UK · UK government-backed scheme, delivered by IASME

Cyber Essentials

Cyber Essentials covers five technical controls. Certification is awarded by a certification body licensed by IASME, the scheme’s delivery partner — through a verified self-assessment for Cyber Essentials, or a hands-on technical audit for Cyber Essentials Plus. It is a baseline, deliberately, and it does not attempt to be a management system.

Scope

Does this apply to you?

Cyber Essentials is voluntary for most organisations. It becomes mandatory through a contract rather than through law.

You are likely in scope if

  • You are bidding for a UK central government contract that involves handling personal information or providing certain ICT products and services — Cyber Essentials has been a procurement requirement for those since 2014.
  • A customer, insurer, or buying framework has named Cyber Essentials or Cyber Essentials Plus in a contract or a security questionnaire.
  • You want a defined technical baseline and a certificate you can point at when asked.

You are probably not in scope if

  • Nobody has asked for it and you are not bidding for public-sector work. There is no general legal duty to hold Cyber Essentials.
  • You need to evidence a broad risk-management posture rather than a technical baseline. Cyber Essentials covers five controls and stops there.

Whether a specific contract requires Cyber Essentials or Cyber Essentials Plus, and what scope it expects, is a question about that contract and about the scheme’s current requirements document. Fortoxa does not interpret either for you.

Requirements

What the framework asks for.

Named as the framework names them, with its own references, so you can check this page against the source below.

  • 1

    Firewalls

    Every device in scope sits behind a correctly configured boundary or host-based firewall. Default administrative passwords changed, unnecessary inbound rules removed, and remote administrative access to the firewall restricted.

  • 2

    Secure configuration

    Devices and software configured to reduce inherent vulnerability: unnecessary accounts and software removed or disabled, default passwords changed, and auto-run of untrusted code disabled.

  • 3

    Security update management

    Software in scope must be licensed, supported, and removed once the vendor stops supporting it. Security updates rated critical or high must be applied within the window the scheme sets — 14 days of release, at the time of writing.

  • 4

    User access control

    Accounts assigned to named individuals through an approval process, administrative accounts used only for administrative work, accounts removed when no longer needed, and multi-factor authentication applied to cloud services.

  • 5

    Malware protection

    Devices in scope protected by anti-malware software, application allow-listing, or equivalent, kept current.

The register

What Fortoxa puts against each requirement.

Three of the five controls produce artifacts Fortoxa can collect from a monitored server. Two do not, and the register says so rather than leaving them blank.

Cyber Essentials — control register

4 of 5 evidenced

  • Firewalls

    Boundary and host firewall configuration

    Blocked inbound connections per host, with source address and timestamp

    log_events · 4 min ago

    Live
  • Secure config

    Devices configured to reduce vulnerability

    Configuration baseline per monitored host, and the drift since the last collection

    fortoxa-agent · 18 min ago

    Live
  • Updates

    Security update management

    Patch level per monitored host and time since the last update applied

    fortoxa-agent · 1 day ago

    Stale
  • Access control

    User access control

    Accounts on the workspace, role held, when granted, and API keys outstanding

    workspace_members · 2 min ago

    Live
  • Malware

    Malware protection

    Fortoxa does not run anti-malware or allow-listing, and does not read the state of yours

    not collected by Fortoxa · never collected

    Not supported yet

Rows marked as not measured are shown, not hidden. A register with every requirement satisfied is the outcome this product exists to prevent.

Example workspace, sample data. Your own register is built from your servers once an agent is installed.

Not covered

What stays your job.

Fortoxa evidences what it can observe on the servers you install the agent on. Everything below is outside that, and the register marks it as not measured rather than as a pass.

  • The certificate

    Certification is awarded by an IASME-licensed certification body after assessment. Fortoxa produces evidence you can use while preparing for one. No output from Fortoxa is a certificate, and holding one is not something Fortoxa can confer.

  • Laptops, phones and other end-user devices

    Cyber Essentials scope includes the devices your staff work on. The Fortoxa agent runs on servers, so end-user devices appear in the register as not measured rather than as a pass.

  • Cloud services

    The scheme covers the cloud services your organisation uses, including the MFA applied to them. Fortoxa does not enumerate your SaaS estate or read its settings.

  • Malware protection

    Fortoxa neither provides anti-malware nor inspects whether yours is installed and current. This is control 5 in full, and it is outside what the agent observes.

Sources

Check this page against the text.

Everything above is Fortoxa's reading of the framework. It is not the framework, and it is not advice about your obligations. The publishers below are authoritative; this page is not.

Next

See what your own servers produce.

Install the agent on one server and the register builds itself from what it finds — including the requirements it cannot see.

The control register and the evidence export are Business features, £349/month. Monitoring, alerts and the live activity feed start at £29 on Micro, which does not include the register. Starter and Business include a 14-day trial on a new subscription.