UK Cyber Essentials
What is UK Cyber Essentials?
NCSC Cyber Essentials + Cyber Essentials Plus. UK government-backed cybersecurity certification.. It comprises 36 controls organised across 6 domains, and applies in the United Kingdom.
How UK Cyber Essentials maps to other frameworks
All 36 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 6 domains UK Cyber Essentials groups its controls into
Frameworks that share controls with UK Cyber Essentials
Each of these has at least one control mapped to a control in UK Cyber Essentials. The number is how many UK Cyber Essentials controls are shared, counted from the mapping graph.
Implementation guides for frameworks that overlap UK Cyber Essentials
Training on frameworks that overlap UK Cyber Essentials
There is no course on UK Cyber Essentials itself. These cover frameworks that share controls with it, so the material carries across even though the standard named is different.
Where UK Cyber Essentials overlaps with the standards you already hold
What UK Cyber Essentials means in your sector
What UK Cyber Essentials means for your job
Questions people ask about UK Cyber Essentials
What is UK Cyber Essentials?
How many controls does UK Cyber Essentials have?
Where does UK Cyber Essentials apply?
How do I get started with UK Cyber Essentials compliance?
Query UK Cyber Essentials programmatically
UK Cyber Essentials, its 36 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
UK Cyber Essentials API reference and MCP config →What UK Cyber Essentials requires, control by control
Each page carries the requirement text for one UK Cyber Essentials control and what an assessor expects to see as evidence.
- CE-AC-1 User Account Approval Process
- CE-AC-2 Authenticate Users Before Granting Access
- CE-AC-3 Remove or Disable Accounts When No Longer Required
- CE-AC-4 Privileged Account Approval and Tracking
- CE-AC-5 Separate Admin Accounts for Administrative Activities
- CE-AC-6 Periodic Review of Privileged Access
- CE-AC-7 MFA for Administrative Accounts
- CE-AC-8 Passwordless Authentication
- CE-FW-1 Boundary Firewalls Deployed
- CE-FW-2 Change Default Firewall Passwords
How much of another standard UK Cyber Essentials already covers
Each crosswalk is judged control by control, and the mappings that were rejected are kept alongside the ones that held.
- ANSSI Guide d'hygiene informatique (42 mesures, v2.0) to UK Cyber Essentials crosswalk
- ASD Strategies to Mitigate Cyber Security Incidents to UK Cyber Essentials crosswalk
- UK Cyber Essentials to AWS Well-Architected Security Pillar crosswalk
- Azure Security Benchmark to UK Cyber Essentials crosswalk
- C5 (Germany) to UK Cyber Essentials crosswalk
- UK Cyber Essentials to CIS Controls v8 crosswalk
- Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 to UK Cyber Essentials crosswalk
- UK Cyber Essentials to CMMC 2.0 crosswalk
How ready are you for UK Cyber Essentials?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.