Negative Zero
Sep 12, 2026Knowledge Baseresearch

What is Cyber Essentials?

A guide to the UK Government-backed scheme, its five technical controls, and who needs it.

Cyber Essentials is the UK Government-backed certification scheme that sets out the basic technical controls every organisation should have in place against the most common cyber attacks. It is owned by the National Cyber Security Centre and delivered through IASME, and it is designed to work for any organisation, whatever its size or sector.

The scheme covers five technical controls. At the basic level you certify by verified self-assessment: you answer the official question set, a board member attests to the answers, and a licensed assessor marks them. Cyber Essentials Plus adds hands-on testing of your devices and internet boundary by an assessor. Both certificates are valid for twelve months.

A valid certificate is a condition of many UK government contracts that involve handling personal data, and larger customers increasingly ask for it across their supply chain. Organisations with a head office in the UK or Crown Dependencies and turnover under £20m are also eligible to opt in to the cyber insurance included with certification. Neither IASME nor your assessor can advise on the insurance itself.

The Five Technical Controls

Firewalls

Every device and internet connection sits behind a configured firewall, with no unnecessary services exposed and default passwords changed.

Secure Configuration

Devices and cloud services are set up to reduce what an attacker can reach: unused accounts and software removed, auto-run disabled, and every device locked with a PIN, password or biometric.

Security Update Management

All software is supported by its vendor, and high-risk or critical updates are applied within 14 days of release. Answering no here fails the assessment.

User Access Control

Every user has their own account, admin accounts are used only for admin tasks, and multi-factor authentication protects cloud services.

Malware Protection

Every in-scope device runs anti-malware software or only allows approved applications to execute.

The Cyber Essentials Question Set

Certification starts with the official self-assessment question set, currently the Danzell release, which maps to the NCSC's Requirements for IT Infrastructure v3.3. The questions are specific and the correct answer is almost always a positive one, but some carry more weight than others. Confirming that all high-risk or critical security updates are installed within 14 days of release, for example, is an automatic fail if the answer is no.

Gathering the evidence for those answers is where most organisations lose weeks. The Negative Zero Agent does it in minutes. Our agentic swarm maps your scope, checks each of the five controls against the live question set and corrects configuration drift before it becomes a non-compliance, so your answers are backed by evidence and your controls stay in shape between assessments.

IASME-licensed Certification Body

Negative Zero is a Certification Body licensed by IASME to assess and certify organisations for Cyber Essentials and Cyber Essentials Plus. Our own certifications are live on the Blockmark registry below.

Get Certified with Negative Zero

Still holding onto the spreadsheet life but ready to experiment? We've provided the raw question set and NCSC infrastructure requirements below. Instead of analysing them manually, try dropping these files directly into Claude, or your own internal knowledgebase to let AI tackle the heavy lifting.

One caution from the assessor's chair: the scheme tells us to check that AI-generated answers fit the organisation actually being assessed, so make sure every answer describes your environment, not a generic one.

Question Set (PDF)
Question Set (Excel)
Requirements for IT infrastructure
Negative Zero Agent

Negative Zero Agent

Cyber Essentials Sub Agent

Agent

Did you know that MFA is a non-negotiable requirement for all cloud services under Cyber Essentials?

Sources:NCSCIASMENZ knowledge base
Try asking:
Run a 2-minute readiness checkWe'll flag the things that might hold up your certification.
Start

Messages are processed by Google Gemini to answer you and kept for 30 days for quality and abuse monitoring. Please do not share passwords, credentials or IP addresses. How this agent handles data

Keep reading

View all