Back to Frameworks

UK Cyber Essentials

United Kingdom
6 domains
42 controls

NCSC Cyber Essentials + Cyber Essentials Plus. UK government-backed cybersecurity certification.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (6)

Firewalls

7 controls
Controls in the Firewalls domain of UK Cyber Essentials7 controls
CodeTitle
CE-FW.1Boundary Firewalls Deployed
CE-FW.2Change Default Firewall Passwords
CE-FW.3Block Unauthenticated Inbound Connections
CE-FW.4Approve and Document Inbound Rules
CE-FW.5Remove or Disable Unused Rules
CE-FW.6Host-Based Firewall for Remote Workers
CE-PLUS.2External Vulnerability Scan of Internet IPs

Malware Protection

8 controls
Controls in the Malware Protection domain of UK Cyber Essentials8 controls
CodeTitle
CE-MP.1Anti-Malware Software Deployed
CE-MP.2Anti-Malware Signatures Updated
CE-MP.3Anti-Malware Scans Files on Access and Web Pages
CE-MP.4Application Allowlisting (Alternative)
CE-MP.5Mobile App Source Restriction
CE-PLUS.3Malware Protection Test - EICAR via Email
CE-PLUS.4Malware Protection Test - Web Download
CE-PLUS.5Removable Media Malware Test

Scope

4 controls
Controls in the Scope domain of UK Cyber Essentials4 controls
CodeTitle
CE-PLUS.8Sample Size and Representativeness
CE-SCOPE.1Scope Definition
CE-SCOPE.2Cloud Services in Scope
CE-SCOPE.3BYOD and Home Working

Secure Configuration

9 controls
Controls in the Secure Configuration domain of UK Cyber Essentials9 controls
CodeTitle
CE-PLUS.1Authenticated Vulnerability Scan of Sample Devices
CE-SC.1Remove or Disable Unused Software
CE-SC.2Change Default Passwords on Devices and Software
CE-SC.3Disable Auto-Run Features
CE-SC.4Authenticate Users Before Access
CE-SC.5Password-Based Authentication Quality
CE-SC.6Multi-Factor Authentication for Cloud Services
CE-SC.7Educate Users on Strong Passwords
CE-SC.8Process for Compromised Passwords

Security Update Management

5 controls
Controls in the Security Update Management domain of UK Cyber Essentials5 controls
CodeTitle
CE-SU.1Software Licensed and Supported
CE-SU.2Automatic Updates Enabled Where Possible
CE-SU.3Critical and High Updates within 14 Days
CE-SU.4Remove Out-of-Support Software
CE-SU.5Firmware Updates

User Access Control

9 controls
Controls in the User Access Control domain of UK Cyber Essentials9 controls
CodeTitle
CE-AC.1User Account Approval Process
CE-AC.2Authenticate Users Before Granting Access
CE-AC.3Remove or Disable Accounts When No Longer Required
CE-AC.4Privileged Account Approval and Tracking
CE-AC.5Separate Admin Accounts for Administrative Activities
CE-AC.6Periodic Review of Privileged Access
CE-AC.7MFA for Administrative Accounts
CE-PLUS.6Account Separation Verification
CE-PLUS.7MFA Verification on Cloud Services

Frequently Asked Questions

What is UK Cyber Essentials?

UK Cyber Essentials is a compliance framework from United Kingdom with 6 domains and 42 controls. NCSC Cyber Essentials + Cyber Essentials Plus. UK government-backed cybersecurity certification. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does UK Cyber Essentials have?

UK Cyber Essentials has 42 controls organised across 6 domains. The largest domains are Secure Configuration (9 controls), User Access Control (9 controls), Malware Protection (8 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does UK Cyber Essentials map to?

UK Cyber Essentials does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I get started with UK Cyber Essentials compliance?

Start your UK Cyber Essentials compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about UK Cyber Essentials requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 42 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 769 frameworks.

Get Started Free →

Free forever — no credit card required