What is Cyber Essentials?
A guide to the UK Government-backed scheme, its five technical controls, and who needs it.
Cyber Essentials is the UK Government-backed certification scheme that sets out the basic technical controls every organisation should have in place against the most common cyber attacks. It is owned by the National Cyber Security Centre and delivered through IASME, and it is designed to work for any organisation, whatever its size or sector.
The scheme covers five technical controls. At the basic level you certify by verified self-assessment: you answer the official question set, a board member attests to the answers, and a licensed assessor marks them. Cyber Essentials Plus adds hands-on testing of your devices and internet boundary by an assessor. Both certificates are valid for twelve months.
A valid certificate is a condition of many UK government contracts that involve handling personal data, and larger customers increasingly ask for it across their supply chain. Organisations with a head office in the UK or Crown Dependencies and turnover under £20m are also eligible to opt in to the cyber insurance included with certification. Neither IASME nor your assessor can advise on the insurance itself.
The Five Technical Controls
Firewalls
Every device and internet connection sits behind a configured firewall, with no unnecessary services exposed and default passwords changed.
Secure Configuration
Devices and cloud services are set up to reduce what an attacker can reach: unused accounts and software removed, auto-run disabled, and every device locked with a PIN, password or biometric.
Security Update Management
All software is supported by its vendor, and high-risk or critical updates are applied within 14 days of release. Answering no here fails the assessment.
User Access Control
Every user has their own account, admin accounts are used only for admin tasks, and multi-factor authentication protects cloud services.
Malware Protection
Every in-scope device runs anti-malware software or only allows approved applications to execute.
The Cyber Essentials Question Set
Certification starts with the official self-assessment question set, currently the Danzell release, which maps to the NCSC's Requirements for IT Infrastructure v3.3. The questions are specific and the correct answer is almost always a positive one, but some carry more weight than others. Confirming that all high-risk or critical security updates are installed within 14 days of release, for example, is an automatic fail if the answer is no.
Gathering the evidence for those answers is where most organisations lose weeks. The Negative Zero Agent does it in minutes. Our agentic swarm maps your scope, checks each of the five controls against the live question set and corrects configuration drift before it becomes a non-compliance, so your answers are backed by evidence and your controls stay in shape between assessments.
IASME-licensed Certification Body
Negative Zero is a Certification Body licensed by IASME to assess and certify organisations for Cyber Essentials and Cyber Essentials Plus. Our own certifications are live on the Blockmark registry below.
Get Certified with Negative Zero
Still holding onto the spreadsheet life but ready to experiment? We've provided the raw question set and NCSC infrastructure requirements below. Instead of analysing them manually, try dropping these files directly into Claude, or your own internal knowledgebase to let AI tackle the heavy lifting.
One caution from the assessor's chair: the scheme tells us to check that AI-generated answers fit the organisation actually being assessed, so make sure every answer describes your environment, not a generic one.

Negative Zero Agent
Cyber Essentials Sub Agent
Messages are processed by Google Gemini to answer you and kept for 30 days for quality and abuse monitoring. Please do not share passwords, credentials or IP addresses. How this agent handles data
