Frameworks · UK & Europe

Cyber Essentials compliance, run as a living system

Cyber Essentials is the UK government-backed baseline cyber scheme covering five technical control themes, with an annual assessment cycle. Cyber Essentials Plus adds independent technical verification of the same controls.

Who it applies to

UK organisations of any size, and frequently a contractual requirement for public-sector supply chains.

What it demands

Boundary & firewalls

Boundary protection, configured and reviewed.

Secure configuration

Hardened builds, default credentials removed, unnecessary services disabled.

Access control

Least privilege, administrative account separation and multi-factor authentication.

Malware & patching

Malware protection and security update timeliness within the scheme's window.

How Compli-Once runs it

  • 1

    The five themes modelled as controls with owners and evidence, so the annual assessment is a report, not a project.

  • 2

    Certificate validity tracked with expiry, so reassessment is raised as work well before it lapses.

  • 3

    Crosswalked to ISO 27001 and SOC 2, so the baseline is a subset of the programme you already run.

What you already satisfy

Cyber Essentials overlaps with frameworks you may already run. The crosswalk quantifies existing coverage on day one, before you plan a single task.

Implement once, satisfy many

Access control
ISO 27001 A.5.15SOC 2 CC6.1SEBI CSCRF PR.AARBI CSF Access Mgmt
Incident response
ISO 27001 A.5.24SOC 2 CC7.3SEBI CSCRF 6-hour report
Change management
ISO 27001 A.8.32SOC 2 CC8.1PCI DSS v4 6.5

In a representative demonstration environment, 61% of a newly adopted regulatory framework was already satisfied by the existing ISO 27001 programme.

Illustrative, computed live per tenant in the platform.

Frequently asked questions

What is Cyber Essentials?

It is the UK's government-backed baseline cyber scheme covering firewalls, secure configuration, access control, malware protection and patch management, assessed annually. The Plus tier adds independent technical verification.

How is the annual cycle managed?

Certification validity is tracked as evidence with an expiry date, so reassessment work is raised automatically ahead of the deadline.

Does an ISO 27001 programme already cover it?

Largely. The crosswalk quantifies coverage control by control, leaving a short, explicit gap list rather than a parallel exercise.

Is Cyber Essentials Plus supported?

Yes. The independent verification evidence is stored against the same controls, with the audit and finding machinery used for any remediation.

You're done. We're not.

The audit ends. The readiness doesn't. See it on your own data.