources
💷 Spread the cost · IT finance

Spread the cost of your Cyber Essentials remediation

Close the five controls the certification demands — FortiGate firewalls, CrowdStrike malware protection, MFA and Intune patch management — on a monthly plan, so a government contract deadline never waits on a capital budget. No credit check at this stage.

Lease or hire-purchase options

Indicative estimate · subject to change · no credit check at this stage · hire purchase, lease & subscription for UK businesses

Indicative illustration only. Servnet Limited is not authorised or regulated by the FCA and does not provide financial advice or arrange finance. All finance opportunities are referred to Number Eight Business Finance. Finance policy

Talk to a UK specialist

Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.

or call 0800 987 4111