Cyber Essentials, done properly.
The five technical controls, the evidence behind them, and a program that survives to next year's renewal.
Small scheme, real consequences
Cyber Essentials is deliberately narrow: five technical controls covering firewalls, secure configuration, user access control, malware protection and security update management. That is the point — it targets the attacks that account for the overwhelming majority of breaches.
It is also a commercial gate. UK government contracts handling sensitive information require it, and increasingly so do private-sector buyers. Certification is annual, and Cyber Essentials Plus adds a hands-on technical audit.
OpenGRC includes the Cyber Essentials requirements bundle — 100 controls across the scheme — on every plan.
Pass it once, then keep passing it.
Asset scope you can defend
The scheme turns on what is in scope. Asset and application registries record devices, owners and lifecycle, so the boundary you certify is documented rather than reconstructed each year.
Patching, evidenced
Security update management is where most organisations actually fail. Recurring assessment cadence and workflow automation chase overdue checks rather than relying on someone remembering.
Ready for Plus
Cyber Essentials Plus adds a technical audit. Evidence attached to each control, plus an auditor portal with time-bounded access, means the assessor works from your records instead of a screen-sharing session.
The five technical controls
| Control | In OpenGRC |
|---|---|
| Firewalls — boundary and device firewalls | Control implementations with test procedures and evidence |
| Secure configuration — remove defaults, reduce attack surface | Implementation tracking with maturity and internal notes |
| User access control — least privilege, account management | User access review campaigns over applications and assets |
| Malware protection | Control implementations with recurring assessment cadence |
| Security update management — patching within defined windows | Workflow automation for recurring checks and overdue chasing |
The bundle also covers the scheme's scoping requirements for cloud services, home working and bring-your-own-device — the parts that most often cause a first-time failure.
Cyber Essentials questions
Does OpenGRC certify us?
No. Certification comes from an IASME-accredited certification body via self-assessment, or a technical audit for Cyber Essentials Plus. OpenGRC is where you keep the controls, evidence and scope that the assessment draws on.
™