Cyber Essentials (NCSC / IASME)
Cyber Essentials, half-written before you start
The UK government-backed Cyber Essentials scheme (NCSC / IASME). The five technical control themes — firewalls and routers, secure configuration, security update management, user access control and malware protection — expanded into 83 self-assessment requirements across the full IASME question set, with a 57-question audit bank and an AI readiness analyser that verdicts each requirement with citations.
5
control themes
83
SAQ requirements
57
audit questions
- The five controls
- The full IASME question set
- AI gap analysis
- Often the first step
What’s in the module
The full IASME self-assessment, instantiated
82 requirements seeded as controls when you enable Cyber Essentials — the same model as ISO 27001 Annex A — each linked to the question it answers.
- 01
The five controls
Firewalls & routers, secure configuration, security update management, user access control and malware protection — the scheme’s five technical themes, modelled in full.
- 02
The full IASME question set
Organisation, scope of assessment, insurance and the technical controls — 82 requirements instantiated per workspace as controls, exactly like ISO 27001 Annex A.
- 03
AI gap analysis
The readiness analyser verdicts each requirement ready, partial or gap with cited evidence and keeps snapshots — so the self-assessment is half-written before you start.
- 04
Often the first step
Cyber Essentials is where many UK SMEs begin. It shares the evidence store and process map with your ISO 27001 and SOC 2 work, so nothing is gathered twice.
The five controls
Five technical themes, modelled in full
Cyber Essentials is built on five control themes. The module maps each one to the IASME question set so the self-assessment and the internal-audit wizard line up with what the assessor actually asks.
- Firewalls and routers
- Secure configuration
- Security update management (patching)
- User access control
- Malware protection
AI gap analysis on every requirement
The readiness analyser verdicts each of the 82 requirements as ready, partial or gap — with the cited evidence behind the verdict — and keeps snapshots, so the self-assessment is mostly drafted before you sit down to complete it.
Often the first step
Cyber Essentials is where many UK SMEs begin. Because it shares the evidence store and process map with your ISO 27001 and SOC 2 work, the controls you put in place here carry straight into the bigger frameworks — nothing is gathered twice.
Ready for the next step?
The hygiene Cyber Essentials proves is the foundation ISO 27001 and SOC 2 build on — and your evidence is already in one place to take you there.
See Cyber Essentials on your scope
A walkthrough of the five controls, the IASME question set and the AI readiness analyser on your workspace.