What is Cyber Essentials?
The UK NCSC's baseline cybersecurity certification — a five-control posture (firewalls, secure config, access control, malware, patches) increasingly required for UK government contracts.
Also known as
Cyber Essentials — explained.
Cyber Essentials is the UK National Cyber Security Centre (NCSC) baseline cybersecurity certification, in operation since 2014. It covers five technical control areas: boundary firewalls and internet gateways, secure configuration, access control, malware protection, and patch management. There are two tiers: Cyber Essentials (self-assessment with third-party verification, valid 12 months) and Cyber Essentials Plus (on-site hands-on technical audit including vulnerability scanning, valid 12 months). The certification is a contractual requirement for UK central-government contracts handling certain types of sensitive information, and is increasingly common in private-sector enterprise procurement and supply-chain due-diligence. For UK-registered SaaS vendors and managed-service providers, Cyber Essentials Plus is the standard baseline — relatively quick to achieve and immediately useful in sales conversations because it is a recognised, named certification.
Zeour solutions that operate on this layer.
Verticals where cyber essentials is operationally critical.
Blog posts that go deeper on cyber essentials.
Adjacent definitions to read next.
ISO 27001
Compliance & DataThe international standard for Information Security Management Systems (ISMS) — a certifiable framework for managing information-security risk.
SOC 2
Compliance & DataA US-originated audit framework — SOC 2 Type II — that attests a service provider has effective controls over security, availability, confidentiality, processing integrity, and privacy.
GDPR
Compliance & DataThe EU's data-protection regulation — establishes consent, purpose-limitation, residency, breach-notification, and the data-subject rights regime.
CCPA / CPRA
Compliance & DataCalifornia's data-protection law — and the CPRA amendment in force since 2023 — establishing data-subject rights for California residents.
Data Subject Access Request (DSAR)
Compliance & DataThe data-subject's right to request a copy of all personal data an operator holds about them, plus deletion, correction and processing-restriction rights — under GDPR, PDPL and equivalent laws.
Explicit Consent
Compliance & DataConsent that is specific, informed, unambiguous and given by a clear affirmative action — separate tickboxes per purpose, not bundled — required under GDPR, PDPL and equivalent laws.
HIPAA
Compliance & DataThe US healthcare-data-protection law governing Protected Health Information (PHI) — covers privacy, security, breach notification, and business-associate agreements.
IEC 62443
Compliance & DataThe international cybersecurity standard for industrial automation + control systems (IACS) — the OT-world analogue of ISO 27001.
Talk to a Zeour engineer.
A 30-minute scoping call to walk your operational profile against where cyber essentials actually sits in your stack, then a fixed-fee Discovery price by the end of the call.