- 1. Summary
- 2. Cyber Assurance of Physical Security Systems (CAPSS)
- 2.1 What is it?
- 2.2 Aim and scope
- 3. FedRAMP
- 3.1 What is it?
- 3.2 Aim and scope
- 4. Secured By Design/Secure Connected Devices (SBD/SCD)
- 4.1 What is it?
- 4.2 Aim and scope
- 5. ETSI EN 303 645
- 5.1 What is it?
- 5.2 Aim and scope
- 6. International Electrotechnical Commission (IEC) 62443-4-2
- 6.1 What is it?
- 6.2 Aim and scope
- 7. The Security Evaluation Standard for IoT Platforms (SESIP)
- 7.1 What is it?
- 7.2 Aim and scope
- 8. Underwriters Laboratories (UL) IoT Framework
- 8.1 What is it?
- 8.2 Aim and scope
- 9. System and Organisational Controls (SOC) 2
- 9.1 What is it?
- 9.2 Aim and scope
- 10. International Organisation for Standardisation (ISO) 9001
- 10.1 What is it?
- 10.2 Aim and scope
- 11. International Organization for Standardization/International Electrotechnical Commission (ISO/IEC) 27001
- 11.1 What is it?
- 11.2 Aim and scope
- 12. National Cyber Security Centre Cyber Assessment Framework (NCSC CAF)
- 12.1 What is it?
- 12.2 Aim and scope
- 13. Cybersecurity Maturity Model Certification (CMMC)
- 13.1 What is it?
- 13.2 Aim and scope
- 14. Cyber Essentials
- 14.1 What is it?
- 14.2 Aim and scope
- 15. Cyber Essentials Plus
- 15.1 What is it?
- 15.2 Aim and scope
This guidance is available to download as a PDF
1. Summary
The Cyber Security Standards Comparison Guide (EIS0066) and additional Cyber Security Standards Comparison Reference Table (EIS0065) are intended to provide readers an overview of some of the most popular cyber security standards and frameworks. The guide includes details of the main requirements in each standard/framework and further information on the time and depth of testing required. The reference table provides an easy-to-understand overview of who and what the standard/framework is aimed at and a rating guide intended to demonstrate the level of testing and complexity involved when undertaken.
2. Cyber Assurance of Physical Security Systems (CAPSS)
2.1 What is it?
CAPSS is an NPSA standard designed for Physical Security products such as Automatic Access Control Systems (AACS), Visitor Management Systems (VMS), Video Surveillance Systems (VSS), Security Management Systems (SMS) and Intrusion Detection Systems (IDS). It is intended to provide assurance that security products have been designed to mitigate cyber threats, protecting system functionality, user data and wider connected cyber systems.
| Continent/Country of Origin: | UK |
|---|---|
| Geographical Scope: | UK and UK overseas territories |
| Assurance issuing body: | National Protective Security Authority (NPSA) |
| Self-Assessment of Independently assured: | Independently assured by NPSA Assured Test Labs |
| Use: | Electronic security product level assurance programme gives assurance that the product is suitable for UK government use. |
| Criteria: | Assurance is based on a set of 87 requirements split across 6 thematic areas. |
| Validity of assurance and continuous monitoring detail: | 6 years with reviews at 2 and 4-year markers. Trademark issued by NPSA for marketing use. |
| Timeline to undertake: | 6-12 months |
| Applicability of standard to product/service e.g., Mandatory or Voluntary: | Some UK government departments and/or regulators mandate CAPSS as part of purchasing new products. |
| Website: | https://www.npsa.gov.uk/cyber-assurance-physical-security-systems-capss |
2.2 Aim and scope
The aim and scope of this standard is to ensure that physical security products designed to protect government organisations assets have suitable mitigations in place to prevent compromise by cyber-attack. CAPSS covers the following areas:
- General
- Physical Security
- Secure Configuration
- Network Security
- Authentication
- Management Monitoring
3. FedRAMP
3.1 What is it?
FedRAMP is a US government-wide program that promotes the adoption of secure cloud services across the US federal government by providing a standardised approach to security and risk assessment for cloud technologies and US federal agencies.
| Continent/Country of Origin: | US |
|---|---|
| Geographical Scope: | US and US overseas territories |
| Assurance issuing body: | FedRAMP |
| Self-Assessment or Independently assured: | Independently assured by a FedRAMP assured assessor. |
| Use: | Assesses cloud services based on the requirements and principles for cloud services to be used by the US federal government. |
| Criteria: | Joint Authorization Board and Agency assessments are based on a set of 125 – 425 requirements for low to high assessment criteria split over 18 thematic areas some of which have prerequisites references to other standards such as ISO27001 and SOC2, Federal Information Processing Standards (FIPS). |
| Validity of assurance and continuous monitoring detail: | Joint Authorization Board (JAB) assessments last 1 year. Agency assessments last 1 year. |
| Timeline to undertake: | Joint Authorization Board (JAB) authorisation 4 weeks. Agency authorisation 12 months plus. |
| Applicability of standard to product/service e.g., Mandatory or Voluntary: | It is mandatory for all cloud services being used within US federal government organisations to have undergone a FedRAMP assessment. |
| Website: | https://www.fedramp.gov |
3.2 Aim and scope
The aim and scope of this program/standard is to provide assurance that the cloud services provide the required level of security and protection of data for use within any/all USA federal government agencies. FedRAMP covers the following areas:
- Access Control
- Awareness and Training
- Audit and Accountability
- Assessment, Authorisation and Monitoring
- Configuration Management
- Contingency Planning
- Identification and Authentication
- Incident Response
- Maintenance
- Media Protection
- Physical and Environmental Protection
- Planning
- Personnel Security
- Risk Assessment
- System and Services Acquisition
- System and Communications Protection
- System and Information Integrity
- Supply Chain Risk Management
4. Secured By Design/Secure Connected Devices (SBD/SCD)
4.1 What is it?
Secured by Design is the official security initiative that is owned by the UK Police Service with the specific aim to reduce crime and help people live and work more safely. Secured by Design’s ‘Secure Connected Device’ accreditation scheme was developed in consultation with the Department for Science, Innovation and Technology (DSIT), and is for companies providing IoT connected products and services. It demonstrates that their products have achieved the appropriate and relevant IoT standards and certification from an SBD recognised certification body. SBD also provides a police endorsed app accreditation via the SCD scheme, which demonstrates that mobile apps have achieved the appropriate and relevant security standards and certifications from an SBD recognised certification body. SBD is the only way for companies to obtain police recognition for security-related and IoT products in the UK.
| Continent/Country of Origin: | UK |
|---|---|
| Geographical Scope: | UK and UK overseas territories |
| Assurance issuing body: | SBD |
| Self-Assessment or Independently assured: | Independently assured by an SBD assured assessor/certification body. |
| Use: | Gives assurance that IoT products/mobile apps for physical security have cyber security resilience and mitigation in place. |
| Criteria: | Products/mobile apps are assessed against the 13 provisions set out in ETSI EN 303 645 and/or the OWASP ASVS/MASVS, as well as build standard assessment. |
| Validity of assurance and continuous monitoring detail: | 1 year |
| Timeline to undertake: | 3-12 months |
| Applicability of standard to product/service e.g., Mandatory or Voluntary: | Is voluntary for companies/organisations to undertake to assure their IoT products/mobile apps for physical security. |
| Website: | https://www.securedbydesign.com/internet-of-things/how-to-get-your-iot-product-scd-accredited |
4.2 Aim and scope
The aim and scope of the scheme is for companies/organisations to implement cyber security measures and practices into their IoT physical security products/services. The scheme echoes the following areas that the Product Security and Telecommunications Infrastructure Act 2022 (PSTI) covers but requires all the provisions of ETSI EN 303 645 standard to be assessed. Where standalone applications are involved, these are assessed via OWASP ASVS/MASVS, which outlines security controls that should be implemented for mobile apps to help reduce the vulnerability against the most common cyber-attacks.
- Ensures that consumer connectable products are more secure against cyber-attacks, protecting individual privacy and security.
- Requires manufacturers, importers, and distributors to comply with new security requirements relating to consumer connectable products.
- Creates an enforcement regime with civil and criminal sanctions aimed at preventing insecure products being made available on the UK market.
- Ensures that where physical security standards form part of the product or service, these must also be tested and certified, to ensure that all elements of the product incorporate an overarching baseline security to reduce the risk/opportunity of adversarial attack from either an IoT or physical perspective.
5. ETSI EN 303 645
5.1 What is it?
ETSI EN 303645 is designed to prevent large-scale, widespread cyber-attacks against IoT devices. The standard sets out a security baseline for connected consumer products that provides a basis for IoT certification schemes. This standard describes building security into IoT products from their design, rather than bolting security measures on at the end.
| Continent/Country of Origin: | France/UK |
|---|---|
| Geographical Scope: | Global |
| Certification issuing body: | 3rd parties |
| Self-Assessment or Independently assured: | Independently assured by ETSI assured test lab/assessor. |
| Use: | Provides assurances that a manufactures IoT devices/products have been built with cyber security resiliency. |
| Criteria: | IoT products/devices are assessed against 68 requirements over 15 thematic areas, in conformance with TS 103 701. |
| Validity of assurance and continuous monitoring detail: | Unknown |
| Timeline to undertake: | Unknown |
| Applicability of standard to product/service e.g., Mandatory or Voluntary: | Is voluntary for companies/organisations to undertake to assure their IoT products. |
| Website: | https://www.etsi.org/ |
5.2 Aim and scope
The aim and scope of the standard is for companies/organisations to implement cyber security measures and practices into their IoT devices/products at the build and design stages of development. Products in the scope include connected children’s toys and baby monitors, connected safety-relevant products such as smoke detectors and door locks, smart cameras, TVs and speakers, wearable health trackers, connected home automation and alarm systems, connected appliances (e.g. washing machines, fridges) and smart home assistants. The standard covers the following areas:
- Reporting implementation
- No universal default passwords
- Implement a means to manage reports of vulnerabilities
- Keep software updated
- Securely store sensitive security parameters
- Communicate securely
- Minimise exposed attack surfaces
- Ensure software integrity
- Ensure that personal data is secure
- Make systems resilient to outages
- Examine system telemetry data
- Make it easy for users to delete user data
- Make installation and maintenance of devices easy
- Validate input data
- Data protection for consumer IoT
6. International Electrotechnical Commission (IEC) 62443-4-2
6.1 What is it?
IEC 62443-4-2 is a standard designed to implement cyber security resilience in Operational technology that run off a computerised system and can be connected to an IT network.
| Continent/Country of Origin: | Switzerland |
|---|---|
| Geographical Scope: | Global |
| Certification issuing body: | 3rd parties |
| Self-Assessment or Independently assured: | Independently assured by IEC assured test lab/assessor. |
| Use: | Provides assurances that a manufacturer’s computerised industrial machinery and equipment have been built with cyber security resiliency and mitigations. |
| Criteria: | Industrial machinery/equipment are assessed against 95 requirements split across 7 thematic areas and that 62443-4-1 has already been acquired. |
| Validity of assurance and continuous monitoring detail: | Unknown |
| Timeline to undertake: | Unknown |
| Applicability of standard to product/service e.g., Mandatory or Voluntary: | Is voluntary for companies/organisations to undertake to assure their computerised industrial machinery/equipment. |
| Website: | https://www.iecee.org/certification/iec-standards/iec-62443-4-22019 |
6.2 Aim and scope
The aim and scope of the standard is to provide assurance that computerised Operational technology has been built with cyber security resiliency and migrations in place. The standard provides detailed technical control system component requirements associated with the seven foundational requirements described in IEC TS 62443- 1-1 including defining the requirements for control system capability security levels and their components. The standard covers the following areas:
- Identification and authentication control
- Use control
- System integrity
- Data confidentiality
- Restricted data flow
- Timely response to events
- Resource availability
7. The Security Evaluation Standard for IoT Platforms (SESIP)
7.1 What is it?
The Security Evaluation Standard for IoT Platforms (SESIP) is a standard which is designed to assure components against cyber security measures to reduce the cost of assuring a product if the same components are used in other devices. The standard includes elements that maps to other standards such as ETSI and NIST. SESIP is split into 5 distinct levels of assurance which range from a company/organisation self-assessing their product to a full evaluation by an approved test lab.
| Continent/Country of Origin: | US |
|---|---|
| Geographical Scope: | Global |
| Certification issuing body: | Global Platform |
| Self-Assessment or Independently assured: | Self-assessed and independently assured against the SESIP criteria depending on the level of assurance being applied. |
| Use: | Provides assurances that components of a product have implemented cyber security mitigations. |
| Criteria: | Components are tested against 40 requirements split over 8 thematic areas. |
| Validity of assurance and continuous monitoring detail: | 2 years |
| Timeline to undertake: | Unknown |
| Applicability of standard to product/service e.g., Mandatory or Voluntary: | Is voluntary for companies/organisations to undertake to assure that their components follow basic cyber security practices. |
| Website: | https://globalplatform.org/sesip/ |
7.2 Aim and scope
The aim and scope of the standard is to assure that components used in IoT devices have been built and designed with cyber security mitigations in place and for those components to be re-used in other devices without the need to reassure. The standard covers the following areas:
- Identification and Attestation of Platforms and Applications
- Product Life Cycle: Factory Reset/Install/Update/Decommission Secure Communication
- Extra Attacker Resistance
- Cryptographic Functionality
- Compliance Functionality
- Access Control
- Availability
8. Underwriters Laboratories (UL) IoT Framework
8.1 What is it?
The Underwriters Laboratories (UL) IoT framework is aimed at IoT devices in a smart home such as smart meters, T.V’s, fridges, etc to implement cyber security mitigations.
| Continent/Country of Origin: | USA |
|---|---|
| Geographical Scope: | Global |
| Certification issuing body: | UL |
| Self-Assessment or Independently assured: | Independently assured. |
| Use: | Provides a guide for smart household appliances to follow to implement cyber security mitigations when designing their products. |
| Criteria: | Companies/organisations are advised to design and implement cyber security mitigations against 20 cyber security principles. |
| Validity of assurance and continuous monitoring detail: | 10 years |
| Timeline to undertake: | 4 weeks |
| Applicability of standard to product/service e.g., Mandatory or Voluntary: | Is voluntary for companies/organisations to implement the framework when designing Smart appliances. |
| Website: | https://www.ul.com/build-trust-your-consumer-iot-device-security-and-demonstrate-compliance |
8.2 Aim and scope
The aim and scope of the framework is to encourage smart appliance manufacturers to implement cyber security mitigations in their products. The framework covers the following areas:
- Provide a manual override for any safety-critical operations
- Ensure parameters which could compromise the system (secret or private cryptographic keys, passwords, etc.) are unique per device
- Test the system to be sure it is free of known, exploitable vulnerabilities prior to release
- Allow for software updates and ensure they are cryptographically authenticated prior to installation and execution. Implement anti-rollback features to prevent the installation of previous vulnerable versions of firmware
- Use industry standard security protocols with best practice defaults for any remote or wireless connections and authentication of connections to management services
- Do not store passwords in clear text
- Authenticate remote access and system management interfaces with session and time-out limits
- Ensure cryptographic key methodologies generate sufficient randomness
- Detail all customer data – including audio, video, and personal details – that can be exported to cloud systems or third parties. Provide an opt-in for such collection
- Only use industry standard cryptographic algorithms and modes of operation for any security protocol (such as firmware authenticity checking)
- Provide ability for users to enable on-demand features they may not want or only use intermittently
- Implement a power-on self-test that validates core functions and integrity of firmware prior to execution. Implement a cryptographic chain of trust from the hardware during boot where possible
- Ensure that any system defaults, such as passwords, certificates, or keys, are forced to be changed prior to initial operation
- Ensure error messages or responses to invalid messages do not expose sensitive data
- Ensure cryptographic keys are only used for a single intended purpose
- Implement least privilege in all systems
- Implement protections to prevent execution of data memory
- Do not allow direct execution of externally provided commands, scripts or other parameters that are not within the defined functions of devices
- Create and compile firmware for devices so that it contains only code and systems required for the defined functions. Always remove/disable debug and development features in devices when creating production code
- Implement a vulnerability management program to regularly monitor and address security flaws in the product prior to release and through end-of-life. Include a process to distribute patches to customers and keep them informed
9. System and Organisational Controls (SOC) 2
9.1 What is it?
System and Organizational Controls (SOC) 2 is a voluntary compliance standard for service organizations, developed by the American Institute of Certified Public Accountants (AICPA), which specifies how organizations should manage customer data. The standard is based on the following Trust Services Criteria: security, availability, processing integrity, confidentiality, privacy. This standard sets out similar principals to the GDPR regulation however unlike GDPR is not a mandatory requirement. There are 2 types of SOC 2 certificates; type 1 describes a vendor’s systems, and a service auditor confirms whether the control design is suitable to meet relevant Trust Services Criteria. Type 2 also details the operational effectiveness of those systems.
| Continent/Country of Origin: | US |
|---|---|
| Geographical Scope: | North America |
| Certification issuing body: | AICPA (American Institute of Certified Public Accountants) |
| Self-Assessment or Independently assured: | Independently assured. An audit must be performed by a Certified Public Accountants from an accredited AICPA firm. |
| Use: | Audits an organisation’s information security level based on requirements and principles. |
| Criteria: | Certification is based on a set of 61 requirements split across 5 thematic areas. |
| Validity of assurance and continuous monitoring detail: | Type 1 or Type 2 report is valid for 1 year following the date the report was issued. |
| Timeline to undertake: | 1 year |
| Applicability of standard to product/service e.g., Mandatory or Voluntary: | Type 1 or Type 2 report is valid for 1 year following the date the report was issued. |
| Website: | https://soc2.co.uk/ |
9.2 Aim and scope
The aim and scope of this standard is to provide assurances that a company has adequate security processes in place to protect data it collects and handles from compromise or exposure from unauthorised parties. SOC 2 covers the following areas:
- Privacy
- Confidentiality
- Processing integrity
- Availability
- Security
10. International Organisation for Standardisation (ISO) 9001
10.1 What is it?
International Organization for Standardization (ISO) 9001 is a globally recognized standard for quality management. It helps organizations of all sizes and sectors to improve their performance, meet customer expectations and demonstrate their commitment to quality. Its requirements define how to establish, implement, maintain, and continually improve a quality management system (QMS).
| Continent/Country of Origin: | Switzerland |
|---|---|
| Geographical Scope: | Global |
| Certification issuing body: | 3rd parties |
| Self-Assessment or Independently assured: | Independently assured by an ISO assured assessor. |
| Use: | Assesses an organisation’s products/services are meeting customer expectations and demonstrates their commitment to quality. |
| Criteria: | Organisations are assessed against 350 requirement criteria split over 8 thematic areas. |
| Validity of assurance and continuous monitoring detail: | 3 years |
| Timeline to undertake: | 3-6 months |
| Applicability of standard to product/service e.g., Mandatory or Voluntary: | Is voluntary for companies/organisations to undertake to prove that they can provide quality and product/service assurance. |
| Website: | https://www.iso.org/standard/62085.html |
10.2 Aim and scope
- Context of the organisation
- Leadership
- Planning
- Support
- Operation
- Performance evaluation
- Improvement
- Annexes
- Structure and Terminology
- Products and Services
- Understanding the needs and expectations of interested parties
- Risk based thinking
- Applicability
- Documented information
- Organisational knowledge
- Control of externally provided processes, products, and services
11. International Organization for Standardization/International Electrotechnical Commission (ISO/IEC) 27001
11.1 What is it?
International Organization for Standardization/International Electrotechnical Commission (ISO/IEC) 27001 is the standard for Information Security Management Systems (ISMS). It defines requirements an ISMS must meet.
The ISO/IEC 27001 standard provides companies of any size and from all sectors of activity with guidance for establishing, implementing, maintaining, and continually improving an information security management system.
Conformity with ISO/IEC 27001 means that an organization or business has put in place a system to manage risks related to the security of data owned or handled by the company, and that this system respects all the best practices and principles enshrined in this International Standard.
| Continent/Country of Origin: | Switzerland |
|---|---|
| Geographical Scope: | Global |
| Certification issuing body: | 3rd parties |
| Self-Assessment or Independently assured: | Independently assured by an ISO assured assessor. |
| Use: | Assesses an organisation on how they handle, process, and protect sensitive information as well as how they deal risk and incidents related to security compromises involving data/information. An organisation can choose the scope of what areas get evaluated e.g. HR, finance etc. |
| Criteria: | Organisations are assessed against 114 requirement criteria split over 8 thematic areas. |
| Validity of assurance and continuous monitoring detail: | 3 years |
| Timeline to undertake: | 3-12 months |
| Applicability of standard to product/service e.g., Mandatory or Voluntary: | Is voluntary for companies/organisations to undertake to prove that they can provide quality and product/service assurance. |
| Website: | https://www.iso.org/standard/27001 |
11.2 Aim and scope
The aim and scope of the standard is for an organisation to adopt and implement an information security management system, that will outline policies, procedures and controls which will govern how an organisation will handle, process, and protect sensitive data/information. This standard does not address GDPR compliance. However, some aspects of the standard will help with becoming compliant. ISO 27001 covers the following areas:
- Context of the organisation
- Leadership
- Planning
- Support
- Operation
- Performance evaluation
- Improvement
- Annexes
- Organisational
- People
- Physical
- Technological
12. National Cyber Security Centre Cyber Assessment Framework (NCSC CAF)
12.1 What is it?
NCSC’s CAF is a cyber security framework that provides guidance for organisations that are responsible for services and activities related to government, UK critical national infrastructure (CNI), Network and Information Systems (NIS) and cyber-related risks to public safety.
| Continent/Country of Origin: | UK |
|---|---|
| Geographical Scope: | UK and UK overseas territories |
| Assurance issuing body: | N/A |
| Self-Assessment or Independently assured: | This is a self-assessment assurance, based off the security principles set out by the framework. |
| Use: | Guidance for organisations to improve/meet an appropriate level of cyber security resilience. |
| Criteria: | The framework provides 14 principles over 4 thematic areas. |
| Validity of assurance and continuous monitoring detail: | N/A |
| Timeline to undertake: | N/A |
| Applicability of standard to product/service e.g., Mandatory or Voluntary: | Voluntary for companies/organisations to follow. |
| Website: | https://www.ncsc.gov.uk/collection/caf |
12.2 Aim and scope
The aim and scope are for an organisation to implement cyber security controls and mitigations to an appropriate level defined by the framework. The framework covers the following areas:
- Managing security risk
- Protecting against cyber attack
- Detecting cyber security events
- Minimising the impact of cyber security incidents
13. Cybersecurity Maturity Model Certification (CMMC)
13.1 What is it?
The Cybersecurity Maturity Model Certification (CMMC) programme is aligned to the US’s Department of Defence’s (DoD) information security requirements for Defence Industrial Base (DIB) partners. It is designed to enforce protection of sensitive unclassified information that is shared by the Department with its contractors and subcontractors. The program provides the Department increased assurance that contractors and subcontractors are meeting the cybersecurity requirements that apply to acquisition programs and systems that process controlled unclassified information.
| Continent/Country of Origin: | US |
|---|---|
| Geographical Scope: | US and US overseas territories |
| Certification issuing body: | DoD |
| Self-Assessment or Independently assured: | CMMC is split into 3 class levels: Class 1, Annual self-assessment, and annual affirmation. Class 2, third-part assessment and annual affirmation. Class 3, Government-led assessment, and annual affirmation. |
| Use: | Provides assurances that contractors and subcontractors are meeting the cybersecurity requirements that apply to acquisition programs and systems that process controlled unclassified information. |
| Criteria: | CMMC is split into 3 different class levels: Class 1, 15 requirements over 6 thematic areas, Class 2, 110 requirements aligned with NIST SP 800-171 over 15 thematic areas, Class 3, 110+ requirements based on NIST SP800-171 and 800-172 over 16 thematic areas. |
| Validity of assurance and continuous monitoring detail: | 3 years |
| Timeline to undertake: | 6-12 months |
| Applicability of standard to product/service e.g., Mandatory or Voluntary: | Is voluntary for companies/organisations to undertake, however it is required of any individual in the DoD supply chain, including contractors who interact exclusively with the DoD and all subcontractors. |
| Website: | https://dodcio.defense.gov/CMMC/About/ |
13.2 Aim and scope
The aim and scope of the programme is to provide assurances that individuals/companies/organisations that have government contracts/subcontracts with the DoD along the supply chain have cyber resiliency and mitigations in place to protect sensitive unclassified information. The programme covers the following areas:
- Access Control
- Asset Management
- Audit and Accountability
- Awareness and Training
- Configuration Management
- Identification and Authentication
- Incident Response
- Maintenance
- Media Protection
- Physical Protection
- Recovery
- Risk Management
- Security Assessment
- Situational Awareness
- System and Communications
- System and Information Integrity
14. Cyber Essentials
14.1 What is it?
NCSC’s Cyber Essentials is a UK Government backed scheme that helps companies/organisations protect their estates against common cyber-attacks. It is designed to get companies/organisations to think and implement basic cyber-security practices.
| Continent/Country of Origin: | UK |
|---|---|
| Geographical Scope: | UK and UK overseas territories |
| Certification issuing body: | IASME Consortium on behalf on NCSC |
| Self-Assessment or Independently assured: | Self-accessed against NCSC Cyber Essentials technical controls. |
| Use: | Provides some assurances that companies/organisations have thought/implemented cyber-security resiliency and mitigations. |
| Criteria: | Companies/organisations are assessed against 5 technical controls. |
| Validity of assurance and continuous monitoring detail: | 1 year |
| Timeline to undertake: | 2 weeks |
| Applicability of standard to product/service e.g., Mandatory or Voluntary: | Is voluntary for companies/organisations to undertake to assure that they follow basic cyber security practices. |
| Website: | https://www.ncsc.gov.uk/cyberessentials/overview |
14.2 Aim and scope
The aim and scope of the scheme is for companies/organisations to implement basic cyber security measures and practices in their networks to protect against common cyber-attacks. The scheme covers the following areas:
- User devices
- Clarification on firmware
- Third-party devices
- Device unlocking
- Malware protection
- Firewalls
15. Cyber Essentials Plus
15.1 What is it?
NCSC’s Cyber Essentials Plus is a UK Government backed scheme that helps companies/organisations protect their estates against common cyber-attacks. It is designed to get companies/organisations to think and implement basic cyber-security practices. Cyber Essentials Plus differs slightly from Cyber Essentials because it has a hands-on technical verification added into the assessment criteria.
| Continent/Country of Origin: | UK |
|---|---|
| Geographical Scope: | UK and UK overseas territories |
| Assurance body: | IASME Consortium on behalf on NCSC |
| Self-Assessment or Independently assured: | Self-accessed against NCSC Cyber Essentials technical controls as well as an independent hands-on technical verification audit. |
| Use: | Provides some assurances that companies/organisations have thought/implemented cyber-security resiliency and mitigations. |
| Criteria: | Companies/organisations are assessed against 5 technical controls, it is recommended that Cyber Essentials has been completely first and then to upgrade to Cyber Essentials plus within 2 months of being issued the certificate. |
| Validity of assurance and continuous monitoring detail: | 1 year |
| Timeline to undertake: | 2-4 weeks |
| Applicability of standard to product/service e.g., Mandatory or Voluntary: | Is voluntary for companies/organisations to undertake to assure that they follow basic cyber security practices. |
| Website: | https://www.ncsc.gov.uk/cyberessentials/overview |
15.2 Aim and scope
The aim and scope of the scheme is for companies/organisations to implement basic cyber security measures and practices in their networks to protect against common cyber-attacks. The scheme covers the following areas:
- User devices
- Clarification on firmware
- Third-party devices
- Device unlocking
- Malware protection
- Firewalls
Disclaimer
This guide has been prepared by NPSA and is intended to provide readers with an overview of some of the most popular cyber security standards and frameworks. This document is provided on an information basis only, and whilst NPSA has used all reasonable care in producing it, NPSA provides no warranty as to its accuracy or completeness.
To the fullest extent permitted by law, NPSA accepts no liability whatsoever for any expense, liability, loss, damage, claim or proceedings incurred or arising as a result of any error or omission in the guidance or arising from any person acting, refraining from acting, relying upon or otherwise using the guidance. You should make your own judgment with regard to the use of this document and seek independent professional advice on your particular circumstances.
Freedom of Information Act (FOIA)
This information is supplied in confidence and may not be disclosed other than to the agreed readership, without prior reference to NPSA. Within the UK, this material is exempt from disclosure under the relevant Freedom of Information Acts and may be subject to exemption under the Environmental Information Regulations and the Data Protection Act 2018.
© Crown Copyright 2026