Back to Frameworks

Cyber Essentials Plus

United Kingdom
v2024
15 domains
20 controls

UK government-backed scheme to protect against common cyber attacks

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (15)

Audit

1 controls
Controls in the Audit domain of Cyber Essentials Plus1 controls
CodeTitle
CEP-AUD-01Annual Hands On Audit and Recertification

Cloud Services

1 controls
Controls in the Cloud Services domain of Cyber Essentials Plus1 controls
CodeTitle
CEP-CLD-01Cloud Services in Scope

Cyber Essentials Plus: Access Control & Identity

0 controls

Managing access to information systems (Cyber Essentials Plus)

Cyber Essentials Plus: Audit & Accountability

0 controls

Audit logging and accountability measures (Cyber Essentials Plus)

Cyber Essentials Plus: Configuration Management

0 controls

Managing system configurations securely (Cyber Essentials Plus)

Cyber Essentials Plus: Incident Response

0 controls

Detecting and responding to security incidents (Cyber Essentials Plus)

Cyber Essentials Plus: Risk Assessment & Management

0 controls

Identifying and managing cybersecurity risks (Cyber Essentials Plus)

Cyber Essentials Plus: System & Communications Protection

0 controls

Protecting systems and communications (Cyber Essentials Plus)

Firewalls

2 controls
Controls in the Firewalls domain of Cyber Essentials Plus2 controls
CodeTitle
CEP-FW-01Boundary Firewall Configuration
CEP-FW-02Host Based Firewall on Devices

Malware Protection

4 controls
Controls in the Malware Protection domain of Cyber Essentials Plus4 controls
CodeTitle
CEP-MA-01Anti-Malware Deployment and Operation
CEP-MA-02Application Allow Listing or Sandboxing
CEP-MA-03Email Attachment Test
CEP-MA-04Web Browsing Malware Test

Mobile and Remote

1 controls
Controls in the Mobile and Remote domain of Cyber Essentials Plus1 controls
CodeTitle
CEP-MOB-01Mobile Device Management and Encryption

Scope

1 controls
Controls in the Scope domain of Cyber Essentials Plus1 controls
CodeTitle
CEP-SCP-01Scope Definition and Whole Organisation Boundary

Secure Configuration

3 controls
Controls in the Secure Configuration domain of Cyber Essentials Plus3 controls
CodeTitle
CEP-SC-01Secure Configuration of Devices
CEP-SC-02Auto-Run and Auto-Play Disabled
CEP-SC-03Multi-Factor Authentication for Cloud Services

Security Update Management

4 controls
Controls in the Security Update Management domain of Cyber Essentials Plus4 controls
CodeTitle
CEP-PM-01High and Critical Vulnerability Patching
CEP-PM-02Unsupported Software Removal
CEP-PM-03Authenticated Vulnerability Scan of Sample Devices
CEP-PM-04External Vulnerability Scan of Internet Facing Services

User Access Control

3 controls
Controls in the User Access Control domain of Cyber Essentials Plus3 controls
CodeTitle
CEP-UA-01Separation of Administrator Accounts
CEP-UA-02Account Provisioning and Deprovisioning
CEP-UA-03Password Policy and Brute Force Protection

Frequently Asked Questions

What is Cyber Essentials Plus?

Cyber Essentials Plus is a compliance framework from United Kingdom with 15 domains and 20 controls. UK government-backed scheme to protect against common cyber attacks It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does Cyber Essentials Plus have?

Cyber Essentials Plus has 20 controls organised across 15 domains. The largest domains are Malware Protection (4 controls), Security Update Management (4 controls), Secure Configuration (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does Cyber Essentials Plus map to?

Cyber Essentials Plus does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I get started with Cyber Essentials Plus compliance?

Start your Cyber Essentials Plus compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Cyber Essentials Plus requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 20 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.

Get Started Free →

Free forever — no credit card required