Cyber Essentials, done properly.

The five technical controls, the evidence behind them, and a program that survives to next year's renewal.

Small scheme, real consequences

Cyber Essentials is deliberately narrow: five technical controls covering firewalls, secure configuration, user access control, malware protection and security update management. That is the point — it targets the attacks that account for the overwhelming majority of breaches.

It is also a commercial gate. UK government contracts handling sensitive information require it, and increasingly so do private-sector buyers. Certification is annual, and Cyber Essentials Plus adds a hands-on technical audit.

OpenGRC includes the Cyber Essentials requirements bundle — 100 controls across the scheme — on every plan.

Built for renewal

Pass it once, then keep passing it.

Asset scope you can defend

Asset scope you can defend

The scheme turns on what is in scope. Asset and application registries record devices, owners and lifecycle, so the boundary you certify is documented rather than reconstructed each year.

Patching, evidenced

Patching, evidenced

Security update management is where most organisations actually fail. Recurring assessment cadence and workflow automation chase overdue checks rather than relying on someone remembering.

Ready for Plus

Ready for Plus

Cyber Essentials Plus adds a technical audit. Evidence attached to each control, plus an auditor portal with time-bounded access, means the assessor works from your records instead of a screen-sharing session.

The five technical controls

ControlIn OpenGRC
Firewalls — boundary and device firewallsControl implementations with test procedures and evidence
Secure configuration — remove defaults, reduce attack surfaceImplementation tracking with maturity and internal notes
User access control — least privilege, account managementUser access review campaigns over applications and assets
Malware protectionControl implementations with recurring assessment cadence
Security update management — patching within defined windowsWorkflow automation for recurring checks and overdue chasing

The bundle also covers the scheme's scoping requirements for cloud services, home working and bring-your-own-device — the parts that most often cause a first-time failure.

Cyber Essentials questions

Does OpenGRC certify us?

No. Certification comes from an IASME-accredited certification body via self-assessment, or a technical audit for Cyber Essentials Plus. OpenGRC is where you keep the controls, evidence and scope that the assessment draws on.

Is this overkill for five controls?

What about Cyber Essentials Plus?

How does renewal work?