What are the Cyber Essentials requirements for IT infrastructure?
Getting IT infrastructure into shape for Cyber Essentials is one of the most useful things a UK business can do to reduce day‑to‑day cyber risk. The scheme focuses on a small set of practical controls that, when applied properly across your networks, devices and cloud services, block a large proportion of common attacks.
What are the Cyber Essentials requirements for IT infrastructure?
The UK Cyber Security Group offers Cyber Essentials certification at a low cost through its compliance services, which is particularly helpful for smaller organisations that want a structured route to basic cyber assurance without overcomplicating things.
Cyber Essentials in context for UK IT teams
Cyber Essentials is the UK’s baseline cyber security certification scheme, backed by the National Cyber Security Centre (NCSC) and administered by IASME through a network of licensed providers.It was launched in 2014 to give organisations a simple, practical standard for defending against the most common internet-borne threats.
The scheme is built around five core technical controls that apply to all in‑scope devices:
- Boundary firewalls and internet gateways
- Secure configuration
- User access control
- Malware protection
- Patch management
Together, these controls focus squarely on IT infrastructure: the networks, servers, endpoints and cloud services that store and process your data. Cyber Essentials does not ask you to be perfect; it asks you to get the fundamentals right and to prove it in a structured way.
There are two levels of certification: standard Cyber Essentials (a self‑assessment questionnaire reviewed by an approved service provider) and Cyber Essentials Plus, which adds independent technical testing of your controls. Both levels use exactly the same five control areas; Plus simply verifies them more deeply through hands‑on tests.
Scoping your IT infrastructure for Cyber Essentials
The starting point for any Cyber Essentials project is deciding what is “in scope”. From an IT infrastructure perspective, this usually includes:
- Office networks and internet connections
- Servers (on‑premises and cloud‑hosted)
- End‑user devices such as desktops, laptops and tablets
- Cloud services used for email, file storage and core applications
- Network equipment such as routers, firewalls and wireless access points
If a device can access or process business data and is connected to the internet directly or indirectly, it is likely to be in scope for the scheme. The same applies to cloud services that staff use to send, receive or store business information. Treating these consistently is key: Cyber Essentials controls must apply wherever data lives, not just in one corner of your infrastructure.
Firewalls and boundary protection: securing the edges
At the boundary of your network, Cyber Essentials expects you to use firewalls or equivalent controls to filter traffic and block unwanted connections.
For IT infrastructure, that translates into requirements such as:
- Internet gateways (for example, office routers or dedicated firewalls) must be configured to allow only necessary inbound connections.
- Externally accessible services, such as web servers or VPN gateways, must be restricted to the ports and protocols they genuinely require.
- Default firewall rules and credentials must be changed before equipment goes into live use.
From a practical point of view:
- You should maintain a simple record of which services are exposed to the internet and why.
- Any remote management interfaces (such as web admin pages for routers or firewalls) should either be disabled externally or strongly protected with access controls and authentication.
These boundary controls are designed to stop opportunistic scanning and basic exploitation of services, which remain a common attack route across UK organisations.
Secure configuration: hardening devices and services
Secure configuration under Cyber Essentials is about making sure systems are not left in a default or insecure state. For IT infrastructure this covers:
- Removing or disabling unnecessary software and services on servers, desktops and network equipment.
- Changing default usernames and passwords on all devices, especially network hardware and admin portals.
- Disabling or limiting features that are not required, such as unused network shares or remote desktop access.
- Ensuring configuration baselines are defined and applied consistently, rather than leaving each device to be set up ad hoc.
In practice, this might include:
- Applying hardened builds or templates to servers and workstations.
- Locking down access to BIOS or boot‑loader settings to prevent unauthorised changes.
- Ensuring wireless networks use strong authentication and modern encryption options.
Secure configuration is one of the areas where relatively small changes can significantly reduce risk. Many successful attacks exploit default settings, unused services or lax configurations rather than sophisticated vulnerabilities.
User access control: accounts, privileges and authentication
User access control is where Cyber Essentials requirements for password‑based authentication and account management sit. It is also a core part of IT infrastructure protection.
Modern guidance on the scheme emphasises controls such as:
- Least privilege: giving users only the access they need for their role.
- Separating standard user accounts from administrator accounts.
- Enforcing sensible password policies and, where possible, multi‑factor authentication.
For infrastructure, that means:
- Each person has a unique user account for systems they use. Shared logins are avoided or tightly controlled.
- Administrator rights are limited to a small, justified group, and admin accounts are not used for everyday email and web browsing.
- Local admin rights on devices are restricted so that users cannot casually install software or change security settings.
- Passwords are sufficiently strong and are protected against brute‑force guessing through lockouts or throttling.
User access control also includes joiner, mover and leaver processes:
- When someone joins, accounts are created with minimum necessary access.
- When roles change, access rights are reviewed and adjusted.
- When people leave, their accounts and remote access are disabled promptly.
Weak account management remains a major factor in breaches and ransomware incidents. Cyber Essentials explicitly tackles this by making user access control one of its five pillars.
Malware protection: defending endpoints and servers
Malware protection in Cyber Essentials is largely about ensuring that devices can detect and block malicious software before it causes harm. For IT infrastructure, key expectations include:
- All in‑scope desktops, laptops and servers run anti‑malware tools that are kept up to date.
- Real‑time scanning is enabled so that files and downloads are checked as they are accessed.
- Regular scans are run, either centrally or by local tools, to catch dormant threats.
- Email and web filtering is in place to block known malicious attachments and sites, especially on gateways.
Malware protection is especially important when thinking about phishing and malicious downloads. Many attacks start with an email or a compromised website; Cyber Essentials requires that your infrastructure has basic defences in place to reduce the chance that one click leads to widespread compromise.
Patch management: keeping infrastructure updated
Patch management under Cyber Essentials focuses on making sure software and firmware are up to date, so that known vulnerabilities cannot be easily exploited. For IT infrastructure this means:
- Operating systems on servers, desktops and laptops must be supported (not end‑of‑life) and regularly updated.
- Third‑party applications, such as browsers, office suites and runtimes, are patched promptly.
- Network equipment firmware is updated when security fixes are released.
- Critical security updates are applied within a defined and reasonable timeframe, often within 14 days of release.
From an IT management perspective, you should:
- Maintain an inventory of in‑scope devices and systems.
- Use automated patch management tools where possible to push updates and monitor status.
- Be prepared to explain how you decide which updates to apply and how quickly.
Unpatched systems are a favourite target for attackers because public information is available about how to exploit them. Cyber Essentials calls this out explicitly to ensure that patching is treated as a core part of infrastructure security, not an optional extra.
Pulling it together: infrastructure as a whole
When you look at the five controls together, you can see how they apply across your IT infrastructure:
- Boundary controls deal with where your networks meet the internet.
- Secure configuration and patching apply to everything inside that boundary, from endpoints to servers to routers.
- User access control covers how people actually log in and what they can do.
- Malware protection addresses what happens if something malicious gets through.
The aim is not to build a perfectly secure environment, but to remove the easy attack paths. According to Cyber Essentials guidance, applying these controls systematically can block a large proportion of routine commodity attacks that otherwise succeed against unprotected or poorly configured systems.
What are the key requirements for achieving Cyber Essentials certification?
Now to address What are the key requirements for achieving Cyber Essentials certification? in a succinct way for IT infrastructure teams.
At a high level, you need to be able to show that:
- All in‑scope devices have appropriate firewall and boundary protection.
- Systems are securely configured, with unnecessary services disabled and default credentials changed.
- User accounts and administrator rights are managed according to least‑privilege principles, with robust authentication.
- Anti‑malware measures are in place and actively working on endpoints and servers.
- Patching processes keep operating systems, applications and firmware up to date, particularly for security updates.
On top of this, you must define your scope and complete the official questionnaire honestly, providing evidence where required. For Cyber Essentials Plus, those controls are then tested through technical verification, such as vulnerability scans and configuration checks.
How can I prepare my small business for Cyber Essentials assessment?
For How can I prepare my small business for Cyber Essentials assessment?, the focus is on practical steps that align IT infrastructure with the scheme.
Some realistic actions include:
- Clarify which devices, networks and cloud services are in scope (for example, office PCs, laptops, office router, email platform, file storage, main business apps).
- Check your boundary devices (routers, firewalls) and confirm that only necessary inbound services are exposed, with changed default passwords.
- Review user accounts on key systems, remove unused accounts, and separate admin roles from day‑to‑day users.
- Ensure all in‑scope devices have anti‑malware enabled and are receiving updates.
- Verify patching: confirm that supported versions are in use and that recent security updates have been applied.
- Document what you find and what you change, so you can refer to it when answering the assessment questions.
The NCSC‑aligned guidance makes clear that Cyber Essentials is intended to be attainable for smaller organisations, including single‑person businesses. The controls are deliberately practical rather than academic, and preparation is largely about getting visibility and tidying up existing infrastructure.
What software solutions support compliance with Cyber Essentials standards?
The statement What software solutions support compliance with Cyber Essentials standards? is essentially asking which tools help you manage those five control areas across your infrastructure.
Commonly used solutions include:
- Centralised firewall or unified threat management platforms to manage boundary rules and logging.
- Endpoint management suites that handle secure configuration baselines, local admin rights and device inventory.
- Directory and identity services to centralise user accounts, password policies and, where possible, multi‑factor authentication.
- Anti‑malware tools that provide real‑time protection and central reporting across servers and endpoints.
- Patch management tools to automate the deployment of operating system and application updates.
Business‑focused commentary on the scheme notes that many Cyber Essentials requirements can be met using features already built into mainstream cloud and device platforms, once they are properly configured. In other words, compliance is often more about turning on and tuning existing capabilities than buying something entirely new.
Can I renew my Cyber Essentials certification through an online service?
Yes, Can I renew my Cyber Essentials certification through an online service? is a common question, and the answer is straightforward.
Standard Cyber Essentials certification is obtained and renewed by completing a self‑assessment questionnaire that is reviewed by an IASME‑licensed provider. The entire process is typically carried out online:
- You log into the provider’s portal.
- You answer the control‑related questions about your infrastructure.
- You update any answers that no longer reflect reality, especially where changes have taken place since your last assessment.
- The provider reviews your responses and may ask for clarifications.
Certification is valid for 12 months and must be renewed annually to remain current. The key for IT infrastructure teams is to maintain controls throughout the year so that renewal is a confirmation of ongoing practice rather than a frantic catch‑up exercise.
Which companies provide Cyber Essentials certification services in the UK?
Turning to Which companies provide Cyber Essentials certification services in the UK?, the scheme is administered by IASME on behalf of the NCSC and delivered via a network of licensed Assured Service Providers.
These providers:
- Offer access to the official Cyber Essentials questionnaire.
- Review completed self‑assessments and issue certificates where requirements are met.
- Carry out Cyber Essentials Plus technical testing for organisations seeking the higher level.
The UK Cyber Security Group is part of this wider community of providers, offering Cyber Essentials certification at a low cost through its compliance services. Other providers range from dedicated cyber companies to broader IT and risk consultancies, giving UK organisations a range of options for how they engage with the scheme.
Which UK-based firms offer Cyber Essentials consultancy services?
The question Which UK-based firms offer Cyber Essentials consultancy services? looks beyond certification to advisory support.
Across the UK, many firms now provide:
- Readiness assessments, where they review your IT infrastructure against the five control areas and highlight gaps.
- Hands‑on help fixing configuration issues, tightening firewall rules, cleaning up accounts and enabling appropriate updates.
- Policy drafting and staff training, so that non‑technical employees understand their role in meeting Cyber Essentials requirements.
- Ongoing managed services that keep your Cyber Essentials controls in place and aligned with changing infrastructure.
The UK Cyber Security Group and related organisations under the same umbrella offer both certification and consultancy, which is particularly beneficial for smaller teams that do not have dedicated IT security staff but still want to get things right.
Making Cyber Essentials work with real-world IT infrastructure
For many UK organisations, Cyber Essentials is the first formal step into structured cyber security. The focus on IT infrastructure is intentional: it is where most attacks hit first, and where sensible controls provide the fastest pay‑off.
If you treat the five control areas as everyday management disciplines rather than one‑off tasks, you gain:
- Clear visibility of what equipment and services you are running.
- Confidence that basic protections are in place at the network edge and on devices.
- Better control over who can log in, what they can do and how easily attackers can guess or steal credentials.
- A repeatable way to stay up to date with patches and malware defences, even as systems evolve.
With that foundation, working with a provider such as the UK Cyber Security Group to achieve and maintain Cyber Essentials certification becomes less of a tick‑box exercise and more of a natural extension of how you already manage your IT infrastructure.
UK Cyber Security Group Ltd is here to help
Please check out our Free Cyber Insurance
If you would like to know more, do get in touch as we are happy to answer any questions. Looking to improve your cybersecurity but not sure where to start? Begin by getting certified in Cyber Essentials, the UK government’s scheme that covers all the technical controls that will provide the protection that you need to help guard against criminal attacks. Or just get in touch by clicking contact us










