Microsoft Teams

UK · Cyber Essentials & Cyber Essentials Plus

Cyber Essentials readiness, evidenced from the Microsoft 365 tenant you already run.

Cyber Essentials covers five control themes, and four of them — secure configuration, security update management, user access control, and malware protection — are exactly the kind of thing we already read live from Entra ID, Intune and Defender for Essential Eight and ISO 27001. We don't start you from a blank questionnaire.

  • 4 of 5 themes automated
  • Basic & Plus
  • Fixed price
  • Your choice of licensed body
Book a Scoping Call Compare to Essential Eight

Why this is different from the usual options

Most Cyber Essentials paths are one of two extremes: a generic questionnaire you fill in yourself against a checklist, or an all-in-one vendor who is both your certification body and your automation, so you're locked into their process end to end. Neither matches how most Microsoft 365 shops already work.

Vanta and Drata can't actually certify this

Neither is IASME-licensed, so neither can issue a UK Cyber Essentials certificate — however good their dashboards look. If Cyber Essentials is the actual goal, that's a real gap, not a feature comparison.

The IASME-licensed bodies bundle everything

Firms like CyberSmart and Fig Group are licensed to certify and also automate — which is convenient, but it means your evidence, your monitoring and your certificate all live with one vendor.

We reuse infrastructure you already have

The same Microsoft Graph checks that already evidence your Essential Eight or ISO 27001 posture cover most of Cyber Essentials' technical controls too — so readiness starts from what's already true in your tenant, not a fresh audit.

What the five control themes actually need

Secure configuration

Default accounts and passwords removed, unnecessary software and services disabled, device and account settings hardened. Read from your existing Entra ID and Intune configuration.

Security update management

Devices and software kept licensed, supported, and patched within vendor-recommended timeframes. The same patch-latency check we already run for Essential Eight applies directly here.

User access control

Account creation processes, admin account discipline, and multi-factor authentication. Evidenced from Conditional Access, Privileged Identity Management and admin role assignments.

Malware protection

Anti-malware software or application allow-listing — Cyber Essentials accepts either approach. If you're already running application control for Essential Eight, that evidence carries across.

Firewalls — the one we can't automate

Boundary firewall and internet gateway configuration sits outside what a Microsoft 365 tenant can see. We guide you through this control directly rather than pretending it's automated when it isn't.

Basic vs Plus

Cyber Essentials Basic is self-assessed and verified by your chosen Certification Body. Cyber Essentials Plus adds independent technical testing of your systems. We prepare you for either — Plus needs the same evidence, verified externally.

Common questions

Do you issue the Cyber Essentials certificate?

No — Cyber Essentials certificates can only be issued by an IASME-licensed Certification Body. We prepare your evidence and self-assessment answers; you submit through a licensed body of your choice, the same way we handle ISO 27001 certification through JASANZ-accredited bodies.

How is this different from CyberSmart or Fig Group?

They're IASME-licensed bodies who also automate — a convenient single vendor, but your evidence lives inside their platform. We work from your own Microsoft 365 tenant using infrastructure you already have, and you keep the flexibility to choose which licensed body actually certifies you.

We're already Essential Eight or ISO 27001 aligned — does that help?

Significantly. Essential Eight's application control, patching and MFA controls overlap heavily with Cyber Essentials' technical themes, and ISO 27001's Annex A controls cover the governance side. Most of the readiness work is mapping evidence you already have, not creating new controls.

Related

Essential Eight The closest Australian equivalent ISO 27001 Now serving Australia, US and UK Free Essential Eight Checklist Score your maturity in 15 minutes

Considering Cyber Essentials for your UK customers or supply chain?

A 30-minute scoping call tells us how much of your evidence already exists — and how fast you could be ready.

Book a Scoping Call

Free monthly digest

Get the monthly Australian compliance digest

Practical updates on ISO 27001, Essential Eight, Privacy Act and AI governance — delivered once a month. No spam, unsubscribe any time.

No spam. Unsubscribe any time. We never share your email.