Skip to content
Live12+ production solutions40+ clients deployeddirect + partner
Glossary · Compliance & Data

What is Cyber Essentials?

The UK NCSC's baseline cybersecurity certification — a five-control posture (firewalls, secure config, access control, malware, patches) increasingly required for UK government contracts.

Also known as

cyber essentials plusncsc cyber essentialsuk cyber essentials
Definition

Cyber Essentials — explained.

Cyber Essentials is the UK National Cyber Security Centre (NCSC) baseline cybersecurity certification, in operation since 2014. It covers five technical control areas: boundary firewalls and internet gateways, secure configuration, access control, malware protection, and patch management. There are two tiers: Cyber Essentials (self-assessment with third-party verification, valid 12 months) and Cyber Essentials Plus (on-site hands-on technical audit including vulnerability scanning, valid 12 months). The certification is a contractual requirement for UK central-government contracts handling certain types of sensitive information, and is increasingly common in private-sector enterprise procurement and supply-chain due-diligence. For UK-registered SaaS vendors and managed-service providers, Cyber Essentials Plus is the standard baseline — relatively quick to achieve and immediately useful in sales conversations because it is a recognised, named certification.

Solutions where cyber essentials applies

Zeour solutions that operate on this layer.

Enterprise Dev

enterprise · development · services

Zeour Enterprise Development — we design, build, and operate corporate-grade software for organizations that take their software seriously. Custom web platforms, mobile apps, kiosk fleets, embedded/hardware-coupled systems, real-time services, AI-augmented workflows, system integrations (CRM / ERP / HRIS / payment gateways / BI / national health systems / lab analyzers / payment terminals / card readers / GPIO barriers), legacy modernization, cloud migration, on-premise deployments, DevOps + CI/CD, security hardening, and 24/7 support. Every other solution on this site — MediCare Clinic Management, Smart Parking, GLARUS Queue Management, Wayfinding, Digital Signage, Visitor Management, Online Appointment, Self-Service Kiosks, Customer Feedback — is something our team designed, built, and operates today. The same team is available for your bespoke engagement.

See the solution

DT Consultation

digital · transformation · consultation

Zeour Digital Transformation Consultation helps companies digitalise their services and operations through three pillars: process automation (workflow engines, RPA, integration platforms that retire repetitive manual work), self-service technologies (customer + employee portals, kiosks, mobile apps, WhatsApp / SMS / IVR channels), and sovereign on-premises AI (open-weight large language models, vision models, voice models, RAG pipelines, and AI-augmented workflows that run entirely on the operator's own hardware — patient data, customer data, and classified material never leave the perimeter). The service stack is the full path from problem to outcome: consulting (digital-maturity assessment, transformation roadmap, business-case modelling, vendor selection), implementation (the build itself, often delivered in partnership with our Enterprise Development team), AI model deployment (open-weight LLMs, fine-tuning, embedding pipelines, on-prem inference infrastructure, GPU sizing), customisation (tailoring deployed AI and automation to your specific operations — prompts, RAG corpora, workflow templates), and training (role-based curricula for executives, operators, and end users, with operations playbooks, runbooks, and train-the-trainer programmes that make your team self-sufficient). The same team that ships our production AI assistant in MediCare (7-mode OpenAI Responses API, evidence-based prompts, audit-logged interactions) is what you engage.

See the solution

MediCare Clinic

medicare · clinic · management · system

Zeour MediCare — the multilingual on-premise clinic and EMR management system for small-to-mid healthcare practices. Covers patients (records, allergies, conditions, medications, body diagrams), appointments + visits with SOAP notes, prescriptions with drug-interaction checks, lab orders + samples + results, billing + payments + invoicing, inventory, expenses, referrals, medical certificates, refill requests, patient communications, telemedicine (WebRTC), an AI clinical assistant (OpenAI-powered with 7 modes), a patient self-service portal, and a full role-based access model across Admin, Doctor, Reception, and Lab Tech roles. Engineered multilingual — (with full RTL) as the production baseline, extensible to any locale — and runs locally on a single server.

See the solution

Smart Parking

smart · parking · management · system

Zeour Smart Parking — a complete on-premise smart parking platform: RFID card lifecycle (issue, top-up, transfer, lost replacement, card-tap exit), staff card-management console, admin operations center with pricing profiles per car size, no-login customer self-service portal, real-time monitoring (live activity, transactions, alerts), an Android kiosk fleet that drives RFID card readers and barrier gates directly with a hardware watchdog, and offline-validated sovereign licensing that ties each deployment to the operator's own server. Single-tenant deployment on the operator's own infrastructure; ships engineered multilingual with full RTL as a production baseline — configurable for any locale and currency per engagement.

See the solution
Related terms

Adjacent definitions to read next.

ISO 27001

Compliance & Data

The international standard for Information Security Management Systems (ISMS) — a certifiable framework for managing information-security risk.

SOC 2

Compliance & Data

A US-originated audit framework — SOC 2 Type II — that attests a service provider has effective controls over security, availability, confidentiality, processing integrity, and privacy.

GDPR

Compliance & Data

The EU's data-protection regulation — establishes consent, purpose-limitation, residency, breach-notification, and the data-subject rights regime.

CCPA / CPRA

Compliance & Data

California's data-protection law — and the CPRA amendment in force since 2023 — establishing data-subject rights for California residents.

Data Subject Access Request (DSAR)

Compliance & Data

The data-subject's right to request a copy of all personal data an operator holds about them, plus deletion, correction and processing-restriction rights — under GDPR, PDPL and equivalent laws.

Explicit Consent

Compliance & Data

Consent that is specific, informed, unambiguous and given by a clear affirmative action — separate tickboxes per purpose, not bundled — required under GDPR, PDPL and equivalent laws.

HIPAA

Compliance & Data

The US healthcare-data-protection law governing Protected Health Information (PHI) — covers privacy, security, breach notification, and business-associate agreements.

IEC 62443

Compliance & Data

The international cybersecurity standard for industrial automation + control systems (IACS) — the OT-world analogue of ISO 27001.

Want to discuss cyber essentials for your operation?

Talk to a Zeour engineer.

A 30-minute scoping call to walk your operational profile against where cyber essentials actually sits in your stack, then a fixed-fee Discovery price by the end of the call.