What is Cyber Essentials v3.3?
The UK's baseline cyber security certification scheme, run by the NCSC and delivered through IASME. It defines five technical control themes and a scope boundary, and certifies against them: Cyber Essentials is a self-assessment verified by a Certification Body, and Cyber Essentials Plus adds a hands-on technical audit of the same controls.
Nobody by general law — but it is mandatory for suppliers bidding on many UK central government contracts handling sensitive or personal information, and it is increasingly a condition of cyber insurance and of enterprise supplier onboarding. For a UK SME selling to the public sector it is effectively the entry ticket.
Firewalls, Secure Configuration, Security Update Management, User Access Control, Malware protection.
For anything the vendor calls critical or high risk, anything at CVSS v3 7.0 or above, and anything where the vendor gives no severity at all.
Or 8 characters with automatic blocking of common passwords from a deny list, or multi-factor authentication. One of the three, by technical control.
Dates that matter
- April 2026The current requirements document, v3.3.
- AnnualCertification lasts twelve months; there is no multi-year cycle as there is with ISO 27001.
What people get wrong
It is pass or fail, and the numbers are where people fail
Unlike a maturity framework there is no partial credit. The requirements carry specific thresholds — updates within 14 days, no more than 10 password guesses in 5 minutes, a 12-character minimum — and the 14-day update window is the one most applications come unstuck on. Our questionnaire asks each of those thresholds at the scheme's own figure rather than in general terms, so answering honestly tells you where you stand. Where a requirement is one we cannot establish, this page names it rather than showing a theme as green.
v3.3 closed the cloud loophole
The April 2026 edition states definitively that cloud services cannot be excluded from scope. If your data or services are hosted on IaaS, PaaS or SaaS, those services are in scope — and the applicant organisation is always responsible for the controls even where the provider implements them, which you must evidence through contractual clauses or referenced documents such as a trust-centre security statement. It also brought FIDO2 into the definition of passwordless authentication.
Scope is where applications get bounced
A scope that does not include end-user devices is not acceptable. Staff-owned devices accessing organisational data are in scope, except where used only for native voice, native text or MFA. Home routers are out of scope, which does not remove the firewall requirement — it moves it onto the user device as a software firewall. Accounts your organisation owns are in scope even when a Managed Service Provider uses them.
Two requirements catch people going the wrong way
Cyber Essentials requires that you do NOT enforce regular password expiry and do NOT enforce complexity requirements. An organisation forcing a 90-day change and a special character is failing the scheme while doing what it believes is good practice — and that would read as strong on most questionnaires, including ours.
What Vivid Risk does with Cyber Essentials v3.3
A coverage view against the NCSC's own five technical control themes, from the published v3.3 requirements document — including the requirements our questionnaire does not reach, listed in full.
Indicative only. Cyber Essentials sets hard numbers where most frameworks set outcomes, and our questions now carry them — the 14-day update window, the 12-character password bar, the ten guesses in five minutes, the six-character device PIN. That is still not the same as passing: these are your own answers about your own estate, nothing here is tested, and a question asked at the right bar can be answered wrongly. Where the scheme sets a threshold and no question of ours reaches it, the page names the requirement rather than netting it away. Certification is awarded by a Certification Body, and Cyber Essentials Plus adds a hands-on audit; we are neither.
Cyber Essentials is certified by a Certification Body, and Cyber Essentials Plus adds a hands-on technical audit. Vivid Risk is neither. This shows which of your assessment answers speak to each of the five technical control themes, so you can see where you stand before you apply. It is not a pass, a pre-assessment or a gap analysis against the scheme's own thresholds — several of those thresholds are numbers our questionnaire does not ask about, and they are listed in full below.
The five themes, and what we do not ask
Vivid Risk has questions that speak to 5 of the 5 themes and to all 30 individual requirements, at the scheme's own thresholds rather than in general terms. None of this is the same as passing. Certification is a Certification Body reading your evidence, and Cyber Essentials Plus is an assessor testing the controls by hand on a sample of your devices. What this gives you is a view of where you stand before you apply.
1. Firewalls
7 scored questions · 7 requirementsTo make sure that only secure and necessary network services can be accessed from the internet.
2. Secure Configuration
8 scored questions · 7 requirementsEnsure that computers and network devices are properly configured to reduce vulnerabilities and provide only the services required to fulfil their role.
3. Security Update Management
7 scored questions · 4 requirementsEnsure that devices and software are not vulnerable to known security issues for which fixes are available.
4. User Access Control
13 scored questions · 9 requirementsEnsure that user accounts are assigned to authorised individuals only, and provide access to only those applications, computers and networks that the user needs to carry out their role.
5. Malware protection
3 scored questions · 3 requirementsTo restrict execution of known malware and untrusted software, from causing damage or accessing data.
Questions
Does Vivid Risk certify me to Cyber Essentials?
No, and no software can. Certification is awarded by a Certification Body through IASME, and Cyber Essentials Plus adds a hands-on technical audit. What you get here is a view of which of your assessment answers speak to each of the five themes, and — more usefully — which of the scheme's requirements our questions cannot establish for you.
Why does the page list requirements you do not cover?
Because a theme shown as covered without that context would be misleading. Cyber Essentials sets hard numbers and our questionnaire asks posture-level questions, so the page separates two different gaps: requirements nothing here asks about at all, and requirements we ask about at a lower bar than the scheme sets. The first needs a new question from us; the second means our question cannot establish the requirement however you answer it, so go and check the setting yourself. Both counts are computed from the mapping, not written down.
Is Cyber Essentials the same as the NCSC CAF?
No, and they serve different organisations. Cyber Essentials is a baseline certification with five technical controls, aimed at any organisation and mandatory for many UK government suppliers. The Cyber Assessment Framework is an outcome-based framework for operators of essential services under the NIS Regulations 2018, with 14 principles and 41 contributing outcomes. Vivid Risk cites CAF on every scored control; Cyber Essentials is the indicative view on this page.
One assessment, every framework
The same answers produce your citations across every framework we cover at once, rather than one questionnaire per regulation.