UK Cyber Essentials
The UK government-backed certification scheme for five foundational technical controls. Cyber Essentials is questionnaire-based; Cyber Essentials Plus adds independent technical verification. Tracking the requirements does not claim either certificate.
Requirements for IT infrastructure v3.3 · UK National Cyber Security Centre · published 2026-04-27
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
UK Cyber Essentials is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
NCSC publishes the technical requirements under UK Crown copyright. Pin the v3.3 requirements and applicable reuse terms before normalization.
02Registry record
- Registry status
- Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
- Control units
- 5Five technical control themes in Cyber Essentials v3.3. This is not a count of individual assessment questions or test procedures.
- Control families
- Firewalls · Secure configuration · Security update management · User access control · Malware protection
- Applies to
- all sectors · government suppliers · small and medium businesses · UK
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-08-30
03Version ledger
| Requirements for IT infrastructure v3.2 | Superseded | 2025-04-28 |
| Requirements for IT infrastructure v3.3 | Current edition · supersedes Requirements for IT infrastructure v3.2 | 2026-04-27 |
05Change history
06Related frameworks
- ASD Essential EightMaturity Model (November 2023)
Also applies to all sectors · The Australian Signals Directorate's prioritized baseline of eight cyber mitigations, implemented through maturity levels zero to three. Independent assessment may be required by policy or contract, but the model is not a universal certification scheme.
- OSCAL1.2.2
Also applies to all sectors · NIST's machine-readable format for control catalogs, baselines, system security plans, and assessment results. An interchange layer, not a regime you comply with.
- HITRUST CSFv11.8.0
Same framework family · A licensed cybersecurity and risk-management framework used across healthcare and other sectors. HITRUST offers scoped assessment and certification programs through its authorized processes; registry tracking claims no certification.
Same framework family · PCI SSC's security requirements for 3-D Secure environments (issuer/ACS, 3DS Server, and DS components) that support cardholder authentication.