Skip to main content
Framework library
Framework module · uk-cyber-essentials-v3-3

UK Cyber Essentials

The UK government-backed certification scheme for five foundational technical controls. Cyber Essentials is questionnaire-based; Cyber Essentials Plus adds independent technical verification. Tracking the requirements does not claim either certificate.

Requirements for IT infrastructure v3.3 · UK National Cyber Security Centre · published 2026-04-27

Standing today
Directory entry

00Answer

from the registry record
What is UK Cyber Essentials?
The UK government-backed certification scheme for five foundational technical controls. Cyber Essentials is questionnaire-based; Cyber Essentials Plus adds independent technical verification. Tracking the requirements does not claim either certificate.
Who does UK Cyber Essentials apply to?
UK Cyber Essentials applies to all sectors, government suppliers, small and medium businesses, UK, per UK National Cyber Security Centre.
What is the current version of UK Cyber Essentials?
The current edition is Requirements for IT infrastructure v3.3, issued by UK National Cyber Security Centre and published 2026-04-27. Source: https://www.ncsc.gov.uk/cyberessentials/resources.
What does an assessment under UK Cyber Essentials require?
5 control units are on record (Five technical control themes in Cyber Essentials v3.3. This is not a count of individual assessment questions or test procedures.), organized into 5 control families: Firewalls, Secure configuration, Security update management, User access control, Malware protection.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

UK Cyber Essentials is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

NCSC publishes the technical requirements under UK Crown copyright. Pin the v3.3 requirements and applicable reuse terms before normalization.

02Registry record

checked 2026-08-30
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
5Five technical control themes in Cyber Essentials v3.3. This is not a count of individual assessment questions or test procedures.
Control families
Firewalls · Secure configuration · Security update management · User access control · Malware protection
Applies to
all sectors · government suppliers · small and medium businesses · UK
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-08-30

03Version ledger

2 editions
Requirements for IT infrastructure v3.2Superseded2025-04-28
Requirements for IT infrastructure v3.3Current edition · supersedes Requirements for IT infrastructure v3.22026-04-27

05Change history

06Related frameworks

scored from registry facts
  1. ASD Essential EightMaturity Model (November 2023)

    Also applies to all sectors · The Australian Signals Directorate's prioritized baseline of eight cyber mitigations, implemented through maturity levels zero to three. Independent assessment may be required by policy or contract, but the model is not a universal certification scheme.

  2. OSCAL1.2.2

    Also applies to all sectors · NIST's machine-readable format for control catalogs, baselines, system security plans, and assessment results. An interchange layer, not a regime you comply with.

  3. Same framework family · A licensed cybersecurity and risk-management framework used across healthcare and other sectors. HITRUST offers scoped assessment and certification programs through its authorized processes; registry tracking claims no certification.

  4. Same framework family · PCI SSC's security requirements for 3-D Secure environments (issuer/ACS, 3DS Server, and DS components) that support cardholder authentication.

UK Cyber Essentials | ControlFrame