This is entirely quoted and verbatim except for the AMERICAN spelling.
"...In November 2021 the NCSC announced an overhaul of the Cyber Essentials technical controls and a change to the pricing structure. Both these changes come into effect on 24 January 2022. (NOTICE - if we provided you with mapping, it's time for an update AND you will have to provide evidence of your license.)
Updating the technical controls
"...When we announced plans to update the Cyber Essential requirements, we said this update was the biggest overhaul of the scheme’s technical controls since its launch in 2014. Six years is a long time in cyber security, but we still believe the basic principles are sound and that Cyber Essentials represents a minimum baseline standard for cyber security in the UK.
But today’s organizations are operating in a very different context to 2014. We’ve seen the rise of cloud computing, greater availability of multi-factor authentication, the pervasive threat of ransomware, and of course the global pandemic, which has brought an unprecedented change in the way organizations are working and technology is used.
This means that although the control themes of firewalls, secure configuration, user access control, malware protection and software updates remain the same, the actual requirements have been expanded to address a range of new scenarios, including home working, the use of BYOD and cloud services. This blog summarizes the key points with the details in the updated Requirements for IT infrastructure document and some helpful FAQs on our website.
Cloud services
For cloud services, we’ve implemented a shared responsibility model. This is a common method that dictates the security obligations of each party − the cloud provider and the cloud user − to ensure accountability is clear. To help organizations, we’ve also mapped the five technical controls to the three main types of cloud service (IaaS, PaaS, SaaS). But this is a guide only; the ultimate responsibility to ensure the cloud provider is implementing services properly is with the applicant.
Home working
When Cyber Essentials was first launched, home working was viewed as an exception and the guidance was written from that standpoint. That has clearly changed, and for many organizations it has become the norm and is here to stay. We have updated the guidance to reflect this and to clarify what should be included in the assessment scope.
One frequently asked question is the role of Internet Service Providers (ISP) routers in a home working scenario. We have consciously taken them out of scope, because expecting individuals to configure routers correctly, even with company guidance, is impractical. But this makes it even more important that firewall controls are correctly applied to end user devices.
Passwords and multi-factor authentication
Multi-factor authentication (MFA) adds a layer of extra protection for accounts and is now widespread and available for free with most services. We have therefore included information from the NCSC guidance on choosing the right additional factor for your organization. Whichever method chosen, the most important thing to remember is that it should be usable and accessible to your employees.
The password requirement has also been updated to align with current NCSC guidance. This includes a reference to ‘Three Random Words’ advice. But we're not mandating that approach for Cyber Essentials as it could discourage other methods such as using a password manager or other strategies in our password administration guidance.
A final note on scope
Most changes to scope are to encompass these new requirements. But the scope of certification in the Cyber Essentials certification process is often misunderstood, which is why we've included some additional guidance to mitigate some of the most common issues our Certification Bodies see. It's important that the scope of certification should cover the IT infrastructure used across all of an organization's business functions or a well-defined subset of it. To help with this we have provided a new definition of ‘sub-set'.
And finally on scope, we've reinforced that it is never acceptable to exclude end-user devices.
Why no backups?
We’re frequently asked about backups and why we don't include them in the Cyber Essentials controls. It’s certainly not because we don’t think they are important. The main reason is that we don’t want to overload organizations in the certification process. Implementing the controls properly makes your organization a harder target for common types of cyber-attack, such as ransomware, and therefore reduces the criticality of backups.
But the NCSC always strongly recommends that all organizations, regardless of size, have a backup and recovery regime, and we now reference this under further guidance in the new Cyber Essentials technical requirements. Belt and braces win the day!
What about the cost?
With the updates to the technical controls, it also felt like the right time to reconsider the price, which hasn't changed since 2014 regardless of the size and complexity of the applicant organization. The price change takes account of the new technologies and scenarios our Certification Bodies are grappling with that can make certification more time-consuming.
We have worked with our partner IASME to balance the price increase and to make sure it doesn't unduly impact smaller organizations − while also ensuring that our Certification Bodies are fairly remunerated for their work. We've adopted a tiered approach with the cost remaining the same for small and micro companies: £300 + VAT for micro-companies and rising to £500 + VAT for larger organizations.
We believe that this still represents excellent value for money compared to other certifications.
And what’s next for Cyber Essentials?
We still view Cyber Essentials as the minimum standard for cyber security in the UK but we also need to ensure it keeps evolving as the threat landscape and technology change. This major update is part of that ongoing regular review. We couldn't do this without our partners in IASME and their Certification Bodies. They keep us on our toes by helping us to understand the cyber security challenges that all organizations face, particularly smaller ones.
We are also looking at what other services we can introduce to support Cyber Essentials. This includes providing an advisory service to help organizations that don't have their own technical support with the practical configuration of their systems, and how to address the security challenges that larger organizations with complex IT estates face meeting the minimum standard.
We really welcome continued feedback on Cyber Essentials. Personally, I’m encouraged by the continued growth in the scheme uptake and the valuable cyber security conversations that are happening because of it.
If you have any thoughts about Cyber Essentials, please get in touch and keep things moving in the right direction. You can find all the important details on the NCSC Cyber Essentials pages and in a blog by our Cyber Essentials partner IASME.

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics