Cyber Essentials Plus
UK government-backed scheme to protect against common cyber attacks
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (15)
Audit
| Code | Title |
|---|---|
| CEP-AUD-01 | Annual Hands On Audit and Recertification |
Cloud Services
| Code | Title |
|---|---|
| CEP-CLD-01 | Cloud Services in Scope |
Cyber Essentials Plus: Access Control & Identity
Managing access to information systems (Cyber Essentials Plus)
Cyber Essentials Plus: Audit & Accountability
Audit logging and accountability measures (Cyber Essentials Plus)
Cyber Essentials Plus: Configuration Management
Managing system configurations securely (Cyber Essentials Plus)
Cyber Essentials Plus: Incident Response
Detecting and responding to security incidents (Cyber Essentials Plus)
Cyber Essentials Plus: Risk Assessment & Management
Identifying and managing cybersecurity risks (Cyber Essentials Plus)
Cyber Essentials Plus: System & Communications Protection
Protecting systems and communications (Cyber Essentials Plus)
Firewalls
| Code | Title |
|---|---|
| CEP-FW-01 | Boundary Firewall Configuration |
| CEP-FW-02 | Host Based Firewall on Devices |
Malware Protection
| Code | Title |
|---|---|
| CEP-MA-01 | Anti-Malware Deployment and Operation |
| CEP-MA-02 | Application Allow Listing or Sandboxing |
| CEP-MA-03 | Email Attachment Test |
| CEP-MA-04 | Web Browsing Malware Test |
Mobile and Remote
| Code | Title |
|---|---|
| CEP-MOB-01 | Mobile Device Management and Encryption |
Scope
| Code | Title |
|---|---|
| CEP-SCP-01 | Scope Definition and Whole Organisation Boundary |
Secure Configuration
| Code | Title |
|---|---|
| CEP-SC-01 | Secure Configuration of Devices |
| CEP-SC-02 | Auto-Run and Auto-Play Disabled |
| CEP-SC-03 | Multi-Factor Authentication for Cloud Services |
Security Update Management
| Code | Title |
|---|---|
| CEP-PM-01 | High and Critical Vulnerability Patching |
| CEP-PM-02 | Unsupported Software Removal |
| CEP-PM-03 | Authenticated Vulnerability Scan of Sample Devices |
| CEP-PM-04 | External Vulnerability Scan of Internet Facing Services |
User Access Control
| Code | Title |
|---|---|
| CEP-UA-01 | Separation of Administrator Accounts |
| CEP-UA-02 | Account Provisioning and Deprovisioning |
| CEP-UA-03 | Password Policy and Brute Force Protection |
Frequently Asked Questions
What is Cyber Essentials Plus?
Cyber Essentials Plus is a compliance framework from United Kingdom with 15 domains and 20 controls. UK government-backed scheme to protect against common cyber attacks It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Cyber Essentials Plus have?
Cyber Essentials Plus has 20 controls organised across 15 domains. The largest domains are Malware Protection (4 controls), Security Update Management (4 controls), Secure Configuration (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Cyber Essentials Plus map to?
Cyber Essentials Plus does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I get started with Cyber Essentials Plus compliance?
Start your Cyber Essentials Plus compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Cyber Essentials Plus requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 20 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required